CruxRelay
First Customer KitFor buyersMethodFirst Customer SprintContact
HomeBETA PRIVACY NOTICE / VERSION 2026-08-10-CRUXRELAY-6

Privacy, kept commercially useful and deliberately narrow.

This notice explains how CruxRelay handles information submitted to the workspace and the First Customer Sprint. The data controller is Himanshu Garg.

What CruxRelay collects

When you apply to the First Customer Sprint, CruxRelay collects the work email, company, role, region, participant type, product URL, target buyer, product stage, and factual workflow description you submit. Basic source and campaign attribution may be recorded to understand how applicants found the program. When you sign in, Firebase Authentication supplies your account identifier, email, display name, and optional profile image. Saved Capability Passports and Problem Rooms include the product or workflow inputs and generated drafts you choose to save.

Unless you select “Exclude this run” before starting, after this browser generates a signed-in report it submits a private validation receipt containing your Firebase account identifier, verified account email, Firebase profile name or the name you supplied, product name, a canonical HTTPS product URL with query parameters and fragments removed, target region, analysis and report versions, and the server receipt time. The server authenticates the account, limits receipt volume, and makes retries idempotent; because the AI pipeline runs in the browser, the receipt remains an authenticated self-report and does not independently prove pipeline completion or helpfulness. It does not contain your product description, generated report, AI prompt, or raw website content.

If you choose to send First Customer Kit feedback, CruxRelay records the selected usefulness verdict, issue category, optional note, kit version and source mode, target region, actions taken on the result before feedback, and basic source/campaign attribution. The feedback submission does not include your product description, generated kit, email, authentication identifier, or social username.

If you separately volunteer public proof, CruxRelay records the display name, product name and canonical URL already linked to your private receipt, your usefulness choice, optional outcome, a versioned public-display consent, and its time. Your email is not copied into the display-safe fields. Every submission remains private and pending human review; it is not published automatically.

When you use Contact CruxRelay, the form records your name, work email, optional company or organization, inquiry topic, message, privacy-notice acknowledgment, and basic source/campaign attribution. Short-lived abuse-prevention records use secret-keyed pseudonymous network and email identifiers; raw network addresses are not stored in those records.

Why it is used

Application information is used to evaluate program fit, contact you about the application, operate the Sprint, prevent abuse, and facilitate a human-reviewed introduction only after both sides agree. Private product-test receipts are processed on the basis of legitimate interests to measure authenticated, self-reported beta use, prevent duplicate retry records and high-volume abuse, investigate failed receipts, and support accurate aggregate product and fundraising reporting. The receipt is not a testimonial, independently verified completion, or customer, and is never public by default. You may exclude a run before it starts or object later through the privacy-contact route below.

Optional kit feedback is used to identify generic or incorrect outputs and improve the beta. Optional public-proof information is reviewed only for the display permission you requested; consent can be withdrawn at any time. Contact-form information is used to review and respond to the request you initiated, prevent abuse, and maintain a limited operational record. It is not added to marketing lists. Optional product news or future program invitations are sent only when the separate marketing box is selected, and that choice can be withdrawn at any time. CruxRelay does not sell personal information, create third-party advertising audiences, or disclose an application or contact inquiry to a prospective buyer, builder, or connector without approval.

AI processing, public website inspection, and optional market signals

The beta uses Firebase AI Logic with Google Gemini. After you sign in and start an analysis, submitted product and workflow text is processed by three bounded AI stages: product-evidence extraction, buyer-hypothesis reasoning, and paid-proof and launch-kit synthesis. If you supply a public product URL, Firebase URL Context attempts to retrieve that exact page. CruxRelay checks the provider’s retrieval metadata before saying the website was inspected, displays the resulting evidence ledger in your report, and treats visible marketing language as a website claim rather than a verified fact.

If you separately run the Market Signal Lens, CruxRelay sends a minimized research context—product name, public URL, one-line capability, current buyer hypothesis, target region, and paid-proof premise—to Firebase AI Logic with Google Search grounding. It asks for recent indexed public evidence and may surface pages from Reddit, X, Quora, or other public websites. CruxRelay does not connect to your social accounts, scrape those platforms, create contact lists, or claim exhaustive coverage. The grounded scan and links remain in the current page session and are included in a local PDF or text file only when you choose to download one; they are not saved into your Firebase workspace.

