CROWDIFAI
  • HOME
  • MARKETPLACE
  • SELL DATA
  • QUALITY
  • LEGAL
  • Language
    🇬🇧 English🇩🇪 Deutsch🇫🇷 Français🇪🇸 Español
  • OPEN MARKETPLACE
CROWDIFAI LEGAL

Privacy Policy

Effective date: 25 September 2026 · Draft for legal review
Important: This document is a legal-review draft. Bracketed fields must be completed and the final text must be approved before publication.
TermsPrivacyRefundsCreator / SellerDataset LicenseKYC PrivacyCommunity Policy

Draft for legal review — complete all bracketed fields before publication. Effective date: 25 September 2026 Controller / Data Fiduciary: [LEGAL ENTITY NAME] (“CrowdifAI”, “we”, “us”) Registered address: [REGISTERED ADDRESS] Privacy contact: [PRIVACY EMAIL] DPO / EU representative, if applicable: [DETAILS OR “NOT APPLICABLE”]

This Privacy Policy explains how CrowdifAI collects, uses, shares, stores and protects personal data when you use our websites, iOS/Android applications, marketplace, contribution tasks, dataset services, seller tools, identity verification, payments, payouts, notifications and support services (the “Service”).

It also explains choices and rights available to you. Additional just-in-time notices may apply to specific processing, including our KYC & Identity Verification Privacy Notice.

1. Who is responsible for your data

[LEGAL ENTITY NAME] is generally the controller/data fiduciary for personal data used to operate CrowdifAI accounts, security, marketplace administration, transactions, KYC decisions, support and platform communications.

For datasets uploaded by creators, enterprise customers or other users, the legal role can vary. A user who uploads personal data may independently be a controller/data fiduciary and is responsible for having a lawful basis and appropriate notices/permissions. Where CrowdifAI processes enterprise data only on documented instructions, a separate data-processing agreement may apply.

This Policy does not replace a creator’s or buyer’s own privacy obligations for personal data contained in a dataset.

2. Personal data we collect

We collect information you provide, information generated through use of the Service, and limited technical information from your device/files.

2.1 Account and authentication data

This may include:

  • email address and username;
  • password-derived authentication records, authentication tokens and verification status;
  • passkey/device credential records;
  • password reset and email-verification events;
  • account role, account status and preferred language; and
  • login/session history.

We do not publish your password. Payment-card credentials are handled through the applicable payment provider where checkout is hosted by that provider; CrowdifAI may receive transaction identifiers and payment status rather than full card numbers.

2.2 Profile and contact data

Depending on what you provide and the feature used, this may include:

  • first and last name;
  • phone number;
  • country;
  • date of birth;
  • biography/profile text;
  • avatar or avatar configuration;
  • creator/buyer role and progression level; and
  • language and accessibility/preferences.

2.3 Business and billing profile data

For business/enterprise users we may process:

  • company/organization name;
  • VAT/tax identifier;
  • billing email;
  • organization membership/role; and
  • quote, invoice and order information.

2.4 User Content and datasets

When you upload or contribute data, we may process:

  • images and photographs;
  • video and audio;
  • text and documents;
  • scans;
  • annotations, labels, bounding boxes, polygons and review data;
  • filenames, descriptions, categories, tags and language;
  • provenance/ownership declarations;
  • dataset license tier and permitted-purpose choices; and
  • other metadata supplied with the upload.

Some User Content may itself contain personal data about you or other people. Do not upload third-party personal data unless you are permitted to do so.

2.5 Technical file and media metadata

Where present in a file, CrowdifAI’s validation/metadata pipeline may read technical properties such as:

  • file type and size;
  • image dimensions;
  • capture date/time;
  • camera make/model; and
  • embedded EXIF GPS/location coordinates. Current server logic may round GPS coordinates before storing them.

If location metadata is not needed for the relevant task or dataset, we recommend removing it before upload. CrowdifAI should configure production collection to minimize location data to what is necessary.

