← getcrawdad.dev

Privacy Policy

Last updated: July 16, 2026

This Privacy Policy explains how Crawdad Security LLC, a Delaware limited liability company (“Crawdad,” “we,” “us,” or “our”), collects, uses, and shares information in connection with the Crawdad software, applications, APIs, websites, and related services (the “Service”). It should be read together with our Terms of Service.


1. The Most Important Thing to Understand First

Crawdad is a security proxy that, in its default configuration, runs locally on your own machine or infrastructure and inspects the traffic between your AI agents and your LLM providers.

In that default configuration, the raw content of the traffic Crawdad inspects — your prompts, responses, and payloads — is analyzed locally and is not transmitted to us. We do not receive it, store it, or have access to it. This is a core design property of the Service.

This Privacy Policy is therefore mostly about the limited account, usage, and operational data we collect to provide the Service — not about the content of your inspected traffic, which in the default configuration we never see.

Two important exceptions to be clear about:


2. Information We Collect

2.1 Information you provide

2.2 Information collected automatically to operate the Service

2.3 Website analytics and cookies

Our website may use cookies and analytics technologies (such as Google Analytics or similar tools) to understand how visitors use the site, measure traffic, and improve the site. These technologies may set cookies in your browser and collect information such as pages visited, referring sites, approximate location, device and browser type, and similar usage data. Where required by law, we will obtain your consent before setting non-essential cookies, and you can control cookies through your browser settings and any cookie-consent controls we provide on the site. This website analytics activity is separate from the Crawdad product itself, which, as described above, analyzes your agent traffic locally and does not transmit its content to us.

2.4 What we do NOT collect in the default product configuration


3. The Fleet / Management Console

If you deploy the fleet or management console to administer multiple Crawdad deployments, the console processes operational and security metadata reported by those deployments, which may include device and deployment identifiers, protection status and configuration, policy and software versions, detection and security-event counts, timestamps, and similar administrative metadata. This metadata enables centralized visibility and management.

The fleet console is designed to run on infrastructure you operate. When you self-host the console, this metadata is stored in the console’s own database within your environment. The console is designed to convey security and operational metadata, not the raw content of inspected traffic.


4. How We Use Information

We use the information we collect to: provide, operate, secure, maintain, and improve the Service; authenticate accounts and manage credentials; meter usage and enforce plan limits; process payments and manage subscriptions; communicate with you about the Service, including service, security, and administrative messages, and, where permitted, product updates; record and evidence your acceptance of our Terms; detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms; and comply with legal obligations and enforce our agreements.

If you subscribe to a newsletter or mailing list, we will use your email to send the communications you signed up for, and you can opt out at any time using the unsubscribe link or by contacting us. We do not sell your personal information.


5. How We Share Information

We share information only as follows:


6. Data Retention

We retain account, usage, and operational data for as long as your account is active and as needed to provide the Service, and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements. We retain records of Terms acceptance as needed to evidence consent.


7. Security

We take reasonable measures to protect the information we hold. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and API keys.


8. Your Rights and Choices

Depending on where you live, you may have rights regarding your personal information, such as the rights to access, correct, delete, or port your data, or to object to or restrict certain processing, and rights regarding cookies and analytics. To exercise any of these rights or to ask a question, contact us at privacy@getcrawdad.dev. We will respond as required by applicable law.


9. International Users

We are based in the United States, and the information we collect is processed in the United States and other locations where we or our service providers operate. If you access the Service from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States.


10. Children’s Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them.


11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and take reasonable steps to notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.


12. Contact Us

Questions or requests regarding this Privacy Policy: privacy@getcrawdad.dev, Crawdad Security LLC.