Privacy Policy
This policy explains what personal information Saarah CRM collects about you, why, who else sees it, how long it is kept, and how you can read it back or have it deleted. It is written to the Australian Privacy Principles in the Privacy Act 1988 (Cth).
The short version
- Only what an account needs: your name, your email address, and a hash of your password.
- Nothing is sold, and nothing is shared for advertising.
- There are no analytics, no tracking pixels and no third-party advertising cookies. None.
- You can download everything held about you, or delete all of it, from Settings. Deletion removes it from the live service immediately; encrypted backups expire under the provider's retention schedule.
What is collected, and why
When you create an account
Your name, email address and password. The password is stored only as a cryptographic hash and cannot be read back by anyone, including us. These exist so you can sign in and so your data is yours.
When you use the service
Saarah CRM is a CRM, so most of what it stores is information your organisation records about other people — its customers and prospects. About you, as a user of the service, it holds:
- Your membership of an account: which account, your role in it, the teams you belong to, and whether you may export data.
- Work assigned to you — tasks, and the contacts, opportunities and projects you are named as the owner of.
- Notes, logged activity and comments you write, which are kept against the record they were written on and attributed to you.
- Files you upload as documents against a record. These are held in private storage and served only to people whose role and team allow them to see the record the file is attached to.
- Discussions you record, or upload from a recording made elsewhere, and the transcript and summary made from each one. These are held in private storage and heard only by people whose role and team allow them to see the recording. If you attach a recording to a contact, deal or project, a note with its title, date and who attached it appears on that record, and anyone who can see the record can see the note; nothing of what was said is in it.
- Your Mail Drop addresses, and email you send to them. Email filed on a contact is kept against that contact like a note you wrote. Email that could not be filed is held for you and your account's administrators to file or dismiss.
- Automations you switch on. A scheduled automation — one that acts because time passed, not because somebody moved a record — acts in the name of the administrator who switched it on, and the changes it makes are recorded against that person as having been made automatically.
- When each of those was created and last changed.
Email sent to your Mail Drop address
If you copy an email to your Mail Drop address, Saarah CRM receives the whole message: who sent it, who it was to and copied to, the subject and the text. That includes information about the people you were writing to, and anything they wrote that you forwarded. It is collected because you sent it, and used only to file it on the right contact. Blind-copied recipients are not recorded.
Records your organisation holds about its customers are its records rather than yours. You can see the ones your role and team give you access to, but a request under “seeing it” below returns what is about you and a count of the rest — asking about your own account is not a way to obtain the customer database. An administrator can export the account in full.
Discussions you record
A recording holds the voice of everyone in the conversation, not only yours, and its transcript and summary hold what each of them said. It is collected because you chose to record or upload it, and used only to produce the transcript and summary you see. Tell the people you are talking to that you are recording before you start, and upload only conversations everyone knew were recorded; in some places the law requires their consent.
Automatically, when you use the site
Your IP address and browser user-agent are recorded against your active sessions, and your IP address is counted against sign-in attempts to stop password guessing. Authenticated high-cost actions use your internal account id instead. Account-id counters are deleted with the account; all counters are removed by the next daily retention sweep after they become 24 hours old.
Cookies
Two, both first-party and both functional. One keeps you signed in. The other remembers whether you had the sidebar open. There are no advertising or analytics cookies, so there is nothing here to opt out of.
Who else sees it
Personal information is not sold, rented, or disclosed for marketing. These providers process it in order to run the service:
- Supabase— the database, hosted in Sydney, Australia. Everything you enter lives here, apart from uploaded files and recorded audio (below). A recording's transcript and summary are kept here.
- Vercel— hosting. Application servers are pinned to Sydney; the content delivery network that serves images and scripts is global, and sees the requests that pass through it. Transcribing and summarising a recording runs as a background job on Vercel, which keeps a record of the job's progress — including the summary as it is written — for up to seven days after it finishes.
- Amazon Web Services— files and recorded discussions, hosted in Australia. Documents, audio and Amazon Transcribe's working copies of transcripts are kept in private, encrypted storage and reached only through links that expire within minutes. Amazon Transcribe turns the audio into text, and Anthropic's Claude, run on Amazon Bedrock within Australia, writes the summary.
