LEGAL
Last Updated: 23 July 2026
1. Introduction
Welcome to Crumdex.
Crumdex is designed to help people organise important information about the assets, accounts, organisations and records that matter to them, while deliberately minimising the amount of personal information that needs to be stored.
Unlike many digital services, Crumdex has been designed on the principle that less information is often better information. Our aim is to provide users with a trusted index of where important things exist rather than becoming a repository for passwords, financial credentials or other highly sensitive authentication information.
Protecting your privacy is therefore not simply a legal obligation for us; it is one of the fundamental principles upon which Crumdex has been designed.
This Privacy Policy explains:
what personal information we collect;
why we collect it;
how we use it;
when we may share it;
how we protect it;
how long we keep it; and
the rights available to you under applicable data protection law.
We encourage you to read this Privacy Policy carefully before creating an account or using the Service.
2. Who We Are
Crumdex is operated by Crumdex Limited, a private company limited by shares incorporated in England and Wales.
Company Number: 17349848
Registered Office:
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom
ICO Registration Number:
ZC203577
Email:
hello@crumdex.com
Throughout this Privacy Policy, references to "Crumdex", "we", "our" and "us" mean Crumdex Limited.
For the purposes of UK data protection legislation, including the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, Crumdex Limited is the data controller in respect of the personal information described in this Privacy Policy.
3. Our Privacy Philosophy
Many online services encourage users to store increasing amounts of personal information.
Crumdex has deliberately been designed differently.
Our objective is to help users remember what exists and where it can be found, without requiring them to store the confidential credentials needed to access those assets.
Accordingly:
we do not require users to store passwords;
we do not require users to store PIN numbers;
we do not require users to store private cryptographic keys;
we do not require users to store recovery phrases or seed phrases;
we do not require users to store authentication codes or security answers; and
we strongly discourage users from storing any information that could itself be used to gain unauthorised access to accounts or assets.
Instead, Crumdex is intended to function as an organised index, helping users and, where appropriate following our verification procedures, authorised individuals identify what exists and where further information may be obtained.
This design philosophy reduces the quantity of highly sensitive information held by Crumdex and forms an important part of our commitment to privacy, security and responsible data minimisation.
Data Protection Principles
In processing personal information, Crumdex seeks to comply with the principles set out in applicable data protection legislation. In particular, we aim to process personal information lawfully, fairly and transparently, to collect only information that is reasonably necessary for specified purposes, to keep information accurate and up to date where appropriate, to retain information only for as long as necessary, and to protect personal information through appropriate technical and organisational security measures. We also seek to demonstrate accountability for our processing activities and to keep our privacy practices under regular review.
4. Scope of this Privacy Policy
This Privacy Policy applies to personal information processed by Crumdex through:
our website;
the Crumdex web application;
communications sent to us by email;
customer support enquiries;
account administration;
Trusted Contact functionality;
security and verification processes; and
any other interactions you have with us in connection with the Service.
This Privacy Policy applies whether you access the Service from a desktop computer, laptop, tablet, mobile telephone or other compatible device.
It does not apply to third-party websites, products or services that may be referenced within your Crums or accessed via external links.
Those services remain subject to their own privacy notices and terms.
Relationship with Other Policies
This Privacy Policy should be read together with our Terms of Use, Cookie Policy (where published), and any other legal notices or policies made available through the Service from time to time. Where there is any inconsistency between this Privacy Policy and another policy regarding the processing of personal information, this Privacy Policy shall prevail unless expressly stated otherwise.
5. Definitions
For the purposes of this Privacy Policy:
Account means your registered Crumdex account.
Crum means an individual record created by a user identifying the existence or location of information, assets, organisations, advisers or other matters chosen by the user.
Personal Information means any information relating to an identified or identifiable individual.
Service means the Crumdex website, web application and associated services provided by Crumdex Limited.
Trusted Contact means an individual nominated by a user within their Crumdex account to be informed that a Crumdex account exists. A Trusted Contact does not receive automatic access to the user's account or Crums and has no entitlement to information unless and until Crumdex has completed its verification procedures in accordance with its policies and applicable legal obligations.
