PRIVACY POLICY
CrewXR Platform, Viewer, and Website
Effective Date: September 3, 2026
Last Updated: September 3, 2026
Version: 1.0
1. WHO WE ARE AND WHAT THIS COVERS
CrewXR, Inc. (“CrewXR,” “we,” “us,” or “our”) is a Delaware corporation with a principal place of business at 11201 Cedar Avenue, Cleveland, OH 44106.
This Privacy Policy explains how we handle personal information across the CrewXR website at crewxr.ai, the hosted CrewXR platform, and the CrewXR viewer software (together, the “Service”). It is incorporated by reference into our End User License Agreement, and capitalized terms not defined here have the meaning given there.
2. SUMMARY
This summary is for orientation only; the sections below govern.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- Our website uses no analytics, advertising, or tracking cookies. The only cookies we set are the ones required to keep you signed in.
- We collect what is needed to operate the Service: account and contact details, subscription and billing records, the content you create, and the technical data required to render and synchronize an XR session.
- Where an institution deploys CrewXR to its users, that institution generally directs how personal information is used, and we act on its instructions.
- We do not accept protected health information, cardholder data, classified information, or export-controlled technical data.
3. INFORMATION WE COLLECT
3.1 Information you give us directly
- Enquiries. When you submit our contact or waitlist form we collect your name, email address, organization, and the content of your message, together with the type of enquiry.
- Account information. When you create an account we collect your email address, name, and authentication identifiers. Authentication is operated for us by Auth0; where you sign in through a third-party identity provider, we receive the profile fields that provider releases to us.
- Subscription and organization details. For platform and enterprise requests we collect your organization name, approximate number of users, intended use case, and any details you choose to add.
- Support correspondence. Records of what you contact us about and how we responded.
3.2 Payment information
Payments are processed by Stripe. Card numbers and other payment credentials are submitted directly to Stripe and are not stored on our systems. We retain the resulting subscription records — customer and subscription identifiers, plan, status, and renewal dates — which we associate with your account.
3.3 Content you create
The Service stores the 3D content, experiences, annotations, and session materials you and your Authorized Users create or upload. As set out in the EULA, that content remains yours.
3.4 XR and session data
Extended reality software necessarily processes data about how a person moves in physical space. Depending on the hardware you use and how your organization configures the Service, this may include head and hand pose, controller input, room-scale spatial mapping and plane data, gaze or eye-tracking data, hand and body tracking data, microphone audio, data derived from passthrough cameras, and anthropometric measurements such as height or interpupillary distance.
Some of this may constitute biometric or otherwise sensitive personal information under applicable law. We process it to render and synchronize sessions, to place participants correctly relative to one another and to the physical room, and to provide the features you have enabled. The categories actually processed vary by device and configuration; much of this data is used transiently to draw a frame and is not retained. If you need an exact inventory for a security or procurement review of your specific deployment, contact us and we will provide it.
3.5 Technical and diagnostic data
We collect usage analytics, crash reports, device and performance metrics, and diagnostic logs to operate, secure, troubleshoot, and improve the Service. Our web servers record standard request logs, including IP address, user agent, and the pages requested, which we use for security, abuse prevention, and debugging.
4. HOW WE USE INFORMATION
- To provide, operate, maintain, and support the Service.
- To create and administer accounts and organizations.
- To process subscriptions, payments, renewals, and cancellations.
- To respond to enquiries, demo requests, and support requests.
- To secure the Service — detecting, investigating, and preventing fraud, abuse, and unauthorized access.
- To improve the Service, including diagnosing faults and understanding which features are used.
- To send service and administrative messages. We will not send you marketing email you did not ask for, and any marketing message we do send will include a way to stop receiving them.
- To comply with law and enforce our agreements.
We may generate aggregated or de-identified data from use of the Service and use it for any lawful business purpose, provided it does not identify you, your Authorized Users, or your content, and we do not attempt to re-identify it.
5. COOKIES AND TRACKING
The CrewXR website does not use analytics cookies, advertising cookies, tracking pixels, social media trackers, or session-replay tools. We do not operate a cookie consent banner because we do not set the kind of cookies that require one.
The cookies we do set are strictly necessary: a session cookie that keeps you signed in after authentication, and the security tokens that protect the sign-in exchange itself. Blocking these will prevent signing in.
