Privacy Policy

Effective Date: July 10, 2025
Last Updated: September 17, 2026

This Privacy Policy explains how CraftUp (“CraftUp”, “we”, “our”, “us”) collects, uses, stores, and shares personal data when you use the CraftUp mobile app, website, and related services (together, the “Services”).

Plain-language summary

CraftUp processes account and learning data to provide the app, subscription and entitlement data to manage paid access, and technical data for analytics, attribution, reliability, and support. The website and mobile app use different analytics and measurement systems, which are described below.

For account deletion, use the in-app flow or see Delete Account. For access, correction, deletion, or other privacy requests, email privacy@craftuplearn.com.

1. Scope and data controller

CraftUp is the data controller for the personal data described in this policy. If you have a privacy question or request, contact privacy@craftuplearn.com. General product support is available through CraftUp Support.

2. Information CraftUp processes

The information we process depends on which parts of CraftUp you use. Current categories include:

  • Account and authentication data: account ID, email address, name or profile information where provided, login method, and authentication metadata. Current sign-in methods can include email and supported Apple or Google sign-in.
  • Learning and product-use data: onboarding data, lesson progress and completion, streaks, achievements, learning or usage limits, product interactions, and related timestamps.
  • Subscription and purchase metadata: subscription status, entitlement and product identifiers, platform, purchase and expiry timestamps, and transaction/customer identifiers used to keep paid access in sync. Mobile purchases themselves are processed by Apple App Store or Google Play; CraftUp uses RevenueCat to manage subscription entitlements and purchase status.
  • Device, technical, analytics, and diagnostic data: device and operating-system information, app/browser version, language, country-level or timezone information, analytics or device identifiers, crash and performance information, and interaction events. This information is not described as automatically anonymous because some systems can use persistent, pseudonymous, device, or account-linked identifiers.
  • Notification data: push notification token, notification send history, and activity, timezone, or country information used to decide whether and when to send reminders.
  • Feedback, support, and other information you submit: in-app feedback type, lesson association, rating or score, and free-text comments; support messages sent through our external support form or email; and other information you choose to include in those messages.
  • Company-access requests: name, work email, company, country, requested team size, invoice preference, and an optional message when you use the For Companies request form.

Free-text feedback, support messages, and company messages are user-entered fields. Please avoid including sensitive information that is not needed for your request.

3. Why CraftUp uses this information

We use information to:

  • create, authenticate, and secure accounts;
  • provide lessons, save learning progress, streaks, achievements, and other app state;
  • manage free and paid access, subscription entitlements, purchase restoration, and related support;
  • measure product use, diagnose failures, improve reliability, and understand how the website and app are used;
  • measure mobile acquisition and conversion attribution;
  • send onboarding, activity, learning, and service communications;
  • answer feedback, support, privacy, and company-access requests;
  • protect the Services, investigate abuse, and enforce our terms.

Our existing legal framework relies on one or more legal bases, including performance of a contract, legitimate interests, and consent where applicable. The basis that applies can depend on the processing activity and your jurisdiction.

4. Analytics, diagnostics, and attribution

These functions are different and should not be treated as one generic analytics category:

  • Amplitude — mobile product analytics. The production app uses Amplitude to measure product interactions and can send app, device, operating-system, language, country-level, and analytics identifier information. When the app has the relevant in-app tracking consent, CraftUp can associate the CraftUp user ID with Amplitude analytics.
  • PostHog — website product analytics. The CraftUp website uses PostHog for website interaction and technical event analytics. The production configuration uses browser persistence and identifiers unless the browser or configuration prevents them, and routes PostHog traffic through CraftUp's website before it reaches PostHog's EU service.
  • Vercel — website traffic and performance measurement. CraftUp's website includes Vercel Web Analytics and Speed Insights alongside Vercel's hosting infrastructure. These services process website request, usage, and performance data needed to operate and measure the site.
  • Sentry — crash and performance diagnostics. The mobile app sends crash and diagnostic events to Sentry and is configured to include default personally identifiable diagnostic context. A diagnostic event can therefore contain account, device, network, or app context associated with an error.
  • Tenjin — mobile attribution and conversion measurement. The current mobile app uses Tenjin for attribution and selected conversion events. The integration can use a Tenjin installation identifier, CraftUp customer/user identifier, device attribution identifiers where available, and conversion events. It also passes attribution information into RevenueCat so subscription outcomes can be connected to acquisition measurement.

