Privacy Policy
Effective 8 August 2026 · Last updated 8 August 2026
When you put a plan into CrowFlo you are trusting us with information about your work, and usually about other people too - a project names the colleagues doing it, who owns what, and what is going wrong. We take that seriously, and this policy is an attempt to be straightforward about it rather than thorough in a way nobody can read.
It explains what we collect and why, who else sees it - including the AI providers that receive your project context when you use an AI feature - how long we keep it, and what you can ask us to do about it. Where there is something you might reasonably expect that we cannot currently do, such as giving your data back in a reusable form, we say so rather than leave you to find out.
1. Who we are and what this covers
CrowFlo is operated by DocuSkill LLC, a Delaware limited liability company (“DocuSkill”, “we”, “us”, “our”). This Privacy Policy explains what information we handle when you use CrowFlo - our AI-powered project-management and project-intelligence platform - our websites, and related services (the “Service”).
It applies to visitors to our websites, to individuals who create an account, and to people whose information appears in a customer’s projects. It does not apply to third-party products you connect to CrowFlo, which have their own policies.
Terms defined in the Terms of Service have the same meaning here.
2. Our two roles: controller and processor
Which privacy role we occupy depends on the information, and the distinction matters for who you should contact about it.
We are the controller (or “business”)
For information we decide the purposes of ourselves: account and identity information, billing information, security and fraud-prevention records, product usage and diagnostic data, support communications, and our own marketing. We are responsible for that processing, and you can exercise your rights with us directly.
We are a processor (or “service provider”)
For the project information a customer puts into CrowFlo, we act on that customer’s instructions. The customer - usually your employer or the organization whose account you use - decides what goes in, who can see it, and how long it stays. If your personal information appears in someone’s project and you want it corrected or removed, contact that organization first; we will support them in responding, and will refer you to them if you contact us instead.
Processing on a customer’s behalf is governed by our Data Processing Addendum at www.crowflo.com/dpa, which applies automatically to business customers on a standard subscription and does not need to be signed separately.
3. The categories of information we handle
We keep these categories distinct because they are collected differently, used differently, and carry different rights.
3.1 Account and identity information
Name, email address, password credentials, organization and role, profile details, language and preferences, and - where your organization uses single sign-on or directory synchronization - the identity attributes its identity provider sends us.
3.2 Customer-controlled project content
What you and your colleagues put into CrowFlo. Depending on the features used, this may include: projects and descriptions; tasks and dependencies; actions and assignments; decisions and approvals; risks and issues; timelines, milestones, schedules and deadlines; resources, roles, participants and responsibilities; scope, requirements and deliverables; documents, attachments, comments and messages; meeting records and notes; and project status, history, changes and activity, including audit trails.
CrowFlo does not currently ingest meeting audio recordings or machine-generated transcripts. Meeting records in CrowFlo are the notes, attendees, dates and linked items entered by users. If we add recording or transcription, we will update this policy and address the consent requirements before doing so.
3.3 AI inputs and outputs
Prompts and instructions you give to Ask Caw or another AI-supported feature, the project context assembled to answer them, the outputs returned, and your interactions with those outputs, including corrections, ratings and feedback.
3.4 Project graph and inferred relationships
CrowFlo derives structure from your content: links between tasks, risks, decisions, actions, meetings and people; dependency and critical-path relationships; and analytical outputs such as forecasts, assessments and rankings. This derived information can constitute personal data where it relates to an identifiable person - for example an inference that particular work depends on a single named assignee - and we treat it as such.
3.5 Product usage and diagnostic information
Log and device information, IP address, browser and operating system, pages and features used, timestamps, performance and error data, and similar technical information generated when you use the Service.
3.5a How you work with Ask Caw
Where you leave it switched on, Ask Caw notices patterns in how you use it and keeps a short record of them against your user account. What it keeps are counts, not content: which days of the week you tend to ask questions, and which subject areas your questions fall into, such as risks, schedule, resources, decisions, issues or cost. It does not store your questions, and it does not store any of your project content in this record.
We use this to order what Ask Caw offers you first, so that someone who asks about risks every Friday is not offered a schedule summary instead. It is personalization of your own experience and nothing else. It is not used to evaluate your performance, is not visible to your employer or to other users, is not used for advertising, and does not feed any model training.
