1. Who we are
Crash Labs (“we”, “us”) operates https://crashlabs.app. The operator is Jeroen Huitema (trading as Crash Labs), based in Netherlands. For privacy requests contact jeroenhuitema2000@gmail.com.
If you are in the EEA/UK, we act as controller of personal data processed through the Service. This policy is written to help you understand our practices under the GDPR and similar laws; it is not legal advice.
2. Data we collect
- Account data: email address, password (hashed by our auth provider), optional display name, plan, and credit balance.
- Workflow & analysis data: n8n workflow JSON you upload, analysis reports, findings, share tokens, and related metadata.
- Billing data: purchase metadata and Stripe session/subscription identifiers. Card details are processed by Stripe; we do not store full card numbers.
- API keys: hashed CI API keys and usage timestamps (Pro).
- Technical data: IP address and request metadata used for rate limiting and abuse prevention; authentication cookies/session tokens.
Do not upload secrets, production credentials, or personal data of third parties that you are not allowed to process. Workflow JSON may contain sensitive content you paste in.
3. Why we process data (legal bases)
- Contract: create your account, run analyses, save reports, provide credits, and support the Service.
- Legitimate interests: security, fraud and abuse prevention, service reliability, and improving simulation quality (using aggregated or de-identified signals where practical).
- Legal obligation: tax, accounting, and responding to lawful requests.
- Consent: where required (e.g. non-essential marketing cookies). We do not use advertising cookies today.
4. Processors & subprocessors
We use trusted providers to operate the Service, including:
- Supabase (authentication and database hosting)
- Vercel (application hosting, Web Analytics, and Speed Insights)
- Stripe (payments)
These providers process data on our instructions and under their own security and privacy terms. Data may be stored or processed in the EU and/or other regions depending on the provider’s infrastructure.
5. Sharing
We do not sell personal data. We share data only with processors above, when you choose to share a report link, or when required by law.
Public share links (`/r/...`) can reveal report content to anyone with the URL. Treat them as confidential unless you intend to publish them.
6. Retention
We keep account, workflow, and report data while your account is active. Credit ledger and billing references may be retained longer for accounting and dispute resolution. You can export or delete your account from your profile; deletion removes account access and associated user content we control, subject to legal retention needs.
7. Your rights
Depending on your location, you may have rights to:
- Access and export your data
- Correct inaccurate data
- Delete your account and associated content
- Object to or restrict certain processing
- Lodge a complaint with a supervisory authority
Use Profile → Privacy controls, or email jeroenhuitema2000@gmail.com. We may need to verify your identity before acting.
8. Security
We use industry-standard controls (HTTPS, hashed passwords via our auth provider, server-side authorization, rate limits). No method of transmission or storage is 100% secure. Reports are simulations and do not guarantee production safety.
9. Children
The Service is not directed to children under 16. If you believe we hold such data, contact us and we will delete it.
10. Changes
We may update this policy. The “Last updated” date at the top will change. Material changes may also be noted in the product.