UK GDPR means the United Kingdom General Data Protection Regulation together with applicable UK data protection legislation.
6. Information We Collect
The personal information we collect depends on how you use the Service. We collect only the information that we reasonably consider necessary to provide, maintain, secure and improve Crumdex and to comply with our legal obligations.
6.1 Information You Provide
When you create and use a Crumdex account, you may provide us with personal information including:
Account Information
your full name;
your email address;
your date of birth;
your mobile telephone number; and
any other information you choose to provide when communicating with us.
Your date of birth is collected to support identity verification and account security processes where appropriate, including future verification procedures that may be implemented to help protect your account.
Your mobile telephone number is collected to support account security and may be used for future security features, including two-factor authentication (2FA), where implemented.
We will not use your date of birth or mobile telephone number for unrelated purposes unless we have another lawful basis to do so.
Crum Information
When using the Service you may create one or more Crums.
Depending upon the type of Crum you create, information may include:
the category or type of Crum;
any custom category;
details of where relevant information may be found;
optional notes entered by you;
the date the Crum was created;
the date it was updated; and
other information you choose to record.
You remain responsible for deciding what information you record within your Crums. Crumdex does not routinely review or monitor the contents of users' Crums. However, where information comes to our attention through customer support interactions, security investigations, verification requests, legal processes or other legitimate operational activities, we may access, review or process such information where reasonably necessary to provide the Service, protect users, investigate suspected misuse, comply with legal obligations or protect our legal rights.
Trusted Contact Information
If you nominate one or more Trusted Contacts we will collect information relating to those individuals, including:
name;
email address; and
relationship to you.
You should ensure that you have an appropriate basis for providing another person's personal information to Crumdex.
By nominating a Trusted Contact you confirm that, to the best of your knowledge, you are entitled to provide their details for this purpose.
Communications
If you contact us, we may collect information including:
your name;
your email address;
correspondence;
support requests;
feedback;
attachments you voluntarily send to us; and
any additional information contained within your communications.
6.2 Information We Collect Automatically
When you use the Service, certain technical information is collected automatically to help operate, protect and secure the platform.
This may include:
IP address;
browser type and version;
operating system;
device information;
login history;
authentication records;
timestamps;
security logs;
application performance information;
error reports; and
similar technical information necessary for maintaining the Service.
We collect this information primarily to:
maintain the security of the platform;
detect suspicious activity;
investigate technical issues;
improve system reliability; and
protect user accounts.
6.3 Information We Do Not Collect
An important feature of Crumdex is that we deliberately avoid collecting certain categories of highly sensitive information.
Unless specifically introduced as part of a future service offering, Crumdex is not intended to collect, store or process:
passwords;
PIN numbers;
online banking credentials;
private cryptographic keys;
cryptocurrency recovery phrases or seed phrases;
authentication tokens;
security answers;
payment card information;
copies of passports or driving licences;
biometric information;
health information; or
other information that could reasonably be used to gain direct access to your accounts or assets.
Users should not upload or record such information within the Service.
If we become aware that such information has been uploaded contrary to this Privacy Policy or our Terms of Use, we may remove it where appropriate to protect users and the integrity of the Service.
7. How We Collect Information
We collect personal information in several ways.
7.1 Directly from You
Most personal information processed by Crumdex is provided directly by you.
For example, when you:
create an account;
complete your profile;
create or edit Crums;
nominate Trusted Contacts;
contact our support team;
respond to communications from us; or
otherwise interact with the Service.
7.2 Automatically
Certain technical information is collected automatically through the operation of the Service, including security logs, authentication information and system diagnostics.
This enables us to:
maintain account security;
prevent unauthorised access;
monitor service performance;
investigate incidents; and
ensure the continued availability of the platform.
7.3 From Trusted Contacts
In limited circumstances we may receive information directly from Trusted Contacts or other individuals who contact us regarding a user's account.
