Privacy Policy
Last updated: September 17, 2026
Cresca, Inc. (“Cresca”, “we”, “us”) is a private relationship-memory app that helps you remember the people you meet and the context of your relationships, with features including digital cards, contacts, notes, meetings, and events. This policy explains what information we collect, how we use it, who processes it on our behalf, and the choices you have. It applies to the Cresca mobile app and the cresca.ai website.
Information we collect
Everything below is either information you choose to put into Cresca, or — in the case of location — something you have to switch on yourself before we record any of it:
- Account. Your email address, sign-in credentials (passwords are stored only in hashed form by our authentication provider), and — if you sign in with Google or Apple — the basic identity those providers share with us.
- Profile and cards. The details you put on your cards and profile: name, photo, title, organization, headline, links, and optional résumé-style sections (work experience, education, skills, languages, certifications, projects, publications, and similar). If you use the LinkedIn import, the archive you upload is parsed into these same profile sections at your direction.
- Contacts and connections. Cards you save or exchange, the contact details on them, and the private notes you keep about your contacts.
- Notes and recordings. Text notes, attachments, and voice recordings with their transcripts. Recording audio, transcripts, and notes are kept until you delete them.
- Meetings and events. Meeting invitations and details, event registrations, check-ins, and event badges.
- Payments. If you buy credits or a plan, or pay admission to an event, you enter your card details on a page run by Stripe; we never receive your full card number. We keep a record of each payment — amount, currency, status (such as paid or refunded) and Stripe’s reference numbers — with your account and, for an event, with your registration.
- Location. Off by default. If you turn it on, Cresca records where you were when you save something, and reads the location stored inside photos you add. See Location below for exactly what this covers and how to switch it off.
- Forms. Forms you create and the responses they collect. When someone submits a public form we also store a one-way hash of their IP address (never the address itself) and a random device identifier, used only for rate limiting and duplicate prevention.
- Technical data. Standard server and security logs kept by our hosting providers. The app contains no advertising and no third-party analytics or tracking SDKs.
How we use your information
- To provide the service: storing and syncing your cards, contacts, notes, meetings, events, and forms.
- To send email on your behalf when you ask us to — for example meeting invitations and follow-ups, or notifications about changes to a meeting. These are sent from cresca.ai addresses via our email provider.
- To run AI features you invoke (see below).
- If you turn location on: to label your own records with where you were, so you can remember where you met someone or took a note.
- To keep the service secure: abuse prevention, rate limiting, and CAPTCHA on public forms.
We do not sell your personal information, and we do not use it for advertising. We may use de-identified or aggregated information that cannot reasonably identify you to operate, secure, and improve the Service.
Location
Location is off until you turn it on, and one switch turns it back off. Cresca never asks for it during sign-up. The first time it could be useful — when you save someone’s card — we explain why and ask. If you say no, or never turn it on, nothing in this section happens.
The two different things we collect
- Where you are when you save something. With location on, we record the device’s coordinates at that moment. We ask your device for an approximate fix (roughly city-block accuracy — we never request navigation-grade precision), we only ever ask while you are using Cresca, and we never collect location in the background or when the app is closed. This applies to: saving a card, connecting with someone, writing a note or adding a photo, file, or voice memo, starting and stopping a long recording, checking in or out of an event, and starting a conversation with the assistant. On the cresca.ai website there are two such moments — event check-in, and saving a card — and your browser asks for its own permission separately.
- The location stored inside a photo you add. Photos usually carry the coordinates and time of where and when they were taken (“EXIF” data). This is not the same thing as where you are now: it is where the camera was, possibly years ago. When you attach a photo and location is on, we read that embedded location and use it for that photo, because it is the more accurate answer to “where was this?”. We do not scan your photo library — only the photos you choose to add.
If a location cannot be obtained quickly, we simply save your note, card, or check-in without one. Location never blocks or delays anything.
Why
To anchor what you save to a place, so you can remember where you met someone or where you took a note. People forget dates but remember places. That is the entire purpose. Location is not used for advertising, not used to track you across apps or websites, not sold, not shared with data brokers, and not shared with other Cresca users — a place you recorded is visible only to you, and is never attached to the card, note, or profile anyone else receives.
