Privacy Policy
How Crucible Group handles personal data across the marketing site and the platform's three lines of work: what is collected, who processes it, how long it is kept, and the rights available to the people it describes.
Overview
We build advisory software and deliver advisory services. Both run on records about people, so this policy says plainly what we collect, why, who touches it, how long it lives, and what you can do about it. Where our practices have gaps, we say so — the same candor we apply everywhere else. A longer, more technical account of how the platform handles data lives at gocruciblegroup.com/trust; this policy is the binding summary.
1. Who we are
Crucible Group, LLC (“Crucible,” “we”) operates the marketing site at gocruciblegroup.com and the Crucible platform at app.gocruciblegroup.com, serving three lines of work: Talent Readiness, Strategic Initiatives, and Retained Advisory. For privacy questions, write to privacy@gocruciblegroup.com. You’ll get the founder, not a form.
2. One distinction that matters
For most records in the platform, our client is the decision-maker and we process on their instructions. If your employer runs its talent program on Crucible, your employer chose what to collect and controls the records; we hold and process them under our agreement with your employer. Requests about those records (access, correction, deletion) go first to your employer — and we help them honor those requests. For everything we collect directly — visitors to our site, people who contact us, prospective clients — we are the decision-maker, and this policy is the whole story.
3. What we collect
If you visit the marketing site: standard server logs (IP address, browser type, pages requested, timestamps), kept briefly for security and operations. We do not run advertising trackers.
If you contact us or submit the interest form: what you give us — name, email, company, role, approximate organization size, and your message. We use free-text fields on purpose; nothing is hidden in them.
If you use the platform as an employee of a client organization:
– Identity and employment context: name, work email, role, reporting line, optional start date.
– Assessment responses, with a consent record captured at the time you take an assessment.
– Review and development content: ratings, written rationales, aspirations, development actions and check-ins, recognition given and received.
– Credentials and proof documents you choose to upload.
If you interact with a Strategic Initiatives engagement as a committee member: your name, work email, and the responses you give through signed one-tap links. Committee members act through those links — we do not create accounts for them or collect anything beyond what the engagement requires.
If your organization is a client: business contact details, engagement and program records, and billing information. Payments run through Stripe; we never see or store card numbers.
We do not collect data from anyone under 18. The platform is a workplace tool.
4. What we use it for
To deliver the services: run assessments and reviews, maintain engagement and program records, send the notifications the work requires, and support the advisory relationship. To operate the business: respond to inquiries, evaluate prospective clients, invoice, and keep the books. To keep the system honest: audit logs, security monitoring, abuse prevention.
We do not sell personal information. We do not share it for advertising. We do not use client records to market to anyone.
5. What AI touches — and what it never does
Parts of the platform use AI (Anthropic’s models) to draft text for human review. The boundaries are structural, not aspirational:
– No model scores, ranks, bands, or decides anything about a person. Assessment scoring is deterministic arithmetic. AI output is a draft a human accepts, edits, or discards.
– AI processing receives the minimum the task needs — first names, strength names, and narrative text. It never receives surnames, email addresses, scores, or proof documents.
– We do not permit our AI processors to train their models on this data.
6. Who else touches it
We use a small set of processors, each for one job:
– Neon — database (United States)
– Vercel — hosting, file storage, and site analytics (United States)
– Clerk — authentication (United States)
– Resend — transactional email (United States)
– Stripe — billing and payments (United States)
– Anthropic — AI drafting, bounded as in §5 (United States)
Each receives only what its job requires. Beyond processors: we disclose personal information if the law compels it, and if Crucible is ever acquired or reorganized, records transfer with the obligations of this policy attached. There is no other sharing.
7. Email
Our emails are pointers, not content: notifications tell you something needs your attention and link you to it. Scores, ratings, and findings do not ride in email bodies. Marketing-side email goes only to people who contacted us or whose inquiry we are answering — we do not buy lists and we do not cold-drip.
8. Cookies
The platform uses essential cookies only: authentication and session security (via Clerk) and the cookies Stripe requires during billing. The marketing site sets no advertising or cross-site tracking cookies. We measure traffic with Vercel Web Analytics, which uses no cookies at all: visitors are counted by an anonymous hash discarded within 24 hours, and we see only aggregate statistics — pages, referrers, country, device type — never an identified person and never activity on other sites.
9. How long records live
– While your organization is a client and you are active: records are retained to deliver the service.
– After you leave your employer: your access ends immediately. Your records are retained for a window your employer configures — default 24 months, configurable from 6 to 84 — to serve the record-keeping purpose your employer selected.
– Purge: deletion of a departed person’s content (assessments, reviews, recognition received, credentials, proof files) is a deliberate human act, never an automatic sweep. What survives a purge is deliberately minimal: audit trails, anonymized job-analysis contributions, recognition the person gave to others, and a tombstone record noting that a purge occurred.
– Leads and inquiries: kept while the conversation is live or plausibly revivable; we close the loop rather than drip forever.
– Server logs: kept briefly, then discarded.
10. Your rights
Regardless of where you live, you can ask us to tell you what we hold about you, correct what’s wrong, delete what we can delete, or export what’s yours. Write to privacy@gocruciblegroup.com. Where your employer is the decision-maker for a record (§2), we’ll route the request to them and help them honor it, and we’ll tell you that’s what we’re doing. We answer within 30 days. We don’t charge for requests and we don’t retaliate for making them.
Self-service export is not yet built; today these requests are handled manually, by the founder. That’s an honest limitation, not a policy.
11. Security
Access control is enforced server-side, not in the interface. Every query is scoped to your organization. Managers see their direct reports, not peers and not raw scores. Credential proof files stream only to the employee who uploaded them and their HR. Administrative actions are audit-logged. We hold no SOC 2 or ISO 27001 certification today and say so rather than imply otherwise; security questions go to security@gocruciblegroup.com.
12. Where this policy lives legally
Crucible Group, LLC is a United States company; data is processed in the United States. This policy is governed by the laws of Georgia. If you are outside the US, understand that using the services means your data is processed in the US.
13. Changes
When this policy changes materially, the effective date above changes with it, and platform users get a notification — a pointer, per §7. We don’t change the rules quietly.
14. Contact
Privacy: privacy@gocruciblegroup.com · Security: security@gocruciblegroup.com · Everything else: hello@gocruciblegroup.com
Crucible Group, LLC · 488 Brown Station Dr, Williamson, GA 30292