Legal

Privacy Policy

What we collect, why we collect it, and what we never do with it — United States edition.

Last updated: September 2026

Applies to users located in the United States · Version this policy documents: Croploo v1.12

1. Who we are and what this policy covers

Croploo is an AI-powered commodity and grain market intelligence terminal. It ships as a native desktop application (Windows, macOS, Linux), a web app, this marketing site, and — in the future — mobile apps, and it exposes a Public API to higher-tier subscribers. Croploo covers both US markets (corn, wheat, soybeans, and related derivatives, energy, and macro data) and — because many US traders also watch global competitor supply — an EU/international market view (EU wheat, maize, rapeseed and other cereals/oilseeds, Brazilian and Argentine crop production, Ukraine grain statistics, and related data). This policy applies regardless of which regional view of the product you use, as long as you are located in the United States.

Croploo is operated by Cultioo Inc., a Delaware corporation, 8 The Green, Dover, DE 19901, USA. "Croploo," "we," "us," and "our" in this policy mean Cultioo Inc.

This policy covers the Croploo desktop application, the Croploo web application, this website, any Croploo mobile application once published, and the Croploo Public API (Desk tier and above). It does not cover third-party sites we merely link to (for example, the original USDA, EIA, or DG-AGRI report pages), which have their own privacy practices.

2. The information we collect

The overwhelming majority of data Croploo processes is public commodity market data — futures prices, USDA/EIA/NOAA/CFTC reports, weather, positioning data, and equivalent international series — which is not personal information at all. This section covers everything that is tied to you personally, organized by the feature that generates it.

2.1 Account & identity data

Name, email address, username, and a password we store only as a PBKDF2 hash — we never see or retain your plaintext password after you set it. If you signed up using someone else's referral code, we record that relationship; if you have your own referral code (your username), we record who signed up under it.

2.2 Regional & display preferences

Your country/region (used to route you to the US or EU/international view of the app and its Daily Brief/alerts), theme (light/dark/dark gray/light gray/system), accent color, border/blur/custom-cursor toggles, whether the price ticker is shown, window-control style and side, CullyAI's response language (auto-detect, English, German, Spanish, French, or Italian), and saved tab layouts.

2.3 Billing data

Handled by our payment processor, Stripe. We store your subscription tier (Basic/Pro/Desk/Team/Institutional), a Stripe customer reference ID, whether you're in a 14-day Pro trial or have used one before, your grandfathered price (if you subscribed before a price change), and any promotional code you redeemed. Croploo never receives, transmits, or stores your card number, CVV, or full billing address — Stripe's own PCI-DSS-compliant systems handle that entirely.

2.4 Usage & content data

Data you create while using the terminal, stored so it can be shown back to you across sessions and devices:

  • Watchlist entries (commodity/US-state or country/product combinations you track) — these also personalize your Daily Brief and Morning Brief email.
  • Portfolio positions: commodity, quantity, storage date, break-even price, and an optional free-text location label.
  • Custom Alert Rules and Price Targets ("sell corn above $5.20") — checked against real futures and basis prices.
  • Custom Dashboards — named, saved widget layouts.
  • Decision Log / Audit Trail entries — your own trade-rationale notes, for your personal recordkeeping.
  • Contract Deadline reminders (forward-contract deadlines, option expirations, delivery windows).
  • Multi-currency display preference and any saved calculator inputs you choose to keep (Position Size, Hedge Ratio, Storage Cost, and Options P&L calculators run their math on the numbers you type in; we do not otherwise retain calculator inputs beyond the current session unless you save them to a dashboard).

2.5 Croploo Chat data (user-to-user messaging)

If you use Croploo Chat, we store the messages you send in direct messages and group chats, which rooms you're a member of, read receipts, online/offline presence, and any files or voice messages you attach. Messages in a group chat are visible to other members of that chat; direct messages are visible only to you and the other participant. If you @mention CullyAI inside a group chat, your message is processed the same way as a direct CullyAI query and the AI's reply is posted visibly to that chat.

2.6 File & voice attachments

Files you attach in Croploo Chat are capped at 8MB and stored as encrypted data within our database. We retain the filename, file type, size, and upload timestamp alongside the file. If you use the microphone button in Chat or in CullyAI, your recording is sent to Google's Gemini API for transcription; the transcribed text lands in your input field for you to review and send — it is never sent automatically. Croploo does not separately retain the audio recording after transcription completes.

2.7 CullyAI conversation & memory data

Messages you send to CullyAI (our built-in AI market analyst) are stored so it can reference earlier context in later sessions. We extract and retain a short rolling list of the commodities/topics you've discussed — capped at five — for this purpose. Voice messages to CullyAI are handled the same way as described in 2.6.

