Cribbit Systems Incorporated
Privacy Policy
Last updated July 23, 2026
This policy explains how Cribbit Systems Incorporated ("Cribbit", "we", "us") collects, uses, discloses, protects, retains, and deletes personal information when you use Cribbit's drawer-design, ordering, and optional model-improvement services. Cribbit is based in British Columbia, Canada. Canada and the United States are our intended initial audience, but the service is technically reachable elsewhere and we do not verify residence.
Privacy contact
Jesse Furlan is Cribbit's Privacy Officer. Questions, access or correction requests, withdrawals, and complaints may be sent to jessefurlan@cribbitinserts.com.
Information we collect
- Account information: your account identifier, verified email address, authentication/session information, and any name or profile details maintained through Clerk.
- Project information: uploaded drawer photos, the perspective-cropped image, dimensions, masks and object labelmaps, layouts, previews, fabrication files, revision/hash metadata, and project status needed to provide and recover the design service. A project-local mask-processing profile records bounded hardware/configuration, aggregate and stage runtimes, mask counts, and up to 64 per-tile pixel dimensions, probe counts, runtimes, and result counts. The profile is linked to you through its project location and contains no tile coordinates, image/mask bytes, filename, account/job field, or error message.
- Order information: contact name, verified account email, delivery method, country, province/state, postal code when shipping, and optional company, phone, timing, and notes, together with approved previews, fabrication files, dimensions, prices, and transaction/workflow records.
- Operational reliability information: the small recovery, storage, backend-failure, browser-failure, and mask-processing reports described below; request/provider logs and metrics; service-health alerts; and deletion records needed to keep the service reliable, secure, and recoverable.
- Optional project contributions: only after per-project affirmative consent, the exact cropped drawer image shown behind the contribution panel; the tool silhouettes represented by the current object and edit-area labelmaps; the immutable original submask labelmap and AMG candidate-mask files; a compact generation recipe; and integrity/lineage metadata described below.
A submitted order may include the postal code, fabrication files, approved previews, dimensions, prices, and transaction/workflow records needed for review and invoicing. Submitting an order does not authorize fabrication.
How we use information
We use information to authenticate you; process, save, restore, and delete projects; generate masks and fabrication designs; provide previews, carts, quotes, invoices, notices, fulfillment, support, security, service reliability, and legally required records. We limit use to disclosed and reasonably appropriate purposes, unless you consent to another use or law permits or requires it.
Operational reliability and service health
Cribbit collects a limited operational set without a diagnostics toggle because it is used to recover projects, identify broken essential workflows, measure mask-processing reliability, and detect service outages — not to measure engagement or general workflow completion.
- Job-linked recovery: checkpoint recovery stores only a bounded outcome; layout recovery stores only a bounded trigger; and hydration failure stores only a bounded reason. Each has the affected job identifier in a separate server-controlled field and is retained for 90 days or deleted sooner with the project/account.
- Minimal backend failures: selected failures store a bounded error class/code/stage, a normalized route template, the server release, and up to eight sanitized Cribbit-owned module/function/line frames — never the exception message. A job identifier is stored only for an approved job route after ownership validation; other reports are unlinked. Retention is 180 days or sooner when a linked project is deleted.
- Selected browser failures: explicit critical catch sites may store a predefined error code, operation/workspace, browser family and major version, OS family, fatal/retryable flags, frontend release, and up to eight sanitized same-origin Cribbit script/line/column frames. The raw user agent is classified locally and is not sent. These reports are unlinked and retained for 90 days.
- Mask-processing attempts: one terminal report stores success/failure, local/Modal backend, bounded failure stage and runtime, initial-tile count, rerun-tile count, and server release. It is unlinked and retained for 90 days. Detailed timing remains only in the project-local profile described above.
Central reports are stored in Railway Postgres or, if the database writer is unavailable, in an equivalent retention-managed fallback file on the Railway application volume. Browser authentication and the requesting IP address are used transiently in process memory for authorization and rate limiting; neither is stored in an unlinked browser report. Operational reports do not contain raw error messages, full stacks, raw user agents, full URLs/query strings, request or response bodies, console logs, image/mask content, or a persistent device identifier.