6. HOW WE SHARE INFORMATION
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only as described here:
- Service providers. Vendors who process information on our behalf, under contract and only on our instructions. These currently include Auth0 (authentication), Stripe (payments), Microsoft Azure (hosting and infrastructure), Google (storage of enquiry records), and Resend (transactional email).
- Your organization. If your account was provisioned by an employer, school, or other institution, that organization’s administrators may access account and usage information associated with it.
- Other session participants. Multi-user sessions are shared by design. Your display name, avatar, voice, and in-session actions are visible to others in the session.
- Legal and safety. Where required by law, or to establish, exercise, or defend legal claims, or to protect the rights and safety of any person.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply to the transferred information.
7. INSTITUTIONAL AND EDUCATION DEPLOYMENTS
Where a school, university, employer, or other institution deploys CrewXR to its users, that institution determines the purposes for which personal information is processed and we act as its processor, on its documented instructions. Questions about how a particular deployment uses data — and requests to access or delete data within it — should be directed to that institution in the first instance.
For deployments in United States educational institutions, we handle student records as a “school official” with a legitimate educational interest under the Family Educational Rights and Privacy Act, use those records only for the purposes authorized by the institution, and do not re-disclose them except as the institution directs or the law requires. The institution is responsible for obtaining any consents required under FERPA, the Children’s Online Privacy Protection Act, applicable state student privacy laws, and any other applicable law.
Institutions requiring a data processing agreement, a student data privacy agreement, or specific data residency arrangements should contact us before deployment.
8. CHILDREN
The Service is not directed to children, and you must be at least 18 years old to create your own account. Individuals under 18 may use the Service only through an account created and supervised by a parent, legal guardian, or authorized educational institution that has accepted the EULA on their behalf and, where required, provided verifiable parental consent. If we learn that we have collected personal information from a child outside those arrangements, we will delete it.
9. DATA WE DO NOT ACCEPT
The Service is not designed or certified for protected health information under HIPAA, cardholder data under PCI DSS, classified information, or export-controlled technical data. Do not submit such data unless we have signed a separate written agreement covering it, including a Business Associate Agreement or Data Processing Addendum where applicable.
10. RETENTION
We keep personal information for as long as needed for the purposes described in this Policy — for the life of your account and afterwards where we must retain records to meet legal, tax, accounting, audit, or dispute-resolution obligations. Enquiry records are kept for as long as needed to respond and to maintain a record of the relationship. Much XR session data is transient and is not retained beyond the session. When information is no longer needed we delete it or de-identify it.
11. SECURITY
We use technical and organizational measures appropriate to the risk, including encryption of data in transit, access controls limiting staff access to what their role requires, and delegation of authentication and payment handling to specialist providers so that credentials and card data are not stored on our systems. No system is perfectly secure, and we cannot guarantee absolute security. If you believe you have found a vulnerability, report it to support@crewxr.ai and we will work with you.
12. INTERNATIONAL TRANSFERS
We are based in the United States and our infrastructure and service providers may process information in the United States and other countries. If you use the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection law may differ from that of your country. Where required, we rely on appropriate safeguards such as the European Commission’s standard contractual clauses. Institutions with specific data residency requirements should contact us before deployment.
13. YOUR RIGHTS AND CHOICES
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal information; to object to or restrict certain processing; to withdraw consent where processing relies on it; and to appeal a decision we make about your request. Residents of certain U.S. states also have the right not to receive discriminatory treatment for exercising these rights. Because we do not sell personal information or share it for cross-context behavioral advertising, there is nothing for you to opt out of in that respect.
To exercise any of these rights, contact support@crewxr.ai. We will verify your request and respond within the time required by applicable law. If your account was provisioned by an institution, we will refer your request to that institution, which controls the data.
If you are in the European Economic Area or the United Kingdom, our legal bases for processing are performance of a contract with you, our legitimate interests in operating and securing the Service, compliance with legal obligations, and your consent where we ask for it. You have the right to lodge a complaint with your supervisory authority.
14. CHANGES TO THIS POLICY
We may update this Policy from time to time. We will change the “Last Updated” date above, and where the changes are material we will provide additional notice through the Service or by email before they take effect.
15. CONTACT US
Questions about this Policy, or about how your information is handled, can be sent to support@crewxr.ai, or by mail to CrewXR, Inc., 11201 Cedar Avenue, Cleveland, OH 44106.
© 2026 CrewXR, Inc. All rights reserved.