Is Cresta safe with your data?
Cresta
Cresta Intelligence Inc.
Weak disclosure · high confidence
Cresta earns a D (43/100) because it leaves much about its data practices unstated.
#147
of 211 apps ranked
43
score · Customer support avg 47
-4
vs category average
Cresta's public privacy notice and terms cover data categories, recipient categories and rights in reasonable detail, but the AI-specific disclosures on training, retention periods and breach notification are absent, and several rights and safeguards are stated only as conditional or region-limited boilerplate.
What Cresta's privacy policy and terms of service say about your data
Rights carry a broad refusal caveat
Access, deletion, portability plus correction appear as bare bullet entries under the caveat that "these rights are not absolute, and in certain cases, we may decline your request as permitted by law". Deletion is further "subject to certain exceptions provided by law".
Transfer and legal-basis detail is Europe-only
The standard-form contracts language sits under the EEA, UK plus Switzerland transfer heading. The purposes-to-legal-bases table is prefaced by "If you are located in the EU or UK, the following information applies to you," so neither reaches users elsewhere.
Notice excludes the product data entirely
The notice explicitly excludes "Customer Personal Information" processed through Cresta's products. Nothing in it addresses model training, opt-out mechanisms, AI-interaction disclosure, synthetic-output marking, post-closure deletion timelines or breach notification.
No adverse clauses found
Every indicator stays adverse:false. The terms state "We do not assert any ownership over your Contributions", deletion is honoured rather than refused, retention is vague rather than indefinite-as-policy, and the "sale"/"sharing" acknowledgment is paired with a named Privacy Settings opt-out, so no reserved-harm clause is present.
What the policy is silent or vague on
- Not stated: keeping user inputs out of model training
- Not stated: a way to opt out of training
- Not stated: whether training use differs by plan
- Not stated: a deletion timeline after closure or request
Cresta privacy rating
Details
- Category
- Customer support
- Modalities
- text, audio
- Processes biometrics
- Yes
- Policy last updated
- 2025-11-27
- Region scored
- Global / US-default
- Last assessed
- 2026-08-13
Documents examined
Other customer support apps
Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.