Privacy Policy

Last updated: August 28, 2026

Policy version: 2026-08-28

1. Who we are and when this policy applies

Closyn LLC, doing business as Crispy, is a Delaware limited liability company at 8 The Green, STE A, Dover, Delaware 19901, United States ("Crispy," "we," "us"). This policy explains how we handle personal data through crispy.sh and the Crispy service.

We generally act as a controller for account, website, billing, security, analytics, and communications data. When a customer uses Crispy to manage LinkedIn contacts, messages, campaigns, or related content, we generally process that data for the customer as a processor. Some connection and security activities may involve separate controller responsibilities depending on the context.

2. Data we collect

  • Account data: email, display name, authentication identifiers, and account or organization membership.
  • LinkedIn connection data: credentials or session-cookie material submitted to connect an account, provider session identifiers, and connection-health information.
  • Proxy connection data: protocol, host, port, and optional username and password that you submit when using your own proxy. Crispy transmits these settings to the LinkedIn connection infrastructure provider for that connection; they are not intentionally persisted in Crispy's application database.
  • Managed storage for contacts and messages: names, profile URLs, roles, employers, locations, contact details, identifiers, tags, notes, enrichment, conversation metadata, message text, sender, timestamps, attachment metadata, labels, and classifications.
  • Campaign and content data: lists, imports, campaign settings, drafts, schedules, sent content, and activity history.
  • Usage and device data: tool calls, timestamps, account identifiers, request metadata, quotas, audit events, IP address, browser or device attributes, page URLs, referrer, UTM parameters, cookies, and similar identifiers.
  • Billing data: Stripe customer and subscription identifiers, plan, invoices, payment status, and transaction metadata. Payment card details are handled by Stripe rather than stored by Crispy.
  • Support and security data: support requests and replies, delivery identifiers, and error, performance, access, fraud, abuse, and security-event data.
  • Optional integration credentials: encrypted third-party API credentials that you choose to store for an integration, such as ElevenLabs.
  • Prospect lead data: email address, form or calculator source, calculator type, and an optional result summary that you submit through a public lead form.

3. How we use data

  • create accounts, authenticate users, manage organizations, and provide the service;
  • connect and operate a LinkedIn account at the user's instruction and monitor session health;
  • power inbox, contact, campaign, search, analytics, reminder, and intelligence features;
  • classify conversation category, intent, sentiment, and action state;
  • operate subscriptions, invoices, refunds, accounting, and fraud controls;
  • deliver transactional, lifecycle, support, and permitted marketing email;
  • secure, troubleshoot, measure, and improve the service; and
  • measure advertising or build retargeting audiences only when the relevant feature is enabled and marketing consent has been granted.

4. AI processing

Crispy sends relevant content to Anthropic, PBC for scheduled or event-triggered conversation labeling, inbox intelligence, intent and sentiment tagging, writing-style analysis, content suggestions, and AI analysis that a user explicitly invokes. This may include message text, contact or profile data, posts, comments, campaign content, feedback, and related account context. Anthropic's contract, processing region, retention terms, and international transfer status for this use are still under review; we do not represent those items as finalized.

5. Legal bases for EEA and UK processing

Where applicable, we rely on:

  • Contract: to provide requested account, LinkedIn, managed-data, billing, and communication functions;
  • Legitimate interests: to secure, operate, troubleshoot, and improve the service, prevent fraud and abuse, and communicate about it, balanced against individual rights;
  • Consent: for non-essential analytics, functional attribution where required, marketing, and advertising pixels; and
  • Legal obligations: including tax, accounting, and lawful requests.

6. When we disclose data

We disclose data to service providers needed to run Crispy, including hosting, database, authentication, LinkedIn connection infrastructure, geolocation, payments, email, operational messaging, monitoring, rate limiting, workflows, analytics, AI, and optional user-configured integration providers. We also project limited prospect lead, customer-relationship, billing, revenue, and referral records to Closyn LLC's internal ShyftOS operations system. If consented advertising features are enabled, advertising platforms may also receive device or account-related event data. We may also disclose data to comply with law, protect rights and safety, complete a corporate transaction, or at your direction.

