Privacy Policy
Effective July 1, 2026
The short version. Crusader is built local-first. The desktop app keeps your work — proxy history, captures, site map, findings, identities, notes, and plugins — in a database on your machine. There is no product analytics or usage telemetry in the app. The app's own Crusader service calls are limited to optional software update checks and paid license activation, refresh, and deactivation. This page also explains user-initiated network features and the measurement tags on this website.
01Scope
This policy applies to the Crusader desktop application ("the app"), the crusaderproxy.com website, and the account and licensing system used for paid plans. It is operated by Crusader Security, LLC ("Crusader", "we", "us"). It does not cover the third-party systems you test with Crusader, or third-party services you choose to connect (such as an LLM provider) — those are governed by their own terms.
02The app is local by default
Everything you capture and create in Crusader is stored locally on your device in a SQLite database and supporting files. That includes proxy history, request/response captures, the site map, scanner findings, tagged identities, comments, notes, and any plugins you write. We do not collect this data, cannot see it, and it never leaves your machine unless you take one of the explicit actions described in the next section.
The app contains no embedded product analytics or usage telemetry — no event tracking, no "anonymous usage statistics," no launch beacon, and no behavioral reporting. Crash logs, if generated, are written to a local folder on your device only and are never automatically transmitted to us. The only Crusader-operated service calls made by the app itself are the update and paid-licensing calls described below.
03When the app connects out
The app makes network connections only in these cases, each of which you control:
- Testing traffic. When you use the proxy, Repeater, Intruder, scanner, or transport features, the app sends the requests you direct at the targets you choose. That traffic goes to those targets — not to us. We never see it.
- Software updates (off by default). If you turn on update checks, the app requests a version manifest from
licenses.crusaderproxy.com. That request necessarily reveals your IP address, platform, and current version to our update host. Automatic update checks are disabled until you opt in. - Licensing checks (paid plans only). When you activate, refresh, deactivate, or validate an existing paid license lease, the app contacts our license server to confirm entitlement and seat status. These calls do not include app usage events, proxy history, request contents, findings, notes, or plugins. See Accounts & licensing. The free tier never contacts the license server.
- AI / LLM features (opt-in). See AI / LLM features. Data goes to the provider you configure, not to us.
- Beacon (OAST) and Team Mode. These use infrastructure you configure or operate (your interaction server, your team workspace). Data flows where you point it.
04The website (crusaderproxy.com)
We use Cloudflare Web Analytics for aggregate site metrics and Google Tag Manager to manage website measurement, affiliate attribution, and checkout-conversion tags. Google Tag Manager may load configured third-party tags and process technical request data such as page URL, referrer, browser details, and IP address.
Hosting and content delivery are provided by Cloudflare, which processes connection metadata (such as IP address and request headers) to serve the site and protect it from abuse. If you arrive through an affiliate link or interact with checkout, see Cookies.
If you previously joined the beta waitlist, we stored the email address and the optional name, role, platform, testing focus, and notes you submitted. We use those details only for release communications and planning. We store a one-way hash of the source IP for abuse throttling, not the raw IP address. You may request deletion at any time by emailing [email protected].
05Accounts & licensing (paid plans)
The free tier requires no account and no activation. When you purchase or activate a paid plan, we collect and store:
- your email address;
- your license key and subscription/seat status;
- a machine hash — a one-way fingerprint of your device used to bind seats and prevent license sharing (it is not reversible into device details);
- the activation user-agent (app version and operating system) and activation timestamps.
Payments are processed by Stripe. We do not receive or store your full card number. We use account data to validate licenses, enforce seat limits, provide support, send transactional and billing emails, and meet tax and accounting obligations. We do not use it for advertising and we do not sell it.
06AI / LLM features (opt-in)
Features such as "Review diff" can send redacted evidence to the large-language-model provider you configure (for example Anthropic, OpenAI, or a local model). That data travels directly from your machine to that provider under the provider's own privacy terms — we do not receive, proxy, or store it. If you configure a local model, nothing leaves your machine. These features are off until you set them up.
09Retention
Local app data stays on your device until you delete it — you control its lifetime entirely. Account and licensing data is retained for the life of your account and for as long as required afterward for legal, tax, and accounting purposes, then deleted or anonymized. Prior beta waitlist data is kept until release communications end, you unsubscribe, or you request deletion. Website analytics are aggregate and contain no personal data.
10Your rights
Depending on where you live (for example under the EU/UK GDPR or the CCPA in California), you may have the right to access, correct, delete, port, or object to the processing of your personal data, and to lodge a complaint with your local authority. Because we hold very little personal data — essentially your account email and license records — most requests are quick to honor. To exercise any right, email [email protected].
11International transfers
We and our processors may process data in Georgia, United States and in other countries where our processors (such as Cloudflare and Stripe) operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses to protect data transferred across borders.
12Security
Secrets stored by the app (such as API keys and tokens) are encrypted at rest on your device — on Windows via the OS Data Protection API. Account and licensing data is protected with industry-standard administrative and technical measures. No system is perfectly secure, and we cannot guarantee absolute security, but we work to protect your information and to keep the app's default posture private.
13Children
Crusader is a professional security tool intended for adults. It is not directed to anyone under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
14Changes to this policy
We may update this policy as the product evolves. We will revise the effective date above, and for material changes we will provide notice through the app or by email where appropriate. Continued use after an update means you accept the revised policy.
15Contact
Questions about privacy or your data: [email protected]. For everything else, see our Terms of Service.