2.6 Identity verification / KYC data

If identity verification is required, we may collect/process:

  • identity-document type;
  • front/back images of an identity document;
  • selfie images;
  • verification provider/session identifiers;
  • verification status and rejection reason;
  • automated confidence, quality, anti-spoofing or liveness results;
  • reviewer notes; and
  • timestamps and evidence needed for fraud, appeal or compliance review.

Identity and selfie information is sensitive and receives additional access controls. See our KYC & Identity Verification Privacy Notice before submitting KYC information.

2.7 Purchases and marketplace transaction data

For buyers, we may process:

  • cart/listing/order identifiers;
  • purchased dataset/license;
  • amount, currency, taxes and status;
  • payment-provider checkout/session/payment/charge identifiers;
  • refund, dispute and chargeback status;
  • delivery/release/download entitlement; and
  • transaction timestamps.

2.8 Creator earnings and payout data

For creators/sellers, we may process:

  • marketplace earnings and task rewards;
  • platform fee and net amount;
  • pending/paid/reversed status;
  • payout-provider account identifiers/status;
  • onboarding/capability status;
  • payout transaction references; and
  • tax/payment information required by CrowdifAI or the payout provider.

Where Stripe or another payout provider collects bank-account or identity details directly, its privacy policy also applies.

2.9 Tasks, annotations and contribution history

We may process task assignments, submitted files, annotations, quality/consensus results, reviewer decisions, reward status, rejection reasons and anti-duplicate/fraud signals.

2.10 Device, network, security and audit data

We may process:

  • IP address;
  • user agent/browser/app information;
  • device/session description;
  • login timestamps and activity;
  • security/audit events;
  • request identifiers and endpoint/activity logs;
  • suspicious login or fraud signals; and
  • crash/diagnostic information if production diagnostics are enabled and disclosed.

2.11 Notifications and communications

We may process:

  • push-notification device tokens;
  • notification channel/preferences;
  • in-app notification/inbox events;
  • service, security, KYC, task, payout and marketplace notifications;
  • marketing preferences; and
  • support messages, deletion requests, complaints and related correspondence.

2.12 Consent, license and privacy choices

CrowdifAI records choices such as:

  • selected data categories;
  • research/statistics permission;
  • AI-training permission;
  • product/market research permission;
  • commercial-use permission;
  • verified-partner sharing permission;
  • exclusive/non-exclusive license selection;
  • selected duration; and
  • selected compensation model.

We may keep evidence of consent/withdrawal and Terms acceptance so we can demonstrate and administer your choices.

3. How we use personal data

We may use personal data to:

  1. create, authenticate and secure your account;
  2. provide profiles, roles and settings;
  3. receive, validate, store, annotate, organize and deliver data you upload;
  4. operate scientific/research and commercial dataset workflows according to applicable permissions;
  5. create and administer marketplace listings;
  6. process orders and provide licensed digital content;
  7. calculate marketplace fees, creator earnings, task rewards and payouts;
  8. verify identity and payout eligibility;
  9. detect fraud, duplicate submissions, account abuse, malicious files and security incidents;
  10. provide customer support and resolve disputes;
  11. send essential account, security, transaction, task, KYC and payout messages;
  12. send optional marketing where you have opted in or where otherwise lawfully permitted;
  13. maintain audit trails and comply with legal, accounting, tax and regulatory requirements;
  14. enforce our Terms, licenses and platform policies;
  15. improve reliability, usability, quality and safety of the Service using appropriately controlled operational data; and
  16. perform additional optional processing only where disclosed and supported by an appropriate legal basis/consent.

We do not treat a creator’s permission to license a dataset for AI training as permission to use unrelated account, KYC, payment or security data to train general-purpose AI models.