See our Subprocessor List for named vendors and our current contract, region, and transfer-status disclosures. Those reviews are pending for several vendors.

7. Analytics, marketing, and cookies

Crispy gates non-essential browser analytics, functional attribution, and marketing technologies on the relevant consent. PostHog, Inc. browser analytics may include account, device, and usage data; it is not described as anonymous. Separately, Crispy may send server-side operational usage events to PostHog under legitimate interests even when browser analytics is off. Those server events do not activate browser cookies or pixels. Cloudflare browser analytics may operate where enabled. Advertising integrations can support conversion measurement and retargeting when a deployment identifier is configured and marketing consent is granted. Implementation and final configuration of these controls are still being completed, so you should not treat this description as a guarantee that every control is already fully deployed.

Details appear in our Cookie Notice.

8. Retention and deletion

  • Account data: while active; an account hard-delete flow applies on deletion, subject to identified legal, audit, security, and suppression exceptions.
  • Message cache: 90 days from cache write, using an expiry field and daily retention sweep.
  • Contacts, activity, and campaign data: while the service is active; the current churn-sweep target is 180 days after the paid term ends.
  • Raw campaign imports: 60 days.
  • Billing records: as needed for subscription operations, disputes, tax, and accounting; the exact schedule is under review.
  • Suppression records: invitation suppression survives subscription churn but is cleared by the current self-service hard-delete path; exact churn-retention schedules and legal bases are under review.
  • Audit and legal-acceptance records: selected minimal records, including user ID and accepted document versions, intentionally survive account hard deletion; exact schedules and legal bases are under review.
  • ShyftOS projections: prospect lead, customer-relationship, billing, revenue, and referral projections are outside the current Crispy account hard-delete path; their exact retention and deletion-reconciliation process are under review. A prospect who never creates an account may request access or deletion through the Data Rights page.

Disconnecting LinkedIn ends the provider connection; it is not the same as deleting the Crispy account or all managed data. Ending a paid term also does not immediately hard-delete all data. To request hard deletion, use the account deletion flow where available or contact us. Applicable exceptions may require us to retain limited records.

9. Security

We use administrative, technical, and organizational measures intended to protect data, including access controls, intended transport safeguards, row-level database controls, monitoring, and credential-redaction controls. Production transport configuration and protocol versions still require validation. These measures reduce risk but cannot guarantee absolute security. We do not claim that all personally identifiable information is removed from telemetry before a monitoring provider receives it.

10. International transfers

Crispy is based in the United States, and vendors may process data in the United States or other countries. Vendor regions and contractual transfer mechanisms are still being verified in several cases. Where transfer safeguards are legally required, we will use an applicable executed mechanism before relying on it. We do not currently claim that Standard Contractual Clauses, the UK Addendum, or another safeguard has been executed with every vendor.

11. Your privacy rights

Depending on where you live and whether a law applies to Crispy, you may request access, correction, deletion, portability, restriction, or objection; withdraw consent; opt out of sale, sharing, or targeted advertising; and appeal a denied request. We aim to respond within 30 days and will meet an applicable state-law maximum, generally 45 days where required. We may verify account control and request proportionate additional information.

U.S. state privacy rights depend on the statute and its applicability thresholds. In particular, Delaware's Personal Data Privacy Act does not automatically apply to every business or request. We nevertheless accept requests through our published channel. EEA and UK residents may also complain to their local supervisory authority.

Instructions are on our Data Rights page.

12. Children

Crispy is not directed to people under 18, and we do not knowingly offer the service to children.

13. Changes

We may update this policy as our practices, vendors, or legal obligations change. We will post the updated date here and provide additional notice where required.

14. Contact

Closyn LLC d/b/a Crispy
8 The Green, STE A
Dover, Delaware 19901
United States

Email: [email protected]