Skip to content
CRUX← Back to Crux

Privacy policy

Last updated: 10 June 2026

1. Who we are (data controller)

Crux (cruxrace.com) is operated by Sweet Deal SL, a company registered in Spain (“we”, “us”). Sweet Deal SL is the data controller for the personal data described in this policy under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

Privacy contact: langelk@gmail.com

2. What data we collect, why, and on what legal basis

a. Marketing list (legacy preview waitlist)

  • Status: Crux is now open to everyone, so we no longer collect new waitlist sign-ups. We retain the addresses already collected (and honour every unsubscribe) until erasure or the retention limit below.
  • Data: your email address, the consent choices you made (recorded verbatim, with timestamps), confirmation status.
  • Purpose: contacting you about Crux; and — only if you separately opted in — sending occasional news, training insights and product updates.
  • Legal basis: your consent (Art. 6(1)(a) GDPR), collected via double opt-in. You can withdraw consent at any time via the unsubscribe link in every email — withdrawal is as easy as signing up.

b. Your Crux account

  • Data: username, password (stored only as a salted cryptographic hash), optional email and full name, your athlete profile (level, objectives, fitness notes, philosophy), race plans, fuelling plans, debrief notes, and feedback you submit in the app.
  • Purpose: providing the Crux service — building and storing your race strategies.
  • Legal basis: performance of a contract (Art. 6(1)(b)) — the data is needed to provide the service you signed up for.

c. Public race-results data

  • Data: if you connect your runner profiles (UTMB Index, ITRA, DUV), we import your publicly available race history and performance indexes from those sources, always at your request and visible to you.
  • Legal basis: performance of a contract (Art. 6(1)(b)); you initiate each import and can delete the data from your profile at any time.

d. Technical & diagnostic data

  • Data: server logs and error records (which feature failed, technical error messages), and AI usage metering (tokens consumed per feature) tied to your account.
  • Purpose: keeping the service reliable and managing costs.
  • Legal basis: our legitimate interest (Art. 6(1)(f)) in operating a secure, functioning service.

3. AI processing

Crux generates race strategies using Anthropic's Claude models. To do that, relevant parts of your data (your athlete profile, goals, the race's course data, your fuelling plan) are sent to Anthropic's API for processing. Anthropic acts as a processor and does not train its models on this API data. We don't send more than the feature needs, and your password and email are never included in AI requests.

4. Who processes your data for us

  • Vercel Inc. — hosting and content delivery.
  • Neon Inc. — database hosting.
  • Anthropic PBC — AI model processing (see section 3).
  • Resend (Plus Five Five Inc.) — transactional and (if you consented) news emails.
  • Stripe Payments Europe — subscription & payment processing.

These providers may process data in the United States. Transfers are safeguarded by the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR). We do not sell your personal data, and we don't share it with anyone beyond these processors.

Crux moments you explicitly choose to share appear at the community campfire and may be used to ground course strategies for other runners on the same race (any third parties named in your story are already anonymised when the moment is created). Moments you keep private are never shared or reused, and you can unshare a moment at any time.

5. Cookies

Crux uses a single strictly necessary session cookie (rp_session) to keep you signed in. It is essential for the service, so no consent banner is required (it is exempt under Art. 22.2 LSSI). We use no advertising, analytics or third-party tracking cookies.

6. How long we keep data

  • Waitlist: until you unsubscribe or ask for erasure, or at most 12 months after the preview programme ends.
  • Account data: for as long as your account exists. Ask us to delete your account and all associated data is erased.
  • Server logs / diagnostics: up to 12 months, then deleted or anonymised.

7. Your rights

Under the GDPR you can, at any time and free of charge:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have your data erased — “right to be forgotten” (Art. 17);
  • restrict processing (Art. 18);
  • receive your data in a portable format (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw any consent you gave, without affecting prior processing (Art. 7(3)).

To exercise any of these, email langelk@gmail.com. We respond within one month. If you believe we haven't handled your data properly, you can lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — aepd.es.

8. Security

Data is encrypted in transit (TLS) and at rest, passwords are stored only as salted scrypt hashes, sessions expire server-side, and admin access is restricted. No internet service can promise perfect security, but we follow current good practice and log errors so we can react quickly.

9. Children

Crux is not directed at children under 14, and we do not knowingly process their data.

10. Changes to this policy

If we make material changes, we'll update this page and the date above, and — where the change affects how we use the email address you gave us — notify you by email before it takes effect.