Controller and contact
Crene, Inc. is a Delaware corporation with its principal place of business in California. Where Crene determines the purposes and means of processing personal data described in this policy, Crene acts as the controller or business responsible for that processing under applicable data protection law.
Privacy contact: support@crene.com.
Where applicable law requires Crene to appoint a representative in the European Economic Area or the United Kingdom, Crene will make the representative's contact details available in this policy or otherwise provide them to affected data subjects.
What we collect
Crene primarily serves institutional and professional users. The categories below describe personal data that may be collected from visitors, prospective customers, account users, private review participants, and people who contact Crene.
- Inquiry and lead data. Name, business email, company, role or title, and information submitted when requesting a private review, product information, data access, or support.
- Account data. Business email, credential and authentication information, display name, permissions, and account preferences.
- Workspace and review data. Content and metadata submitted to private workspaces or review workflows, including thesis questions, assumptions, comments, decisions, and related records. Users should avoid including unnecessary personal or sensitive information in investment content.
- API and access data. Where an API or other authenticated interface is used, identifiers, request metadata, timestamps, response codes, and operational information used for security, reliability, rate limiting, and abuse prevention.
- Technical and session data. IP address, user agent, browser or device characteristics, referring URL, timestamps, and similar operational information.
- Analytics and diagnostic data. Aggregate or pseudonymous usage information such as page views, session duration, click or scroll behavior, and similar interaction data. Crene may use analytics or diagnostic providers, including Google Analytics and Microsoft Clarity, where enabled.
- Cookies and similar technologies. Session, security, locale, preference, analytics, and similar browser identifiers used according to their purpose and applicable consent requirements.
- Communications. Emails, support requests, procurement correspondence, and other communications sent to Crene.
Crene does not ask users to submit special category or highly sensitive personal data through ordinary product, review, or support workflows. Users should not include such information unless it is necessary and Crene has expressly agreed to receive it.
How we use personal data
Crene uses personal data for the following purposes:
- Operating accounts, private review workflows, public and private product surfaces, and any contracted data or API access.
- Responding to private review requests, product inquiries, support requests, procurement, legal, privacy, and security communications.
- Authenticating users, administering permissions, maintaining service reliability, and preventing fraud, abuse, and unauthorized access.
- Understanding aggregate product usage, diagnosing product issues, and improving Crene's public and private interfaces.
- Sending necessary service communications and, where permitted, product or commercial communications requested by the recipient.
- Complying with legal obligations, resolving disputes, enforcing agreements, and protecting the rights and security of Crene, its users, and others.
Crene does not sell personal data. In normal product operation, Crene does not intentionally include customer personal data in the investment questions and structured market context sent to third-party model providers for analytical generation.
Legal bases (GDPR and UK GDPR)
Where the GDPR or UK GDPR applies, Crene relies on one or more lawful bases depending on the processing activity:
- Performance of a contract. Processing necessary to provide an account, private review workflow, contracted data service, or other service requested by the user or customer.
- Legitimate interests. Security, abuse prevention, service reliability, business administration, product improvement, and other legitimate operational purposes where those interests are not overridden by the rights and freedoms of the data subject.
- Consent. Processing based on consent where applicable, including certain non-essential analytics technologies or communications where consent is required by law.
- Legal obligation. Processing necessary to comply with applicable legal, regulatory, tax, accounting, or similar obligations.
Recipients and processors
Crene may disclose personal data to the following categories of recipients where necessary for the purposes described in this policy:
- Infrastructure and hosting providers. Providers used to host, secure, store, monitor, and deliver the platform and related services.
- Analytics and diagnostic providers. Providers used to understand aggregate product usage and diagnose performance or usability issues.
- Email and communications providers. Providers used for transactional email, support, and other necessary communications.
- Third-party AI and model providers. Providers used to generate analytical outputs. In normal model querying, Crene is designed to provide investment questions and structured market context rather than customer personal data.
- Professional advisers. Accountants, auditors, insurers, and legal advisers subject to appropriate confidentiality obligations.
- Authorities and transaction counterparties. Government or regulatory authorities where disclosure is legally required, and potential successors or transaction counterparties in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and data protection obligations.
Crene does not sell personal data and does not disclose personal data to advertising networks for cross-context behavioral advertising.
International transfers
Crene operates from the United States and may use service providers located in the United States or other jurisdictions. As a result, personal data may be transferred to and processed outside the country where the data subject is located.
Where applicable data protection law requires a transfer mechanism or additional safeguard, Crene uses an appropriate lawful mechanism for the relevant transfer. Depending on the circumstances, this may include an adequacy decision, Standard Contractual Clauses approved by the European Commission, a United Kingdom transfer mechanism, contractual safeguards, or another mechanism permitted by applicable law.
