deepcrest
NewsletterResourcesSign in

Contents

Privacy Policy

Last Updated: August 13, 2026 • Version 3.0

TL;DR - Human-Readable Summary

Your privacy matters to us. Here's what you need to know:

What we collect: Email, name, payment info (via Dodo Payments), and content you upload or generate using DeepCrest. We don't sell your data to anyone.

How we use it: To provide the Service, process payments, send you updates, and improve our platform. We use AI services (OpenAI, Anthropic) to analyze content and generate insights.

Who we share with: Dodo Payments (payments), OpenAI/Anthropic (AI processing), and essential service providers. We never sell your personal data.

Your rights: Access, correct, delete, or export your data anytime. Email support@deepcrest.ai to exercise these rights.

Security: Industry-standard encryption, secure servers, and regular security audits protect your data.

Read the full policy below for complete details.

1. Introduction

This Privacy Policy explains how DeepCrest ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our AI-powered content system. DeepCrest is operated by RevivalBytes AI Labs LLP, a limited liability partnership registered in Durgapur, West Bengal, India, and it is the company responsible (the data controller) for the personal information described here.

This policy covers all three places DeepCrest lives:

  • •deepcrest.ai: our website, including the resources we publish and the short check you can take on it. See Section 2.4 for what a visit collects.
  • •app.deepcrest.ai: the DeepCrest app, where you hold an account and your content is created and stored.
  • •read.deepcrest.ai: The Crest, our newsletter, which is hosted on Substack. Substack is the controller of subscriber data there, under its own terms and privacy policy. See Section 4.1.

By using DeepCrest, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, do not use the Service.

GDPR & Data Protection: We comply with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws.

2. Information We Collect

What we collect depends on how you use DeepCrest. If you only visit our website, we collect what Section 2.4 describes and nothing more. If you hold an account in the app, we also collect what Sections 2.1 to 2.3 describe.

2.1 Information You Provide Directly

When you create an account or use DeepCrest, you provide:

  • •Account Information: Name, email address, password
  • •Profile Information: Brand details, content pillars, target audience
  • •Content Data: YouTube links, audio files, PDFs, and content you upload to generate ideas
  • •Communications: Messages you send to our support team
  • •Connected Account Data: When you connect a social platform (e.g., LinkedIn), the OAuth tokens and basic profile information that platform shares with us. See Section 4.2 for details.

2.2 Payment Information

Important: We do not store your credit card details. All payment information is processed securely by Dodo Payments, our payment processor.

Dodo Payments collects and processes:

  • •Billing name and address
  • •Payment card information
  • •Transaction history
  • •Tax identification numbers (where applicable)

2.3 Automatically Collected Information

When you use DeepCrest, we automatically collect:

  • •Usage Data: Features used, content analyzed, time spent, actions taken
  • •Device Information: Browser type, operating system, device type
  • •Log Data: IP address, access times, error logs
  • •Cookies: See Section 7 for cookie details

2.4 Information We Collect From Website Visitors

You can read deepcrest.ai, take the short check on it and read our published resources without an account. On those pages:

  • •The check stores nothing: your answers stay in your browser for as long as the page is open. They are not sent to us and not saved anywhere.
  • •Analytics: we measure page views and loading speed using Vercel Web Analytics and Vercel Speed Insights. Both are cookieless and give us anonymized aggregates, not a record of a person. See Section 7.
  • •Server logs: our hosting provider records standard request logs, which include your IP address, the page requested, the time, and your browser and device type. We use them to keep the site available and secure, and we keep them for no longer than 30 days.

2.5 Purchases Through Third-Party Marketplaces

Some of our digital products, such as ebooks and playbooks, are sold through third-party marketplaces, which sell to you as their own merchant. When you buy one, the marketplace passes us your name, your email address and a purchase reference so that we can deliver the product and answer questions about it. Where the marketplace's purchase page says so, we also add your email address to our mailing list, and every email we send carries an unsubscribe link.

3. How We Use Your Information

We use your information to:

Provide & Improve the Service

  • •Deliver content ideas and generate posts for LinkedIn, newsletters, and other platforms
  • •Process AI-powered analysis using services like OpenAI and Anthropic
  • •Personalize recommendations based on your brand and preferences
  • •Monitor usage patterns to improve features and performance

Manage Your Account

  • •Create and maintain your account
  • •Process subscription payments and billing
  • •Send transactional emails (receipts, password resets, account notifications)
  • •Verify your identity and prevent fraud

Communicate With You

  • •Respond to your support requests and questions
  • •Send important Service updates and announcements
  • •Notify you of new features or changes to Terms/Privacy Policy
  • •Send marketing emails (you can opt out anytime)

Legal & Security

  • •Comply with legal obligations and law enforcement requests
  • •Protect against fraud, abuse, and security threats
  • •Enforce our Terms and Conditions
  • •Resolve disputes and protect our legal rights

Legal Bases for Processing

Where data protection law requires us to name a legal basis for each purpose, these are ours:

  • •Performance of a contract: running the Service for you, including your account, your content and your payments.
  • •Legitimate interests: keeping the Service secure, preventing fraud and abuse, and understanding how our pages are used through anonymized aggregate analytics.
  • •Consent: where we ask for it, such as subscribing to our newsletter or connecting a social account. You can withdraw consent at any time.
  • •Legal obligation: keeping billing and tax records, and responding to lawful requests.

