Crow Nest

Crow Nest Privacy Policy

Effective date: October 6, 2026
Last updated: October 7, 2026

This policy explains what personal information Defi LLC, doing business as Crow Nest ("we", "us"), collects when you use crow-nest.com, app.crow-nest.com, api.crow-nest.com, our command line tool and MCP connector (the "Service"), and what we do with it. The Service is for people in the United States who are 18 or older.

The short version:

1. Who is responsible

Defi LLC, a Utah limited liability company, 1565 Grizzly Way, Payson, Utah 84651, hello@crow-nest.com. For information in accounts and Tools we run on your behalf, see section 6.

2. What we collect

Information you give us

What Why
Account details: your email address, name and profile picture (from Google or Microsoft, or just your email if you use an emailed code) Create and run your account; show who you are to people you share with and to your organization
Sign-in identifiers: a unique ID from Google or Microsoft for your account Recognize you when you sign back in
Your Tools: names, descriptions, the files and source code you publish, version history, who you share with (their email addresses), visibility settings Host, serve and share them
Data your Tools store: database records and uploaded files, and settings and secrets you add (such as API keys) Run your Tools. Secrets and AI keys are stored encrypted and are never shown back to you
Billing details: your plan and status. Card details are entered on Stripe's pages, not ours (Stripe asks for a card when you choose Pay as you go). We keep a Stripe customer ID, whether a card is on file, and billing period dates Charge you, show your plan, enforce payment rules
Domain purchase details: name, email, mailing address and phone number you give us for registering a domain Required by domain registration rules; passed to the registrar
Organization details: organization name, members, roles, invites (the invited person's email), permissions Run organizations
Reports and messages to us: abuse reports (the reason, your description, and your email if you give it) and emails to hello@crow-nest.com Handle reports, support, and legal requests

Information collected automatically

What Why
Sessions and tokens: sign-in session records, API tokens (we store only a one-way hash), OAuth connection records for AI assistants you connect Keep you signed in and secure your account
Usage counts: each time a Tool's page is opened, we record the Tool, the day, and (if the viewer is signed in) their account, or (if signed out on a public Tool) a hashed visitor identifier. Raw events are kept 90 days; daily totals are kept longer Show Tool owners and organizations how much a Tool is used; find out which organizations use Crow Nest
Metering: counts such as database size, storage, function requests, and AI calls and tokens. We record counts, not the text of prompts or responses Billing and limits
MCP/assistant activity: a log of which Crow Nest tool an assistant called for your account, which client, and whether it worked. Never file contents Security, support, and debugging
Sign-in attempts: when you request an emailed code we record your email and IP address to limit abuse Prevent abuse
IP address and device data: your IP address and browser information reach us (and our hosting providers) with every request. We use them for security, abuse prevention and rate limiting. For signed-out visitors to public Tools we use a keyed, one-way hash of the IP address, and not the address itself, to rate-limit and let Tool owners block abusive visitors Security
Cookies: see section 5 Sign-in and security

We do not knowingly collect information from anyone under 18.

Information from others

3. How we use information

4. Who can see your information

Your employer or organization. If you join an organization, or your account is moved into one because your email domain belongs to it, that organization's administrators can see your name and email, the Tools you publish (and who opens them), usage and cost information, and your role and permissions. Your Tools and their data then belong to the organization's workspace. We tell you before this happens.

People you share with. Anyone you share a Tool with, or any person who opens a public Tool, can see what the Tool shows them. People you share with see your name or email when the Tool or Crow Nest shows who made it.

Other users of Tools. Tool owners may see who opened their Tool (for signed-in viewers) and entries people submit to it.

Service providers that help us run Crow Nest, under contract and only to provide services to us. They are listed by kind, with what each receives, in our Subprocessor List: hosting and infrastructure, source code storage, payments and tax, email delivery, domain registration, sign-in, and website content delivery.

AI providers. When a Tool uses Crow Nest AI, the prompts and files it sends pass through our systems to the AI company that runs the model you picked (for example Anthropic or OpenAI), and the answer comes back the same way. If a Tool uses your own API key, requests go to the provider you chose (Anthropic, OpenAI, Google, or another service you configure). In both cases the AI company's own terms and privacy policy govern what it does with that data. We don't store the text of prompts or answers, only usage counts, and we don't use them to train AI models.

AI assistants you connect. If you connect an AI assistant (like Claude) to your Crow Nest account, it can act with the permissions you approved and receive information about your account and Tools. Its handling of that information is governed by its own provider's terms.

Legal and safety. We may disclose information if we believe it's required by law or legal process, or necessary to protect people, the Service or our rights (for example to investigate fraud or abuse).