Service-level health records use bounded component/state/event codes, the server release, and small aggregate counts such as dirty jobs, oldest dirty age, parked/backoff jobs, and consecutive failures. They go to provider logs and, for alert-worthy state changes, a bounded Resend email to Cribbit's operator; they are not stored as user telemetry. UptimeRobot checks only Cribbit's two public frontend/backend URLs. Hosting providers may also process ordinary network/account metadata and resource/deployment metrics under their configured policies. Provider log, metric, uptime, and alert-email retention follows the applicable provider/account settings; Cribbit records and reviews the actual production periods and access roles rather than copying these records into its telemetry database.
Optional model-improvement contributions
A project is never contributed automatically. The first time you select Create Layout, Cribbit may show one optional offer. You can inspect the exact undimmed cropped image in the workspace while the tool silhouettes, masks, dimming, cursors, and vector overlays are hidden. The small contribution panel starts near the center of the workspace and can be dragged aside. Clicking behind it or pressing Escape does not make a choice; only Contribute, No thanks, or the close button proceeds. Contribution requires an unchecked authority confirmation. Declining, closing, or an upload failure does not affect the project, price, order, or service. The automatic offer is not repeated, and there is no later project setting for contribution or project-specific withdrawal.
A contribution contains only the cropped image; current
object_labelmap.png and
object_submask_labels.png; immutable
original_submask_labelmap.png,
amg_best_mask_labels.png, and
amg_masks.rle.json; a compact generation recipe containing
calibration, model/checkpoint identity hashes, output-affecting
settings, and resolved generation values; artifact hashes; revision;
notice version; and collection metadata. It does not contain the full
amg_profile.json, hardware name, timings, or mask-count
profile. Storage keys use
a random sample identifier and do not contain your account or project
identifier. A protected Postgres record initially retains account and
source-project links needed for consent governance and deletion.
Contributions are therefore pseudonymous, not
anonymous.
Subject to the separate approvals described below, Cribbit may use a contribution to develop, train, test, and improve image-processing models and related features, including object detection and automatic tool alignment. Automatic tool alignment is a planned related feature, not a feature currently available in the Cribbit layout editor.
Choosing to contribute creates a separate copy for the disclosed model-improvement purpose. Moving the source project to the Recycle Bin does not affect that copy. Permanently deleting the source project deletes the working project but not the contribution; Cribbit removes the protected project link and records when that happened. The protected account link remains only as needed for contribution deletion, account deletion, governance, and retention while the contribution exists. Deleting the account deletes its contributions before the Clerk identity is deleted.
If object-editor changes or layout-source deletion changes either current contributed labelmap, a later successful Add to Cart or Update Cart may replace both current labelmaps together at the same committed editor revision. The cropped image, immutable AMG evidence, generation recipe, original consent date, privacy-review status and deadline, and maximum retention date remain unchanged.
Every sample must be reviewed for privacy and quality before use. In the current collection-only mode, Cribbit's operator reviews the exact cropped photo in each new contribution for sensitive or confidential information within 90 days. Mask quality is not yet assessed during this initial collection review and would require a separately approved review step before model use. Unreviewed or rejected samples are withdrawn and deleted. Accepted samples remain unavailable for training, fine-tuning, evaluation, dataset assembly/export, threshold tuning, or any other model-development use in the current collection-only mode. No such use will begin until a separate Canadian privacy/technology legal review and approval; that review may require re-consent or deletion of earlier contributions.
Consent and contribution controls
Project contribution consent is separate from ordinary service and operational reliability collection. Under Manage account > Data & privacy, Show contribution requests controls only whether Cribbit shows the optional request when an eligible project first progresses to the layout editor. It is on by default for new accounts. Turning it off does not delete or otherwise change an existing contribution, and turning it on never authorizes a contribution; every contribution still requires a new, specific per-project affirmative choice.
Delete all contributions makes every contribution that exists at the time of confirmation unavailable for future use immediately and starts permanent deletion, which finishes within 30 days. It does not affect your projects or the contribution-request setting. A contribution made afterward remains available under its own consent and retention terms unless you press the deletion button again. There is no project-specific self-service deletion control.
Service providers and processing locations
Cribbit uses service providers acting on our behalf: Clerk for identity/authentication; Netlify for the web frontend and proxy; Railway for application hosting, Postgres, and attached storage; Cloudflare R2 for private object storage; Modal for GPU image/mask processing (project images are sent to it); Resend for limited order and infrastructure-alert email delivery; and UptimeRobot for public service-availability checks. QuickBooks is used for invoicing and business records after order review. These providers may process information in Canada, the United States, or other jurisdictions in which they or their subprocessors operate, where lawful authorities may access information under local law. We do not sell personal information or model-improvement contributions. Contributions are not shared with contractors or other third parties for their own use.