This may include information provided as part of enquiries relating to a user's death or verified loss of mental capacity, or other matters requiring us to consider whether information may lawfully be disclosed.
Any such information will be processed only for the purposes of considering the request, verifying identity or authority where appropriate, complying with our legal obligations and protecting the rights of all affected individuals.
7.4 From Third Parties
In limited circumstances we may receive information from:
legal representatives;
executors or personal representatives;
attorneys acting under a registered Lasting Power of Attorney;
deputies appointed by the Court of Protection;
regulatory authorities;
law enforcement agencies;
courts or tribunals; or
other persons whom we reasonably consider to have a legitimate legal interest in relation to a request.
We will process such information only where we reasonably consider there to be an appropriate legal basis for doing so.
8. Why We Use Your Information
We use personal information only where we have a legitimate business purpose or another lawful basis under applicable data protection legislation.
The principal purposes for which we use your information include:
8.1 Providing the Service
Including:
creating and managing your account;
enabling you to create and manage Crums;
maintaining your account;
enabling Trusted Contact functionality;
providing customer support;
responding to enquiries; and
administering the Service generally.
8.2 Protecting Users
Including:
verifying identity where appropriate;
maintaining account security;
investigating suspicious activity;
detecting fraud;
preventing unauthorised access;
protecting users from misuse of the Service; and
implementing future security features such as two-factor authentication.
8.3 Improving the Service
We may use information to:
improve system reliability;
fix software defects;
monitor performance;
enhance functionality;
develop new features; and
improve the overall user experience.
At launch, Crumdex does not use behavioural profiling or advertising analytics to monitor how individual users interact with the Service.
8.4 Legal and Regulatory Compliance
We may process personal information where necessary to:
comply with applicable law;
respond to lawful requests;
maintain appropriate business records;
comply with regulatory obligations;
protect our legal rights;
defend legal proceedings; or
prevent or investigate unlawful activity.
9. Lawful Bases for Processing
Depending upon the circumstances, we process personal information under one or more of the lawful bases set out in Article 6 of the UK GDPR.
These include:
Performance of a Contract
Where processing is necessary to provide the Crumdex Service and fulfil our contractual obligations to you.
Legitimate Interests
Where processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms.
Our legitimate interests include, amongst other things:
operating the Service;
maintaining security;
improving functionality;
preventing fraud;
verifying identity where appropriate;
protecting users;
responding to enquiries;
enforcing our contractual rights; and
maintaining appropriate business records.
Legal Obligation
Where processing is necessary for us to comply with applicable legal or regulatory obligations.
Consent
Where we specifically request and obtain your consent for particular processing activities.
10. Trusted Contacts
10.1 Purpose of Trusted Contacts
As part of the Service, users may nominate one or more Trusted Contacts.
The purpose of a Trusted Contact is solely to identify an individual whom the user wishes to be aware that a Crumdex account exists should the user die or lose mental capacity.
A Trusted Contact does not:
become a joint account holder;
obtain access to the user's account;
receive login credentials;
gain authority to manage the account;
acquire ownership of any information;
have any automatic right to receive information from Crumdex.
Nomination of a Trusted Contact does not create any contractual relationship between Crumdex and that individual.
10.2 Contacting Crumdex
Crumdex will not proactively contact Trusted Contacts regarding the status of a user's account.
If a Trusted Contact, family member, personal representative or another interested person wishes to obtain information from Crumdex following a user's death or suspected loss of mental capacity, they must contact Crumdex directly and comply with our verification requirements.
10.3 Verification Requirements
Before releasing any information relating to a user's account, Crumdex may require whatever evidence, documentation and verification it reasonably considers appropriate in the circumstances. Crumdex's verification requirements may be supplemented by published guidance, frequently asked questions, operational procedures or additional instructions issued from time to time. Such materials are intended to assist applicants but do not limit Crumdex's discretion to request such further evidence or information as it reasonably considers necessary in the circumstances.
Verification requirements may vary depending upon the nature of the request, the jurisdiction involved, the information requested and the legal authority relied upon.
