Privacy Policy
Last updated: September 24, 2026
1. Who we are and what this policy covers
Context AI Technologies Pte. Ltd. (UEN 202537678Z), 59 Ubi Avenue 1, #03-11, Singapore 408938 (Crator, we, us) operates Crator, an AI platform that helps businesses build, customise and run ERPNext, and build AI agents on top of it.
This policy explains how we collect, use, share and protect personal data when you visit cratorlabs.ai, create an account, or use the Crator platform (the Services). It should be read with our Terms of Service.
In short: your business data in your ERP belongs to you, we use it only to run the Services for you, and we never use it to train AI models.
2. Our role: two kinds of data
We handle two different kinds of data, and our responsibilities differ for each.
| Account and Usage Data | Customer ERP Data | |
|---|---|---|
| What it is | Information about you and your users as customers of Crator, and how you use the Services | Everything stored in or processed from your ERP instance: transactions, customer and supplier records, pricing, inventory, employees, documents, and custom apps you provide |
| Our role | We decide how it is used. Under the PDPA we are the organisation responsible for it; under the DPDP Act, the data fiduciary | We process it on your behalf. Under the PDPA we are your data intermediary; under the DPDP Act, your data processor |
| Who sets the rules | This policy | Your instructions and our Terms of Service (section 6) |
| Used to train AI models? | Only after de-identification, and you can opt out (section 5) | Never |
If you are an individual whose personal data is held in a Crator customer's ERP (for example, a supplier contact or an employee of that customer), that customer is responsible for your data. Please contact them first. We will help them respond to your request.
3. Information we collect
3.1 Account information. Name, work email, company name, role, phone number, and login credentials (passwords are stored only in hashed form). Billing details are handled by our payment processor, Stripe; we do not store full card numbers.
3.2 Usage Data. How you and your users use the Services: features used, instructions and prompts you give our AI agents, steps the agents take, configurations generated, errors, corrections, feedback, whether Output is accepted or rejected, and Credits consumed.
3.3 Technical data. IP address, browser and device type, operating system, approximate location (city or country), log files and performance data.
3.4 Customer ERP Data. Data stored in your ERP instance or that you upload, connect or import, including any personal data of your customers, suppliers and employees. We process this only as your data intermediary (section 2).
3.5 Integrations. You can connect your ERP instance to external services, such as marketplaces, messaging apps, payment gateways or banks (for example, IndiaMART or WhatsApp). Data that flows between your ERP and an external service moves at your direction and is governed by your agreement with that service, not this policy. If we set up an integration for you, we do so only with your explicit permission. We store the access tokens needed to operate an integration in encrypted form.
3.6 Communications. Emails, contact form submissions, newsletter sign-ups, support requests, call notes and meeting bookings when you contact us, subscribe or book a demo.
3.7 Website. Cookies and similar technologies when you visit cratorlabs.ai (section 15).
4. How we use information
| Purpose | Data used |
|---|---|
| Provide the Services: host your ERP instance, run AI agents, apply the changes you request | Account, Usage, Customer ERP Data |
| Manage your account, subscription, Credits and billing | Account, Usage |
| Support and troubleshooting, including accessing your ERP instance when you ask for help | Account, Usage, Customer ERP Data (only as needed) |
| Security, fraud and abuse prevention | Account, Usage, Technical |
| Improve the Services and train our own models and agents | De-identified Usage Data only (section 5) |
| Service messages, such as security alerts, product changes and invoices | Account |
| Marketing emails, the Crator newsletter and product updates (you can unsubscribe at any time) | Account |
| Measure how our website and advertising perform | Technical, website usage |
| Comply with law and enforce our Terms | Any, as required |
We do not sell personal data and we do not use Customer ERP Data for advertising.
5. AI and model training
5.1 Crator never trains on Customer ERP Data. We do not use Customer ERP Data to train, fine-tune or improve any AI model, and none of the AI models we use are permitted to train on it.
5.2 Usage Data may be used, after de-identification. We learn from how people use Crator so our agents get better at building ERP workflows. Before Usage Data is used to train or evaluate our models, we remove or de-identify Customer ERP Data within it (such as names, amounts, prices, addresses and document contents) and anything that identifies you or your users.
5.3 Your choice. You can opt out of Usage Data being used for model training at any time by emailing dpo@cratorlabs.ai. Opting out is free and does not affect your service.
5.4 AI Providers do not train on your data. When our agents work on your request, relevant Inputs and Customer ERP Data are sent to our AI model providers to generate a response. Every AI model we use is accessed under terms that prohibit the provider from training on this data, and under zero data retention, so providers do not store it after generating a response.
6. AI providers and subprocessors
We use the service providers below to run Crator. A current list is kept at cratorlabs.ai/subprocessors, and we will give customers at least 14 days' notice before adding a new subprocessor that handles Customer ERP Data.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Google Cloud Platform | Hosting ERP instances and the Crator platform, and storing backups | All | India, Qatar (Doha), Singapore or United States, based on the customer's region |
| Microsoft Azure (Azure OpenAI) | Running OpenAI models | Inputs, relevant Customer ERP Data | Global: may run in any Azure region worldwide |
| Google Cloud Vertex AI | Running Anthropic Claude models | Inputs, relevant Customer ERP Data | Global: may run in any Google Cloud region worldwide |
| OpenAI | Voice features | Voice input, relevant Customer ERP Data | United States |
| OpenRouter | Routing requests to other models, including Google, Meta, xAI, Z.ai, Moonshot AI (Kimi), DeepSeek, MiniMax and Alibaba (Qwen) | Inputs, relevant Customer ERP Data | United States, and the locations of the model hosts it routes to |
| GitHub | Storing code, including your ERP customisations and Custom Apps | Code, configurations | United States |
| Stripe | Payments and billing | Account, billing | United States and other Stripe locations |
| Clerk | Sign-in and authentication | Name, email, login details | United States |
| Microsoft 365 | Business email | Account, communications | Singapore |
| Resend | Transactional and marketing emails | Name, email, email content | United States |
| PostHog | Product and website analytics | Usage, Technical | United States |
| Vercel | Hosting our website | Technical | United States |
| Google Analytics and Google Ads | Website analytics and advertising measurement | Technical, website usage | United States |
| Loops | Newsletter and contact form emails | Name, email, message | United States |
| Calendly | Booking calls and demos | Name, email, booking details | United States |
Customer ERP Data is stored only on Google Cloud Platform and, for code such as your customisations and Custom Apps, on GitHub. Our AI providers process data under zero data retention and do not keep it.