- Resend — email, operated from the United States. It receives your email address and the account-verification or password-reset message being sent. If you use the Mail Drop Box, it also receives every email you send to your drop address, in full, and keeps a copy for up to 30 days.
Sending an account email, or using the Mail Drop Box, therefore involves an overseas provider. The primary application database stays in Australia.
How long it is kept
- Your account — until you delete it. Your sign-in is shared with the other applications that use the same login (Paella, mployd and Circular); deleting your Saarah CRM account removes the sign-in too unless you still use one of them.
- Anything deleted in the app — contacts, deals, projects, tasks, notes — stays in the Trash for 30 days so a mistake can be undone, and is then removed by a daily sweep, together with any files attached to it. A file deleted on its own, and a deleted recording, are removed at once. Deleting a whole workspace removes its files and recordings shortly afterwards; a workspace that ends because its last member deleted their account has them cleared by a periodic clean-up. Files uploaded before they moved to Amazon Web Services also keep a copy in Supabase's private storage, where they were first kept, for 30 days after the move.
- Email filed from your Mail Drop address — as long as the entry it became. Held email — until it is filed or dismissed; a filed message goes when its entry is removed, and dismissed email is kept, not deleted.
- Recorded discussions, with their transcripts and summaries — until the person who recorded one, or an administrator, deletes it. Recordings do not go to the Trash: deleting one removes the audio, transcript and summary at once.
- Abuse-prevention counters, which hold an IP address or internal account id — account-linked rows are deleted with the account; all become eligible after 24 hours and are removed by the next daily sweep.
Deleting removes information from the live database immediately. Routine encrypted backups may retain a copy for a limited period afterwards before they expire in the normal course; those backups are not used for anything except restoring the service after a failure.
Seeing it, correcting it, deleting it
- See it. Settings → Download my data returns everything held about you, in every workspace you belong to, as a file — including the notes and comments you wrote, the emails you were on, the invitations you sent, and the transcripts and summaries of discussions you recorded. Your current password is required before the download. Anything on a record your role or team no longer lets you see is not in it; an administrator of that workspace can find it for you. The password hash and session tokens are deliberately excluded because they are credentials. So are your API tokens themselves, which we hold only as a fingerprint: the download lists each by the name you gave it and when it was last used. An API token lets a program act as you in one workspace until you revoke it in Settings, or leave that workspace. IP-based counters shared by a household or network are also excluded because they cannot reliably be assigned to one account. Files you uploaded are listed in the download with their name, type and size; their contents stay in the app, where you can download each from its record and access is checked, rather than being packed into the export file.
- Correct it. Your name in Settings, and your email in Settings after approving the change from the old inbox and verifying the new one. Contact us at privacy@example.com if you cannot access the old address.
- Delete it.Settings will delete your account and everything attached to it, including any workspace nobody else belongs to. Notes you wrote and work assigned to you in a shared workspace are that workspace's records and stay with it; your name comes off them once your sign-in is removed. Account deletion asks for your password and for your email address typed out, because it cannot be undone. If you are the only owner of a workspace other people use, it passes to the longest-standing administrator there, or member if there is none; if everyone else there is suspended, you will be asked to restore someone's access and make them an owner, or delete the workspace, first.
You do not have to ask us to do any of this and you will not be charged for it.
Keeping it safe
Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form. The application connects to the database with an account that has only the permissions it needs, and it cannot see the data of any other application sharing the same server. User-owned data is additionally protected by database row-level policies tied to the signed-in account. Every response containing your information is marked so that it is never cached by anything between our servers and your browser. No system is perfectly secure, and this policy does not claim otherwise.
Children
This service is not intended for people under 16. If you believe a child has created an account, contact us and it will be removed.
Complaints
If you think your privacy has been mishandled, write to privacy@example.com. We will acknowledge your complaint and respond within a reasonable time.
If you are not satisfied with the response, you can escalate to the Office of the Australian Information Commissioner, the independent regulator for privacy in Australia.
Changes
If this policy changes in a way that affects how your information is used, the change will be noted here and the date at the foot of the page updated. Continuing to use the service after a change means accepting the updated policy.