Skip to content
craze_

Privacy Policy

Last updated 3 September 2026

The short version

We collect two kinds of data: the account information you give us so you can sign in, and the research data you create by building populations and running simulations. We do not sell either. We do not use your research data to train models that other customers benefit from unless you explicitly turn that on.

Respondents whose interviews ground our panels are a third category, and they are the group with the most at stake. Their protections are described below and they take precedence over any customer's convenience.

Account data

When you create an account we store your email address and, if you sign in with Google, the account identifier Google returns. Passwords are never stored in a readable form. Authentication is handled by Supabase; their processing of that data is governed by their own terms.

We keep account data for as long as the account exists, and delete it within thirty days of the account being closed.

Research data

Populations you define, simulations you run, and the transcripts they produce belong to you. They are visible to members of your workspace and to nobody else.

You can export everything at any time from Settings, and you can delete individual runs or the entire workspace. Deletion is permanent and we cannot recover it for you.

Two optional settings change this. Turning on alignment improvement lets us use your run outcomes to measure and improve population accuracy. Turning on sector research sharing lets us include anonymised, aggregated findings in research we publish openly. Both are off unless you switch them on, and turning them off stops future use.

Panel respondents

Our populations are grounded in interviews with real people who agreed to take part and were paid for their time. Respondents are told what their answers are used for before they answer.

College respondents are verified on a live school account, one person per account. Respondents under sixteen are only reached through a verified guardian, who sees the questions before the session and can end it at any point.

Respondent identities are never exposed to customers. The digital twins you interact with carry behavioural signals, not names, contact details or anything that would identify the person a twin was grounded in.

Cookies

We set one cookie, which keeps you signed in. There is no advertising cookie, no cross-site tracking and no third-party analytics on the application.

Sub-processors

We use Supabase for authentication and data storage, and Vercel for hosting. Both process data on our instructions. We will update this page before adding a sub-processor that handles customer or respondent data.

Your rights

Depending on where you live you may have the right to access, correct, export or delete the personal data we hold about you, and to object to certain processing. Settings covers export and deletion directly. For anything else, write to privacy@craze.com and we will respond within thirty days.

Changes

If we change this policy in a way that materially affects how your data is handled, we will tell you by email before the change takes effect rather than quietly updating this page.

This is demonstration copy for a product that is not yet operating. It is not legal advice and has not been reviewed by counsel. Replace it before collecting real data from real people.