Crow Nest Privacy Policy
Effective date: October 6, 2026
Last updated: October 7, 2026
This policy explains what personal information Defi LLC, doing business as Crow Nest ("we", "us"), collects when you use crow-nest.com, app.crow-nest.com, api.crow-nest.com, our command line tool and MCP connector (the "Service"), and what we do with it. The Service is for people in the United States who are 18 or older.
The short version:
- We collect what we need to run accounts, hosting, billing and safety. We don't sell your information and we don't run ads or advertising trackers.
- Your payment card goes to Stripe when you add it (including at sign-up if you choose Pay as you go). We never see or store the card number.
- If your employer uses Crow Nest, they can see your Tools and usage.
- Tools published on Crow Nest are made by other people. Each Tool's owner decides what it collects from you. See section 6.
- You can delete your account yourself, and you can ask us about your data any time at hello@crow-nest.com.
1. Who is responsible
Defi LLC, a Utah limited liability company, 1565 Grizzly Way, Payson, Utah 84651, hello@crow-nest.com. For information in accounts and Tools we run on your behalf, see section 6.
2. What we collect
Information you give us
| What | Why |
|---|---|
| Account details: your email address, name and profile picture (from Google or Microsoft, or just your email if you use an emailed code) | Create and run your account; show who you are to people you share with and to your organization |
| Sign-in identifiers: a unique ID from Google or Microsoft for your account | Recognize you when you sign back in |
| Your Tools: names, descriptions, the files and source code you publish, version history, who you share with (their email addresses), visibility settings | Host, serve and share them |
| Data your Tools store: database records and uploaded files, and settings and secrets you add (such as API keys) | Run your Tools. Secrets and AI keys are stored encrypted and are never shown back to you |
| Billing details: your plan and status. Card details are entered on Stripe's pages, not ours (Stripe asks for a card when you choose Pay as you go). We keep a Stripe customer ID, whether a card is on file, and billing period dates | Charge you, show your plan, enforce payment rules |
| Domain purchase details: name, email, mailing address and phone number you give us for registering a domain | Required by domain registration rules; passed to the registrar |
| Organization details: organization name, members, roles, invites (the invited person's email), permissions | Run organizations |
| Reports and messages to us: abuse reports (the reason, your description, and your email if you give it) and emails to hello@crow-nest.com | Handle reports, support, and legal requests |
Information collected automatically
| What | Why |
|---|---|
| Sessions and tokens: sign-in session records, API tokens (we store only a one-way hash), OAuth connection records for AI assistants you connect | Keep you signed in and secure your account |
| Usage counts: each time a Tool's page is opened, we record the Tool, the day, and (if the viewer is signed in) their account, or (if signed out on a public Tool) a hashed visitor identifier. Raw events are kept 90 days; daily totals are kept longer | Show Tool owners and organizations how much a Tool is used; find out which organizations use Crow Nest |
| Metering: counts such as database size, storage, function requests, and AI calls and tokens. We record counts, not the text of prompts or responses | Billing and limits |
| MCP/assistant activity: a log of which Crow Nest tool an assistant called for your account, which client, and whether it worked. Never file contents | Security, support, and debugging |
| Sign-in attempts: when you request an emailed code we record your email and IP address to limit abuse | Prevent abuse |
| IP address and device data: your IP address and browser information reach us (and our hosting providers) with every request. We use them for security, abuse prevention and rate limiting. For signed-out visitors to public Tools we use a keyed, one-way hash of the IP address, and not the address itself, to rate-limit and let Tool owners block abusive visitors | Security |
| Cookies: see section 5 | Sign-in and security |
We do not knowingly collect information from anyone under 18.
Information from others
- From Google or Microsoft when you sign in with them: your verified email, name, profile picture and a unique account ID.
- From your organization, when an administrator invites you or adds you.
- From Stripe: payment status and plan information (not card numbers).
- From people who report a Tool.
3. How we use information
- To provide, secure, support and improve the Service (including hosting your Tools and showing them to the people you choose).
