Cribbit Systems Incorporated

Privacy Policy

Last updated July 23, 2026

This policy explains how Cribbit Systems Incorporated ("Cribbit", "we", "us") collects, uses, discloses, protects, retains, and deletes personal information when you use Cribbit's drawer-design, ordering, and optional model-improvement services. Cribbit is based in British Columbia, Canada. Canada and the United States are our intended initial audience, but the service is technically reachable elsewhere and we do not verify residence.

Privacy contact

Jesse Furlan is Cribbit's Privacy Officer. Questions, access or correction requests, withdrawals, and complaints may be sent to jessefurlan@cribbitinserts.com.

Information we collect

A submitted order may include the postal code, fabrication files, approved previews, dimensions, prices, and transaction/workflow records needed for review and invoicing. Submitting an order does not authorize fabrication.

How we use information

We use information to authenticate you; process, save, restore, and delete projects; generate masks and fabrication designs; provide previews, carts, quotes, invoices, notices, fulfillment, support, security, service reliability, and legally required records. We limit use to disclosed and reasonably appropriate purposes, unless you consent to another use or law permits or requires it.

Operational reliability and service health

Cribbit collects a limited operational set without a diagnostics toggle because it is used to recover projects, identify broken essential workflows, measure mask-processing reliability, and detect service outages — not to measure engagement or general workflow completion.

Central reports are stored in Railway Postgres or, if the database writer is unavailable, in an equivalent retention-managed fallback file on the Railway application volume. Browser authentication and the requesting IP address are used transiently in process memory for authorization and rate limiting; neither is stored in an unlinked browser report. Operational reports do not contain raw error messages, full stacks, raw user agents, full URLs/query strings, request or response bodies, console logs, image/mask content, or a persistent device identifier.

Service-level health records use bounded component/state/event codes, the server release, and small aggregate counts such as dirty jobs, oldest dirty age, parked/backoff jobs, and consecutive failures. They go to provider logs and, for alert-worthy state changes, a bounded Resend email to Cribbit's operator; they are not stored as user telemetry. UptimeRobot checks only Cribbit's two public frontend/backend URLs. Hosting providers may also process ordinary network/account metadata and resource/deployment metrics under their configured policies. Provider log, metric, uptime, and alert-email retention follows the applicable provider/account settings; Cribbit records and reviews the actual production periods and access roles rather than copying these records into its telemetry database.

Optional model-improvement contributions

A project is never contributed automatically. The first time you select Create Layout, Cribbit may show one optional offer. You can inspect the exact undimmed cropped image in the workspace while the tool silhouettes, masks, dimming, cursors, and vector overlays are hidden. The small contribution panel starts near the center of the workspace and can be dragged aside. Clicking behind it or pressing Escape does not make a choice; only Contribute, No thanks, or the close button proceeds. Contribution requires an unchecked authority confirmation. Declining, closing, or an upload failure does not affect the project, price, order, or service. The automatic offer is not repeated, and there is no later project setting for contribution or project-specific withdrawal.

A contribution contains only the cropped image; current object_labelmap.png and object_submask_labels.png; immutable original_submask_labelmap.png, amg_best_mask_labels.png, and amg_masks.rle.json; a compact generation recipe containing calibration, model/checkpoint identity hashes, output-affecting settings, and resolved generation values; artifact hashes; revision; notice version; and collection metadata. It does not contain the full amg_profile.json, hardware name, timings, or mask-count profile. Storage keys use a random sample identifier and do not contain your account or project identifier. A protected Postgres record initially retains account and source-project links needed for consent governance and deletion. Contributions are therefore pseudonymous, not anonymous.

Subject to the separate approvals described below, Cribbit may use a contribution to develop, train, test, and improve image-processing models and related features, including object detection and automatic tool alignment. Automatic tool alignment is a planned related feature, not a feature currently available in the Cribbit layout editor.

Choosing to contribute creates a separate copy for the disclosed model-improvement purpose. Moving the source project to the Recycle Bin does not affect that copy. Permanently deleting the source project deletes the working project but not the contribution; Cribbit removes the protected project link and records when that happened. The protected account link remains only as needed for contribution deletion, account deletion, governance, and retention while the contribution exists. Deleting the account deletes its contributions before the Clerk identity is deleted.

