Loading…
Loading…
Last updated: August 2026
Crux (“we”, “us”, “our”) is the product-research workspace operated at www.crux-hq.com. This Privacy Policy explains how we collect, use, store, and share personal data when you use Crux, including Google user data obtained through optional Google OAuth connections.
Privacy and Google user data requests: simon@crux-hq.com.
Related documents: Terms of Use and Data security & privacy.
Crux is an AI-powered product research and experience workspace. You can create projects, import research and documents, model product experience, connect optional third-party sources, and use AI-assisted tools grounded in your own project data.
Some Crux features optionally connect to Google APIs via OAuth. Each integration (Google Drive, Gmail, Google Analytics) is a separate connection with its own scopes. You start the connection yourself from Settings or the relevant import flow. We do not access Google user data until you complete Google’s consent screen. You can disconnect at any time in Settings. We request only the narrow read-only scopes needed for each feature.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. See section 4.5.
https://www.googleapis.com/auth/drive.readonly, via the Google Drive API). After you connect, we may list and search files you can already access in My Drive and shared drives, and read file metadata only for that list (name, type, last modified time, and a link to open the file in Drive). We download or export file content only for files you explicitly choose to import (for example Google Docs, Sheets, Slides, PDFs, Word documents, and similar research files). Native Docs/Sheets/Slides are exported to a portable format (such as PDF or CSV) so they can be stored in your Crux project. We do not create, edit, move, share, or delete Drive files. We do not scan Drive in the background or access file content you have not imported.gmail.metadata, userinfo.email): your Google account email address and message metadata / headers only (for example From, To, Cc, Subject, Date, and related headers). We do not request or access Gmail message bodies or attachment contents.https://www.googleapis.com/auth/analytics.readonly, via the Google Analytics Admin API and Analytics Data API). After you connect, we list the GA4 properties you can access so you can choose one. We then run read-only aggregate reports you request — fixed presets such as audience, acquisition, top pages, key events, and device/browser split, and the same class of aggregate report when you ask a question in Crux. We do not request user-level or personally identifying Analytics dimensions, and we do not edit properties, audiences, or measurement settings.We use Google user data only to provide or improve user-facing features that are visible in Crux, specifically:
We do not use Google user data for advertising, retargeting, personalized or interest-based ads, selling data, data brokerage, credit scoring, lending decisions, or any purpose unrelated to providing or improving these Crux features.
We do not sell Google user data. We do not share Google user data with third parties for their own advertising or unrelated purposes. We do not transfer Google user data except:
Those subprocessors currently include:
Disconnecting stops further Google API access. Copies you already imported into a Crux project stay as project content until you delete them, delete the project, or delete your account (see 4.7).
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Crux’s use and transfer of information received from Google APIs also adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you use AI-powered features, relevant inputs from your project (which may include content originally imported from Google) are sent to third-party AI providers for processing. Practices include:
Crux is intended for business and professional use. It is not directed to children under 16, and we do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date and, where appropriate, notifying you through the Service. Continued use after changes constitutes acceptance of the updated policy.
For privacy questions, Google user data requests, or data deletion requests, contact simon@crux-hq.com.