A pattern has to be seen at least three times before it changes anything, and each record loses weight the longer it goes unseen. A record that has not been seen for long enough is deleted automatically. You can see every record we hold, including ones not yet acted on, delete any or all of them, and switch the whole thing off at Settings, Ask Caw. Switching it off stops anything new being recorded. Deleting your account deletes these records with it.
This is switched on by default. We rely on our legitimate interest in making the product useful to the person using it (clause 8), and the switch in Settings is how you object: turning it off stops the processing for you, with no effect on anything else in the Service.
3.6 Billing information
Plan, subscription status, transaction history, billing contact and address, tax status, and the limited payment details our payment processor returns to us. We do not store full payment card numbers.
3.7 Integration information
Information exchanged with third-party products you connect, and the credentials or tokens needed to maintain the connection - including, where you use Bring Your Own AI, the AI provider credentials you choose to store.
3.8 Cookies and marketing information
See clause 9.
3.9 Aggregated and de-identified information
Information processed so that it no longer identifies you or your organization. We do not attempt to re-identify it, and we require the same of anyone we share it with. Where re-identification remains reasonably possible, we continue to treat the information as personal data rather than describing it as anonymous.
4. Where the information comes from
- From you, when you register, subscribe, configure the Service, contact us, or use AI features.
- From your organization or its administrators, when it provisions your account or configures single sign-on or directory synchronization.
- From colleagues, when they add information about you to a project.
- Automatically, from your use of the Service.
- From third-party products you connect to CrowFlo.
- From our payment processor, in relation to transactions.
5. Why we process information
- To provide the Service, including generating the analysis, summaries, forecasts and recommendations you ask for.
- To build and maintain project relationships and project graphs, which is how the analytical features work at all.
- To personalize AI results for you and your organization, as described in clause 6.
- To create, administer and secure accounts, and to authenticate users.
- To process payments, manage subscriptions and AI credits, and prevent payment fraud.
- To provide support and respond to your requests.
- To monitor, maintain, troubleshoot, evaluate, secure and improve the Service, as described in clause 6.
- To detect, investigate and prevent misuse, abuse, security incidents and unlawful activity.
- To send service and transactional messages, and - where permitted or with your consent - marketing about CrowFlo, which you can stop at any time.
- To comply with legal obligations, and to establish, exercise or defend legal claims.
6. How your data is used to provide and improve AI results
This is the part of the policy most specific to CrowFlo, so we set it out in full and distinguish four different activities. They are not the same thing, and they do not carry the same choices.
6.1 Providing what you asked for
When you use an AI feature, we process the relevant project content, relationships, history, your instructions and your account context to produce the result you requested. Without this the feature cannot function.
6.2 Personalizing results for you
We may use information from your projects, interactions, corrections, usage and feedback to make results more relevant and useful for you and your organization. This stays within your organization: it is not used to shape the results other customers receive.
6.3 Maintaining, evaluating, securing and improving the Service
We may analyze usage, feedback, errors, performance information and patterns across projects to keep CrowFlo working, measure whether its output is any good, detect abuse and security problems, and improve CrowFlo, CrowFlo Intelligence, Ask Caw, our prompts, retrieval systems, evaluation systems and safety systems.
Where it is operationally practical to do so, we use aggregated or de-identified information for this purpose rather than identifiable content. People at DocuSkill can access identifiable customer content where it is necessary to provide support you have asked for, to investigate a fault, or to respond to a security incident. We limit this to what the task requires and to personnel who need it, and we do not browse customer projects out of interest. Access controls and logging around that access are an area we are still building out, and we would rather say so than describe controls we do not yet have.
6.4 Training AI models
We do not train or fine-tune AI models on raw, identifiable customer content. Your projects, documents, prompts and AI interactions are not used to build or improve a model that serves other customers.
Where we use customer information for the general product and AI improvement described in clause 6.3, we work with aggregated or de-identified information. Improving AI results, in this policy, means improving our prompts, retrieval, evaluation and safety systems and the product around them - not training a shared model on what you wrote.
This is a commitment about what we do, and we will not change it quietly. If we ever decide to train models on identifiable customer content, we will update this policy, give advance notice, and obtain consent or provide an opt-out where the law requires one - and we will not apply the change retroactively to content already processed under this version.
The position of the third-party AI providers we send requests to is a separate question, addressed in clause 7. Our commitment here cannot bind a provider you select yourself under Bring Your Own AI. CrowFlo has no training or fine-tuning pipeline: no code in the product collects customer content to build or improve a model, and no such job runs.
