Privacy Policy
We built Crolyo to be lightweight — and our privacy stance matches: we collect what we need to deliver the chat widget, and nothing more. Here's exactly what that looks like.
On this page
Introduction
We built Crolyo to be lightweight — and our privacy stance matches: we collect what we need to deliver the chat widget, and nothing more.
This Privacy Policy explains how Crolyo (“Crolyo”, “we”, “us”, or “our”) collects, uses, discloses, and protects information in connection with your use of our website, dashboard, and embeddable chat widget (collectively, the “Service”). By accessing or using the Service, you agree to the terms of this Privacy Policy.
Data controller. For the purpose of applicable data protection laws, Crolyo is the data controller of personal data collected through the Service.
Information We Collect
Here's exactly what we touch and why — split into two groups: what you give us as a site owner, and what we receive from visitors who use the chat widget on your site.
From site owners (you):
- Account information. When you sign in, we receive your email address and any name or avatar provided by your authentication provider (currently magic-link email and Supabase Auth).
- Workspace configuration.The name you give each site, your Slack workspace ID, the encrypted Slack bot token, the Slack channel ID where chats are routed, the widget's primary color and welcome message, and the list of allowed domains that may embed the widget.
- Support correspondence. Anything you send us when you contact support.
From visitors (your end users):
- Chat content. The text messages a visitor sends through the widget on your site, plus the message timestamps and a persistent visitor identifier (an anonymous cookie or browser-fingerprint ID) that ties their messages into a single conversation.
- Slack thread reference.The Slack thread timestamp (“thread_ts”) for the visitor's conversation, used to route agent replies back to the right visitor in real time.
We do not intentionally collect special categories of personal data (such as government identifiers, financial information, or health data) through the widget. If a visitor types sensitive information into a chat message, that information is stored as ordinary message content.
How We Use Your Information
We use the information we collect for one reason: to deliver the Service. Specifically, we use it to:
- Authenticate you and operate your Crolyo dashboard.
- Forward visitor messages from your embedded widget to the configured Slack channel.
- Receive agent replies from Slack and deliver them back to the right visitor in real time via Supabase Realtime.
- Enforce the allowed-domains list you configure, to prevent unauthorized sites from embedding your widget.
- Detect, prevent, and respond to abuse, security incidents, and fraud.
- Communicate with you about the Service, including security and policy notices.
We do not sell personal data, and we do not use visitor chat content to train machine-learning models.
Data Storage and Security
Your bot tokens are encrypted, webhook requests are signed, and your domains are whitelisted. We treat these as table stakes, not extras.
Where your data lives.Persistent data is stored in a managed PostgreSQL database provided by Supabase. The application runs on Vercel's hosting platform; static assets (including the embeddable widget at /widget.js) are served from Vercel's edge CDN. Slack bot tokens, conversation records, and message bodies are stored in the Supabase database.
Encryption. Slack bot tokens are encrypted at rest in the database. Data is transmitted over HTTPS/TLS between your browser, our application, Supabase, and Slack.
Slack signature verification. Every request Slack sends to our webhook endpoint at /slack/events is verified against the X-Slack-Signatureheader using Slack's signing secret. Requests that fail verification are rejected.
Domain allow-list. Widget configuration and conversation creation requests are checked against the allowed_domains list you set for each site. Requests originating from domains not on the list are refused.
No system is perfectly secure. We work hard to protect your data, but we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify you in accordance with applicable law.
Third-Party Services
We lean on a small handful of trusted vendors to run the Service. Each one processes data on our behalf under their own terms and privacy practices.
- Supabase— PostgreSQL hosting, auth, and real-time WebSocket delivery. Supabase acts as a sub-processor for data you store in your Crolyo workspace.
- Vercel— application hosting and edge CDN for the embeddable widget.
- Slack— delivery of visitor messages to your channel and receipt of agent replies via the Slack Events API and Web API. Slack processes conversation content as a sub-processor and on its own terms.
Where required, we enter into data-processing agreements with our sub-processors to ensure your data is handled consistently with this Privacy Policy.
Your Rights
You can access, export, or delete your data anytime — just ask. Depending on where you live, you may also have additional rights under applicable law.
- Access. Request a copy of the personal data we hold about you.
- Correction. Ask us to correct inaccurate or incomplete data.
- Deletion. Ask us to delete your personal data, subject to our legal record-keeping obligations.
- Export. Receive your data in a portable, machine-readable format.
- Objection and restriction. Object to, or request that we restrict, certain processing of your personal data.
To exercise any of these rights, contact us at support@crolyo.com. We will respond within the timeframes required by applicable law.
Children's Privacy
Crolyo isn't for kids. The Service is not directed to children under the age of 13 (or such higher age as required by local law), and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete the information.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. If the changes are material, we will give you reasonable notice — for example, by emailing account holders or posting a prominent notice in the dashboard — before the changes take effect.
Your continued use of the Service after the effective date of the updated Policy constitutes acceptance of the changes.
Contact
Questions? Just ask. The fastest way to reach us is by email at support@crolyo.com.