On iOS, CraftUp reads and stores Apple App Tracking Transparency (ATT) status. The app also has an in-app tracking-consent setting. These controls affect some analytics identification and identifier access, but they do not currently operate as a single universal switch that disables every technical, diagnostic, or attribution service. Device-level ATT choices can be changed in iOS settings; CraftUp's in-app privacy setting can be changed in the app where available.

5. Service providers and sharing

CraftUp uses third parties to operate different parts of the Services. Material current systems include:

  • Supabase for authentication, database, backend, and Edge Function infrastructure;
  • Amplitude, PostHog, Vercel, Sentry, and Tenjin for the analytics, performance, diagnostics, hosting, and attribution purposes described above;
  • RevenueCat for mobile subscription and entitlement infrastructure;
  • Expo for push-notification delivery;
  • Resend for CraftUp email delivery and the For Companies request flow;
  • Tally for the external support form linked from CraftUp's Support page;
  • Apple and Google for app distribution, purchases, and supported sign-in flows where applicable.

This section describes material provider relationships; it is not presented as an exhaustive subprocessor registry. Providers can process information under their own service terms and retention practices as well as CraftUp's instructions, depending on the service.

6. Communications and notifications

CraftUp currently uses:

  • Push notifications such as activation, lesson, streak, and inactivity reminders. CraftUp stores a push token and send history and can use activity and timezone/country data to choose reminder timing. Push delivery is handled through Expo.
  • Email such as welcome messages and inactivity/return-to-learning reminders. Resend receives the recipient address and email content needed to deliver these messages. Activity and learning context can be used to decide whether to send a reminder and what course or module to reference.

You can disable push notifications in your device settings. Current CraftUp email templates do not provide an in-message preference center or a universal unsubscribe link. For questions or requests about CraftUp communications, contact support@craftuplearn.com or privacy@craftuplearn.com.

7. Storage, security, and retention

CraftUp uses Supabase as core backend infrastructure and uses other providers for the specific purposes described in this policy. We apply reasonable technical and organizational safeguards to reduce the risk of unauthorized access, alteration, or loss.

Retention is not governed by one fixed period across every system. Account, learning, notification, analytics, diagnostic, support, subscription, store, and provider records can have different lifecycles. We therefore do not promise that every record is erased at the same moment when an account is deleted. If you need deletion or retention information for your account, contact privacy@craftuplearn.com.

8. Account deletion and privacy actions

You can start account deletion in the CraftUp app or follow the instructions on the Delete Account page. The current in-app workflow removes the Supabase authentication account, the primary CraftUp account record, and active account-linked product data including learning progress, streaks, feedback, energy/usage state, notification state and send history, achievements, and the active device-to-account link.

Subscription or transaction records, referral/reward and anti-abuse history, provider records, support communications, operational logs, and infrastructure backups can follow separate retention lifecycles. The deletion workflow deactivates a deleted account's active referral code rather than treating referral history as ordinary product state. To request deletion or confirmation for additional personal data, contact privacy@craftuplearn.com.

Deleting a CraftUp account does not itself cancel a subscription billed by Apple or Google Play. Subscription cancellation is handled through the store that billed the purchase; see the cancellation section of the Terms.

9. Your privacy rights

Depending on your jurisdiction, you may have rights relating to your personal data, such as access, correction, deletion, restriction or objection, portability, and the ability to complain to a competent supervisory authority.

To make a privacy request, email privacy@craftuplearn.com. We may need information sufficient to identify the relevant account and respond to the request.

10. International processing

CraftUp and the providers described above can process data in different countries or regions. Where applicable law requires safeguards for an international transfer, the applicable legal and contractual mechanism depends on the provider and processing path.

11. Children's privacy

CraftUp is not intended for use by children under the age of 13. If you believe a child has provided personal information to CraftUp, contact privacy@craftuplearn.com.

12. Changes to this policy

We may update this policy when our Services or data practices change. When we make a substantive update, we will update the Last Updated date above and provide any additional notice required for that change.

13. Contact

For privacy requests or questions, email privacy@craftuplearn.com. For general product help, use CraftUp Support or email support@craftuplearn.com.