CruxRelay does not intentionally store raw website content or AI prompts in Firestore; the generated report can be kept on your device and is stored in your private Firebase workspace only when you choose to save it. Contact-form messages are not sent to an AI model. Do not submit credentials, special-category data, personal customer records, confidential invoices, private URLs, or data you are not authorized to process. Generated claims, buyer hypotheses, public-signal interpretations, and market conclusions remain unverified until human review.

Infrastructure and location

The intended beta data plane is Cloud Firestore in an EU multi-region. Firebase Authentication, Hosting, App Check, Cloud Functions, and AI Logic are Google services and may involve additional processing locations and subprocessors under Google’s terms. A copy of each contact inquiry is delivered through Google Gmail to a private operational mailbox; the recipient address and mail credential are held only as server-side secrets and are not exposed by the website. Enterprise corridor requirements will be assessed before any confidential or production data is accepted.

Retention and rights

Sprint applications, optional kit feedback, and Firestore contact records are scheduled to expire 90 days after submission; Firestore deletion normally completes shortly after expiry unless the person enters an active relationship, asks us to retain necessary information, or a longer period is required by law. The private Gmail notification copy is deleted separately on the same 90-day schedule, and an applicable deletion request covers both copies. Pseudonymous contact rate-limit records are scheduled to expire after 48 hours. Private product-test receipts are scheduled to expire after 365 days. An active public-proof consent and its public projection are scheduled to expire after 365 days unless consent is renewed; after withdrawal, display-safe fields are removed immediately and only a minimal suppression and audit record is retained for up to 730 days.

Workspace records are retained while the account is active and reviewed after a deletion request. You may request access, correction, export, restriction, objection, or deletion where applicable. Public-display and marketing consent can be withdrawn at any time; a minimal suppression record may be retained to honor that choice. The product checks linked public-proof status on reload and provides a withdrawal control for an active permission; the privacy-contact route below remains available for any record.

Sprint outcomes

The First Customer Sprint has a target of helping selected founders reach a first paid proof within 45 days. Selection, an introduction, a customer, a purchase, revenue, or any particular timing is not guaranteed. Application information is used to support the process described above, not to fabricate demand or make an automated purchasing decision.

Cookies, feedback, and analytics

Essential Firebase authentication and security storage may be used. Kit feedback is sent only when you actively submit the feedback form and accept its separate notice; that feedback choice is separate from analytics consent.

Google Analytics for Firebase loads only after you select “Allow analytics.” When allowed, Google may receive page and session events, a limited set of recognized referral and campaign tags, browser and device information, an approximate region, and a pseudonymous first-party identifier. CruxRelay does not intentionally send your product description, generated kit, feedback note, email, Firebase authentication identifier, or social username to Analytics. Advertising storage, advertising user data, ad personalization, Google Signals, and personalization storage are disabled. The email-link completion route is excluded, automatic page views are disabled, and query strings or fragments outside the recognized campaign allowlist are not sent.

Refusing analytics does not restrict the product. CruxRelay stores a versioned record of your choice on this browser for up to 180 days so it can remember it, after which it asks again. You can allow or withdraw analytics at any time through “Analytics choices” in the footer or the persistent site control. Withdrawal stops future collection on that browser and removes accessible Google Analytics cookies, but it does not automatically delete information already sent to Google. Contact the controller below to request deletion or exercise another applicable right.

Contact the controller

Himanshu Garg is the data controller for this beta. Use Contact CruxRelay and select “Privacy request” to request access, correction, export, restriction, objection, or deletion, or write to 3186, Sector 21 D, Chandigarh. If you are in a jurisdiction with a data-protection authority, you may also have the right to lodge a complaint with that authority.

HUMAN CONTACT

Need a human answer?

Product feedback, buyer problems, founder-program questions, partnerships, beta support, or privacy requests.

Contact CruxRelay Read the method
CruxRelay

From a shipped B2B AI product to a testable first-buyer plan.

Build a free kit
ProductFirst Customer KitFor buyersPrivate workspace
Work with usFirst Customer SprintMethod & safeguardsContact CruxRelay
TrustPrivacy noticeBeta terms
© 2026 CruxRelay · Global betaOperated by Himanshu Garg · Chandigarh, IndiaBuyer hypotheses, not verified demand · nothing is shared without approval