Crawdad crawdad
For MSPs Enterprise Regulated Developers Pricing Docs Threat Intel How it works Get Started
For MSPs Enterprise Regulated Developers Pricing Docs Threat Intel How it works FAQ Changelog Privacy Terms

Privacy Policy

Last updated: July 16, 2026

See also: Terms of Service

This Privacy Policy explains how Crawdad Security, Inc., a Delaware corporation (“Crawdad,” “we,” “us,” or “our”), collects, uses, and shares information in connection with the Crawdad software, applications, APIs, websites, and related services (the “Service”). It should be read together with our Terms of Service.


1. The Most Important Thing to Understand First

Crawdad is a security proxy that, in its default configuration, runs locally on your own machine or infrastructure and inspects the traffic between your AI agents and your LLM providers.

In that default configuration, the raw content of the traffic Crawdad inspects — your prompts, responses, and payloads — is analyzed locally and is not transmitted to us. We do not receive it, store it, or have access to it. This is a core design property of the Service.

This Privacy Policy is therefore mostly about the limited account, usage, and operational data we collect to provide the Service — not about the content of your inspected traffic, which in the default configuration we never see.

Two important exceptions to be clear about:

  • Optional cloud analysis backends. If you explicitly configure Crawdad to use an external or cloud-based analysis backend for certain features, the relevant content will be sent to that backend. That is your choice and your configuration; it is never enabled silently. The data handling for such a backend depends on the backend you choose.
  • Fleet/management console metadata. If you use the fleet or management console, it processes operational and security metadata (not raw traffic content) reported by your deployments. See Section 3.

2. Information We Collect

2.1 Information you provide

  • Account information: your email address and selected plan when you sign up.
  • Communications: if you contact us for support or otherwise, the contents of your messages.
  • Payment information: if you purchase a paid tier, you provide payment details to our third-party payment processor. We do not receive or store your full payment card number.

2.2 Information collected automatically to operate the Service

  • Authentication data: API keys and credentials issued to your account (stored hashed where applicable).
  • Usage and metering data: API call counts, plan limits, timestamps, and similar data needed to operate and meter the Service.
  • Technical data: version, platform, and similar operational information; and your IP address at signup, which we use for rate-limiting and to record your acceptance of the Terms of Service (the acceptance record includes the terms version, a timestamp, and your IP).

2.3 Website analytics and cookies

Our website may use cookies and analytics technologies (such as Google Analytics or similar tools) to understand how visitors use the site, measure traffic, and improve the site. These technologies may set cookies in your browser and collect information such as pages visited, referring sites, approximate location, device and browser type, and similar usage data. Where required by law, we will obtain your consent before setting non-essential cookies, and you can control cookies through your browser settings and any cookie-consent controls we provide on the site. This website analytics activity is separate from the Crawdad product itself, which, as described above, analyzes your agent traffic locally and does not transmit its content to us.

2.4 What we do NOT collect in the default product configuration

  • The content of the prompts, responses, or payloads that Crawdad inspects between your agents and your LLM providers (analyzed locally; not transmitted to us).
  • The content of your files, code, or data that your agents process.

3. The Fleet / Management Console

If you deploy the fleet or management console to administer multiple Crawdad deployments, the console processes operational and security metadata reported by those deployments, which may include device and deployment identifiers, protection status and configuration, policy and software versions, detection and security-event counts, timestamps, and similar administrative metadata. This metadata enables centralized visibility and management.

The fleet console is designed to run on infrastructure you operate. When you self-host the console, this metadata is stored in the console’s own database within your environment. The console is designed to convey security and operational metadata, not the raw content of inspected traffic.


4. How We Use Information

We use the information we collect to: provide, operate, secure, maintain, and improve the Service; authenticate accounts and manage credentials; meter usage and enforce plan limits; process payments and manage subscriptions; communicate with you about the Service, including service, security, and administrative messages, and, where permitted, product updates; record and evidence your acceptance of our Terms; detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms; and comply with legal obligations and enforce our agreements.

If you subscribe to a newsletter or mailing list, we will use your email to send the communications you signed up for, and you can opt out at any time using the unsubscribe link or by contacting us. We do not sell your personal information.


5. How We Share Information

We share information only as follows:

  • Service providers / processors: third parties that help us operate the Service under contract and on our behalf — for example, our payment processor, our email delivery provider, and our hosting and infrastructure providers. They may process the account and operational data described above only to provide services to us.
  • Legal and safety: when required by law, legal process, or to protect the rights, safety, and security of Crawdad, our users, or the public.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • With your direction: where you configure the Service to interoperate with third parties you choose (such as your LLM providers, or an external analysis backend you enable), information flows according to your configuration and those parties’ terms.

6. Data Retention

We retain account, usage, and operational data for as long as your account is active and as needed to provide the Service, and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements. We retain records of Terms acceptance as needed to evidence consent.


7. Security

We take reasonable measures to protect the information we hold. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and API keys.


8. Your Rights and Choices

Depending on where you live, you may have rights regarding your personal information, such as the rights to access, correct, delete, or port your data, or to object to or restrict certain processing, and rights regarding cookies and analytics. To exercise any of these rights or to ask a question, contact us at privacy@getcrawdad.dev. We will respond as required by applicable law.


9. International Users

We are based in the United States, and the information we collect is processed in the United States and other locations where we or our service providers operate. If you access the Service from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States.


10. Children’s Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them.


11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and take reasonable steps to notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.


12. Contact Us

Questions or requests regarding this Privacy Policy: privacy@getcrawdad.dev, Crawdad Security, Inc.

crawdad

Security for the threat that's already inside. Local proxy, zero-knowledge, open benchmark.

Product

Getting Started Documentation API Reference Fleet Console Changelog Pricing

Segments

For MSPs Enterprise Regulated Developers

Resources

Threat Intel FAQ Trust Center Benchmark

Company

Privacy Terms Contact
© 2026 Crawdad Security, Inc. Licensed under BSL 1.1.
Privacy Terms