CrewloBack to the studio

Your world · your data

Privacy at Crewlo

Last updated: 23 September 2026

Crewlo is a desktop app that runs on your computer. The Crewlo project does not operate a cloud inbox for your agent conversations. Connecting an agent or a messaging service does, however, send the information needed for that service to work to the provider you choose.

Who runs this project?

Crewlo is an open-source project maintained by Hafid Idrissi and contributors. Its source is at github.com/HafidIdrissi/Crewlo. For a privacy question or request, email idrissihafez@gmail.com. For a security issue, use private vulnerability reporting.

What stays on your computer?

The desktop app keeps studio settings, agent/session metadata, local work history, and messaging exchanges in its local application data. Your agent CLI can read the files and context you authorize for a task. Crewlo stores Telegram and WhatsApp credentials using the operating system's encrypted storage when that storage is available; the connection is refused when secure storage is unavailable. Pairing restricts remote messaging to the owner confirmed in the desktop app.

Disconnecting Telegram or WhatsApp removes the stored connection credentials and pairing, but does not erase existing local conversation history. Crewlo does not currently impose a fixed automatic deletion period for that history. The operator controls the computer and its local application data and backups.

What leaves your computer?

Crewlo does not deliberately put bot tokens, internal agent prompts, or raw terminal logs into outgoing messaging replies. This is a product safeguard, not a guarantee about what you choose to send through an agent or third-party service.

GitHub star counter

The homepage requests the public repository star count from the GitHub API. GitHub receives normal request information such as your IP address. No account token is sent and clicking the button only opens the repository; starring it remains your choice on GitHub.

Product analytics

The desktop code includes optional PostHog product-usage analytics. They run only when a build includes a PostHog key, analytics remain enabled in Settings → Privacy, and Do Not Track is not set. Source builds without that key do not start this analytics client. The event allowlist is visible in the source code; it excludes message bodies, prompts, file paths, bot tokens, and raw terminal logs. If enabled, events include a random installation identifier and coarse app/platform details. You can turn analytics off in the app's Privacy settings.

Live agent activity shown inside the desktop app is separate from these outbound product-usage events.

This website

The Crewlo website is a static GitHub Pages site. Its own script does not run analytics, set tracking cookies, or collect form submissions. The site may store no personal information itself, but GitHub can receive standard request information, such as your IP address, when serving pages; see GitHub's privacy statement. External links are governed by their destinations' policies.

Keeping and controlling information

Local app data remains under the operator's control until they remove it or their backups. Third-party providers apply their own retention rules to information sent to them. If you share information with the Crewlo project in a GitHub issue or discussion, GitHub hosts that submission and it may be public; do not post credentials, private chats, or personal files there.

If you want access, correction, or deletion of information you shared directly with the project, email idrissihafez@gmail.com. See the data deletion instructions for local data and provider boundaries. For information held only on your PC or by Telegram, Meta, an AI provider, or GitHub, use the controls and contact channels of the relevant operator or provider. Where applicable, you may also complain to your data-protection authority.

Changes

This page will be updated when Crewlo's data flows materially change. The date above and the public repository history show revisions. The operator should review the privacy terms of each agent and messaging provider they enable.