Retention
- Active projects remain with your account; deleted projects remain in Recently Deleted for up to 90 days before permanent deletion unless you delete them sooner.
- Inactive carts are deleted after 90 days. Unattached final previews and renders are deleted after 7 days.
- Checkpoint, layout-recovery, hydration-failure, browser-failure, and mask-processing-attempt reports are retained for 90 days. Minimal backend-error reports are retained for 180 days. Job-linked reports are deleted sooner with the project/account. Equivalent fallback files use the same schedule; an unreadable/unknown fallback file uses the current 180-day maximum.
- The project-local detailed mask-processing profile and project-local generation recipe remain with their project, including up to 90 days in Recently Deleted, and are permanently deleted with the project/account. The full profile is never included in a model-improvement contribution; a separately copied compact recipe follows the contribution's independent retention.
- Infrastructure logs, metrics, uptime history, and alert email follow provider/account-configured retention and access controls recorded by Cribbit; they are not copied into the central telemetry store.
- Model-improvement preference/consent history and completed deletion audit records currently have no automated expiry. They are retained as evidence of choices and to prevent restore from reactivating deleted data while Cribbit completes its minimization/retention review.
- Pending model-improvement contributions are deleted if not accepted within 90 days. Accepted contributions have a hard application maximum of 3,648 days from original collection, backed by a 3,650-day R2 lifecycle rule, reviewed for continuing need annually, and deleted earlier when the improvement purpose is complete. A point-in-time Delete all contributions request, rejection, review timeout, account deletion, and applicable privacy handling override that maximum for the contributions they cover; permanent source-project deletion does not.
- Submitted/cancelled orders not authorized for manufacturing remain with the account pending final legal review of their maximum schedule and are deleted with the account. Paid, otherwise authorized, or fabricated records may be retained for legal, accounting, warranty, recall, or dispute purposes. The current provisional schedule is seven years after the end of the latest manufacturing-activity year, subject to legal review, legal holds, and active claims.
- Minimal deletion tombstones and non-identifying/hash-based ledgers may be retained to prevent deleted data from being restored.
As of this policy date, Railway Postgres backups and volume snapshots are not configured. Before they are enabled, Cribbit will record and publish their actual schedule and retention. Once backups exist, records deleted from live systems may remain in protected backups until rotation expires; individual requests will not rewrite old backups, and restore procedures reapply completed deletions before service resumes.
Safeguards and access
Cribbit uses authentication and owner checks, private buckets, separate bucket-scoped credentials, least-privilege administrative routes, pseudonymous contribution keys, integrity hashes, fail-closed collection gates, deletion ledgers, retention sweeps, and transport security. Internal contribution access is limited to Cribbit's operator. No safeguard eliminates all risk; please do not upload or contribute content that is unnecessary, highly sensitive, confidential, or outside your authority to share.
Access, correction, deletion, and complaints
Contact the Privacy Officer to ask what personal information Cribbit controls about you, how it has been used or disclosed, or to request access or correction, subject to lawful exceptions. You can withdraw all model-improvement contributions that currently exist, control whether future contribution requests are shown, or request account deletion under Manage account > Data & privacy. Account deletion removes projects, ordinary unmanufactured orders, job-linked operational reports and fallback files, contribution files and identifying contribution mappings, then deletes the Clerk identity. Unlinked browser and processing reports have no account mapping and expire on their 90-day schedule; minimal consent/completed-deletion audit records and legally required manufacturing/business records may remain as described above. You may raise a complaint with Cribbit first and may also contact the Office of the Information and Privacy Commissioner for British Columbia.
Cookies and local browser storage
Clerk uses session cookies or equivalent browser storage to keep you signed in. Cribbit uses local browser storage for non-authoritative interface preferences and caches; server records control consent, contributions, contribution-request preferences, and deletion.
Changes
We may update this policy as the service, providers, or legal requirements change. We will change the date above and provide additional notice or seek new consent when a material change requires it. A materially changed model-improvement purpose or notice does not automatically authorize use of samples collected under an earlier version.