iPhone app
Privacy Policy for Crisp0
Last updated 13 September 2026
Crisp0 ("we," "our") is operated by Crisp0. This policy explains what we collect, why, and your rights. Questions: info@crisp0.app.
Crisp0 is an iPhone app. This site does not run the product.
What we collect
Account info: email, name, and Apple or Google identity when you sign in.
Usage data: app opens and screens viewed via PostHog.
Device info: App Store subscription status on the device. TestFlight purchases are sandbox transactions.
Payment info: processed by Apple In-App Purchase. We never see full card numbers.
Content you create: chat messages, photos, and voice you send to the assistant, plus generated mini-apps.
Usage counts: tokens and images, so we can apply the free allowance.
How we collect it
Directly from you when you sign in or use the app; automatically via the app; from Apple or Google if you use those sign-in options.
Why we collect it
To provide and improve the app; authenticate your account; generate replies and mini-apps; apply the free allowance and Plus status; process payments through Apple; prevent fraud and abuse; comply with legal obligations.
Who we share it with
Third-party service providers acting on our behalf:
- Supabase — accounts and data
- OpenRouter / model providers — replies
- Apple — Sign in with Apple and In-App Purchase
- Google — optional sign-in
- PostHog — product analytics
We do not sell your personal data. We do not use your chat content for advertising.
Your rights
You can access, correct, or delete your data from in-app Settings (Delete account), or by emailing info@crisp0.app. For EU/UK users: you have additional rights under GDPR including data portability and objection. For California users: you have rights under CCPA/CPRA including to know, delete, and opt out of sale/sharing (we do not sell your data).
Data retention
Signed-in chat logs are kept for up to 90 days for abuse review, then deleted. We retain account data while your account is active. If you delete your account, we delete it within 30 days, except where retention is required by law.
Security
Data is encrypted in transit (TLS) and at rest. We follow industry practices for access control and incident response. No system is perfectly secure; we will notify you of any breach affecting your data within 72 hours.
International transfers
Your data may be processed in the United States or other countries. Where required, we use Standard Contractual Clauses to protect transfers.
Children
Crisp0 is not directed to children under 13 (or 16 in the EU). We do not knowingly collect data from them. If we learn we have, we delete it promptly.
Changes
Material changes to this policy will be posted here with a new "Last updated" date and notified in-app.
Contact
Crisp0