Privacy Policy
Last updated: June 12, 2026
Cresca, Inc. (“Cresca”, “we”, “us”) is a professional networking app: digital cards, contacts, notes, meetings, and events. This policy explains what information we collect, how we use it, who processes it on our behalf, and the choices you have. It applies to the Cresca mobile app and the cresca.ai website.
Information we collect
Everything below is information you choose to put into Cresca:
- Account. Your email address, sign-in credentials (passwords are stored only in hashed form by our authentication provider), and — if you sign in with Google or Apple — the basic identity those providers share with us.
- Profile and cards. The details you put on your cards and profile: name, photo, title, organization, headline, links, and optional résumé-style sections (work experience, education, skills, languages, certifications, projects, publications, and similar). If you use the LinkedIn import, the archive you upload is parsed into these same profile sections at your direction.
- Contacts and connections. Cards you save or exchange, the contact details on them, and the private notes you keep about your contacts.
- Notes and recordings. Text notes, attachments, and voice recordings with their transcripts. Recording audio is transient: after a recording is transcribed, the audio file is permanently deleted from our servers within about 48 hours. Transcripts and notes are kept until you delete them.
- Meetings and events. Meeting invitations and details, event registrations, check-ins, and event badges.
- Forms. Forms you create and the responses they collect. When someone submits a public form we also store a one-way hash of their IP address (never the address itself) and a random device identifier, used only for rate limiting and duplicate prevention.
- Technical data. Standard server and security logs kept by our hosting providers. The app contains no advertising and no third-party analytics or tracking SDKs.
How we use your information
- To provide the service: storing and syncing your cards, contacts, notes, meetings, events, and forms.
- To send email on your behalf when you ask us to — for example meeting invitations and follow-ups, or notifications about changes to a meeting. These are sent from cresca.ai addresses via our email provider.
- To run AI features you invoke (see the next section).
- To keep the service secure: abuse prevention, rate limiting, and CAPTCHA on public forms.
We do not sell your personal information, and we do not use it for advertising. We may use de-identified or aggregated information that cannot reasonably identify you to operate, secure, and improve the Service.
AI features
Some features use large-language-model APIs operated by third parties — currently Google (Gemini); we may also use other providers such as OpenAI (ChatGPT) or Anthropic. When you invoke an AI feature (asking the assistant a question, transcribing a recording in the cloud, or generating a summary), the relevant content — your prompt, the recording audio, or the transcript — is sent to the provider’s API to produce the result, under that provider’s API terms. We do not use your content to train models. The app also offers on-device transcription: with it enabled, transcription happens entirely on your phone and the audio content is not sent to a cloud AI. You can turn AI features off at any time in Settings.
Who processes data for us
We use a small set of service providers to run Cresca:
- Supabase — database, authentication, file storage, and server functions (our backend).
- Vercel — hosting for the cresca.ai website.
- Expo (EAS) — app builds and over-the-air app updates.
- Resend — delivery of the emails described above.
- Google — Sign in with Google; Gemini API for AI features.
- Apple — Sign in with Apple.
- Cloudflare — Turnstile CAPTCHA on public form pages.
- Sentry — crash and error reporting (device/OS details, app version, and a stack trace when the app crashes or hits an unexpected error).
Each provider processes only what its role requires, and your data may be processed in the regions where these providers operate.
When we may disclose information
Beyond the processors above and the people you choose to share things with, we disclose information only: to comply with law or a valid legal request; to protect the rights, safety, or property of Cresca, our users, or others; to enforce our terms; or — if Cresca is ever part of a merger, acquisition, or sale of assets — to the successor entity, in which case this policy continues to apply and we will notify you of material changes.
What other people see
Cresca is a networking product: when you share or exchange your card, the recipient keeps their own copy — like a paper business card. That copy is the recipient’s record. If you later change your card or delete your account, copies you already gave to others remain with them, but they stop linking back to your live profile. What recipients do with their copy is their responsibility — the same as with a paper business card — and you are responsible for choosing what you share and with whom.
Retention and deletion
- Account deletion. You can delete your account at any time in the app (Settings → Account → Delete account). Deletion is immediate and irreversible from your perspective — you are signed out everywhere and your account disappears — and the underlying data is permanently erased from our systems within 30 days.
- Recording audio is permanently deleted within about 48 hours of successful transcription, as described above.
- Cards held by others remain with the people you gave them to, as described above.
- Unsubscribe records are kept so that an address that opted out of email stays opted out.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise access, correction, and deletion directly in the app; for export or anything else, contact us at the address below and we will respond within 30 days.
Security
Data is encrypted in transit, stored with per-user access controls enforced at the database layer, and accessible only through audited server functions. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
Children
Cresca is not directed to children and may not be used by anyone under 16. We do not knowingly collect information from children.
Changes
We will post any changes to this policy on this page and update the date above. For material changes we will notify you in the app or by email.
Contact
Questions or requests: support@cresca.ai