Skip to content
Crixaa

Privacy Policy

Last updated 29 July 2026

This explains what we collect when you use Crixaa, why we collect it, who else sees it, and what you can ask us to do about it.

Who we are

Crixaa is a document template and PDF generation service operated by Crixaa.

If you use Crixaa through an account your employer created, they control that workspace and the content in it. We process that content on their instructions. Questions about their own access and retention decisions are best put to them directly.

What we collect

This is everything the application stores, as of 29 July 2026.

CategoryWhat that includes
Account detailsName, email address, password hash, avatar image, and the sign-in method used (email, one-time code, Google or GitHub).
Workspace detailsOrganisation name, logo, membership records and roles, and invitations you send.
Your contentTemplates and their version history, the data you supply when generating documents, the generated PDFs themselves, and comments you write.
Usage and audit recordsAn activity log of actions taken in your workspace, document lifecycle history, notifications, and webhook delivery attempts and responses.
API credentialsA hash of each API key (never the key itself), plus the time and IP address it was last used from.
Billing recordsYour subscription status, billing period, and a record of each successful charge including the amount and a payment reference. We do not store card numbers — see “Payments” below.
Technical dataServer logs and rate-limiting counters, which include IP addresses.

How we use it

To run the service: authenticating you, storing and rendering your templates and documents, delivering notifications and transactional email, taking payment for paid plans, enforcing rate limits, and investigating problems.

We do not sell your data, we do not share it for advertising, and we do not use the contents of your documents to train any model of our own.

Payments

Paid plans are billed through Razorpay. When you subscribe, your payment details are collected by Razorpay directly in their own checkout — card numbers and bank credentials never reach our servers and we cannot see them.

What we do keep is the outcome: your subscription status and billing period, and for each successful charge, the amount, currency, date and Razorpay's payment reference. That is what appears in the billing history in your workspace settings.

Razorpay processes this as an independent controller under their own privacy policy and the regulations governing payment processors.

AI features

When you use an AI feature — generating a template from a description, or repairing a page layout — the instruction you type and the relevant template layout are sent to our AI provider so it can produce a result. This happens only when you actively invoke one of those features.

If that is not acceptable for a particular document, do not use the AI tools on it. Everything else in the editor works without them.

Who else receives data

We use these providers to operate the service:

ProviderPurposeData involved
Amazon Web ServicesApplication hosting and databaseAll account, workspace and document data
VercelHosting for this websiteStandard web request logs
Cloudflare R2Object storageGenerated PDFs, avatars and organisation logos
ResendTransactional emailRecipient email address and message content
RazorpaySubscription paymentsBilling contact details and payment instrument data, collected directly by Razorpay
DeepSeekAI template generation and layout repairThe instructions you type and the template layout being edited, when you use an AI feature
Google and GitHubOptional single sign-onBasic profile and email, only if you choose to sign in that way

We may also disclose data where the law requires it, or where it is necessary to investigate abuse or protect our users.

How long we keep it

CategoryRetention
Account and workspace dataFor as long as the account is open, then deleted within 90 days of closure.
Templates, documents and commentsUntil you delete them, or within 90 days of the workspace closing.
Billing recordsRetained for as long as tax and accounting law requires, even after closure.
Activity and audit logsUp to 12 months.
Server logsUp to 30 days, unless retained longer for a specific security investigation.

Backups lag deletion by design. Data removed from the live service can persist in encrypted backups for a further 30 days before those are cycled out.

Your rights

You can ask us to do any of the following.

RightWhat it means
AccessAsk what personal data we hold about you and get a copy.
CorrectionCorrect anything inaccurate — most of it is editable in your profile.
DeletionAsk us to delete your account and personal data, subject to records we must keep by law.
PortabilityReceive your data in a machine-readable form. Templates export as JSON from the editor.
ObjectionObject to a particular use of your data, and we will stop unless we have an overriding legal reason.

Write to privacy@crixaa.com and we will respond within 30 days. We may need to verify who you are first — that is a safeguard for you, not an obstacle.

Where your data is held

Our infrastructure runs in India, and our providers may process or store data in other countries. Where data crosses a border, we rely on the safeguards our providers offer — standard contractual clauses or an equivalent mechanism — and we require them to protect it to the standard described here.

Security

Traffic is encrypted in transit. Passwords are stored hashed, never in plain text, and API keys are stored as hashes so the original value cannot be recovered — which is why a key is shown only once when you create it.

Generated documents are held in private storage and served through short-lived links rather than public URLs. Access within a workspace is governed by the role each member holds.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority without undue delay once we understand the scope.

Cookies and local storage

We do not use cookies. Signing in stores an access token and a refresh token in your browser’s local storage, along with small preferences such as your chosen theme and which workspace you last had open. These stay on your device, are sent only to our own API to authenticate your requests, and are cleared when you sign out. There is no advertising, no cross-site tracking, and we do not currently run third-party analytics. If that changes, this section changes with it and we will ask for consent where required.

Children

Crixaa is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.

Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we handle your personal data, we will tell you in the app or by email rather than relying on you noticing.

Contact

Questions, requests, or complaints: privacy@crixaa.com.

See also our Terms of Service.