2.8 Team & Institutional account data

If you create or join a Team or Institutional account, we store your role (owner/admin/member), which of your resources you've marked as shared with the team, and — visible only to your team's admins — your daily CullyAI message count and last-login time. Every team action is written to a team audit log that admins can view and export as CSV.

2.9 Community & public-facing data (opt-in, off by default)

If you opt in to a public trader profile, your username and the commodities you track are visible to anyone with the profile link. If you post a Community Insight, that post (and CullyAI's fact-check verdict on it) is visible to other Croploo users. Both are entirely optional.

2.10 SMS / phone data (opt-in, off by default)

If you enable SMS alerts, we store the phone number you provide and deliver alert text messages to it via Twilio. This feature is off until you affirmatively provide a number and turn it on — see Section 10 for TCPA-related consent details.

2.11 API keys

Desk tier and above can generate a Public API key. We store only a hash of the key, never the key itself, so we cannot recover a lost key — only reissue a new one.

2.12 Newsletter & marketing email data

If you subscribe to the weekly Croploo Signals newsletter, or leave the daily Morning Brief email enabled (on by default, toggle in Settings), we use your account email address to send those messages via Mailgun. Each is a distinct, separately toggleable subscription.

2.13 Communications with us

If you contact us through the contact form, by email, or otherwise, we retain that correspondence to respond to you and keep a support record.

2.14 Technical & log data

Basic request logs — IP address, timestamp, requested endpoint, and user agent — kept for a limited period (see Section 5) for security, abuse prevention, and diagnosing service issues.

What we do not collect

We do not collect precise device geolocation, contacts, biometric identifiers, or your browsing activity outside the Croploo app itself. We do not use any of this data to build advertising profiles, we do not serve third-party ads inside Croploo, and we do not sell or "share" (as that term is defined under the CCPA/CPRA) your personal information.

3. Third parties we work with

3.1 Service providers who may process personal information on our behalf

  • Stripe — billing, payment processing, referral-credit bookkeeping.
  • Mailgun — transactional email and opt-in marketing email (Morning Brief, Croploo Signals newsletter).
  • Twilio (only if you enable SMS alerts) — delivery of alert text messages.
  • Anthropic (Claude API) — powers CullyAI's chat responses, report commentary, Daily Brief generation, and Community Insight fact-checking. Only the data needed to answer a given query is sent; we do not forward your entire account history on every request.
  • Google (Gemini API) — used as an automatic fallback if Claude is temporarily unavailable, and to transcribe voice messages.
  • Google Cloud Platform — hosts our backend (Cloud Run) and database (Cloud SQL). Our infrastructure currently runs in Google's europe-west1 (Belgium) region, meaning account data for US users, like everyone else's, is technically stored on servers located in the EU. We require Google's standard contractual and technical safeguards for this arrangement.

None of the above processors are permitted to use your personal information for their own independent purposes; they process it only to provide their service to Croploo.

3.2 One-way public/market data providers

These sources supply market data into Croploo. They do not receive personal information about you — Croploo only queries their public, non-personalized data endpoints: USDA (AMS AgTransport, NASS Quick Stats, FAS), CFTC, EIA, NOAA, Alpha Vantage, Yahoo Finance, FRED, Financial Modeling Prep, the EU's DG-AGRI Agri-food Data Portal, Eurostat, the European Central Bank, Euronext (MATIF), PEGELONLINE, Open-Meteo, Ukraine's state statistics service, Brazil's CONAB, and Argentina's federal open-data portal.

3.3 We do not sell or share your personal information

Croploo does not sell personal information for money, and does not "share" it for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months and have no plans to.

3.4 Legal disclosures and business transfers

We may disclose personal information if required by law, subpoena, or court order, to protect the rights, property, or safety of Croploo, our users, or the public, or in connection with a merger, acquisition, or sale of assets.

4. How we use your information

  • To create, authenticate, and secure your account.
  • To sync your watchlist, portfolio, alerts, dashboards, decision log, and tab layouts across the desktop and web app.
  • To process payments, manage your subscription, and apply referral credits, via Stripe.
  • To send transactional email and, if you opt in, the Morning Brief and/or Croploo Signals newsletter, via Mailgun.
  • To send SMS alerts, only if you've opted in and provided a phone number, via Twilio.
  • To power CullyAI — answering your questions with real tool-retrieved data, generating your Daily Brief and proactive dashboard insights, and remembering the topics of earlier conversations.
  • To operate Croploo Chat and deliver your messages/attachments/voice notes to their intended recipients in real time.
  • To let Team/Institutional admins manage seats, review usage, and audit team activity.
  • To detect and prevent abuse and to provide customer support.
  • To comply with our legal and tax/accounting obligations.