7. AI providers and what is sent to them
DocuSkill is not an AI foundation-model company. We use third-party AI models to deliver AI features.
What is transmitted, and why
To answer a request, we may transmit to an AI provider: your prompt or instruction; the project context relevant to it, which can include task, register, meeting, schedule and relationship information and the names of people recorded in it; and limited technical metadata. The purpose is to generate the result you asked for. We do not transmit your password, and we do not transmit payment card details.
Which providers
The providers used may vary by feature, availability, performance, your configuration, geography, security requirements, contractual arrangements and business need. Providers that CrowFlo supports or may use currently include Anthropic, OpenAI, Google (including Gemini models) and xAI (including Grok models).
That list is illustrative and not exhaustive, and it is not fixed. We are not limited to those providers: we may add, substitute or stop using any AI provider, and we may use providers not named here, as models, pricing, capability, availability, security terms and regulatory requirements change. We do not use every provider for every feature, and a provider being supported in the product does not mean it is used for your plan. The authoritative and current record of who processes your information is the subprocessor list, not this paragraph.
The providers CrowFlo can call today are Anthropic, OpenAI, Google Gemini and xAI Grok. Which of them serves the CrowFlo-provided path, and which model, is a platform configuration that can change without a change to this policy; the subprocessor list records the current position.
Failover between providers
On the CrowFlo-provided path, a request may be routed automatically to a different provider than the one that would ordinarily handle it - for example if a provider is unavailable, rate-limited, erroring or too slow. This happens without notice to you, because its purpose is to keep the feature working. It means we cannot presently guarantee that a particular request will be handled by a particular provider, or in a particular country, and you should not rely on either unless a separate written agreement says otherwise.
We record which provider handled each request, so we can answer that question after the fact. We cannot currently show you that record, and we cannot restrict processing to named providers or to a particular region. If either matters to you, please ask before subscribing.
The current list is published at www.crowflo.com/subprocessors, and that page rather than this paragraph is the authoritative record.
On what terms
We use these providers under their standard published API terms. We have not negotiated bespoke data-processing terms with them, and we have not enabled zero-retention or enterprise configurations. Those standard terms differ between providers and commonly permit a provider to retain inputs and outputs for a limited period for abuse monitoring and safety purposes.
So while our own commitment in clause 6.4 is unqualified, we cannot extend it to the providers on their behalf. If how a particular provider handles your data matters to you, read its terms directly, or use Bring Your Own AI so that you contract with it yourself. We will say here if we later negotiate stronger terms.
Because the set of providers is open rather than fixed, this matters at the moment one is added. Our commitment in clause 6.4 is about what CrowFlo does, and it holds whichever provider we use; what we cannot do is guarantee a provider’s own behaviour, since we take their standard terms. When we add a provider we update the subprocessor list. We do not yet operate a documented onboarding standard for new providers, and we would rather record that than describe a process we have not written down.
- Retention of inputs and outputs is governed by each provider’s standard terms, not by an agreement specific to CrowFlo. Those periods differ between providers and can change.
- We hold no provider-specific written confirmation that CrowFlo inputs are excluded from that provider’s model training. Where a provider states such a position in its published API terms, that statement is the provider’s and not ours.
- Zero-retention and enterprise configurations are not enabled on our accounts.
Bring Your Own AI
If you configure your own AI provider credentials, your requests and the associated project context go to the provider you have chosen, under your own agreement with that provider. Its privacy policy and terms govern what it does with that information, including retention and training. We do not control those terms and cannot make commitments about them on that provider’s behalf. We store the credentials you give us in order to make the connection. BYOAI credentials are encrypted at rest using AES-GCM, the same treatment applied to other secrets we hold, and are never returned in full through the interface or an API response. They are deleted with the rest of your account data when your account closes.
8. Legal bases for processing
Where we act as controller, we process personal information only where we have a lawful basis for doing so. The bases we rely on are:
- Performance of a contract - to create and administer your account, provide the Service, process payments and give support.
- Legitimate interests - to secure the Service, prevent fraud and abuse, understand how the product is used, maintain and improve it, personalize what Ask Caw offers the person using it (clause 3.5a), and market to business contacts, where those interests are not overridden by your rights.
- Legal obligation - to meet tax, accounting, and other legal requirements, and to respond to lawful requests.
- Consent - for optional cookies, certain marketing, and any processing for which the law requires consent. You can withdraw consent at any time, without affecting processing already carried out.
