All apps

Is Cresta safe with your data?

D
Cresta icon

Cresta

Cresta Intelligence Inc.

43/100

Weak disclosure · high confidence

Cresta earns a D (43/100) because it leaves much about its data practices unstated.

#147

of 211 apps ranked

43

score · Customer support avg 47

-4

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Cresta's public privacy notice and terms cover data categories, recipient categories and rights in reasonable detail, but the AI-specific disclosures on training, retention periods and breach notification are absent, and several rights and safeguards are stated only as conditional or region-limited boilerplate.

What Cresta's privacy policy and terms of service say about your data

Rights carry a broad refusal caveat

Access, deletion, portability plus correction appear as bare bullet entries under the caveat that "these rights are not absolute, and in certain cases, we may decline your request as permitted by law". Deletion is further "subject to certain exceptions provided by law".

Transfer and legal-basis detail is Europe-only

The standard-form contracts language sits under the EEA, UK plus Switzerland transfer heading. The purposes-to-legal-bases table is prefaced by "If you are located in the EU or UK, the following information applies to you," so neither reaches users elsewhere.

Notice excludes the product data entirely

The notice explicitly excludes "Customer Personal Information" processed through Cresta's products. Nothing in it addresses model training, opt-out mechanisms, AI-interaction disclosure, synthetic-output marking, post-closure deletion timelines or breach notification.

No adverse clauses found

Every indicator stays adverse:false. The terms state "We do not assert any ownership over your Contributions", deletion is honoured rather than refused, retention is vague rather than indefinite-as-policy, and the "sale"/"sharing" acknowledgment is paired with a named Privacy Settings opt-out, so no reserved-harm clause is present.

What the policy is silent or vague on

  • Not stated: keeping user inputs out of model training
  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: a deletion timeline after closure or request

Cresta privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inSilent
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsPartial
Data-subject rights1 of 5 disclosed
Grants a right to access your dataPartial
Grants a right to delete your dataPartial
Offers data portability in a usable formatPartial
Grants a right to correct your dataPartial
Grants a way to object to or opt out of processingDisclosed
Retention and deletion0 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestSilent
Sets a shorter retention for AI conversation logsSilent
Commits to collecting only the data it needsPartial
Third-party sharing1 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementPartial
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersPartial
States a standard for government and law-enforcement accessPartial
Transparency2 of 5 disclosed
Discloses that you are interacting with AISilent
Marks AI-generated or synthetic outputSilent
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesPartial
Is versioned and dated, with change noticeDisclosed
Sensitive data and children2 of 3 disclosed
Discloses automated decisions and a human-review pathNot applicable
Limits the use of special-category dataDisclosed
Governs biometric data specificallyPartial
States protections for children's dataDisclosed
Security and accountability1 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
Customer support
Modalities
text, audio
Processes biometrics
Yes
Policy last updated
2025-11-27
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Other customer support apps

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Cresta safe with your data? Grade D | AI App Trust & Transparency Index