4. Legal bases under GDPR/UK GDPR where applicable

Where the GDPR or UK GDPR applies, CrowdifAI relies on one or more of the following legal bases:

Contract

Processing needed to create an account, deliver purchased datasets, manage licenses, perform marketplace transactions, administer eligible creator rewards/payouts, provide support and otherwise perform our contract with you.

Consent

Used where required for optional purposes, including certain creator data-use permissions, optional marketing, optional partner/commercial uses, and any other processing that applicable law requires to be consent-based. You may withdraw consent prospectively using the relevant settings or contact route.

Legitimate interests

Where permitted, we may process limited data for network/account security, fraud prevention, service integrity, enforcing rights, measuring service reliability and protecting users, provided those interests are not overridden by your rights and interests.

Legal obligation

We may process/retain data to comply with tax, accounting, sanctions, law-enforcement, court, consumer-protection or other applicable legal obligations.

Where special-category or biometric data is processed within the meaning of applicable law, CrowdifAI will identify and document the additional legal condition required before production processing.

5. India DPDP framework where applicable

Where India’s Digital Personal Data Protection Act, 2023 and applicable rules are in force for the processing, CrowdifAI acts as a Data Fiduciary for relevant personal data and will provide clear notice of the personal data and specified purposes, obtain consent where consent is the lawful basis, enable withdrawal in a manner compliant with applicable law, and provide mechanisms for applicable Data Principal rights and grievances.

This Privacy Policy is intended to support, but not replace, any standalone notice required at the point of collection.

6. User-provided datasets and commercial licensing

CrowdifAI is specifically designed so creators can choose to contribute or license certain data for research, AI training or commercial use. When you intentionally list a dataset for sale/license or opt into an applicable sharing purpose, the data covered by that choice may be provided to buyers/authorized partners under the selected license.

This is different from selling unrelated account data. CrowdifAI does not authorize buyers to receive your password, private authentication secrets, KYC documents, payout credentials or private account-security records merely because they buy a dataset.

If a dataset contains identifiable personal data, its creator and buyer must independently ensure that the disclosure and downstream use are lawful. CrowdifAI may moderate or scan content, but does not represent that every dataset is anonymous or suitable for every intended use unless a listing expressly and accurately states a specific completed review.

7. When we share personal data

We may disclose data to the following recipients/categories where necessary:

Buyers and licensees

Data intentionally included in a purchased/licensed dataset, listing information, creator-facing marketplace information and associated permitted metadata may be supplied to the buyer under the applicable license.

Creators/sellers

We may show sellers transaction/order information needed to administer a sale, while minimizing buyer personal data to what is necessary.

Payment, payout and identity providers

Production integrations may include Stripe and its services such as Stripe Checkout, Stripe Connect and/or Stripe Identity. These providers may process identifiers, payment, bank, business, fraud, device or identity information under their own privacy terms and applicable agreements with CrowdifAI.

Hosting and object-storage providers

Uploaded files, generated packages, databases, backups and application infrastructure may be hosted using CrowdifAI infrastructure and/or S3-compatible/cloud infrastructure.

Notifications and communications providers

We may use notification infrastructure such as Novu, Apple Push Notification service (APNs), Firebase Cloud Messaging (FCM), and email/SMTP providers to deliver messages.

App stores and operating-system providers

Apple and Google may process store-account, billing, device, diagnostics and transaction information independently when you download the app or use store billing.

Avatar/media service providers

If an external avatar service (for example DiceBear) is enabled, a request to that provider may expose ordinary network information such as IP address and the requested avatar URL/seed configuration. Production use should be included in the processor inventory or proxied/hosted locally where appropriate.

Professional advisers and authorities

We may disclose information to lawyers, accountants, auditors, insurers, regulators, courts, law enforcement or other authorities where necessary to establish/defend legal claims or comply with lawful requirements.

Corporate transactions

If CrowdifAI is involved in a merger, financing, acquisition, reorganization or sale of assets, relevant data may be disclosed subject to confidentiality and applicable data-protection requirements.