Without limitation, Crumdex may request:
an official death certificate;
a Grant of Probate;
Letters of Administration;
confirmation of appointment as executor or personal representative;
a registered Property and Financial Affairs Lasting Power of Attorney;
a Court of Protection Deputyship Order;
proof of identity;
proof of address;
evidence of authority to act;
additional supporting documentation;
statutory declarations;
affidavits;
certified copies of documents;
independent verification from third parties; or
any other information that Crumdex reasonably considers necessary.
No particular document guarantees that information will be released.
Likewise, the absence of any particular document does not necessarily prevent Crumdex from considering a request where other satisfactory evidence is available.
10.4 International Requests
Where requests originate outside the United Kingdom or involve overseas documents, Crumdex may require additional verification.
Without limitation, we may require:
certified English translations;
notarisation;
legalisation;
apostilles;
certification by appropriately qualified professionals;
verification through foreign authorities;
additional identity checks; or
any other evidence that we reasonably consider appropriate.
Crumdex reserves the right to determine the nature and extent of verification required in each individual case.
10.5 Our Discretion
The release of information following a user's death or verified loss of mental capacity is entirely subject to Crumdex being reasonably satisfied that:
the relevant event has occurred;
the requester has appropriate authority or entitlement;
the information requested is appropriate to disclose;
disclosure would be lawful; and
disclosure is consistent with our legal obligations.
Crumdex may:
request further evidence;
refuse incomplete applications;
seek clarification;
pause consideration while additional enquiries are undertaken;
obtain independent verification where appropriate; or
decline to release information where we are not reasonably satisfied that our verification requirements have been met.
Nothing in this Privacy Policy obliges Crumdex to release information merely because documentation has been submitted. Crumdex may revise or update its verification procedures from time to time to reflect changes in law, technology, fraud prevention practices or operational requirements. Any such changes shall not affect Crumdex's right to determine, in each individual case, whether it has received sufficient evidence to permit the lawful disclosure of information.
10.6 Information That May Be Released
Where Crumdex has completed its verification process and decides that disclosure is appropriate, we may provide information relating to the user's Crumdex records.
At launch, information will generally be provided in the form of:
an Excel spreadsheet; or
a PDF copy of the relevant information.
The information released will generally be limited to the contents of the user's Crums and such accompanying information as Crumdex reasonably considers appropriate.
Crumdex may redact or withhold information where we reasonably consider this necessary to protect the rights, privacy, security or legitimate interests of any person or to comply with legal obligations.
10.7 Information That Will Not Be Released Automatically
Even where verification has been completed, Crumdex does not guarantee that every item of information associated with an account will be disclosed.
Depending upon the circumstances, we may withhold information where disclosure could:
infringe another person's privacy;
prejudice ongoing legal proceedings;
facilitate fraud;
create security risks;
breach legal obligations;
expose confidential business information; or
otherwise be inappropriate.
Each request will be considered individually.
11. Information We Ask You Not to Store
One of the core principles of Crumdex is that it is intended to act as an organised index of important information rather than a repository of confidential authentication credentials.
Accordingly, users should not store within Crumdex:
passwords;
PIN numbers;
online banking credentials;
private cryptographic keys;
cryptocurrency recovery phrases or seed phrases;
authentication codes;
one-time passwords;
answers to security questions;
payment card numbers;
CVV numbers;
passport scans;
driving licence scans; or
any information that could reasonably enable another person to gain unauthorised access to an account, asset or service.
Although Crumdex implements appropriate technical and organisational security measures, no online system can guarantee absolute security.
Users remain responsible for exercising reasonable care when deciding what information to record within the Service.
If Crumdex becomes aware that information of this nature has been uploaded, we reserve the right to remove, redact or otherwise restrict access to that information where we reasonably consider doing so necessary to protect users or the integrity of the Service.
12. Sharing Your Information
Crumdex does not sell personal information.
We do not rent personal information.
We do not share personal information for advertising purposes.
