Privacy Policy
This policy explains which personal data CR_IA collects when you use this site, what we use it for, who we share it with and how you can exercise your rights. It covers the whole site, including the chat with CR_IA.tura, our assistant.
1. Who controls your data
CR_IA (Brazilian company, CNPJ 18.038.734/0001-25). For any privacy matter, write to felipe@cria.pro.
2. What we collect
- In the CR_IA.tura chat: the messages you send and, when you choose to share them, your name, email, company, role, WhatsApp, project context and briefing files (PDF, text or image).
- Technical data: IP address (used only for rate limiting and abuse protection, kept for 24h) and browser type.
- Cookies: detailed in our Cookie Policy.
3. What we use it for
- Answering your contact and understanding your project.
- Preparing proposals and commercial follow-up when you ask for it.
- Sending communications about our products, when you agree.
- Improving CR_IA.tura's answers and our service.
- Protecting the site against abuse and fraud.
Legal basis under LGPD (Brazilian data protection law): consent for the data you share in the chat and for communications; legitimate interest for security and service improvement.
4. Who we share it with
We do not sell your data. We use processors acting on our behalf, only for the purposes above:
- Anthropic (US): processes chat messages to generate CR_IA.tura's replies.
- Supabase (US): hosts our database.
- Cloudflare (US): infrastructure, security and cookieless audience metrics.
- Klaviyo (US): email when you leave contact details.
- Notion (US): internal organization of business contacts.
- Discord (US): internal team notification when a new contact arrives.
- Resend (US): transactional email to our team.
5. How long we keep it
- Business contacts (leads): while the relationship lasts or until you ask for deletion.
- Chat conversations: up to 90 days, for support context.
- Technical rate-limit logs: 24 hours.
6. Your rights
You can request confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing and consent withdrawal. Write to felipe@cria.pro. We reply within 15 days.
7. Security
We use encryption in transit (HTTPS), role-based access control in the database and encrypted keys for integrations. No system is perfect; if anything relevant happens, we will notify you and the authorities as required by law.
8. Updates
This policy may change as the site evolves. The date at the top shows the current version.