We do not permit service providers to use CrowdifAI data for unrelated purposes merely because they process it for us.

8. International data transfers

CrowdifAI and its providers may process data in countries other than your own. Before publication, CrowdifAI will maintain a production processor/subprocessor inventory identifying relevant locations and transfer safeguards.

Where GDPR/UK GDPR requires a transfer mechanism, CrowdifAI will use an applicable mechanism such as an adequacy decision, approved standard contractual clauses and supplementary measures where necessary.

Production policy must identify material transfer regions/providers once hosting and vendor locations are finalized.

9. Data retention

We keep personal data only for as long as reasonably necessary for the stated purpose, the contract, security, dispute handling and legal requirements.

The production retention schedule must be finalized before publication. At minimum, it should separately define:

DataRetention approach
Active account/profilewhile account is active, then deleted/anonymized subject to lawful exceptions
User Content not sold/licenseduntil user deletion/removal or applicable dataset/task retention expiry, subject to backups/legal holds
Purchased/licensed dataset transaction recordsfor contract, accounting, tax, refund, license-evidence and dispute periods required by law
KYC documents/selfiesonly for the shortest period needed for verification/compliance, then delete unless a lawful retention duty requires more
KYC result/audit evidencefor [KYC RETENTION PERIOD] or legal/fraud limitation period as approved by counsel
Payment/payout/accounting recordsfor [FINANCIAL RECORD RETENTION PERIOD] required by applicable tax/accounting law
Security/audit/IP/device logsfor [SECURITY LOG RETENTION PERIOD], longer only for active investigations/legal holds
Support/complaint recordsfor [SUPPORT RETENTION PERIOD] after closure, longer where needed for a legal claim
Consent/Terms evidencefor the life of the relevant processing/contract plus an appropriate legal-evidence period
Push tokensuntil invalid, logout/account deletion or notification registration is removed
Backupsexpire according to [BACKUP RETENTION PERIOD] unless isolated for legal/security reasons

When we retain data after an account deletion request because law or fraud/security obligations require it, we will restrict it to that purpose and disclose the retention category as required.

10. Account deletion

You may initiate account deletion in CrowdifAI account settings. We will also provide a public web deletion route at:

[ACCOUNT DELETION URL — recommended: https://www.crowdifai.com/account-deletion]

Deletion generally removes or de-identifies account data and User Content that CrowdifAI no longer needs. Some records may remain where necessary for:

  • completed purchase/license evidence;
  • tax/accounting obligations;
  • refunds, disputes and chargebacks;
  • fraud/security investigations;
  • legal claims, court orders or regulatory duties;
  • protecting rights of other users; and
  • time-limited backup rotation.

Deletion does not necessarily revoke a buyer’s lawfully acquired license to content that was already sold/licensed before deletion. CrowdifAI will assess conflicting data-protection obligations and contractual rights under applicable law.

If an external processor holds data solely for CrowdifAI, we will instruct it to delete/return data where required and technically applicable.

11. Your privacy rights

Depending on your location and applicable law, you may have rights to:

  • obtain information about processing;
  • access personal data;
  • correct inaccurate data;
  • request deletion/erasure;
  • withdraw consent prospectively;
  • object to or restrict certain processing;
  • obtain portable data in applicable circumstances;
  • request review of certain automated decisions where the law provides that right;
  • nominate another person or exercise grievance rights where applicable law provides; and
  • complain to a competent data-protection authority/board.

CrowdifAI already provides account/data export functionality for certain data. You can also contact [PRIVACY EMAIL].

We may need to verify your identity before fulfilling a request. We will not discriminate against you for exercising a privacy right protected by law.

12. Consent withdrawal and creator settings

You can change supported privacy/usage selections in CrowdifAI settings. Withdrawal of consent is prospective.

It will not make earlier lawful processing unlawful, erase mandatory financial/security records, or automatically cancel a buyer license already granted before withdrawal. We will stop future processing that depends solely on the withdrawn consent where required by law.

