ข้ามไปยังเนื้อหาหลัก
cronable
Legal

Privacy Policy

Your privacy is built into how Cronable works. Because the software runs entirely on your own infrastructure, the things that matter most — the secret and credential values your jobs use, and the accounts you connect — stay on your machine, and the software never sends them to us of its own accord. Its routine outbound calls are a periodic licence check that reports simple counts (such as the number of jobs and users) and a check for updates; neither carries the content of your work. Three optional features can send your content through us, and you choose each one: the built-in AI Assistant on its hosted option, inbound webhooks, and remote control. We explain all three in full below.

Last updated July 20, 2026

This policy explains the small amount of personal data we do handle to run our business — mainly to give you an account, take payment, and answer your messages — and the rights you have over it.

Your data stays with you

This is the most important thing to understand about Cronable, so we will say it plainly. Cronable is self-hosted software. It installs and runs on your own computer or server, and everything you do with it stays there.

Left to itself, the software sends us almost nothing: a periodic licence check (which confirms your subscription and reports only simple counts — how many jobs and users your install has) and a check for new releases. Neither carries the content of your work, and neither can carry a secret value, because nothing in your install ever sends one to us. That is a deliberate design choice: what we never hold, we cannot lose. Three features change this, each opt-in and each described on this page — the hosted AI Assistant, inbound webhooks, and remote control. Remote control is the one to understand before you switch it on: your browser reaches your server through our relay, so while it is in transit your dashboard traffic passes through our infrastructure — job definitions, run logs, and a secret value at the moment you type one into the remote dashboard. It is a pipe, not a store: we do not retain that traffic. Run the dashboard on the same machine as the engine and none of it applies.

There is one deliberate exception, and we would rather be upfront about it than hide it: the built-in AI Assistant. If you run it on the hosted Cronable Assistant (rather than your own AI key or your machine's local Claude CLI), your messages to it — and the job details it needs to help you — are sent through us to a third-party AI model provider to generate the replies. We describe exactly what is and isn't sent, and what we keep, in the sections below.

The rest of this policy is about the limited personal data we handle to run our website, your subscription, and the hosted Assistant — not what happens inside your Cronable install, because (the hosted Assistant aside) that never reaches us.

Who is responsible for your data

Jefe Digital Pte. Ltd. is responsible for the personal data described in this policy. We are registered in Singapore with UEN 201601734E, at 2 Havelock Road, #06-01, Havelock II, Singapore 059763. You can reach us about privacy at privacy@cronable.ai.

What we collect, and why

We keep what we collect deliberately small. Here is the full list.

  • Account data — your name, email address, a hashed (scrambled) version of your password, your plan, and your subscription or licence status. To keep your licence active and enforce your plan's limits, your running install also periodically reports simple counts — how many jobs and users it has, never the jobs themselves. We use this to create and secure your account and administer your licence. It is held by our own licence server.
  • Billing data — we use Stripe to take payment. Stripe handles your card details; we see your subscription status and billing records, but not your full card number. We use this to manage your subscription and meet our accounting and tax obligations.
  • Contact and support messages — if you contact us, we receive your name, email, company and team size (if you give them) and your message, delivered to us by email through Resend. We use this to reply and to help you.
  • Waitlist — before Cronable opens to sign-ups, you can join our waitlist with your email (and your name, if you like). We use it only to email you when Cronable launches. We store it in a spreadsheet hosted by Google, and delete it after launch or sooner if you ask.
  • Website analytics — we measure how our website is used with privacy-friendly, cookieless analytics (Vercel Analytics and Plausible). These produce aggregate figures only. There is no cross-site tracking and there are no advertising profiles.
  • AI Assistant messages (hosted option only) — if you use the hosted Cronable Assistant, rather than your own AI key or your machine's local CLI, your messages to it and the details it needs to help you pass through our assistant service to a third-party AI model provider that generates the replies. Those details are your jobs' configuration and non-secret variable values, the names — never the values — of your secrets, and, when you ask the Assistant to look at a run (for example “why did this fail?”), that run's history and its log output. Run logs are secret-masked before they are ever stored, so the values of your secrets are not in them; they can, however, contain whatever your own job printed, and file paths from your server. We record only a per-day count of your messages, to enforce your plan's allowance; we do not store the messages or their content. Your secret and credential values are never sent.
  • Technical and security logs — our systems and our host (Vercel) keep short-lived logs that can include your IP address, browser type, and a record of the messages you send us. We use these to keep the service secure, diagnose problems, and prevent abuse.

