Your world · your data
Privacy at Crewlo
Crewlo is a desktop app that runs on your computer. The Crewlo project does not operate a cloud inbox for your agent conversations. Connecting an agent or a messaging service does, however, send the information needed for that service to work to the provider you choose.
Who runs this project?
Crewlo is an open-source project maintained by Hafid Idrissi and contributors. Its source is at github.com/HafidIdrissi/Crewlo. For a privacy question or request, email idrissihafez@gmail.com. For a security issue, use private vulnerability reporting.
What stays on your computer?
The desktop app keeps studio settings, agent/session metadata, local work history, and messaging exchanges in its local application data. Your agent CLI can read the files and context you authorize for a task. Crewlo stores Telegram and WhatsApp credentials using the operating system's encrypted storage when that storage is available; the connection is refused when secure storage is unavailable. Pairing restricts remote messaging to the owner confirmed in the desktop app.
Disconnecting Telegram or WhatsApp removes the stored connection credentials and pairing, but does not erase existing local conversation history. Crewlo does not currently impose a fixed automatic deletion period for that history. The operator controls the computer and its local application data and backups.
What leaves your computer?
- AI agents: prompts, relevant files, and outputs may be sent by the agent CLI to its selected AI provider under that provider's terms and privacy policy. A local model may behave differently.
- Telegram: if you connect a bot, Crewlo polls the official Telegram Bot API and sends replies through it. Telegram receives the messages, bot identifiers, and delivery data needed to provide the service.
- WhatsApp: if you connect Meta's WhatsApp Cloud API, Meta processes incoming messages, replies, phone/account identifiers, and delivery events. To receive webhooks on your PC, you must supply a public HTTPS route; its provider can also handle the routed traffic.
- GitHub and other links: opening a repository, issue, release, or optional support link takes you to that external service.
Crewlo does not deliberately put bot tokens, internal agent prompts, or raw terminal logs into outgoing messaging replies. This is a product safeguard, not a guarantee about what you choose to send through an agent or third-party service.
GitHub star counter
The homepage requests the public repository star count from the GitHub API. GitHub receives normal request information such as your IP address. No account token is sent and clicking the button only opens the repository; starring it remains your choice on GitHub.
Product analytics
The desktop code includes optional PostHog product-usage analytics. They run only when a build includes a PostHog key, analytics remain enabled in Settings → Privacy, and Do Not Track is not set. Source builds without that key do not start this analytics client. The event allowlist is visible in the source code; it excludes message bodies, prompts, file paths, bot tokens, and raw terminal logs. If enabled, events include a random installation identifier and coarse app/platform details. You can turn analytics off in the app's Privacy settings.
Live agent activity shown inside the desktop app is separate from these outbound product-usage events.
This website
The Crewlo website is a static GitHub Pages site. Its own script does not run analytics, set tracking cookies, or collect form submissions. The site may store no personal information itself, but GitHub can receive standard request information, such as your IP address, when serving pages; see GitHub's privacy statement. External links are governed by their destinations' policies.
Keeping and controlling information
Local app data remains under the operator's control until they remove it or their backups. Third-party providers apply their own retention rules to information sent to them. If you share information with the Crewlo project in a GitHub issue or discussion, GitHub hosts that submission and it may be public; do not post credentials, private chats, or personal files there.
If you want access, correction, or deletion of information you shared directly with the project, email idrissihafez@gmail.com. See the data deletion instructions for local data and provider boundaries. For information held only on your PC or by Telegram, Meta, an AI provider, or GitHub, use the controls and contact channels of the relevant operator or provider. Where applicable, you may also complain to your data-protection authority.
Changes
This page will be updated when Crewlo's data flows materially change. The date above and the public repository history show revisions. The operator should review the privacy terms of each agent and messaging provider they enable.