If a particular dataset cannot lawfully remain available after withdrawal, contact [PRIVACY EMAIL] so we can assess takedown, buyer notification and legal-retention obligations.

13. Automated processing and KYC review

CrowdifAI may use automated rules or models to assess upload quality, duplicates, fraud, security and KYC image/liveness signals. These systems can be imperfect.

Where an automated result has a significant adverse effect and applicable law requires human involvement, CrowdifAI will provide an appropriate review/appeal route. For KYC issues contact [KYC SUPPORT EMAIL].

We do not claim that an automated score proves identity or fraud with certainty.

14. Security

CrowdifAI uses administrative, technical and organizational safeguards designed to protect data, including authenticated access, role controls, secure transport, session/security monitoring and restricted provider credentials.

No system can guarantee absolute security. Users should protect account credentials and report suspected compromise promptly.

Production secrets must be stored outside client applications/source repositories, access should follow least privilege, and sensitive identity/content storage should use appropriate encryption/access logging.

15. Children

CrowdifAI is intended for adults aged 18 and over. We do not knowingly permit children to create CrowdifAI marketplace/contributor accounts.

If you believe a person under 18 has created an account or submitted personal data, contact [PRIVACY EMAIL]. We will investigate and take appropriate action subject to applicable law and preservation obligations.

16. Marketing communications

Essential security, transaction, account, KYC, task and payout notices are service communications and may be sent when needed to operate the Service.

Optional marketing email/push messages are controlled by applicable preferences and legal requirements. You can opt out of marketing without disabling essential service notices.

17. Permissions on mobile devices

Depending on features you use, the app may request access to:

  • **Camera** — to capture upload photos, identity documents and selfies;
  • **Photo/media library** — to select images/videos for upload or verification;
  • **Notifications** — to deliver enabled push alerts; and
  • other device permissions only when a feature requiring them is implemented and disclosed.

You can manage operating-system permissions in device settings. Denying a permission may prevent the related optional feature from working.

Device permission does not replace this Privacy Policy or a legally required just-in-time disclosure.

18. App-store privacy disclosures

CrowdifAI will maintain Apple App Privacy and Google Play Data Safety declarations consistent with the production app, backend and enabled third-party SDKs/services.

Store labels are summaries; this Policy provides additional detail. If a production feature changes collection or sharing, CrowdifAI will update both the policy and applicable store disclosures.

19. Do Not Sell/Share and U.S. state privacy laws

Before launching broadly in the United States, CrowdifAI should complete a state-law applicability assessment (including thresholds and definitions of “sale,” “sharing,” targeted advertising and sensitive data).

CrowdifAI’s core creator marketplace intentionally licenses selected creator-provided datasets to buyers. That product transaction must not be confused with selling unrelated account/KYC/security information for advertising.

If CrowdifAI engages in activity that constitutes a regulated “sale” or “sharing” of personal information under an applicable U.S. state law, CrowdifAI will provide the required notices and opt-out mechanisms.

20. Changes to this Policy

We may update this Policy to reflect legal, vendor, security or product changes. We will publish the new effective date and provide additional notice or obtain new consent where required by law.

Materially new processing will not be justified merely by silently changing this Policy where applicable law requires a new notice or consent.

21. Complaints and contact

For privacy questions, rights requests or complaints:

[LEGAL ENTITY NAME] [REGISTERED ADDRESS] Email: [PRIVACY EMAIL] DPO/Representative: [DETAILS IF APPLICABLE]

You may also have the right to complain to your local data-protection authority or, where the India DPDP framework applies, use the applicable grievance/Data Protection Board process once available for the relevant matter.

Crowdifai

AI Data Marketplace for commercially usable data with documented rights.

DISCOVER DATA
Legal

Privacy Policy
Terms of Service
Refund & Cancellation
Dataset License