Turning coordinates into a place name
Coordinates on their own are not a memory aid, so we look up a place name for them. We try, in order: places you have already named yourself; the address of the event you are checked into; a shared place-name dictionary that stores names by map square and contains no user identifiers; and your phone’s own built-in geocoder (part of iOS or Android, which resolves the name on the device). Only when those come up empty — or when you tap a place and tell us the name is wrong — do we send the coordinates to Google’s Geocoding API to get a name back. In that case we send the coordinates and a language, and nothing else: not your identity, not your note, not who you met.
Turning it off, and deleting places
- One switch. Settings → Location in the app turns location off entirely. From that moment we collect no location at all, from any of the moments listed above. You can also revoke the permission in your phone’s or browser’s own settings, which has the same effect.
- Per-record deletion. Where a record shows a place, tap it and you can correct it or remove it. Removing the location deletes only that place — the note, card, or check-in it was attached to is untouched. A few records hold coordinates we were never able to turn into a place name, so nothing is displayed on them; write to us at support@cresca.ai and we will remove any location we hold for you, displayed or not.
- Retention. A place is stored as part of the record it belongs to, not as a separate location history, and it is kept for as long as you keep that record. Deleting your account erases all of it, on the same schedule as the rest of your data (see Retention and deletion below).
AI features
Some features use large-language-model APIs operated by third parties — currently Google (Gemini); we may also use other providers such as OpenAI (ChatGPT) or Anthropic. When you invoke an AI feature (asking the assistant a question, transcribing a recording in the cloud, or generating a summary), the relevant content — your prompt, the recording audio, or the transcript — is sent to the provider’s API to produce the result, under that provider’s API terms. We do not use your content to train models. The app also offers on-device transcription: with it enabled, transcription happens entirely on your phone and the audio content is not sent to a cloud AI. You can turn AI features off at any time in Settings.
Who processes data for us
We use a small set of service providers to run Cresca:
- Supabase — database, authentication, file storage, and server functions (our backend).
- Vercel — hosting for the cresca.ai website.
- Expo (EAS) — app builds and over-the-air app updates.
- Resend — delivery of the emails described above.
- Google — Sign in with Google; Gemini API for AI features; Maps Geocoding API, used as the last resort to turn coordinates into a place name (coordinates only — see Location above).
- Apple — Sign in with Apple.
- Cloudflare — Turnstile CAPTCHA on public form pages.
- Sentry — crash and error reporting (device/OS details, app version, and a stack trace when the app crashes or hits an unexpected error).
- Stripe — payments: credits and plans, and admission to events whose organizers charge for it (paid into the organizer’s own Stripe account).
Each provider processes only what its role requires, and your data may be processed in the regions where these providers operate.
When we may disclose information
Beyond the processors above and the people you choose to share things with, we disclose information only: to comply with law or a valid legal request; to protect the rights, safety, or property of Cresca, our users, or others; to enforce our terms; or — if Cresca is ever part of a merger, acquisition, or sale of assets — to the successor entity, in which case this policy continues to apply and we will notify you of material changes.
What other people see
Sharing works the way professional networking always has: when you share or exchange your card, the recipient keeps their own copy — like a paper business card. That copy is the recipient’s record. If you later change your card or delete your account, copies you already gave to others remain with them, but they stop linking back to your live profile. What recipients do with their copy is their responsibility — the same as with a paper business card — and you are responsible for choosing what you share and with whom.
If you pay admission to an event, its organizer sees in Cresca whether you’ve paid or been refunded, and sees the payment in their own Stripe account, including your name, email address, and your card’s brand and last four digits.
Retention and deletion
- Account deletion. You can delete your account at any time in the app (Settings → Account → Delete account). Deletion is immediate and irreversible from your perspective — you are signed out everywhere and your account disappears — and the underlying data is permanently erased from our systems within 30 days.
- Recording audio is kept until you delete the recording it belongs to, and is erased with your account.
- Cards held by others remain with the people you gave them to, as described above.
- Locations are kept with the record they belong to. You can remove any place shown on a record at any time, you can ask us to remove any location we hold for you, and account deletion erases them all.
- Unsubscribe records are kept so that an address that opted out of email stays opted out.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise access, correction, and deletion directly in the app; for export or anything else, contact us at the address below and we will respond within 30 days.
Security
Data is encrypted in transit, stored with per-user access controls enforced at the database layer, and accessible only through audited server functions. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
Children
Cresca is not directed to children and may not be used by anyone under 16. We do not knowingly collect information from children.
Changes
We will post any changes to this policy on this page and update the date above. For material changes we will notify you in the app or by email.
Contact
Questions or requests: support@cresca.ai