CleverCrow is operated by Clever Crow, LLC. This page is a plain-English description of what we collect, why, who else sees it, and how long we keep it. We try to collect as little as possible while still being able to charge cards correctly and maintain a trustworthy audit trail of where money went.
Last updated 26 July 2026.
Sign-in, attributing backings, and checking maintainer access to repositories.
Charging your card for backings and crediting your CleverCrow wallet. We never see or store your card number, Stripe holds it; we hold an opaque token.
The audit trail that lets us show you what you funded, what was spent, what was refunded to your wallet, and what was paid to maintainers.
Paying maintainers when a fix merges. Stripe collects and holds the identity and bank details its verification requires; we store only an opaque account reference and its status, never your bank details or identity documents.
Maintainers connect CleverCrow to their repos and choose which repos can take backing.
Operating the service and giving everyone a permanent record of what was funded and paid. Every settled issue carries a line-item receipt, and the merged pull request that triggered it is public and timestamped on GitHub. (A retired earlier version of the service ran a coding agent; its execution records have since been deleted, and the money side of those settlements remains in the ledger and receipts like any other.)
Within the product, funded work is transparent to the people involved in it. If you are a maintainer, the backers who funded an issue can see its funding and settlement record: the pool, the line-item receipt, and the merged pull request that closed it. That audit trail shows backers what their backing paid for. If you are a backer, your identity is shown to the maintainer and to other backers of the same issue as part of that funding record.
Beyond the platform, we do not sell or rent your data. We share it with a small set of providers we depend on to operate the service:
Money records are permanent. Ledger entries, backings, pool records, and settlement receipts are the audit trail that answers “where did my money go?” and we don't expire them.
Short-lived operational data, such as service logs, is retained for between 14 and 30 days depending on the path and then purged automatically.
We set a NextAuth session cookie when you sign in, and a CSRF cookie so that form submissions can't be forged. That is the full set. We do not use advertising cookies, and we do not run page-view analytics.
Email privacy@clevercrow.io from the address on file (or with proof you control the GitHub account in question) and tell us what you'd like: a copy of what we hold about you, a correction, or a deletion. We respond within 2 business days.
One caveat on deletion: we cannot remove your share of the financial audit trail (ledger entries, the Stripe-side record of charges and refunds), that's a record-keeping obligation we have to both you and to tax authorities. We can and will detach your GitHub identity from those rows on request, so they read as anonymous.
If we materially change what we collect or who we share it with, we'll update the “last updated” date at the top of this page and, for accounts with email on file, send a heads-up before the change takes effect.