Privacy Policy
Last updated: August 6, 2026
This Privacy Policy explains how Patry ("we", "us"), operator of Cromanion, handles personal information. Cromanion is a conversion-optimization service: a website owner installs a small tag, and our agent observes visitor behaviour and, at the right moment, shows a helpful on-page intervention — with impact proven causally through a permanent control group and written back into the tools the owner already uses.
We designed Cromanion to be private by default: it is cookieless, it does not collect the values visitors type into forms, and raw behavioural events are never sent to a language model.
1. Who is responsible for your data (controller vs processor)
There are two distinct relationships. For the behavioural data of visitors to a client's website, the client (the website owner) is the data controller and we act as their data processor, handling that data only on their instructions to provide the service. For that visitor data, please also consult the privacy policy of the website you visited.
For the personal information of our own account holders (name, email, billing details) and for website visitors of sites we operate directly, we are the data controller.
In addition, where we de-identify and aggregate service data to improve and train our models as described in section 3 below, we act as the data controller for that de-identified data, and our clients authorise this processing under our Terms of Use.
2. What we collect and how it is processed
On a client site, the tag streams anonymous behavioural events — page views, clicks, scrolling, dwell time, cursor movement, and which form fields were focused. It does NOT capture the values a visitor types (for example, we record "filled 3 fields then abandoned", never the content of those fields).
These raw events are compiled, in plain code at the edge, into a short readable text "narrative" of the session. Only that compressed narrative — never the raw event stream — is ever sent to a language model for analysis.
For account holders, we collect the email you sign in with (via a one-time magic link), and, if you subscribe, the billing information processed by our payment provider (we do not store full card numbers).
3. Service improvement and model training
To make Cromanion better for everyone, we use session narratives and derived signals (for example, which interventions were shown and whether they led to a conversion) to develop, train, evaluate, and improve our machine-learning models and the service itself, including models trained across multiple client sites.
Before any data is used for training:
- it is stripped of the visitor hash and of any client-account identifiers, so that it can no longer be linked to an individual visitor or, where feasible, to a specific website;
- it never includes form values, lead-capture emails, or raw behavioural events, which are never collected or never stored in the first place (see sections 2 and 6).
This training data is de-identified and aggregated. Insights and models derived from it do not identify any individual and may be retained and used even after a client relationship ends, as described in our Terms of Use.
4. Cookieless visitor identity
We do not set cookies to track visitors and we do not store raw IP addresses. To recognise a returning visitor as a soft, approximate signal, the edge computes a one-way hash from the visitor's IP address and browser user-agent; the raw IP is discarded at the edge and only the short hash is kept. The hash cannot be reversed to an IP address and is never used to identify a person by name.
A limited, compressed "visitor memory" (visit count, last seen, whether they converted, coarse interests, last funnel stage) may be stored against this hash to personalise assistance, and it expires automatically after a short retention window.
5. The control group (holdout)
To prove impact honestly, a random 10% of sessions are a permanent control group that receives no intervention. This lets a client compare exposed vs. control outcomes in their own analytics. Control-group sessions are still measured, but nothing is shown to them.
6. Lead-capture emails are pass-through and never stored
If a client enables a lead-capture intervention and a visitor voluntarily submits their email, that email is relayed directly to the destination the client configured (e.g. their CRM or automation tool) and is never stored by us, never sent to a language model, never used for model training, and never written to analytics. If no destination is configured, the email is discarded.
7. Results written to the client's own tools
Rather than a separate dashboard, Cromanion writes event signals (such as an intervention shown, an intervention clicked, an assisted conversion, and the holdout flag) into the analytics the client already runs — for example Google Analytics, Plausible, Matomo, Fathom, or Segment. What those third-party tools then do with that data is governed by their own policies and the client's configuration.
8. Sub-processors
We use a small number of reputable service providers to operate Cromanion. Each processes data only as needed to provide their part of the service:
- Supabase — Application database (Postgres + vectors) and account authentication (United States / EU).
- Cloudflare — Edge compute (Workers, Durable Objects, KV) — the real-time hot path (Global edge network).
- Anthropic (Claude) — Language-model inference over the compiled narrative only — never raw events (United States).
- Voyage AI — Text embeddings for narrative similarity retrieval (United States).
- Resend — Transactional and impact-report email delivery (United States).
- Vercel — Application hosting and cookieless web analytics (United States).
- Stripe — Subscription billing and payment processing (account owners only) (United States).
9. International data transfers
Some sub-processors listed above are located in the United States or other countries outside Québec and the EU/UK. Where personal information is transferred internationally, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses or an equivalent mechanism) and assess the recipient before transferring.
10. Data retention
We keep personal information only as long as needed for the purposes above. Our current retention windows are:
- Raw behavioural events: not retained — compiled into the session narrative and discarded.
- Session narratives and derived records: up to 14 months (aligned with common analytics retention such as GA4's maximum).
- Cookieless visitor memory (edge cache): expires automatically, approximately 180 days.
- Account and billing records: for the life of the account plus the period required by applicable tax and legal obligations.
- Waitlist / marketing contacts: until you ask us to remove them.
De-identified and aggregated data used for model training (section 3), and the models and statistics derived from it, are no longer personal information and may be retained indefinitely.
11. Your rights (Law 25 & GDPR)
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to withdraw consent, and to object to or restrict certain processing. To exercise a right, contact us at privacy@cromanion.com. If your data is processed by us on behalf of a website you visited, we will refer your request to that website owner (the controller).
These rights apply to personal information. They do not extend to data that has been de-identified and aggregated so that it no longer relates to an identifiable individual (section 3), because we can no longer link that data back to you.
You also have the right to lodge a complaint with a supervisory authority — for residents of Québec, the Commission d'accès à l'information du Québec (CAI), and — for individuals in the EU/UK — your local data-protection supervisory authority.
12. Client responsibility for consent
If you are a client using Cromanion on your website, you are responsible for informing your visitors about this processing — including the service-improvement processing described in section 3 — in your own privacy policy and for obtaining any consent required in your jurisdiction before deploying the tag.
13. Security
We use industry-standard measures to protect personal information, including encryption in transit, access controls, and data minimisation by design. No method of transmission or storage is completely secure, but we work to protect your information and to limit what we collect in the first place.
14. Changes to this policy
We may update this policy from time to time. We will change the "last updated" date above and, for material changes, provide a more prominent notice.
15. Contact us
For any privacy question or to exercise a right, contact Patry at privacy@cromanion.com, or by mail at 323 chemin de la Glacière, Stoke, Québec, J0B 3G0, Canada.