Privacy Policy
Last Updated: September 24, 2026
1. Who We Are
This Privacy Policy explains how CrumWorld Industries (Private) Limited ("CrumWorld", "we", "us", "our") collects, uses, shares and protects personal information. We are a company registered in Pakistan, founded on 2 August 2025 and formally registered on 19 August 2026. We build CrumAtlas, CrumSurf and CrumStudio, and sell the CrumWorld Cloud Subscription subscriptions.
Registered address: 403-BB, Sector D, Bahria Town, Lahore, Pakistan
Telephone: +92 321 8416921
Email:
support@crumworld.com
(or alizafar@crumworld.com)
For the purposes of applicable data protection law, CrumWorld Industries (Private) Limited is the data controller for the information described in this policy.
2. Scope of This Policy
This policy covers crumworld.com, our web applications, our desktop and mobile applications, and any related service that links to it. It does not cover third-party websites or services that we link to, including the identity providers you may choose to sign in with — those are governed by their own privacy policies.
3. Information We Collect
We aim to collect as little as possible. Depending on how you use CrumWorld, we may collect:
- Account information: your email address, display name, profile picture URL and a unique user identifier, supplied when you sign in through an identity provider.
- Identity provider metadata: basic profile details returned by the provider you authenticate with (Google, GitHub or Microsoft). We never receive or store your password for those accounts.
- Subscription and billing information: your plan, subscription status, billing country, and a payment reference. Card numbers and full payment credentials are collected and stored by our payment processor, not by us.
- Content you create: files, projects, documents and prompts you deliberately save to the CrumWorld Cloud Subscription, and the prompts and files you submit to CrumAtlas.
- Technical and security data: IP address, browser and device type, operating system, approximate location derived from IP address, and timestamps of sign-in and usage events.
- Usage data: feature usage counts and quota consumption, used to apply plan limits and to understand which parts of the product are working.
- Support communications: the content of emails or messages you send us, including any attachments.
4. How We Collect Information
- Directly from you when you sign in, create content, subscribe to a paid plan, or contact support.
- Automatically through cookies, local storage and server logs as you use the sites and applications.
- From third parties — specifically the identity provider you authenticate with, and our payment processor, which confirms your subscription status to us.
5. Why We Use Your Information
We use personal information only for these purposes:
- To create and authenticate your account and keep you signed in.
- To operate the CrumWorld Cloud Subscription: storing and syncing your files, and enforcing plan storage and usage limits.
- To generate responses and perform tasks you request through CrumAtlas.
- To process payments, issue invoices, apply tax, and handle refunds.
- To provide customer support and respond to your enquiries.
- To secure the service: detecting abuse, fraud, automated bot traffic and unauthorised access.
- To send service-critical messages such as billing failures, security notices and material changes to our terms. We do not send marketing email without your consent, and you can opt out at any time.
- To comply with legal obligations and to establish or defend legal claims.
We do not sell your personal information, and we do not use it for advertising or behavioural profiling.
6. Legal Bases for Processing
Where data protection law requires a legal basis, we rely on: performance of a contract (providing the service you subscribed to); your consent (optional features and marketing); our legitimate interests (security, fraud prevention, product improvement, direct communication with existing customers); and compliance with legal obligations (tax, accounting and lawful requests).
7. Third Parties We Rely On
We use a small number of carefully selected providers to run the service. Each is contractually limited to processing data on our instructions:
- Google Firebase (Authentication and Firestore) — account identity and data storage.
- Google, GitHub and Microsoft — the identity providers you may choose to sign in with.
- Our payment gateway — when paid subscriptions go live, payments and refunds will be processed by a third-party payment gateway acting on our behalf. We will name that provider on this page once it is confirmed.
- Cloudflare — content delivery, security and edge infrastructure.
- Netlify — hosting for crumworld.com.
- AI model providers — used to generate CrumAtlas responses. Prompts you submit are transmitted to these providers to produce an answer.
We do not sell or rent personal information to any of these parties, and none of them is permitted to use your data for their own purposes.
8. Cookies and Local Storage
We use cookies and browser local storage for essential purposes only: keeping you signed in, remembering interface preferences such as theme, and protecting against cross-site request forgery. We do not use third-party advertising cookies or cross-site tracking pixels. You can block or delete cookies in your browser settings, but doing so will sign you out and may prevent some features from working.
9. CrumAtlas and Artificial Intelligence
When you send a prompt to CrumAtlas, we transmit it to an AI model provider in order to generate a response. Content you submit may be retained temporarily for abuse monitoring and to debug failures. We do not use your private content or prompts to train models. Because AI output can be inaccurate, you should review anything important before relying on it, and you should not submit information you are not comfortable sharing.
10. How Long We Keep Your Information
- Account data: retained while your account is active.
- Cloud content: retained while your subscription is active. After cancellation, content remains available in read-only form for 30 days so you can export it, and is then deleted.
- Security and access logs: typically retained for up to 12 months.
- Billing and tax records: retained for the period required by applicable law, generally a minimum of several years.
- Support correspondence: retained for up to 24 months.
You may delete your account at any time, which removes your personal data except records we are legally required to keep.
11. Security
We protect your information with encryption in transit (HTTPS/TLS), encryption at rest where supported, strict access controls, and domain-restricted authentication configuration. Credentials and tokens are handled by Firebase Authentication; we do not store passwords. No system is perfectly secure, so we also maintain monitoring and a documented response process. If we become aware of a breach affecting your personal data, we will notify you and any required regulator as the law requires.
12. International Data Transfers
We operate from Pakistan and use providers with infrastructure in multiple countries, so your information may be processed outside your country of residence, including in the United States. Where we transfer data internationally, we rely on contractual protections and take reasonable steps to ensure your information continues to be protected to a standard comparable to this policy.
13. Your Rights
Subject to applicable law, you have the right to access the personal information we hold about you; to correct inaccurate information; to delete your account and data; to receive a portable copy of your data; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, email support@crumworld.com. We will respond within 30 days. We may ask you to verify your identity before acting on a request. Exercising these rights is free of charge and will never result in a degraded service for you.
14. Children's Privacy
CrumWorld is not directed at children under the age of 13, and we do not knowingly collect personal information from them. Accounts require a minimum age of 13, or 16 where local law requires it. If you believe a child has provided us with personal information, contact support@crumworld.com and we will delete it promptly.
15. Do Not Track and Global Privacy Control
We honour the Global Privacy Control (GPC) signal and browser Do Not Track settings. Since we do not conduct cross-site tracking or targeted advertising, these signals have no effect on advertising but are respected for any optional analytics.
16. Changes to This Policy
We may update this policy as the product changes. When we do, we will revise the "Last Updated" date above. If a change materially affects how we handle your personal information, we will give you advance notice by email or by a prominent notice in the product before it takes effect.
17. Contact Us
For any question about this Privacy Policy, or to make a privacy request:
CrumWorld Industries (Private) Limited
403-BB, Sector D, Bahria Town, Lahore, Pakistan
Telephone: +92 321 8416921
Email: support@crumworld.com
Email: alizafar@crumworld.com
We aim to acknowledge every privacy enquiry within 3 business days and to resolve it within 30 days.