Business transfers. If Crow Nest is involved in a merger, sale or financing, information may transfer to the new owner, who must honor this policy for existing data unless you're told otherwise.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

Our staff can access account, Tool and usage information when needed for support, security, abuse handling, billing and legal compliance. Access is limited to people who need it.

5. Cookies and similar technologies

We use a small number of first-party cookies, set by us, to keep you signed in, secure sign-in and bot checks, and, for signed-out visitors to public Tools, to count unique visitors. We do not use advertising or cross-site tracking cookies, and we don't run third-party analytics services.

All of our cookies are first-party, host-only, secure (HTTPS only) and HttpOnly:

Cookie What it does How long
__Host-crow_session Keeps you signed in to Crow Nest Up to 30 days, or until you sign out
__Host-crow_tool Lets you open a protected Tool you have access to (that Tool's address only) Up to 7 days, or until you sign out
__Host-crow_oauth Protects the sign-in handshake with Google or Microsoft, or when you connect an AI assistant A few minutes
__Host-crow_pending Holds your place between signing in and creating an account (only a random ID) About 10 minutes
__Host-crow_anon Random ID so a Tool's owner can count how many different signed-out people opened a public Tool. We store only a one-way hash of it Up to 1 year
__Host-crow_pass Remembers you passed the human check, so it doesn't repeat for every action About 30 minutes

Tools made by other people may set their own cookies, which we don't control.

Some of our pages load fonts from Google Fonts, and some sign-in pages load Cloudflare's Turnstile bot check; when they do, your browser contacts those companies and shares your IP address and browser details with them. Our home page also loads a code library from the cdnjs content delivery network.

Do Not Track. We don't track you across other sites, so we don't change our behavior in response to Do Not Track signals.

6. Tools made by other people (important)

Crow Nest hosts Tools made by individuals and organizations. When you use someone else's Tool, that Tool's owner, not Crow Nest, decides what information it collects and why, and is responsible for it. For example, if you submit a form on someone's booking page hosted on Crow Nest, that person receives your submission. We store and process that data for them to run their Tool, as their service provider. Look for the Tool owner's own privacy notice, and contact them first for requests about data you gave to their Tool. If you can't reach them, write to us.

Don't submit information to a Tool you don't trust. If you think a Tool is misusing information, use the "Report" link or email us.

7. How long we keep information

Data How long
Account information While your account is open, then deleted 30 days after you delete your account (we hold it for 30 days so we can restore it if you ask)
Tools, their data and files While the Tool exists. After a Tool or account is deleted, kept for 30 days, then permanently deleted
Raw usage events 90 days. Daily totals are kept without personal identifiers beyond the Tool and day
Sign-in sessions and tool sessions Up to 30 days and 7 days respectively, and removed when you sign out or delete your account
Emailed sign-in codes 10 minutes
Billing records Kept by Stripe and by us as long as needed for tax, accounting and legal reasons (generally 7 years)
Domain registration contact details While you own a domain through us, then as the registrar and the law require
Abuse reports 2 years, longer if tied to a legal matter
Backups and logs A limited time after deletion, then overwritten

We may keep information longer if the law requires it, or to resolve disputes, enforce our agreements, or prevent fraud.

8. Security

We use reasonable measures including encryption in transit, encryption of stored secrets and keys, hashing of API tokens, restricted staff access, and rate limits. No system is perfectly secure, and we can't guarantee absolute security. Don't store information in a Tool that you couldn't afford to have exposed, and don't store regulated or highly sensitive data (see our Terms). If we learn of a breach affecting you, we will notify you and authorities as the law requires.

9. Your choices and rights

You can:

We won't discriminate against you for using these rights.

US state privacy laws. Some states (such as California, Colorado, Connecticut, Virginia, Utah and others) give residents rights to access, correct, delete and get a copy of their personal information, and to opt out of sale, targeted advertising and certain profiling. We honor these requests for all US users, whether or not a particular law applies to us. We don't sell personal information or use it for targeted advertising. California residents may also ask about disclosures to third parties for their direct marketing; we make none. You can use an authorized agent to make a request; we may ask for proof.

10. Children

The Service is not directed to anyone under 18, and we don't knowingly collect information from them. If you think a child has given us information, tell us at hello@crow-nest.com and we'll delete it.

11. Where information is processed

We and our providers process information in the United States and potentially other countries where our providers operate. The Service is intended for US users. If you use it from outside the US, you understand your information will be transferred to and processed in the US.

12. Changes to this policy

We'll post changes here with a new date, and for material changes we'll email you or show a notice in the product before they take effect.

13. Contact

Defi LLC, doing business as Crow Nest 1565 Grizzly Way, Payson, Utah 84651 hello@crow-nest.com