For information about the transfer mechanism applicable to a particular processing activity, contact support@crene.com.
Retention
Crene retains personal data only for as long as reasonably necessary for the purposes described in this policy, including providing the service, maintaining security, meeting contractual commitments, resolving disputes, and complying with legal obligations.
- Inquiry and lead data: generally up to 24 months after the last substantive contact unless the relationship becomes active or a longer period is reasonably necessary.
- Account data: generally for the duration of the account and for a limited period afterward for security, legal, and recordkeeping purposes.
- Workspace and review data: according to the relevant account, engagement, contractual terms, product lifecycle, backup practices, and applicable legal or recordkeeping requirements.
- Operational and API logs: for the period reasonably necessary for security, reliability, abuse prevention, and investigation.
- Analytics and diagnostic data: according to Crene's configured provider settings and the purposes for which the data is collected.
- Communications and support records: for the period reasonably necessary to manage the relationship, maintain business records, and resolve disputes.
Specific records may be retained for longer where required by law, necessary to establish or defend legal claims, or reasonably required to preserve security and audit records.
Your rights (GDPR and UK GDPR)
If you are a data subject in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights, subject to applicable conditions and exceptions:
- Right of access to your personal data and information about how it is processed.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure (right to be forgotten) where applicable.
- Right to restriction of processing under specified conditions.
- Right to data portability for data processed on the basis of contract or consent and by automated means.
- Right to object to processing based on legitimate interests, including profiling.
- Right to withdraw consent at any time for processing based on consent, without affecting the lawfulness of prior processing.
- Right to lodge a complaint with your local supervisory authority (for example, the Information Commissioner's Office in the United Kingdom or your national Data Protection Authority in the EEA).
To exercise these rights, email support@crene.com. We respond within one month, extendable by two months for complex requests as permitted by GDPR Article 12(3).
California rights (CCPA / CPRA)
To the extent the California Consumer Privacy Act, as amended, applies to Crene and to your personal information, California residents may have rights including:
- The right to know the categories and specific pieces of personal information collected, the sources, purposes, and categories of recipients.
- The right to request deletion of personal information, subject to applicable exceptions.
- The right to request correction of inaccurate personal information.
- The right to opt out of the sale or sharing of personal information where applicable. Crene does not sell personal information or share it for cross-context behavioral advertising.
- The right to limit certain uses or disclosures of sensitive personal information where the statutory right applies.
- The right not to receive discriminatory treatment for exercising applicable privacy rights.
To make a California privacy request, email support@crene.com with "California Privacy Request" in the subject line. Crene may take reasonable steps to verify the identity or authority of the person making the request before responding.
Even where a particular statutory privacy right does not apply, Crene may choose to honor a comparable request where doing so is reasonable, lawful, and technically feasible.
Cookies and similar technologies
Crene may use cookies and similar browser technologies for the following purposes:
- Strictly necessary. Authentication, session state, security, fraud prevention, locale, and other functions required to provide the service.
- Analytics and diagnostics. Understanding aggregate usage, product performance, and interaction patterns, including through analytics or diagnostic providers where enabled.
- Preferences. Remembering settings or choices that are not strictly necessary to operate the service.
Non-essential cookies and similar technologies are used subject to applicable consent and notice requirements. Browser settings may also allow users to block, delete, or limit cookies, although doing so may affect some product functionality.
Security
Crene uses technical and organizational measures designed to protect personal data in a manner appropriate to the nature of the processing and the associated risk. Measures may include encryption in transit, access controls, least-privilege practices, structured logging, monitoring, backups, and incident response procedures.
No system can be guaranteed to be completely secure. Where applicable law requires notification of a personal data breach, Crene will provide notice to affected individuals, regulators, or other parties in accordance with the applicable requirements.
Automated decision-making
Crene does not use personal data to make decisions that produce legal effects on individuals or similarly significantly affect them within the meaning of GDPR Article 22. The probability forecasts Crene produces concern macroeconomic, market, and policy events; they are not individual scoring decisions.
Children
The service is intended for use by businesses and adults in a professional capacity. The service is not directed to children, and Crene does not knowingly collect personal data from individuals under 16. If you believe a child has provided personal data, contact support@crene.com and we will delete it.
Changes to this policy
Crene may revise this policy. Material changes will be posted on this page with an updated date, and where required by law we will provide additional notice. Continued use of the service after a revision constitutes acknowledgement of the changes.
Contact
Crene, Inc.
Delaware corporation, principal place of business in California.
Privacy email: support@crene.com
See also the Terms of Service.