- To create and manage accounts, including moving your account into an organization workspace (section 4).
- To bill you and prevent fraud and abuse.
- To investigate reports and enforce our Terms and Acceptable Use Policy, including suspending Tools.
- To send service emails: sign-in codes, invitations, billing and payment notices, security alerts, moved-account notices, domain renewal notices, and policy updates. These aren't marketing.
- To understand our customers and find businesses to contact. We look at sign-ups and usage grouped by email domain (for example "five people at example.com published tools") to decide which companies might benefit from Crow Nest, and we may contact those organizations as a business. We do not sell this information.
- To comply with the law and respond to legal requests.
- We do not use your Tools' contents or your data to train AI models.
4. Who can see your information
Your employer or organization. If you join an organization, or your account is moved into one because your email domain belongs to it, that organization's administrators can see your name and email, the Tools you publish (and who opens them), usage and cost information, and your role and permissions. Your Tools and their data then belong to the organization's workspace. We tell you before this happens.
People you share with. Anyone you share a Tool with, or any person who opens a public Tool, can see what the Tool shows them. People you share with see your name or email when the Tool or Crow Nest shows who made it.
Other users of Tools. Tool owners may see who opened their Tool (for signed-in viewers) and entries people submit to it.
Service providers that help us run Crow Nest, under contract and only to provide services to us. They are listed by kind, with what each receives, in our Subprocessor List: hosting and infrastructure, source code storage, payments and tax, email delivery, domain registration, sign-in, and website content delivery.
AI providers. When a Tool uses Crow Nest AI, the prompts and files it sends pass through our systems to the AI company that runs the model you picked (for example Anthropic or OpenAI), and the answer comes back the same way. If a Tool uses your own API key, requests go to the provider you chose (Anthropic, OpenAI, Google, or another service you configure). In both cases the AI company's own terms and privacy policy govern what it does with that data. We don't store the text of prompts or answers, only usage counts, and we don't use them to train AI models.
AI assistants you connect. If you connect an AI assistant (like Claude) to your Crow Nest account, it can act with the permissions you approved and receive information about your account and Tools. Its handling of that information is governed by its own provider's terms.
Legal and safety. We may disclose information if we believe it's required by law or legal process, or necessary to protect people, the Service or our rights (for example to investigate fraud or abuse).
Business transfers. If Crow Nest is involved in a merger, sale or financing, information may transfer to the new owner, who must honor this policy for existing data unless you're told otherwise.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Our staff can access account, Tool and usage information when needed for support, security, abuse handling, billing and legal compliance. Access is limited to people who need it.
5. Cookies and similar technologies
We use a small number of first-party cookies, set by us, to keep you signed in, secure sign-in and bot checks, and, for signed-out visitors to public Tools, to count unique visitors. We do not use advertising or cross-site tracking cookies, and we don't run third-party analytics services.
All of our cookies are first-party, host-only, secure (HTTPS only) and HttpOnly:
| Cookie | What it does | How long |
|---|---|---|
__Host-crow_session |
Keeps you signed in to Crow Nest | Up to 30 days, or until you sign out |
__Host-crow_tool |
Lets you open a protected Tool you have access to (that Tool's address only) | Up to 7 days, or until you sign out |
__Host-crow_oauth |
Protects the sign-in handshake with Google or Microsoft, or when you connect an AI assistant | A few minutes |
__Host-crow_pending |
Holds your place between signing in and creating an account (only a random ID) | About 10 minutes |
__Host-crow_anon |
Random ID so a Tool's owner can count how many different signed-out people opened a public Tool. We store only a one-way hash of it | Up to 1 year |
__Host-crow_pass |
Remembers you passed the human check, so it doesn't repeat for every action | About 30 minutes |
Tools made by other people may set their own cookies, which we don't control.
Some of our pages load fonts from Google Fonts, and some sign-in pages load Cloudflare's Turnstile bot check; when they do, your browser contacts those companies and shares your IP address and browser details with them. Our home page also loads a code library from the cdnjs content delivery network.