Each provider is bound by a written agreement requiring it to protect the data, use it only to provide services to us, and meet security standards at least as protective as ours.
7. Other sharing
We share personal data only:
- with your organisation: account administrators can see their users' activity;
- with partners you ask us to involve, such as an implementation or training partner, and only the data they need;
- for legal reasons: to comply with law, a court order or lawful government request, or to protect the rights, safety and security of Crator, our customers or others;
- in a business transfer: if we are involved in a merger, acquisition or asset sale, subject to this policy, with notice to you;
- with your consent.
8. International transfers
Crator is based in Singapore. Customer ERP Data is hosted on Google Cloud Platform in the region assigned to your account, currently India, Qatar (Doha), Singapore or the United States, generally the one closest to you. Our AI Providers and other subprocessors may process data in other countries, including the United States. When we transfer personal data outside Singapore, we take appropriate steps under the PDPA to make sure recipients protect it to a standard comparable to the PDPA, including binding contractual commitments. Where the DPDP Act applies, we transfer data only to countries not restricted by the Government of India.
9. Security
We protect data with measures appropriate to its sensitivity, including:
- encryption in transit (TLS) and at rest;
- a separate environment for each customer's ERP instance, with sandbox and production kept apart;
- role-based access, with staff access to Customer ERP Data limited to what is needed for support, and logged;
- encrypted storage of integration credentials;
- regular backups and patching;
- confidentiality obligations for all staff and contractors.
Our SOC 2 report and security practices are available at our Trust Center.
No system is completely secure. If a data breach affects your personal data, we will notify you, and the relevant authorities where required, in line with applicable law. Customers will be notified within 72 hours of us becoming aware of a breach affecting their Customer ERP Data.
10. Retention
| Data | How long we keep it |
|---|---|
| Customer ERP Data | While your subscription is active, then 30 days for you to export it. Deleted from active systems within 30 days after that, and from backups within a further 60 days |
| Account information | While your account is active, then up to 90 days after closure |
| Usage Data (identifiable) | Up to 24 months, then deleted or de-identified |
| De-identified Usage Data | May be kept indefinitely, as it no longer identifies you |
| Billing and tax records | 5 years, or longer if the law requires |
| Support communications | Up to 3 years |
11. Your rights and choices
Subject to applicable law, you can:
- access the personal data we hold about you and learn how it has been used or disclosed in the past year;
- correct inaccurate or incomplete data;
- withdraw consent or ask us to delete your data, where we are not required to keep it;
- port your data, including a full export of your ERP instance;
- opt out of Usage Data being used for model training (section 5.3);
- unsubscribe from marketing emails and the newsletter using the link in any email.
To make a request, email dpo@cratorlabs.ai. We may need to verify your identity. We will respond within 30 days. If your data is Customer ERP Data held by another business using Crator, please contact that business first.
12. Singapore (PDPA)
We comply with the Personal Data Protection Act 2012. We collect, use and disclose personal data with your consent or as otherwise permitted by the PDPA, for the purposes in this policy. We have appointed a Data Protection Officer (section 18). If you are not satisfied with our response to a concern, you may contact the Personal Data Protection Commission (PDPC).
13. India (DPDP Act)
If you are in India, the Digital Personal Data Protection Act 2023 and its rules apply as they come into force.
- For Account and Usage Data, we are the data fiduciary. We process it on the basis of your consent given when you sign up, or for legitimate uses permitted by the Act.
- For Customer ERP Data, your business is the data fiduciary and we act as its data processor.
- You have the right to access a summary of your data, to correct, complete, update or erase it, to withdraw consent, to nominate another person to exercise your rights, and to seek grievance redressal.
- Grievances can be sent to our grievance contact at dpo@cratorlabs.ai. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
14. Other jurisdictions
Crator primarily serves businesses in Singapore and India. If you use it from elsewhere, such as the EU, UK or United States, you may have additional rights under local law, such as the right to object to or restrict processing, or to complain to your local regulator. Contact us at dpo@cratorlabs.ai and we will honour valid requests in line with the law that applies to you.
15. Cookies and analytics
Our website and app use essential cookies to keep you signed in and secure. We also use analytics and advertising cookies from PostHog, Google Analytics and Google Ads to understand how the site is used and to measure our advertising. You can control non-essential cookies through your browser settings. We do not use Customer ERP Data for advertising or share it with advertising networks.
16. Business users only
Crator is a business service for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact dpo@cratorlabs.ai and we will delete it.
17. Changes to this policy
We may update this policy as our Services or the law change. We will post the updated version with a new "Last updated" date, and notify customers by email at least 30 days before material changes take effect.
18. Contact us
Data Protection Officer and privacy requests: dpo@cratorlabs.ai
Post: Context AI Technologies Pte. Ltd., 59 Ubi Avenue 1, #03-11, Singapore 408938
India grievance contact: dpo@cratorlabs.ai