If object-editor changes or layout-source deletion changes either current contributed labelmap, a later successful Add to Cart or Update Cart may replace both current labelmaps together at the same committed editor revision. The cropped image, immutable AMG evidence, generation recipe, original consent date, privacy-review status and deadline, and maximum retention date remain unchanged.

Every sample must be reviewed for privacy and quality before use. In the current collection-only mode, Cribbit's operator reviews the exact cropped photo in each new contribution for sensitive or confidential information within 90 days. Mask quality is not yet assessed during this initial collection review and would require a separately approved review step before model use. Unreviewed or rejected samples are withdrawn and deleted. Accepted samples remain unavailable for training, fine-tuning, evaluation, dataset assembly/export, threshold tuning, or any other model-development use in the current collection-only mode. No such use will begin until a separate Canadian privacy/technology legal review and approval; that review may require re-consent or deletion of earlier contributions.

Consent and contribution controls

Project contribution consent is separate from ordinary service and operational reliability collection. Under Manage account > Data & privacy, Show contribution requests controls only whether Cribbit shows the optional request when an eligible project first progresses to the layout editor. It is on by default for new accounts. Turning it off does not delete or otherwise change an existing contribution, and turning it on never authorizes a contribution; every contribution still requires a new, specific per-project affirmative choice.

Delete all contributions makes every contribution that exists at the time of confirmation unavailable for future use immediately and starts permanent deletion, which finishes within 30 days. It does not affect your projects or the contribution-request setting. A contribution made afterward remains available under its own consent and retention terms unless you press the deletion button again. There is no project-specific self-service deletion control.

Service providers and processing locations

Cribbit uses service providers acting on our behalf: Clerk for identity/authentication; Netlify for the web frontend and proxy; Railway for application hosting, Postgres, and attached storage; Cloudflare R2 for private object storage; Modal for GPU image/mask processing (project images are sent to it); Resend for limited order and infrastructure-alert email delivery; and UptimeRobot for public service-availability checks. QuickBooks is used for invoicing and business records after order review. These providers may process information in Canada, the United States, or other jurisdictions in which they or their subprocessors operate, where lawful authorities may access information under local law. We do not sell personal information or model-improvement contributions. Contributions are not shared with contractors or other third parties for their own use.

Retention

As of this policy date, Railway Postgres backups and volume snapshots are not configured. Before they are enabled, Cribbit will record and publish their actual schedule and retention. Once backups exist, records deleted from live systems may remain in protected backups until rotation expires; individual requests will not rewrite old backups, and restore procedures reapply completed deletions before service resumes.

Safeguards and access

Cribbit uses authentication and owner checks, private buckets, separate bucket-scoped credentials, least-privilege administrative routes, pseudonymous contribution keys, integrity hashes, fail-closed collection gates, deletion ledgers, retention sweeps, and transport security. Internal contribution access is limited to Cribbit's operator. No safeguard eliminates all risk; please do not upload or contribute content that is unnecessary, highly sensitive, confidential, or outside your authority to share.

Access, correction, deletion, and complaints

Contact the Privacy Officer to ask what personal information Cribbit controls about you, how it has been used or disclosed, or to request access or correction, subject to lawful exceptions. You can withdraw all model-improvement contributions that currently exist, control whether future contribution requests are shown, or request account deletion under Manage account > Data & privacy. Account deletion removes projects, ordinary unmanufactured orders, job-linked operational reports and fallback files, contribution files and identifying contribution mappings, then deletes the Clerk identity. Unlinked browser and processing reports have no account mapping and expire on their 90-day schedule; minimal consent/completed-deletion audit records and legally required manufacturing/business records may remain as described above. You may raise a complaint with Cribbit first and may also contact the Office of the Information and Privacy Commissioner for British Columbia.

Cookies and local browser storage

Clerk uses session cookies or equivalent browser storage to keep you signed in. Cribbit uses local browser storage for non-authoritative interface preferences and caches; server records control consent, contributions, contribution-request preferences, and deletion.

Changes

We may update this policy as the service, providers, or legal requirements change. We will change the date above and provide additional notice or seek new consent when a material change requires it. A materially changed model-improvement purpose or notice does not automatically authorize use of samples collected under an earlier version.

Return to Cribbit