Crucible — Privacy Policy
Last updated: 14 September 2026 · Version 0.1 (Beta)
This Privacy Policy explains how Bear Tech LLC ("Crucible", "we", "us") handles personal data in connection with the Crucible service at crucible-crm.com. Crucible is a recruiting system of record used by recruiting agencies ("Customers").
Crucible handles personal data in two different roles, and it is important to understand which applies:
- As a controller — for data about our Customers and their users (the recruiters who sign up and use Crucible). We decide how this data is used, and this Policy governs it.
- As a processor — for the candidate and contact data that Customers upload and manage in Crucible. For that data, the Customer is the controller and decides why and how it is processed; we act on the Customer's instructions under our Data Processing Agreement. If you are a candidate or contact and want to exercise rights over your data, your request generally goes to the agency that holds your record; see "Candidates and contacts" below.
1. Data we handle
About Customers and users (we are controller):
- Account and profile data: name, work email, agency name, role, password (hashed), and authentication data.
- Usage and device data: log data, IP address, browser type, pages viewed, and actions taken, used to operate and secure the Service.
- Communications: messages you send us (support, feedback).
- Billing data (when paid plans launch): handled per the Billing & Subscription Agreement; payment card data is handled by our payment processor, not stored by us.
About candidates and contacts (Customer is controller; we are processor):
- Identity and professional data that a Customer chooses to enter or import, such as name, LinkedIn URL, employment history, skills, availability, compensation notes, screen notes and transcripts, and recruiter activity. We do not require or request special categories of data; Customers should not upload more than needed.
2. How we use data
For Customer and user data, we use it to: provide, secure, and improve the Service; authenticate users and enforce per-firm isolation; provide support; send service-related communications; and comply with law.
For candidate and contact data, we process it only to provide the Service to the Customer and on the Customer's instructions: storing, structuring, de-duplicating, matching, generating documents (such as résumés), and reporting. We do not sell it, share it across Customers, or use it to build an independent candidate database or a product that competes with our Customers.
3. AI processing
Some features send data to an AI model provider (see Subprocessors) to structure notes, generate documents, and summarize records. We route these calls through a single controlled gateway and use the provider under terms that do not permit the provider to train its models on your data and that apply limited retention. AI output is labeled as fact or inference and must be verified by the user.
4. How we share data
We share data only with:
- Subprocessors who host and power the Service (database, hosting, AI, email), listed at /subprocessors, each bound by confidentiality and data-protection obligations.
- Legal and safety recipients, when required by law, valid legal process, or to protect rights, safety, and the integrity of the Service.
- A successor in a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal data and do not share it for cross-context behavioral advertising, as those terms are used under California law.
5. Security
We maintain administrative, technical, and organizational measures designed to protect personal data, including:
- Per-firm logical isolation enforced at the database layer (row-level security), so one Customer's data is not reachable on another Customer's data path.
- Encryption of sensitive record data at rest and in transit.
- Crypto-shredding erasure: sensitive fields are encrypted per person with a dedicated key, so honoring an erasure request destroys the key and renders the data unrecoverable while preserving an immutable, de-identified audit trail.
- Access controls, least-privilege database roles, and audit logging.
No system is perfectly secure, but these measures reflect how Crucible is actually built.
6. Retention and deletion
We keep Customer and user data for as long as your account is active and as needed to provide the Service, then delete or de-identify it within a reasonable wind-down period after account closure, unless longer retention is required by law. Candidate and contact data is retained and deleted per the Customer's instructions and the DPA. Consistent with how Crucible works, historical facts are kept in an append-only, provenanced log and managed by recency windowing rather than deletion, except where an erasure request or legal obligation requires removal, in which case crypto-shredding is used.
7. Your rights
Customers and users may access, correct, download, or delete their account data by using in-product controls or contacting privacy@crucible-crm.com. Depending on where you live, you may have rights under:
- California (CCPA/CPRA): to know, access, correct, delete, and to not be discriminated against for exercising rights. We do not sell or share personal data. You may submit a request to privacy@crucible-crm.com.
- Other U.S. states with comprehensive privacy laws: comparable rights, which we honor where applicable.
- Canada (PIPEDA): to access and correct your personal information and to withdraw consent, subject to legal and contractual limits. Contact privacy@crucible-crm.com.
We will verify requests and respond within the time required by applicable law. You may appeal a denial by replying to our response.
8. Candidates and contacts
If you are a candidate or contact and your data is in Crucible, it was provided by a recruiting agency that uses Crucible and that agency controls it. To access, correct, or delete your data, contact that agency. If you contact us directly at privacy@crucible-crm.com, we will refer your request to the relevant Customer and assist them in responding, as required of a processor. Crucible provides Customers the tools (including erasure) to honor these requests.
9. Cookies and similar technologies
Crucible uses only what it needs to function: authentication and session cookies to keep you logged in, and local browser storage to remember interface preferences (such as saved table views). We do not use third-party advertising or cross-site tracking cookies. Because these are strictly necessary or preference cookies, Crucible does not show an ad-consent banner; you can clear cookies and local storage in your browser at any time, though this will log you out and reset preferences.
10. Data location and international transfers
The Service is hosted in the United States. If you use Crucible from Canada, your data will be transferred to and processed in the United States. By using the Service you understand this transfer occurs. During the beta the Service is intended for use only with U.S. and Canadian data; do not use it for individuals in the EU, UK, or EEA (see the Acceptable Use Policy).
11. Children
The Service is for business recruiting use by adults and is not directed to children under 16. Customers should not upload data about children. We do not knowingly collect data from children.
12. Changes
We may update this Policy. For material changes we will provide notice (email or in-app). The "Last updated" date reflects the current version; prior versions are retained in our records.
13. Contact
Privacy questions and requests: privacy@crucible-crm.com. Bear Tech LLC · 1112 S 17th St, Philadelphia, PA 19146.