Crew

Subprocessors

Last updated

Crew Platforms, Inc. ("Crew") engages a small number of third-party vendors to provide the service. This disclosure lists each of them, the purpose it serves, its service category, and the categories of data it may process.

It is maintained from the application's own source rather than from a vendor questionnaire: a vendor is listed here because the code transmits data to it. It is updated when a vendor is added or removed.

1. Definitions and scope

Subprocessor
A vendor Crew itself engages, and depends on, to provide the service. Customers do not select these individually; they are engaged by Crew and are listed in section 2.
Customer-directed connected service
A system a customer connects and authorises Crew to access on its behalf. Crew acts on the customer's authorisation and holds no relationship with the provider of its own. These are not Crew subprocessors and are listed separately in section 3.

Data categories used in the table below have the meanings given in the Privacy Policy: Customer Content is the material a workspace works with; credentials are connection authorisations and stored keys; operational data is Crew's structured record of what the service did.

2. Crew subprocessors

Vendors Crew engages to provide the service
VendorService categoryPurposeData categories
SupabasePlatform infrastructurePrimary database, private file storage and authentication. Holds the application's system of record, and issues sign-in and one-time verification messages.Customer Content, credentials, operational data, account information
VercelPlatform infrastructureApplication hosting and scheduled execution; all request traffic is processed here. Where a deployment is configured to use it, Vercel also provides the isolated execution environments in which AI employees run.Customer Content, credentials, operational data
AnthropicAI model processingThe language model on which AI employees run. Receives the working context of a task: relevant company knowledge, employee notes, conversation, tool results and material read during the task. Where configured, an organisation-level cost total is retrieved for Crew's own billing reconciliation.Customer Content, operational data
ComposioConnected-application infrastructureInfrastructure for application connections made through Crew's connector catalogue. Holds the credential for each such connection and transmits the request and response of each action performed through it.Customer Content, credentials
E2BExecution environmentDefault provider of the isolated environment in which an AI employee runs commands: working files, cloned repositories, and any stored key injected into a command it executes.Customer Content, credentials
Voyage AISearch and retrievalGenerates the vector representations that allow an employee to retrieve information by meaning. Receives the text of recorded company knowledge and employee notes. Used where configured; where it is not, the same function is performed by OpenAI.Customer Content
OpenAIAI model processingSeveral distinct functions: vector generation where Voyage AI is not configured; transcription of voice notes and audio tracks; real-time voice sessions; and image generation. For image generation and transcription a key stored by the customer takes precedence over Crew's, in which case the relationship is the customer's own. Video generation never runs on Crew's key.Customer Content
TavilySearch and retrievalWeb search. Receives the search query, which is derived from the task an employee was given, and returns titles, links and extracts. Retrieval of a specific page is performed directly by Crew and does not pass through this vendor.Customer Content (queries)
StripePaymentsCrew's own billing: customer and subscription records, plan, invoices and the billing contact's address. Distinct from a customer's own Stripe account connected as an integration, which appears in section 3.Operational data, billing contact details
SentryError reportingApplication error reports from the server, edge and browser runtimes. Request bodies, cookies and authorisation headers are removed before transmission, session replay is not enabled, and reports that cannot be established as safe are discarded rather than sent.Operational data

One further outbound request is noted for completeness: when an AI employee renders a design, the renderer is a browser with network access and will retrieve any web font the design references, typically from Google Fonts. Those requests carry a font name and no workspace data. The application's own fonts are compiled at build time and are not retrieved by a visitor's browser.

3. Customer-directed connected services

The following are systems a customer connects. Crew accesses them on the authorisation the customer granted, for the actions the customer's permission settings allow. They are not Crew subprocessors and are listed here because a reviewer assessing where data can travel needs a single view of it.

Systems a customer connects, and the effect of disconnecting each
ServiceAccess grantedOn disconnection
Google — Gmail, Drive, CalendarReads mail and files, reads and creates calendar events, and sends mail as the customer's organisation, under a single grant taken through Google's consent screen.Revoked with the provider
SlackReads and posts in the channels the installed application can reach.Revoked with the provider
GitHub — OAuth applicationIdentifies the person connecting and acts on repositories under their grant.Revoked with the provider
GitHub — installed applicationAccesses repositories using installation-scoped tokens, separately from the OAuth application. The binding is verified twice: a signed state parameter, and confirmation that the connecting account controls the installation being claimed.Removed by the customer at GitHub
Stripe — connected accountReads the customer's Stripe account so that an employee can answer questions about payments, revenue and customers. Distinct from Crew's own billing in section 2.Revoked with the provider
VercelDeploys and inspects projects under a delegated authorisation taken through Vercel's consent screen.Revoked with the provider
Applications connected through ComposioAs exposed by the connected application and permitted by the customer's settings. Composio holds the credential; Crew does not store it.Connected account deleted at Composio
API keys stored by the customerUsed only for requests to the hosts a key is scoped to, issued by Crew's credential broker so the value is never exposed to the model. Permitted hosts, permitted employees and whether each use requires approval are set by the customer.Rotated by the customer at the provider
Revoked with the provider
Crew requests revocation of the grant with the provider before deleting its own copy of the credential. Where the provider refuses or is unreachable, the disconnection still completes and the failure is recorded, so a disconnection never silently has no effect.
Removed by the customer at GitHub
Crew deletes its installation record. No programmatic method exists to uninstall a GitHub application on a customer's behalf, so removal of the installation itself is performed in the customer's GitHub settings.
Rotated by the customer at the provider
A stored key has no remote revocation. Deleting it removes Crew's copy; rotating the key with its provider is a step only the customer can perform, and the product states this rather than implying the access is gone.

4. Updates and contact

This disclosure is updated when a subprocessor is added or removed. The date at the top indicates when every entry was last verified against the application's source. Crew does not currently operate an advance notification list for changes to this page.

Processing locations are not listed. Crew has not verified where each vendor processes the data it receives, and an unverified location on a disclosure of this kind is worse than an absent one.

5. Contact

Questions about this disclosure, or about a specific vendor, may be sent to the address below.

Questions about this disclosure, or about a specific vendor, can be sent to legal@crewplatforms.com.