Trust & Security
Jump to a section
Last updated: September 2026
Crewnum runs trivia about your own team, so we hold a small amount of personal information about your colleagues. This page says how it's protected. Anything it doesn't answer: ask us through the contact form.
Four commitments
- We never sell personal data or share it for advertising. There are no trackers and no ad networks.
- We never use customer data to train AI models.
- Every member can view, export and delete their own data self-serve — no ticket, no admin. Both actions live on each member's own facts page.
- We never run face recognition or any other biometric processing on member photos, video or audio, and we never will. No biometric identifiers or templates are extracted from member media, by us or by any subprocessor we use.
No passwords, by design
There are no passwords anywhere. All access is by signed, expiring links sent to work email — no password database to steal, nothing to reuse across sites, nothing to phish. Links are HMAC-signed server-side; an admin can invalidate a member's links instantly, and rotating our signing key invalidates every outstanding link at once.
Who's responsible for what
Your organisation is the data controller; Crewnum is the processor, acting on your instructions. Members are told who will see a fact before they write it and keep a personal off-switch for sharing beyond their team. Employees hand over nothing beyond a name and work email.
Where data lives
The app and database run on Cloudflare's network, placement managed by Cloudflare. Uploaded photos, video and audio are stored in Cloudflare R2 (object storage) with a location hint for Cloudflare's Oceania region — best-effort placement, not a residency guarantee. The one server-side media-processing fallback runs in Oracle Cloud's Melbourne, Australia region, reachable only over a private tunnel, with files deleted immediately after processing. We're an Australian service and don't offer per-customer data-residency guarantees.
Retention: short on purpose
Quiz question content is purged 30 days after use, automatically, with no archive. Deleted members cascade: facts, media and scores go together. We keep no message-level delivery log — only daily aggregate counts plus expiring rate-limit counters. We hold little, and briefly.
Support tickets get a longer window: closed tickets, including the raw inbound email, are purged 365 days after closing. If a team's bill goes unpaid, nothing is deleted right away — see billing and payment failure in the Terms of Service for the 180-day clock and what happens at the end of it.
Payments
Stripe processes all payments. Card details go straight to Stripe and never touch our servers (PCI DSS SAQ-A). Adding members never charges a card — only buying seats does.
Subprocessors
The only third parties that handle personal data on our behalf:
- Cloudflare — hosting, database, media storage, inbound email routing to our support mailbox, and Turnstile bot verification on the contact form.
- Resend — outbound email, including our operational alerts.
- Stripe — payments and billing.
- Oracle Cloud (Melbourne, Australia) — media-processing fallback only; files deleted after processing.
If something goes wrong
We keep a written incident-response plan with per-jurisdiction notification timelines, including the Australian Notifiable Data Breaches scheme and GDPR's 72-hour window. If a breach affects your team's data, we notify you in line with those timelines — what happened, which data, what we did, and what you need to do.
Certifications
No SOC 2 attestation yet. Everything we do instead is written down here, in the privacy policy, in the terms of service, and in the subprocessor list above. Send a security questionnaire through the support form.