Do Not Track. We don't track you across other sites, so we don't change our behavior in response to Do Not Track signals.
6. Tools made by other people (important)
Crow Nest hosts Tools made by individuals and organizations. When you use someone else's Tool, that Tool's owner, not Crow Nest, decides what information it collects and why, and is responsible for it. For example, if you submit a form on someone's booking page hosted on Crow Nest, that person receives your submission. We store and process that data for them to run their Tool, as their service provider. Look for the Tool owner's own privacy notice, and contact them first for requests about data you gave to their Tool. If you can't reach them, write to us.
Don't submit information to a Tool you don't trust. If you think a Tool is misusing information, use the "Report" link or email us.
7. How long we keep information
| Data | How long |
|---|---|
| Account information | While your account is open, then deleted 30 days after you delete your account (we hold it for 30 days so we can restore it if you ask) |
| Tools, their data and files | While the Tool exists. After a Tool or account is deleted, kept for 30 days, then permanently deleted |
| Raw usage events | 90 days. Daily totals are kept without personal identifiers beyond the Tool and day |
| Sign-in sessions and tool sessions | Up to 30 days and 7 days respectively, and removed when you sign out or delete your account |
| Emailed sign-in codes | 10 minutes |
| Billing records | Kept by Stripe and by us as long as needed for tax, accounting and legal reasons (generally 7 years) |
| Domain registration contact details | While you own a domain through us, then as the registrar and the law require |
| Abuse reports | 2 years, longer if tied to a legal matter |
| Backups and logs | A limited time after deletion, then overwritten |
We may keep information longer if the law requires it, or to resolve disputes, enforce our agreements, or prevent fraud.
8. Security
We use reasonable measures including encryption in transit, encryption of stored secrets and keys, hashing of API tokens, restricted staff access, and rate limits. No system is perfectly secure, and we can't guarantee absolute security. Don't store information in a Tool that you couldn't afford to have exposed, and don't store regulated or highly sensitive data (see our Terms). If we learn of a breach affecting you, we will notify you and authorities as the law requires.
9. Your choices and rights
You can:
- See and update your name and email information in your account or by contacting us.
- Delete your account yourself in Settings → Manage account. This deletes your Tools, cancels a Flat subscription, removes your AI keys, secrets and sign-ins, and removes shares to your email. (If you're in an organization, ask an administrator or write to us.)
- Ask for a copy of your personal information, or a correction, or deletion of information we hold, by emailing hello@crow-nest.com. We'll verify it's you, and we'll respond within 45 days (and tell you if we need more time).
- Opt out of non-essential email. Service emails (sign-in, security, billing) are necessary. Any marketing emails will include an unsubscribe link.
- Manage cookies in your browser. Blocking them may stop sign-in from working.
- Appeal a decision about a request by replying to us; if you're still not satisfied, you may be able to contact your state's attorney general.
We won't discriminate against you for using these rights.
US state privacy laws. Some states (such as California, Colorado, Connecticut, Virginia, Utah and others) give residents rights to access, correct, delete and get a copy of their personal information, and to opt out of sale, targeted advertising and certain profiling. We honor these requests for all US users, whether or not a particular law applies to us. We don't sell personal information or use it for targeted advertising. California residents may also ask about disclosures to third parties for their direct marketing; we make none. You can use an authorized agent to make a request; we may ask for proof.
10. Children
The Service is not directed to anyone under 18, and we don't knowingly collect information from them. If you think a child has given us information, tell us at hello@crow-nest.com and we'll delete it.
11. Where information is processed
We and our providers process information in the United States and potentially other countries where our providers operate. The Service is intended for US users. If you use it from outside the US, you understand your information will be transferred to and processed in the US.
12. Changes to this policy
We'll post changes here with a new date, and for material changes we'll email you or show a notice in the product before they take effect.
13. Contact
Defi LLC, doing business as Crow Nest 1565 Grizzly Way, Payson, Utah 84651 hello@crow-nest.com