Data security & privacy
How Crux protects your research — no model training, tenant isolation, encryption, and data ownership.
Research data is sensitive by nature. Crux is built so that your data stays yours.
No model training
Your data is never used to train or improve AI models. AI processing goes through API endpoints whose terms exclude training use, and processing is ephemeral — providers don't retain your prompts or outputs beyond short operational windows. Every request runs server-side against a model Crux manages — including the Fast, Sharp, and Capable options in the Agent. There is no browser-side provider key and no way to point Crux at an unvetted provider, so the terms above hold whichever option you pick.
Tenant isolation
Project data is scoped to your user and organisation at the database level. AI features can only read data inside the authenticated user's current project and organisation; cross-tenant access is not possible by design.
You own your data
- You retain full ownership of everything you upload or create, including AI-generated output produced from your inputs.
- You can take your data with you at any time.
- Deleting a project permanently removes its content, files, embeddings, and AI interaction history.
Sharing is explicit
Projects are private by default. Wider access — sharing with your organisation — happens only when the owner enables it, and can be revoked at any time. See Sharing projects.
Infrastructure
Crux runs on established managed infrastructure (Vercel hosting, Neon Postgres, Clerk authentication) with encryption in transit. Payment details are handled by the billing provider and never touch Crux servers.
Related
- AI safety & content filtering
- Privacy Policy — including Google user data from Drive, Gmail, and Analytics
- Terms of use — platform terms of use
Related articles
Documents: Security & privacy