We disclose personal information only where we reasonably consider it necessary and lawful to do so.
12.1 Service Providers
We may share personal information with carefully selected third-party service providers who assist us in operating the Service.
At the date of publication of this Privacy Policy, these providers include:
Supabase
Purpose:
Secure hosting, authentication and database services.
Resend
Purpose:
Transactional email delivery.
Microsoct 365
Purpose:
Business email services.
Framer
Purpose:
Website hosting.
Lovable
Purpose:
Application development platform.
Each provider processes information only to the extent reasonably necessary to perform services on our behalf.
Where appropriate, contractual safeguards are in place requiring those providers to protect personal information.
12.2 Corporate Transactions
If Crumdex undergoes or proposes:
a merger;
acquisition;
investment;
corporate restructuring;
sale of assets;
refinancing; or
similar corporate transaction,
personal information may be disclosed where reasonably necessary for due diligence, evaluation or completion of that transaction.
Any recipient will be expected to respect the confidentiality of personal information and comply with applicable data protection law.
12.3 Professional Advisers
We may disclose information where reasonably necessary to:
solicitors;
barristers;
accountants;
auditors;
insurers;
banks;
regulatory advisers; or
other professional advisers,
where such disclosure is reasonably necessary for the operation of our business or protection of our legal rights.
12.4 Legal and Regulatory Disclosures
We may disclose personal information where we reasonably believe disclosure is necessary or appropriate:
to comply with applicable law;
to comply with a court order, tribunal order or other legally binding process;
to comply with requests from regulators, law enforcement agencies or other public authorities acting within their lawful powers;
to establish, exercise or defend legal claims;
to enforce our contractual rights;
to investigate suspected unlawful activity;
to detect, prevent or investigate fraud, cybercrime or security incidents;
to protect the rights, property, safety or legitimate interests of Crumdex, our users or others; or
where disclosure is otherwise required or permitted by law.
Where reasonably practicable, we will limit disclosures to the information that we consider necessary for the relevant purpose.
12.5 No Sale of Personal Information
Crumdex does not sell users' personal information to third parties and does not disclose personal information for targeted advertising purposes.
Where consent is relied upon, you may withdraw it at any time, although doing so will not affect processing already carried out lawfully before withdrawal.
13. International Transfers
Crumdex is based in the United Kingdom.
We seek, wherever reasonably practicable, to store and process personal information within the United Kingdom or the European Economic Area (EEA).
At the date of publication of this Privacy Policy, our primary database infrastructure is hosted by Supabase in Frankfurt, Germany.
Some of our service providers or their sub-processors may, from time to time, process personal information outside the United Kingdom or the EEA.
Where personal information is transferred internationally, we will take appropriate steps to ensure that your information continues to receive an adequate level of protection in accordance with applicable data protection legislation.
Depending upon the circumstances, those safeguards may include:
an adequacy decision made by the UK Government;
the UK International Data Transfer Agreement (IDTA);
the UK Addendum to the EU Standard Contractual Clauses;
Standard Contractual Clauses approved by the European Commission where appropriate; or
any other lawful transfer mechanism recognised under applicable data protection law.
Further information regarding international transfers may be requested by contacting us using the details set out in this Privacy Policy.
14. Data Security
Protecting users' information is one of the core principles upon which Crumdex has been designed.
We implement appropriate technical and organisational measures intended to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
The security measures implemented by Crumdex may include, where appropriate:
encrypted communications using Transport Layer Security (TLS);
encrypted storage where appropriate;
secure authentication processes;
role-based access controls;
least privilege access principles;
security monitoring;
audit logging;
vulnerability management;
software updates;
regular backups;
business continuity procedures; and
appropriate contractual controls with third-party service providers.
We also seek to minimise risk by intentionally limiting the types of highly sensitive information that users are encouraged to store within the Service.
Despite these measures, no method of electronic transmission or storage can be guaranteed to be completely secure.
Accordingly, while we take reasonable steps to protect personal information, we cannot guarantee absolute security.
