1. Introduction and scope
This Privacy Policy applies to Crab products and services provided by Beyondnote Technology Inc, including the crab.build website, documentation, release downloads, install scripts, support channels, the Crab CLI, Crab Desktop, and optional hosted or enterprise services.
For purposes of this Policy, the term Crab means the serverless Git remote helper, related command-line tools, Desktop application, documentation, and optional supporting services. Customer, user, you, and your refer to an individual or organization using Crab.
If your organization has entered into a written agreement, order form, data processing addendum, or other contract with Beyondnote Technology Inc, that agreement may contain additional or different privacy, security, support, and data processing terms.
2. Crab architecture and data boundary
Crab is designed so repository contents do not need to pass through a Crab-hosted repository service during ordinary CLI operations. The Crab CLI stores Git pointer data locally, chunks and deduplicates file content, and transfers object data to the object storage location configured by the user or organization, such as AWS S3, Google Cloud Storage, Azure Blob Storage, or S3-compatible storage.
The configured bucket, account, identity provider, network, cache, and access policy are ordinarily controlled by the customer. Beyondnote Technology Inc does not receive repository contents, local source files, cloud access keys, or raw bucket contents through normal self-managed CLI use unless you submit them to us, enable a service that sends them to us, or enter into an agreement that expressly provides for such processing.
3. Information we collect
We may collect or receive the following categories of information, depending on how you use Crab:
- Contact and account information. Name, email address, organization, role, billing contact, and similar information submitted through forms, support requests, enterprise onboarding, or other communications.
- Website, documentation, and download information. IP address, user agent, referrer, requested URL, timestamps, error diagnostics, and download records generated by hosting, delivery, security, or observability providers.
- Support and diagnostic information. Logs, command output, screenshots, configuration excerpts, support bundles, reproduction steps, issue reports, and other materials that you or your organization choose to provide.
- Enterprise service information. Tenant, account, entitlement, authorization, audit, cache, service health, usage, billing, and support metadata needed to provide optional hosted, managed, or enterprise services.
- Identity and credential metadata. Identity claims, provider names, token expiry metadata, repository URLs, operation names, policy decisions, and audit events processed by customer configured or contracted authentication services. We do not intentionally log secret token values or private key material.
4. CLI, Desktop, credentials, and local data
The Crab CLI keeps local operational state such as repository configuration, pointer metadata, chunk cache entries, logs, staging data, and encrypted authentication tokens. Local cache and token data remains on the user machine unless the user shares it, syncs it through their own systems, or configures a service that receives it.
Crab supports multiple credential modes. In static credential mode, Crab builds storage clients from environment variables, repository or user environment files, or the cloud SDK default credential chain. In federated modes, Crab may cache encrypted login tokens locally and use them to obtain scoped cloud credentials. See Static Credentials and Enterprise Authentication for the technical credential model.
Crab Desktop may use the operating system keychain and may pass configured cloud credentials to a Crab subprocess so the CLI can access the configured object store. Those credentials are governed by the customer environment, operating system, cloud provider, and organization policy.
5. How we use information
We use information for the following purposes:
- To provide, operate, secure, maintain, and improve Crab.
- To deliver documentation, release artifacts, updates, install scripts, support, and service notices.
- To respond to product, support, security, enterprise, sales, and billing requests.
- To authenticate users, evaluate authorization policies, maintain audit records, and provide contracted enterprise services.
- To investigate failures, abuse, security incidents, service reliability issues, and suspected violations of applicable terms.
- To comply with legal, tax, accounting, regulatory, and contractual obligations.
Where required by applicable law, our legal bases may include performance of a contract, legitimate interests in operating and securing Crab, consent, compliance with legal obligations, and protection of rights and safety.
7. Retention and security
We retain information for as long as reasonably necessary to provide Crab, comply with legal and contractual obligations, resolve disputes, maintain security, prevent abuse, and enforce applicable terms. Retention periods may vary based on the type of information, the service used, the customer agreement, and legal requirements.
We use administrative, technical, and organizational safeguards designed to protect information. No system is perfectly secure, and users are responsible for protecting their own cloud credentials, buckets, identity provider configuration, devices, local caches, secrets, backups, and repository access controls.
8. Your choices and privacy rights
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information about you. You may also have the right to withdraw consent where processing is based on consent.
You can avoid sharing optional support materials, revoke credentials in your cloud provider, delete local Crab caches or token files using documented commands, and manage identity provider access through your organization. Enterprise users should direct requests through their organization when the organization controls the relevant Crab service or account.
9. International transfers
Beyondnote Technology Inc and its service providers may process information in countries other than the country where you are located. Where required, we rely on contractual, technical, and organizational safeguards for cross-border transfers.
10. Children
Crab is intended for professional and developer use. It is not directed to children, and we do not knowingly collect personal information from children under the age required by applicable law. If you believe a child has provided personal information to us, please contact us.
11. Changes and contact
We may update this Privacy Policy from time to time. If we make material changes, we will update the date above and provide additional notice when required by applicable law.
Questions or requests about this Privacy Policy may be submitted through the Crab contact form.