Where we act as processor for a customer’s project information, that customer is responsible for establishing the lawful basis for the information it puts into CrowFlo.
9. Cookies and similar technologies
We use cookies and similar technologies that are strictly necessary to run the Service - keeping you signed in, maintaining your session, and protecting security. Where we use analytics, preference or marketing technologies that are not strictly necessary, we will ask for your consent where the law requires it and give you a way to change your mind.
We do not deploy analytics, advertising or cross-context tracking technologies in the Service. If that changes we will update this policy and, where consent is required, ask for it before setting anything that is not strictly necessary.
The technologies we do use are these, all strictly necessary to sign you in and keep you signed in:
- cf_oauth - a cookie holding the state of a sign-in started with an external identity provider, so the reply can be matched to your request and a forged one rejected. Expires after 10 minutes and is deleted when sign-in completes.
- cf_sso - the same, for single sign-on. Expires after 10 minutes and is deleted when sign-in completes.
- pp_token - your session token, held in your browser’s local storage rather than in a cookie. It keeps you signed in between page loads and is removed when you sign out.
None of these is used to track you across other websites, and none is used for advertising.
10. When we disclose information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not operate an advertising business, and no advertising or tracking technology is deployed in the Service. If that ever changes we will update this policy and provide the opt-out rights the law requires before making the change.
We disclose information:
- Within your organization - to other Authorized Users and administrators, according to the permissions your organization configures.
- To service providers and subprocessors who help us run the Service - hosting, database, content delivery, authentication and directory services, payment processing, email delivery and AI providers - under contracts limiting them to our instructions. Each is listed at www.crowflo.com/subprocessors.
- To third-party products you connect, at your direction.
- For legal reasons - to comply with law, respond to lawful requests, enforce our terms, or protect the rights, property or safety of DocuSkill, our customers or the public. Where we may lawfully do so, we will tell an affected customer about a request for their data.
- In a business transfer - in connection with a merger, acquisition, financing, reorganization or sale of assets, subject to this policy continuing to apply or notice being given of a material change.
- With your consent, or at your direction.
We give notice of a new subprocessor by updating that page, which carries the date it last changed. We do not currently send individual notifications, so please check it if the identity of our subprocessors matters to you.
11. International transfers
Information is processed in the United States, which may not be the country you are in and whose privacy laws may differ from those where you live. AI requests may additionally be processed wherever the relevant provider operates.
Your information stays in the United States. We host in a single United States region and do not move personal information to another region in the course of providing the Service, other than the AI processing described above. If we extend the offering to another region, the safeguards that region requires will be in place before launch, together with an assessment covering DocuSkill and every subprocessor.
CrowFlo is hosted in a single region in the United States, and customer data is stored there. There is no multi-region deployment and no data-residency option: we cannot currently offer to store or process your data in a particular country. AI requests are additionally processed by the providers described in clause 7, whose processing locations we do not control and which may change on failover. Their processing locations are recorded on the subprocessor page where known.
12. How long we keep information
CrowFlo is not an archive, a backup service or a records-retention system. You should keep your own copies of anything you need to preserve.
We keep account, billing and security information for as long as your account is open and afterwards for as long as needed for the purposes described here, including tax, accounting and legal-claim purposes. We keep project content for as long as the customer’s plan provides for, subject to the deletion rules in the Terms of Service.
When a paid plan ends we may delete account data, project data, AI interactions, generated content, history and audit trails from our primary systems at any time. We do not undertake to delete it by any particular date. Once deletion has occurred, restricted backups are overwritten in the ordinary cycle, which takes up to 90 days, and information remains protected by this policy while it sits in them; after that it may not be recoverable.
There is no retrieval period after a plan ends, and no structured export while it is running: the only export in the product is a PDF of the project dashboard. Please keep your own records of anything you need to preserve, as you go.
Deletion is subject to law, legal holds, fraud and security investigations, dispute preservation and financial-record requirements. A downgraded account stays open and is not deleted; a suspended account is retained while the suspension is resolved.
We do not retain the content of your AI prompts or the outputs returned: our request log records who made a request, when, which provider served it and what it cost, but not what was written. Any retention by an AI provider is a separate matter, described in clause 7.
Free accounts that have never been on a paid plan are retained while they remain in use and deleted on the same schedule once closed or dormant.