4. Information Sharing & Disclosure

We do not sell your personal data to third parties.

4.1 Service Providers We Use

We share your information with trusted service providers who help us operate DeepCrest:

Dodo Payments (Payment Processing)

Handles all payment transactions, billing, and subscription management. Dodo Payments is PCI-DSS compliant and acts as our Merchant of Record.

OpenAI & Anthropic (AI Services)

Processes your content to generate ideas and create posts. Your content may be sent to these services for analysis.

Supabase (Database & Authentication)

Securely stores your account data and content. Data is encrypted at rest and in transit.

Email Service Provider

Sends transactional and marketing emails on our behalf. You can unsubscribe from marketing emails anytime.

Vercel (Hosting & Analytics)

Hosts our sites and runs Vercel Web Analytics and Vercel Speed Insights on all our pages. Both are cookieless and produce anonymized aggregates. Vercel processes this data on our instructions.

Substack (The Crest Newsletter)

Hosts read.deepcrest.ai and delivers The Crest. If you subscribe there, your email address and subscription are held by Substack under its own terms and privacy policy, and Substack is the controller of that data rather than a processor acting for us. You can unsubscribe from any issue using the link in the email itself.

4.2 Connected Social Accounts

DeepCrest lets you connect external social accounts (LinkedIn first; more platforms over time) so we can publish your finished posts on your behalf. You're always in control: you only connect an account when you click "Connect LinkedIn" (or the equivalent), you can disconnect at any time from Settings → Integrations, and we never post without your explicit "Schedule" or "Post Now" action on a specific piece of content.

What we collect from LinkedIn (with your consent on the LinkedIn consent screen)

  • •Your LinkedIn member ID and profile name
  • •Your email address as confirmed by LinkedIn
  • •Your profile picture URL (for display in DeepCrest)
  • •An OAuth access token and refresh token, which let DeepCrest publish on your behalf
  • •For each post we publish for you: the post's LinkedIn URL and ID
  • •Engagement metrics for posts we published for you (impressions, likes, comments, shares, clicks) — collected 24 hours and 7 days after each post, for your dashboard's Performance Score

What we send TO LinkedIn (only when you act)

  • •The text of a post you have explicitly approved ("Mark as Ready" + "Post Now" or "Schedule")
  • •Your LinkedIn member ID (as required by LinkedIn's API)

How we store this

  • •OAuth tokens are encrypted at rest and never displayed in any DeepCrest UI or API response.
  • •Tokens are scoped to the specific permissions LinkedIn granted us: creating posts on your behalf and reading analytics on those same posts. We do NOT have access to your LinkedIn connections, messages, or other LinkedIn content.

How to withdraw consent

  • •Disconnect LinkedIn at any time from Settings → Integrations.
  • •On disconnect, we immediately delete your OAuth access and refresh tokens, cancel any scheduled posts that haven't fired yet, and stop collecting any new data from LinkedIn.
  • •Previously-published posts and their stored engagement metrics remain on your DeepCrest dashboard until you delete them or close your account.

Data sharing

  • •Your LinkedIn content and performance data may be processed by our AI providers (such as Anthropic, via our AI gateway) to generate content and insights for you — never for those providers' own purposes.
  • •We never sell or rent your data, and we don't share your LinkedIn-derived data with third parties for their own purposes.

4.3 Legal Disclosures

We may disclose your information if required by law or if we believe in good faith that such disclosure is necessary to:

  • •Comply with legal obligations, court orders, or government requests
  • •Protect our rights, property, or safety (or that of our users)
  • •Investigate fraud, security, or technical issues
  • •Prevent harm to individuals or the public

4.4 Business Transfers

If DeepCrest is acquired, merged, or undergoes a business transfer, your information may be transferred to the new entity. We will notify you via email before your information becomes subject to a different privacy policy.

4.5 Links to Other Sites

Our pages link to sites we do not run, including Substack, LinkedIn and the marketplaces that sell our digital products. Once you follow one of those links, that site's own terms and privacy policy govern what happens there, not this policy.

5. Data Security

We take data security seriously and implement industry-standard measures to protect your information:

Encryption

  • •All data transmitted between your browser and our servers is encrypted using TLS/SSL
  • •Data stored in our database is encrypted at rest
  • •Passwords are hashed using industry-standard algorithms

Access Controls

  • •Limited employee access to user data (only when necessary for support)
  • •Multi-factor authentication for internal systems
  • •Regular security audits and vulnerability assessments

Infrastructure Security

  • •Hosted on secure cloud infrastructure (Vercel, Supabase)
  • •Automatic security patches and updates
  • •Regular backups to prevent data loss

Important: While we implement strong security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we continuously work to protect your data.

