Privacy Policy

Effective date: March 29, 2026

This Privacy Policy explains how Crosstalk Studios (“we”, “us”, or “our”) collects, uses, discloses, and protects personal information when you use Box, related websites, account portals, APIs, remote services, and support services.

1. Information We Collect

Account and identity data

We may collect:

  • email address
  • password hash, if you set a password
  • account-verification status
  • account identifiers and authentication tokens

License and device data

We may collect:

  • license keys and activation status
  • machine identifiers or device identifiers used for activation and device limits
  • device names, activation timestamps, and last-seen timestamps
  • subscription tier, trial status, renewal status, and entitlement state

Billing data

When you purchase a paid plan, payment and billing information is processed by payment providers such as Stripe. We may receive records such as:

  • Stripe customer identifiers
  • Stripe subscription identifiers
  • price or plan identifiers
  • billing status and renewal status
  • limited customer-contact details needed to link purchases to your account

We do not store full payment-card numbers on our own servers.

Product and support data

Depending on the features you use, we may process:

  • license-validation requests
  • app, activation, and subscription status
  • support requests and account-reset requests
  • diagnostics, logs, or crash information you send to us or that the app stores locally

Local project and analysis data

Box is primarily designed to analyze your sessions locally on your machine. The app may access project metadata, device state, track names, meter values, and similar session data to provide its features. By default, that processing is intended to happen locally unless you enable a feature that requires network access.

Optional third-party or network feature data

If you enable optional cloud, relay, AI, lookup, or remote-control features, we or our service providers may process additional data needed to provide those features, such as:

  • remote-session messages and control-state payloads
  • prompts, context, or snippets sent to an AI provider you configure
  • limited metadata sent to optional lookup or fingerprinting providers you enable
  • relay connection metadata such as room, device, or session identifiers

You control whether many of these optional integrations are enabled.

2. How We Use Information

We use personal information to:

  • create and manage accounts
  • verify email ownership
  • start and manage trials
  • validate licenses and enforce device limits
  • process subscriptions, renewals, cancellations, and entitlement changes
  • operate remote, relay, and companion-app services
  • provide customer support
  • secure the Services and detect abuse, fraud, piracy, or unauthorized access
  • maintain logs, troubleshoot issues, and improve reliability
  • comply with legal obligations and enforce our terms

3. Legal Bases

Where required by law, we rely on one or more of the following legal bases:

  • performance of a contract with you
  • our legitimate interests in operating, securing, and improving the Services
  • your consent, where a feature is optional and consent is appropriate
  • compliance with legal obligations

4. How We Share Information

We may share information with:

  • payment processors such as Stripe
  • hosting, infrastructure, email, security, and support vendors
  • optional third-party AI, relay, or lookup providers that you choose to use
  • professional advisers, auditors, or insurers
  • law enforcement or regulators when required by law or necessary to protect rights and safety

We do not sell your personal information in exchange for money.

5. Data Retention

We retain information for as long as reasonably necessary to:

  • provide the Services
  • maintain account history, billing records, and license state
  • prevent abuse and enforce device or trial limits
  • comply with legal, tax, accounting, and dispute-resolution obligations

Retention periods may differ by data type. For example:

  • account and billing records may be retained for legal and tax compliance
  • device-registration data may be retained while an account remains active and for a limited time afterward for fraud prevention and support
  • diagnostics and logs may be retained according to operational needs

6. Security

We use reasonable administrative, technical, and organizational measures to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

You are responsible for maintaining the confidentiality of your credentials and for protecting access to your devices.

7. International Transfers

Your information may be processed in countries other than your own, including by service providers or infrastructure providers. Where required, we take steps intended to provide an adequate level of protection for such transfers.

8. Your Choices and Rights

Depending on your location, you may have rights to:

  • access your personal information
  • correct inaccurate information
  • delete certain information
  • object to or restrict certain processing
  • withdraw consent where processing depends on consent
  • receive a portable copy of certain information

You can also:

  • manage registered devices from the account flow when that feature is available
  • cancel a subscription before renewal
  • disable optional integrations you do not want to use

To exercise privacy rights, contact privacy@crosstalkstudios.com.

9. Children

Box is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can review and delete it where appropriate.

10. Third-Party Services

Third-party services integrated with Box have their own privacy practices. This Policy does not govern third-party services except to the extent we control the data flow into or out of them.

11. Cookies and Analytics

Our websites and account portals may use cookies, local storage, and similar technologies to keep you signed in, remember preferences, and understand how visitors use the site. We may also use privacy-respecting analytics to measure traffic, diagnose issues, and improve the Services.

Most browsers allow you to block or delete cookies. Disabling cookies may break parts of the account flow (for example, sign-in sessions).

12. Regional Rights (GDPR, UK GDPR, CCPA)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the GDPR or UK GDPR, including the right to access, correct, delete, restrict, or object to processing, and to lodge a complaint with your local supervisory authority.

If you are a California resident, the California Consumer Privacy Act (CCPA/CPRA) gives you the right to know what personal information we collect, request deletion or correction, and opt out of any sale or sharing of personal information. We do not sell personal information for money, and we do not knowingly share personal information for cross-context behavioral advertising.

13. Automated Processing and AI Features

Some Box features use machine-learning and AI models to analyze sessions, suggest changes, or answer questions. These features do not make legally significant decisions about you. Output from AI features is informational only and should be reviewed before being applied to important work.

14. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we may provide notice through the website, the app, the account portal, or other reasonable means. The updated Policy becomes effective on the date posted.

15. Contact

Questions or requests about privacy may be sent to privacy@crosstalkstudios.com.