13. Security
We maintain technical and organizational measures intended to protect information against unauthorized access, alteration, disclosure and loss, including encryption in transit, access controls and authentication, and logging of administrative activity. No service can be guaranteed secure, and we do not claim that ours is.
The measures currently in place include: encryption of traffic in transit; AES-GCM encryption at rest for secrets such as AI provider credentials and payment-related identifiers; role-based access control within each organization; audit logging of changes to project records; and support for single sign-on and directory synchronization for organizations that use them. We describe only measures that are in place rather than a general standard.
We do not hold a third-party security certification, and we describe measures rather than standards on purpose. If we obtain an audit or certification we will say so here.
If a security breach affects your personal information, we will notify the affected customer within 72 hours of becoming aware of it, provide what we know at the time, and keep you updated as we learn more. Notification is not an admission of fault.
14. Your privacy rights
Depending on where you live, you may have rights to: access the personal information we hold about you; correct it; delete it; obtain a portable copy; object to or restrict certain processing; withdraw consent; and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
CrowFlo produces automated analysis, forecasts and recommendations. They are decision-support outputs for human review: the product proposes changes and a person accepts or rejects them, and nothing is applied to a plan automatically. We do not intend CrowFlo to be used to make solely automated decisions producing legal or similarly significant effects on an individual, and customers must not use it that way.
To exercise a right, contact [email protected]. We will verify your identity before acting, using information already associated with your account; we may ask for additional information where a request is high-risk, and will not use it for anything else. We respond within the period the applicable law requires.
You may use an authorized agent where the law allows. We will not discriminate against you for exercising a right.
If your information is in a customer’s project, that customer controls it and we will refer your request to them. See clause 2.
15. United States state privacy disclosures
This clause supplements the rest of the policy for residents of US states with comprehensive privacy laws, including California, Colorado, Connecticut, Virginia, Utah and others as they come into effect.
The categories of personal information we collect, the sources, the purposes and the categories of recipient are described in clauses 3, 4, 5 and 10. We collect identifiers, customer records, commercial information, internet activity, professional or employment information, and inferences drawn from project content. Sensitive personal information should not be submitted to CrowFlo except as described in the Terms of Service.
We do not sell personal information for money. See clause 10 for why the position on “sharing” for cross-context behavioural advertising is marked for confirmation rather than asserted.
California residents may request the categories and specific pieces of personal information collected, deletion, correction, and to opt out of sale or sharing if applicable; Californians may also have rights regarding sensitive personal information. Requests may be made at [email protected].
Because we do not sell personal information or share it for cross-context behavioural advertising, we do not publish a “Do Not Sell or Share My Personal Information” link, and there is no opt-out for us to apply when a Global Privacy Control signal is received. If that ever changes, we will honour the signal and publish the link before making the change.
16. Where CrowFlo is offered
CrowFlo is designed primarily for organizations and individuals acting for business or professional purposes. Our current operations, support, and commercial focus are centered in the United States, and availability may vary by location. Extending the Service to another region brings that region’s requirements with it, including any local representative, transfer safeguards and additional notices, and those will be in place before we operate there.
If you are outside the United States and use the Service through an organization that has an account with us, your information will be processed in the United States as described in clause 11, and the protections in this policy apply to you regardless of where you are.
This policy is written in English for a United States offering, and it is not a substitute for local-law compliance elsewhere. Extending the Service to another region will have its own assessment, and in most cases additional notices, a transfer mechanism, translations or consent flows.
17. Children
CrowFlo is not directed to children. We do not knowingly collect personal information from a child below the minimum age set out in the Terms of Service. If you believe a child has provided us with personal information, contact [email protected] and we will take appropriate steps to delete it.
18. Changes to this policy
We may update this policy. Where a change is material - particularly a change to how AI features use your data - we will give notice before it takes effect, by email, in the product, or both, and will obtain consent where the law requires it. The effective date and last-updated date at the top of this page will always reflect the current version.
We archive each published version of this policy with its effective date, and will make a prior version available on request. That is the only reliable way to evidence what you were told at the time.
19. How to contact us
- Privacy and data-rights requests: [email protected]
- Product support: [email protected]
- Corporate: [email protected]
- Websites: www.crowflo.com and www.docuskill.com
We do not publish a postal address, and we have not appointed a Data Protection Officer; neither is required for the offering as scoped in clause 16. Privacy requests reach us at [email protected] and are handled by DocuSkill directly.