6. Data Retention & Deletion

6.1 How Long We Keep Your Data

  • •Active accounts: Data retained indefinitely while your subscription is active
  • •Canceled accounts: Data retained for 30 days after cancellation (in case you return)
  • •After 30 days: All personal data and content permanently deleted
  • •Billing records: Retained for 7 years as required by tax and accounting laws
  • •Connected social-account tokens (LinkedIn, etc.): Retained while the account is connected. Immediately deleted when you disconnect the account, or within 48 hours of account closure.
  • •Website visitors: Server logs are kept for no longer than 30 days and are then deleted. Analytics data is anonymized and aggregate, so it holds nothing that points back to you.

6.2 Deleting Your Account

You can request immediate account deletion by:

  • •Emailing support@deepcrest.ai with "Delete My Account" in the subject
  • •Using the "Delete Account" option in Account Settings (when available)

Upon deletion, your account and all associated data — including any connected social-account OAuth tokens, scheduled posts, and stored post analytics — will be permanently removed within 48 hours, except for billing records required by law.

7. Cookies & Tracking Technologies

We use cookies only where the Service cannot work without them, and we run no advertising or cross-site tracking anywhere.

7.1 What We Set, On Each Site

deepcrest.ai (our website)

Our website sets no cookies of its own. You can read it, take the short check on it and read our published resources without a cookie being stored on your device. One exception exists for people who use the app: signing in there leaves a signed-in marker (a cookie named dw_signed_in) that this website can see, so its menu can offer “Go to your dashboard” instead of “Sign in”. The marker holds no name and no identifier — only the fact that a sign-in happened — our servers never read it, and signing out removes it.

app.deepcrest.ai (the app)

The app sets strictly necessary cookies only: the session cookies set by Supabase, our authentication provider, which keep you signed in and keep your account secure, and a small number of short-lived first-party cookies that make signing in, checkout and offers work. Without them you cannot stay signed in. Signing in also sets the signed-in marker described above; signing out clears it.

Analytics, on all our pages

We measure page views and loading speed using Vercel Web Analytics and Vercel Speed Insights. Both are cookieless: they set no cookies, keep no identifier that follows you from one day to the next, and give us anonymized aggregates rather than a record of a person.

7.2 Why There Is No Cookie Banner

There is no cookie banner on our sites because we set nothing that requires your consent. The only cookies we set are the first-party ones that make signing in to the app work — including the signed-in marker that reflects it on our website — and our analytics use no cookies at all. We run no advertising, marketing or cross-site tracking cookies, and we do not sell your data.

You can still block or delete cookies through your browser settings. If you block the app's session cookies, you will not be able to stay signed in.

8. Your Privacy Rights

Depending on your location, you have the following rights regarding your personal data:

Right to Access

Request a copy of all personal data we hold about you in a machine-readable format.

Right to Correction

Request that we correct inaccurate or incomplete personal data.

Right to Deletion (Right to be Forgotten)

Request immediate deletion of your account and all associated personal data (except records required by law).

Right to Data Portability

Request an export of your data in a structured, machine-readable format to transfer to another service.

Right to Object

Object to processing of your personal data for direct marketing purposes (you can unsubscribe from marketing emails anytime).

Right to Restrict Processing

Request that we limit processing of your personal data in certain circumstances (e.g., while verifying accuracy).

To Exercise Your Rights:

Email support@deepcrest.ai with your request. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

9. International Data Transfers

DeepCrest is operated from India. Your data may be transferred to and processed in countries other than your own, including:

  • •United States (where some of our service providers are located)
  • •European Union (for EU-based users, data may be stored in EU data centers)
  • •Other countries where our infrastructure or service providers operate

Data Protection: We ensure that all international data transfers comply with applicable data protection laws (GDPR, CCPA, etc.) and that adequate safeguards are in place.

10. Children's Privacy

DeepCrest is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18.

If we discover that we have collected personal information from a child under 18, we will immediately delete that information. If you believe we have collected information from a child, please contact us at support@deepcrest.ai.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we will:

  • •Post the updated policy on this page and update the "Last Updated" date at the top, which is where a visitor as well as an account holder can always see the current version
  • •Email account holders at least 30 days before material changes take effect
  • •Display a notice in the app for material changes

Your continued use of DeepCrest after changes take effect constitutes acceptance of the updated Privacy Policy. If you disagree with the changes, please stop using the Service and delete your account.

12. Governing Law

This Privacy Policy is governed by the laws of India, without regard to conflict of law principles, and any dispute about it will be resolved exclusively in the courts of Kolkata, India. This mirrors Section 11 of our Terms and Conditions.

Nothing in this section removes a right you have under a data protection law that applies to you, including your right to complain to your local supervisory authority.

13. Contact Us

Questions about this Privacy Policy or how we handle your data?

  • •Email: support@deepcrest.ai
  • •Website: https://deepcrest.ai
  • •Operator: RevivalBytes AI Labs LLP (DeepCrest is its product)
  • •Registered Address: Durgapur, West Bengal, India

By using DeepCrest, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described.

deepcrest
NewsletterThe Crest NewsletterResourcesContact