Privacy Policy

How CrystalSlate handles account and workflow information.

Effective July 26, 2026 · Last updated July 30, 2026 · Version 1.2.0

1. Scope

This policy applies to crystalslate.com, app.crystalslate.com, CrystalSlate accounts, subscriptions, support, documentation, and the hosted workflow workspace. It does not govern Smartsheet, Stripe, Render, AWS, Cloudflare, or other third parties when you interact with them directly.

2. Information you provide

  • Account information: work email, password hash, optional organization name, verification state, profile settings, and agreement acceptances.
  • Subscription information: selected interval, purchased seat quantity, seat invitations and assignments, subscription status, and Stripe customer or subscription references.
  • Support information: messages, redacted screenshots, problem descriptions, and other context you choose to provide.
  • Smartsheet connection information: a personal API token you enter in Settings and the role/account details returned by Smartsheet. Token mode keeps the token in tab memory by default. If you explicitly choose “Remember” on a trusted browser, an encrypted copy and its non-exportable device key remain only in that browser profile for up to 30 days; CrystalSlate does not store that remembered copy in its database.

Do not send tokens, passwords, session cookies, one-time links, or unnecessary customer data to support.

3. Smartsheet workflow information

CrystalSlate processes the Smartsheet information needed for the workflow you request, which may include asset metadata, rows or columns, formulas, users, groups, sharing details, attachments, and API response information visible to the connected Smartsheet account.

The current token-mode workspace sends requested calls through the CrystalSlate server proxy. Smartsheet sheet contents and attachment files are processed on demand and are not retained as a general server-side copy. CrystalSlate may retain limited operational metadata about a supported write, such as the tool used, timestamp, result, and affected-object reference, for audit, security, and troubleshooting purposes.

Tokens are excluded from Activity payloads and are not intended to appear in diagnostics. A remembered browser copy is scoped to the signed-in CrystalSlate account and selected workspace, is removed by Clear or Forget, becomes unavailable at expiry and is deleted the next time CrystalSlate loads in that browser, and is removed if Smartsheet rejects it. Browser encryption reduces at-rest exposure but cannot protect a token from malicious code running in the same signed-in browser origin. Exports and screenshots created from workspace data should be treated as customer data by your organization.

4. Information collected automatically

CrystalSlate may collect session identifiers, IP address, browser or user-agent details, request timestamps, security and rate-limit events, service health information, and Activity records for supported write operations. Optional diagnostics begin only after the applicable opt-in and are sanitized to reduce emails, token-like values, long identifiers, and URL query data.

Tool selections, workflow settings, and Activity records may still be customer or personal information when associated with an account or organization. CrystalSlate minimizes these records and does not describe identifiable operational data as anonymous.

5. How information is used

  • Provide and secure accounts, sessions, trials, subscriptions, seats, and workflows.
  • Send verification, password-reset, invitation, trial, billing, cancellation, security, and support messages.
  • Process requested Smartsheet operations and create Activity evidence for supported writes.
  • Prevent abuse, investigate failures, enforce limits, and maintain service reliability.
  • Meet legal, tax, accounting, dispute, and security obligations.
  • Improve CrystalSlate using voluntary feedback and aggregated or de-identified operational information.

CrystalSlate does not sell personal information, use customer data for behavioral advertising, or use Customer Data or Smartsheet data to train or improve artificial-intelligence or machine-learning models. Any future customer-content AI feature would require a separate, explicit written opt-in and disclosed service-provider terms; it will not be enabled by a general diagnostics or product-update preference.

6. Service providers and disclosures

CrystalSlate uses service providers to operate the service:

  • Render: application hosting, managed PostgreSQL, and persistent service storage.
  • Stripe: Checkout, subscriptions, invoices, customer billing portal, payments, and tax calculation where enabled.
  • Amazon SES: transactional email delivery.
  • Cloudflare: DNS, TLS, caching, and public-site delivery.
  • Better Stack: external uptime monitoring and public status-page hosting, plus privacy-restricted Sentry-compatible application error reporting when enabled.
  • Smartsheet: the third-party platform receiving API requests you direct CrystalSlate to make.

Information may also be disclosed when required by law, needed to protect rights or safety, involved in a business transaction, or directed by the customer. Service providers receive only the information reasonably needed for their function.

7. Retention and deletion

CrystalSlate retains account, subscription, security, support, and Activity information only for as long as reasonably needed to provide the service and satisfy legal, tax, dispute, fraud-prevention, and audit obligations. Smartsheet sheet contents and attachments processed on demand are not retained as a general server-side archive. The current account-deletion design uses a 90-day processing window before direct profile identifiers are removed or anonymized, while non-identifying billing and audit references may be retained longer where required. Deletion from encrypted provider backups may follow the provider’s normal rotation schedule.

Because the retention mapping is still undergoing legal and operational review, broader customer launch remains gated on that review. You may request deletion or ask about a specific record by email.

8. Security

CrystalSlate uses password hashing, session and CSRF protections, role and entitlement checks, encrypted transport, restricted service credentials, confirmation controls, Activity logging, rate limits, and diagnostic scrubbing. No system can guarantee absolute security. Protect your account and rotate a Smartsheet token immediately if you believe it was exposed.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of certain personal information, or object to particular processing. You can update some information through your account and can email a request for anything not available there. CrystalSlate may need to verify your identity and retain records that cannot lawfully or safely be deleted immediately.

10. Children and international use

CrystalSlate is a business service for adults and is not directed to children under 13. Accounts require users to be at least 18. Information may be processed in the United States and other locations used by the listed service providers, subject to applicable safeguards.

11. Changes and contact

Material policy changes will be posted here and communicated where required. CrystalSlate is using email-only contact during its controlled initial launch. For privacy requests, email hello@crystalslate.com with “Privacy request” in the subject.

No physical mailing address is published at this stage. A registered postal contact will be added when required for a particular communication, program, or legal obligation.