Trust Centre
Plain answers about your data. This page says what exists and what does not, and it does not claim more than Crossbox can show. The first answer covers this website and its waitlist; the others describe the private application, which is not open to the public yet.
What does the website and its waitlist collect?
The waitlist stores your email address, your name and what you would use Crossbox for if you choose to give them, the page you joined from, the notice version you acknowledged and the time, and nothing else.
Only the email address is required; it is stored in lower case with spaces trimmed, so the same address is recognised twice. The name and the short note about what you would use Crossbox for are optional plain text. With them are stored the page you joined from, the version of the privacy notice you acknowledged, and the date and time the entry was added. If the same address joins again, the earlier entry is kept as it was.
The waitlist does not store your network address, although the hosting provider's own request logs may record it. A keyed hash of it (an HMAC) is used only in short-lived rate-limit counters, which are deleted the next time someone joins once they are a day old, so one can outlast a day if nobody joins.
Entries are stored on the server side, in a PostgreSQL database hosted by Supabase, and are written only by the website's server code through one database function. The website uses no analytics and no advertising trackers.
The database is in the Sydney, Australia region (Supabase: Oceania).
What happens to my data?
Your conversations are kept so you can return to them, and each message is sent to an AI model to produce the answer.
When you chat with Crossbox, your messages, the files you attach and the answers you receive are kept as your conversation history and activity, so you can come back to them. Each message is also sent to an AI model to produce the answer; the next section says to whom.
Crossbox also holds your account and profile data, your sign-in sessions, usage records and audit entries. How long each is kept, and how it ends, is under “What is kept, and what is deleted?”.
Who receives it?
An AI gateway and a model receive your prompts and files, and an email service receives sign-in emails; no payment provider receives anything.
These are the services Crossbox has recorded as receiving your data. For each: why, and what it receives.
The AI model, through an AI gateway
Crossbox is configured so that every model call goes through Vercel AI Gateway first. The gateway forwards it to the model Crossbox is configured to use, currently GLM-4.7-Flash, made by Z.ai (Zhipu AI). The model can change; this page names the configured model, not a record of every call.
Purpose: to produce the answer. Received: your prompt, the contents of any files you attach, and the agent's outputs, for every model call.
Email, for sign-in codes
Sign-in codes and invitations go out by email. The email service Crossbox's software is built to use is Resend, a service in the United States. Purpose: to deliver that email. Received: the recipient's email address and the text of the message.
This describes what the software is built to do. It is not a delivery history for any deployment.
Payments
No payment provider receives your data. Nothing can be bought on Crossbox today, and the payment code in the product is not switched on.
Where is it stored?
On a single production deployment, in a place this page does not itemise.
- Crossbox runs a single production deployment. You cannot choose a region, and Crossbox does not offer a choice. This page does not itemise where that deployment is hosted, and it does not claim regional failover.
- Model calls are handled where the AI gateway sends them. Crossbox does not confirm where that is.
- No third-party compliance certification (such as SOC 2 or ISO 27001) has been completed for this deployment, and none is claimed.
What is kept, and what is deleted?
Some things expire, some are kept without limit, and conversation history is deleted only on request.
Two things are easy to confuse. Expiry means something stops working; erasure means the record is gone. Where this page says something expires, it does not say the stored record is erased. And a period Crossbox intends is not the same as one that anything enforces; the table says which is which.
| Data | Kept for | How it ends |
|---|---|---|
| Conversation history and activity | Until it is deleted. There is no automatic purge. | Removed only on request. The live record is deleted; copies in daily database backups can remain until they age out. |
| Account and profile data | No limit is enforced. | No account-deletion process exists yet. Closing an account does not remove profile data on any schedule. |
| Sign-in sessions | 30 days of inactivity (enforced). | The session stops working. The stored record is not deleted at that point. |
| Sign-in codes | 15 minutes (enforced). | A used or expired code is refused. This page does not say when the stored record is erased. |
| Usage records | Intended maximum of 3 years. Nothing enforces it. | Nothing deletes them, so in practice they are kept without limit. They cannot be erased on request. |
| Audit entries | At least one year; in practice with no end. | Crossbox does not allow audit entries to be edited or deleted. They cannot be erased on request, and no process exists to remove an entry's content. |
Deleting conversation history
- Nothing deletes conversation history automatically. It is removed only when it is requested.
- Deleting it removes the live copy; Crossbox cannot make a deleted conversation unrecoverable from backups today.
- A deleted conversation can remain in daily database backups until they age out. This page does not state how long backups are kept.
- How to make a request, and how quickly it is handled, is not published on this page, and no response time is promised.
How can I get help or report a concern?
Use Help for product problems and Contact for anything else; no security reporting address is published yet.
No security incidents have been published. That is not a statement that none has occurred: there is no published incident history yet.