Skip to content

Privacy Policy

Last updated: July 2026

1. Introduction

CrossGL ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services, including CrossTL and Credora.

For privacy-related inquiries or to exercise a privacy right, contact us at privacy@crossgl.net.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and authentication credentials. If you sign in via Google, we receive your basic profile information from Google.

Usage Data

We collect account and product activity needed to operate the service, including analysis requests, credit usage, API-key activity, and support communications. Our hosting providers may also process basic request and security metadata such as IP address and browser information in service logs.

Credora — Uploaded Documents

When using Credora, you may upload documents for analysis and verification. Original uploads and generated annotated PDFs are processed for the request and are not retained by Credora after that request completes. For signed-in users, we retain an analysis summary associated with the account, such as the filename, extracted fields, scores, findings, and billing data, so it can appear in the document history.

Payment Information

When you purchase credits or subscribe to a plan, payment details are collected and processed directly by Stripe. We receive payment, customer, and subscription identifiers plus transaction status needed to provide billing support. We do not store full payment card numbers on our servers.

3. How We Use Your Data

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send technical notices, updates, and security alerts
  • Respond to your support requests and inquiries
  • Monitor and analyze usage trends to improve user experience
  • Detect, prevent, and address technical issues and fraud
  • Comply with legal obligations

4. Third-Party Services

We use the following third-party services to operate our platform:

  • Google Cloud Platform — infrastructure hosting and data processing
  • Google Vertex AI and Vision — document extraction, OCR, and analysis for Credora
  • Stripe — payment processing, subscription management, and billing (Stripe collects payment card details directly; we do not store your full card number)
  • Firebase Authentication — user identity and session management

Each third-party provider has their own privacy policy governing their use of your information.

5. Data Retention

We retain account, billing, and product records for as long as needed to provide the service, meet legal obligations, resolve disputes, and prevent fraud. You can request account deletion from account settings or by contacting privacy@crossgl.net. We will confirm the scope and timing of the request after verifying the account.

Credora does not retain original uploads or generated annotated PDFs after processing. Signed-in analysis summaries remain in the document history until you remove them or request account-data deletion, subject to any legally required retention.

6. Your Rights

California Residents (CCPA)

If you are a California resident, you have the right to: know what personal information we collect about you; request deletion of your personal information; opt out of the sale of your personal information (we do not sell personal information); and not be discriminated against for exercising your rights.

EU/EEA Residents (GDPR)

If you are located in the European Union or European Economic Area, you have the right to: access your personal data; rectify inaccurate data; request erasure ("right to be forgotten"); restrict processing; data portability; and object to processing. To exercise these rights, contact us at privacy@crossgl.net.

7. Children's Privacy

Our services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at privacy@crossgl.net.

8. Security Measures

We use technical and organizational safeguards designed to protect service data, including encrypted transport, provider managed encryption at rest, authentication and access controls, least-privilege service identities, and operational monitoring. No transmission or storage system can be guaranteed completely secure.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of our services after changes are posted constitutes acceptance of the revised policy.

10. Contact Us

If you have questions about this Privacy Policy, please contact us:

CrossGL
Email: privacy@crossgl.net