Users also play an important role in protecting their own information and should:
keep login credentials confidential;
use strong passwords;
protect access to their email account;
enable additional security features where available;
avoid sharing account access with others; and
refrain from storing passwords or other confidential authentication information within Crumdex.
If you believe your account has been compromised, you should contact us as soon as reasonably practicable.
15. Data Retention
We retain personal information only for as long as is reasonably necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, accounting and security requirements.
Retention periods may vary depending upon the type of information involved.
15.1 Active Accounts
We will generally retain personal information associated with an active account for as long as your account remains open.
15.2 Account Closure
Where you permanently delete your Crumdex account, we will ordinarily arrange for your account information, Crums and Trusted Contact records to be deleted from our live production systems within a reasonable period, unless continued retention is required or permitted by law.
15.3 Backup Systems
Copies of deleted information may temporarily remain within encrypted backup systems until those backups are overwritten or expire through our normal backup retention processes.
Backup copies are maintained solely for disaster recovery, business continuity and system resilience purposes.
Where information remains within encrypted backups, it will not ordinarily be restored except where reasonably necessary for legitimate operational purposes.
15.4 Legal Requirements
We may retain information for longer where reasonably necessary to:
comply with legal obligations;
resolve disputes;
investigate suspected wrongdoing;
establish, exercise or defend legal claims;
enforce our contractual rights;
comply with regulatory requirements; or
protect the legitimate interests of Crumdex or others.
16. Your Rights
Subject to applicable data protection law, you may have the following rights in relation to your personal information.
These rights are not absolute and may be subject to legal exemptions or limitations.
16.1 Right of Access
You may request confirmation of whether we process your personal information and request access to that information.
16.2 Right to Rectification
You may request correction of inaccurate personal information or completion of incomplete personal information.
Many account details can also be updated directly through your Crumdex account.
16.3 Right to Erasure
In certain circumstances you may request deletion of your personal information.
This right is sometimes referred to as the "right to be forgotten".
Deletion may not be possible where we are legally required or otherwise entitled to retain certain information.
16.4 Right to Restrict Processing
You may request that we restrict the processing of your personal information in certain circumstances prescribed by law.
16.5 Right to Object
You may object to certain processing activities where we rely upon legitimate interests as our lawful basis.
We will consider all such objections in accordance with applicable law.
16.6 Right to Data Portability
Where applicable, you may request a copy of certain personal information in a structured, commonly used and machine-readable format.
16.7 Right to Withdraw Consent
Where processing is based upon consent, you may withdraw that consent at any time.
Withdrawal of consent will not affect processing already carried out lawfully before consent was withdrawn.
16.8 Exercising Your Rights
Requests relating to your privacy rights should be sent to:
hello@crumdex.com
Before responding to certain requests we may ask for information necessary to verify your identity.
This helps us ensure that personal information is disclosed only to the appropriate individual.
We will respond to valid requests in accordance with applicable data protection legislation.
17. Cookies
Crumdex uses cookies and similar technologies only where reasonably necessary for the operation, security and functionality of the Service.
At launch, Crumdex does not use cookies for behavioural advertising or targeted marketing.
17.1 Essential Cookies
Essential cookies may be used to:
enable secure login;
maintain authenticated sessions;
protect against fraudulent activity;
remember basic user preferences;
support website functionality; and
improve security.
These cookies are necessary for the operation of the Service.
17.2 Optional Cookies
At the date of publication of this Privacy Policy, Crumdex does not use optional analytics, advertising or marketing cookies.
Should this change in the future, this Privacy Policy and any applicable cookie controls will be updated accordingly.
18. Third-Party Services
In operating the Service, Crumdex relies upon trusted third-party providers.
These providers may change from time to time as our business develops.
At the date of publication of this Privacy Policy, principal providers include:
Supabase
Database hosting, authentication and backend infrastructure.
Resend
Transactional email delivery.
Microsoft 365
Business email services.
Framer
Website hosting.
Lovable
Application development platform.
