← Back to app

Privacy Policy

Last updated: July 2026

What Crack is

You enter a brief. We generate creative concepts. That's the product. We're not interested in your data beyond what it takes to make that work.

What we collect

To use Crack, you sign in with your email address. We store that email and a session token — nothing else identifying. No name, no phone number, no payment details beyond what's needed to manage your subscription.

Our server logs basic request data — IP address, browser type, timestamp, pages visited. Standard stuff that exists for debugging. It's not linked to you as a person.

Your briefs

The briefs you enter are sent to Anthropic's Claude API to generate concepts. We don't store your brief text after the session ends. We don't read it, sell it, or use it for anything other than generating your output. Your client's brief stays yours.

The exception is sharing — a concept you share is stored so the link works, until you delete it. Only the concept content is stored (no brief text). You can delete a shared concept at any time using the Unshare button on the concept card.

Anthropic doesn't use API inputs to train their models by default — your work isn't feeding someone else's machine. Their full privacy policy is at anthropic.com/privacy.

Where your work lives

We use a session cookie to keep you signed in. Your brief history is saved to your account, so your work follows you between machines — and cached in your browser so it loads fast. PostHog sets a first-party cookie so our product counts aren't double-counted. No third-party advertising cookies, ever. We're an advertising tool. We find that stuff distasteful.

Who else is involved

Crack uses Anthropic's Claude API for concept generation, OpenAI's API for scamp images and archive search, Pinecone for searching our archive of award-winning campaigns, Supabase for account and session storage, Stripe for payments (we never see your card number), Resend for the sign-in emails, Railway for hosting, Cloudflare for keeping the site fast and up, and PostHog for product analytics. Each has their own privacy policy. That's the full list. On PostHog: we use it to count product events — briefs generated, errors hit, features used. It tells us what happened, not who you are. No session recording, no cross-site tracking, and your briefs and concepts are never in the data. We don't use Google Analytics or advertising trackers.

Your data, your call

We store your email address, session data and your brief history. If you want us to delete your account and everything associated with it — history included — email [email protected] and we'll do it within 30 days. Deleting a brief in the app removes it from your account, not just from the device you're on.

Questions

Email us at [email protected]. We're a small team and we actually read it.