5. Data retention

Data categoryRetention period
Account dataUntil you delete your account, then purged within 30 days
Billing recordsAs required by tax/accounting law (typically 7 years), held by Stripe
CullyAI chat history & rolling memoryUntil you delete it in-app or close your account
Croploo Chat messages & attachmentsUntil you delete the message/room, or your account is closed
Request/security logs90 days
Decision Log / audit entriesUntil you delete them or close your account
Team audit logFor the life of the team account

If you close your account, we delete your personal information within 30 days, except where we are legally required to retain billing records for tax or accounting purposes.

6. Your privacy rights

Regardless of where in the US you live, you can — mostly self-service from Settings, or by emailing support@cultioo.com — access, correct, export, or delete your personal information, and opt out of any consent-based processing at any time.

6.1 California residents (CCPA/CPRA)

You have the right to know what personal information we've collected (and confirm we haven't sold or shared it), delete it, correct it, and exercise these rights without discrimination. Since Croploo doesn't sell or share personal information or collect sensitive personal information, the corresponding opt-out rights don't change anything about how we treat your data. You may also designate an authorized agent to submit requests on your behalf, and appeal a denied request (Section 6.4). We verify your identity before fulfilling a request and respond within 45 days, with one 45-day extension available for complex requests.

6.2 Virginia, Colorado, Connecticut, Utah, and other state laws

If you live in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), or another state with a comprehensive consumer privacy law, you generally have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and automated profiling — none of which Croploo engages in.

6.3 How to exercise your rights

Most account data is directly viewable, editable, and deletable from Settings in the app, including full account deletion. For anything not self-service, email support@cultioo.com with "Privacy Rights Request" in the subject line.

6.4 Appeals

If we deny your rights request in whole or in part, you may appeal by replying to our denial email within 30 days. We respond to appeals within 45 days, and, if we uphold the denial, we'll explain why and, where required, point you to your state's Attorney General or applicable regulator.

7. Children's privacy (COPPA)

Croploo is a professional trading and market-data tool. It is not directed at, and may not be used by, anyone under 18 years of age (see our Terms and Conditions). We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided us with personal information, we will delete it promptly. If you believe a child has done so, contact support@cultioo.com.

8. Data security

Passwords are hashed with PBKDF2 and never stored or transmitted in plaintext. Sessions use signed tokens. All traffic between the app and our backend is encrypted in transit (TLS). API keys and chat attachments are stored hashed/encrypted at rest. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If you believe you've found a security vulnerability, please report it to security@cultioo.com rather than filing a public issue.

9. Cookies, local storage, and "Do Not Track"

The web app and marketing site use browser local storage — not third-party advertising or tracking cookies — for your theme preference and session token. We do not use third-party advertising trackers or analytics pixels, and because we do not track you across sites for advertising purposes in the first place, our systems do not respond differently to a browser's "Do Not Track" signal.

10. Marketing email and text messages (CAN-SPAM & TCPA)

Email: the Morning Brief and the Croploo Signals newsletter are each opt-in. Every marketing email includes a working unsubscribe mechanism, our accurate sending identity, and a valid postal address, consistent with the CAN-SPAM Act. Transactional emails are not marketing and do not have an unsubscribe link, since they are necessary to operate your account.

SMS: SMS alerts are off by default and require you to affirmatively enter a phone number and enable the feature — this constitutes your express consent to receive automated account-related text messages at that number, as required by the Telephone Consumer Protection Act (TCPA). Message and data rates may apply; frequency varies with your alert rules. Reply STOP to any Croploo text to opt out at any time, or disable the toggle in Settings; reply HELP for assistance. We do not use this number for marketing calls or texts without separately obtaining your consent.

11. Automated processing and AI features

CullyAI analyzes real market data and generates commentary, alerts, and clearly labeled speculative directional reads. CullyAI's output never constitutes financial advice, and it is never used to make an automated decision that produces a legal or similarly significant effect concerning you — every trading decision remains entirely yours. Some voice input is transcribed by a third-party AI model; this transcription step does not involve any automated decision-making about you. See our Terms and Conditions for the full "not financial advice" disclaimer. If California's automated-decision-making-technology (ADMT) regulations under the CPRA later impose additional obligations on our use of AI, we will update this policy accordingly.

12. Changes to this policy

If we make a material change to this policy, we will update the "Last updated" date above and, for significant changes, notify account holders by email in advance of the change taking effect.

13. Contact us

Questions about this policy, or to submit a privacy rights request: support@cultioo.com. Security reports: security@cultioo.com.

Cultioo Inc. — 8 The Green, Dover, DE 19901, USA

See also our Terms and Conditions.