Each provider operates under its own privacy documentation and contractual arrangements.
While we undertake reasonable due diligence when selecting service providers, we are not responsible for the privacy practices of independent third-party organisations.
Where those providers process personal information on our behalf, we seek to ensure that appropriate contractual safeguards are in place.
19. Changes to this Privacy Policy
Crumdex may update this Privacy Policy from time to time to reflect changes including:
changes to applicable law or regulation;
changes to our business operations;
changes to the Service or its functionality;
changes to our service providers;
security improvements;
technological developments; or
any other reason that we reasonably consider makes an update appropriate.
Where changes are minor, we may update this Privacy Policy by publishing the revised version on our website or within the Service.
Where we consider changes to be material, we may also notify users by email, through the Service, or by another appropriate method.
The version number and "Last Updated" date appearing at the beginning of this Privacy Policy indicate the current published version.
Your continued use of the Service following publication of an updated Privacy Policy constitutes acknowledgement that you have had the opportunity to review the updated policy.
20. Contact Us
If you have any questions regarding this Privacy Policy or the way in which Crumdex processes personal information, please contact us.
Crumdex Limited
Company Number: 17349848
Registered Office:
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom
Email:
hello@crumdex.com
We will endeavour to respond to enquiries as promptly as reasonably practicable.
21. Complaints
We hope that we can resolve any concerns you may have regarding the way we process personal information.
If you have any concerns, we encourage you to contact us first so that we have an opportunity to investigate and, where appropriate, resolve the matter.
If you remain dissatisfied, or believe that we have not processed your personal information in accordance with applicable data protection legislation, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
The ICO is the United Kingdom's independent authority responsible for upholding information rights.
Further information about making a complaint can be found on the ICO's official website.
Schedule 1
Categories of Personal Information Processed
Depending upon how you use the Service, Crumdex may process one or more of the following categories of personal information.
Identity Information
Name
Date of birth
Contact Information
Email address
Mobile telephone number
Account Information
Username (if introduced)
Authentication records
Login history
Account status
Security settings
Crumdex Information
Crums
Crum categories
Custom categories
"Where to look" information
Optional notes
Dates created
Dates updated
Trusted Contact Information
Name
Email address
Relationship to the user
Communications
Customer support requests
Emails
Feedback
Correspondence
Attachments voluntarily provided
Technical Information
IP address
Device information
Browser information
Operating system
Security logs
Error reports
Audit records
Session information
Verification Information
Where required for verification purposes, information provided by or on behalf of individuals requesting information following a user's death or verified loss of mental capacity, including identity documentation and evidence of authority.
Schedule 2
Summary of Lawful Bases
Creating and maintaining accounts
Lawful basis: Performance of a contract.
Providing the Service
Lawful basis: Performance of a contract.
Creating and storing Crums
Lawful basis: Performance of a contract.
Managing Trusted Contacts
Lawful basis: Performance of a contract.
Customer support
Lawful basis: Performance of a contract / Legitimate interests.
Platform security
Lawful basis: Legitimate interests.
Fraud prevention
Lawful basis: Legitimate interests.
Verification of identity
Lawful basis: Legitimate interests / Legal obligation (where applicable).
Improving the Service
Lawful basis: Legitimate interests.
Legal compliance
Lawful basis: Legal obligation.
Responding to lawful requests
Lawful basis: Legal obligation / Legitimate interests.
Defending legal claims
Lawful basis: Legitimate interests.
Business administration
Lawful basis: Legitimate interests.
Schedule 3
Third-Party Service Providers
At the date of publication of this Privacy Policy, Crumdex uses the following principal service providers.
Supabase
Authentication, backend infrastructure and database hosting.
Framer
Website hosting.
Lovable
Application development platform.
Resend
Transactional email services.
Microsoft 365
Business email services.
These providers may change from time to time as our business evolves.
Where providers are added, removed or replaced, this Privacy Policy may be updated accordingly where appropriate.
Version History
Version: 1.0
Date: 23 July 2026
Summary: Initial publication.