Why we are allowed to use it

Under Singapore's Personal Data Protection Act, we handle your data with your consent and for the reasonable purposes described here. For customers in the EU or UK, the equivalent legal bases under the GDPR are:

  • Contract — to provide your account, subscription and support.
  • Legitimate interests — to run, secure and improve our website (including cookieless, aggregate analytics that never identify you as an individual), and to communicate with you.
  • Legal obligations — such as meeting our tax and accounting duties.
  • Consent — for example, to add you to our pre-launch waitlist and email you when Cronable opens. You can withdraw it at any time.

Who we share it with

We do not sell your personal data, and we never will.

We may disclose personal data if the law genuinely requires it, or to establish or defend our legal rights — always kept to the minimum necessary.

Otherwise, we share the limited data above only with the service providers that help us run Cronable — our sub-processors — and only so they can do their job for us. You can see them, and what each one does, on our Sub-processors page. In short:

  • Stripe — to process subscription payments.
  • Resend — to deliver our transactional and contact or support emails.
  • Vercel — to host our website and provide cookieless website analytics.
  • Plausible Analytics — to provide cookieless website analytics.
  • Google — a spreadsheet where we hold pre-launch waitlist sign-ups until Cronable launches; and Google Cloud, which hosts our licence server, hosted Assistant and relay.
  • A third-party AI model provider (US-based) — only if you use the hosted Cronable Assistant: it receives your assistant messages and the job details needed to generate the replies, so it can return them. We can tell you the specific provider on request. If you use your own AI key or your machine's local CLI instead, nothing goes to us or to this provider for the Assistant.

Sending data outside Singapore

Some of our service providers are based in, or process data in, countries outside Singapore, including the United States and the European Union. When your data is transferred abroad, we rely on appropriate contractual safeguards — such as the standard data protection clauses these providers offer — so that it stays protected to a comparable standard.

How long we keep it

We keep account data for as long as your subscription is active. We keep billing and transaction records for at least 5 years after the end of the financial year they relate to, because Singapore tax and company law requires it, after which we delete or anonymise them. We keep contact and support messages for up to 24 months after your query is resolved, unless we need them longer to handle a dispute. Technical and security logs are short-lived. Hosted AI Assistant messages are not stored by us at all — we keep only a per-day count to enforce your plan's allowance. We keep waitlist sign-ups only until Cronable launches, or until you ask us to remove you, then delete them. Cookieless analytics are aggregate and are not tied to you as an individual.

How we protect it

We use sensible technical and organisational measures to protect the data we hold. Passwords are stored hashed, not in plain text. Access to account and billing systems is limited to the people who need it. Payment card details are handled by Stripe, not by us.

And the most sensitive material of all — your secret values and your credentials — is protected by the fact that our systems never store it, whichever way you run the Assistant. Unless you turn on remote control, it never reaches us at all.

Your rights

You have rights over the personal data we hold about you. Depending on where you live — for example under Singapore's PDPA, the GDPR in the EU or UK, or the CCPA in California — these include the right to:

  • Access — ask for a copy of the personal data we hold about you.
  • Correct — ask us to fix data that is wrong or out of date.
  • Delete — ask us to erase your data, where we are not required to keep it.
  • Port — ask for your data in a portable form, or that we send it to another provider.
  • Withdraw consent — change your mind about a use you previously agreed to.
  • Object or restrict — ask us to stop or limit certain uses, including any marketing.

How to exercise your rights

To make any of these requests, email us at privacy@cronable.ai. We will respond within 30 days; if a request is complex and we need more time, we will tell you within that period and explain why — and in every case within the maximum the applicable law sets (for example, one month under the GDPR, extendable for complex requests, and 45 days under the CCPA). We will not charge you or treat you differently for exercising your rights, and we may need to confirm your identity first, to keep your data safe.

If you are in California, we do not sell or share your personal information, and we will not discriminate against you for exercising your rights. If you are in the EU or UK, you also have the right to complain to your local data protection authority; if you are in Singapore, you may contact the Personal Data Protection Commission (PDPC) — though we hope you will come to us first.

Children

Cronable is a business and developer tool, and it is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has given us personal data, contact us at sales@cronable.ai and we will delete it.

Changes to this policy

We may update this policy as Cronable grows or the law changes. If we make a significant change, we will update the date at the top and, where appropriate, let you know by email or a notice on the website.

How to reach us

For any privacy question or request, email privacy@cronable.ai, or write to Jefe Digital Pte. Ltd., 2 Havelock Road, #06-01, Havelock II, Singapore 059763. We are the company responsible for your data, and we are happy to help.

All legal & trust pages