Privacy Policy
Last updated: 20 August 2026
SmallCRM (smallcrm.org) is operated by Odd Solutions Ltd, a company registered in England and Wales (company number 16186575). References to "we", "us", or "our" mean Odd Solutions Ltd. References to "you" mean the person or organisation using SmallCRM.
Contact: hi@sdocs.dev.
Summary
- SmallCRM is a hosted CRM and persistence layer for coding agents and humans. Hosted use stores account, workspace, CRM, form, webhook, email, saved-view, and event-log data on SmallCRM servers.
- Workspace data can include personal data, confidential business data, and data about people who are not SmallCRM account holders, depending on what you and your agents store.
- Connected email providers can send and synchronize CRM conversations. Separately approved Gmail research can return mailbox metadata, subjects, or bodies to a user-authorized CLI agent.
- SmallCRM does not operate the external coding agent or model provider a user chooses. Data returned to that agent may be processed under the external provider's own terms and privacy settings.
- Public form and webhook endpoints are write-only, but they are public. Anyone with the endpoint URL can submit data.
- We do not currently use third-party analytics, advertising trackers, device fingerprinting, payment processing, or user-content training for AI models.
- SmallCRM is an early prototype. Unless we separately agree otherwise in writing, it is provided without uptime, backup, recovery, retention, or support commitments.
1. Data we process
Account and authentication data
We process your email address, account id, linked sign-in identities, workspace memberships, authentication session records, and authorized CLI installations. Transitional password sign-in stores a salted scrypt hash, never the raw password. Hosted session and CLI credential records store token hashes, timestamps, expiry or last-used information, and revocation status.
Browser login uses a scrm_session cookie. CLI login stores the returned session cookie locally in ~/.smallcrm/sessions.json by default.
Workspace data
Workspace data includes collections, schemas, records, relation indexes, saved query views, form configs, webhook configs, and event logs. Each workspace is stored in its own SQLite workspace database.
Records can contain whatever you or your agents put in them. That may include names, email addresses, URLs, notes, lead research, customer records, incident records, webhook-derived fields, and other personal or confidential data.
Email connections and messages
Email connections are separate from signing in to SmallCRM. Depending on the provider and capabilities you authorize, we process encrypted OAuth tokens or provider credentials, connected account identity, domain and DNS setup state, sender addresses, message participants, subjects, bodies, dates, provider message/thread identifiers, delivery events, drafts, normalized CRM threads, and links to CRM records.
Resend provides a shared workspace mailbox with sending, receiving, and delivery events. Gmail provides personal sending and tracked-reply synchronization. Outlook currently provides personal sending. The current capability and permission boundary is shown in Email settings.
Routine Gmail synchronization stores only conversations SmallCRM already tracks. An authorized CLI agent can separately request wider Gmail research. The mailbox owner must approve the content level, history window, duration, and requesting CLI installation in the browser. Approved results may include addresses, interaction metadata, subjects, or message bodies. Attachments are excluded. Results are returned to the requesting CLI and are not automatically stored as CRM records, although the agent can deliberately write selected findings through normal CRM commands. We retain the grant, its scope, status, expiry, use count, and last-used time.
User-chosen agents and model providers
The SmallCRM CLI can be invoked by a coding agent or other software selected and controlled by the user. When SmallCRM returns workspace or approved mailbox data to an authorized CLI installation, that data reaches the process running the CLI. If that process uses an external model, agent platform, plugin, tool, logging, or telemetry service, that service may receive or retain the data under the user's arrangement with it. SmallCRM does not select, operate, train, or supervise that external service.
Public form submissions
Public form endpoints accept configured HTML form fields and create records in the target workspace. Accepted submissions may store submitted field values, generated submission ids, form ids, tags, timestamps, request context, and event-log entries.
Inbound webhook deliveries
Webhook endpoints accept JSON or form-encoded deliveries from external services. SmallCRM stores configured mapped fields, server-owned metadata, generated delivery ids, timestamps, resulting record data, and event-log entries. Unmapped payload fields are not intentionally stored.
Event logs and request context
Workspace event logs may include method, source, action, collection, record id, actor, reason, metadata, request URL, user agent, remote address, changed fields, and before/after record data. Mutation logs can contain the same personal or confidential information as workspace records.
Local CLI and browser data
The local workspace binding file .smallcrm/workspace.json stores only the hosted origin and workspace identity/path. It does not store CRM records.
The browser app uses localStorage and sessionStorage for view preferences and same-workspace navigation state. This storage is not used for analytics or advertising.
2. How we use data
We use the data described above to:
- Provide hosted account login, workspace membership, and authenticated workspace access.
- Store, render, query, validate, and update CRM workspace data.
- Connect email providers; send, receive, synchronize, and display CRM conversations; and perform mailbox research within a grant approved by the mailbox owner.
- Receive public form submissions and inbound webhook deliveries.
- Maintain event history so humans and agents can inspect reads, writes, and changes.
- Secure, debug, maintain, and improve the service.
- Detect abuse, protect the service, and comply with legal obligations.
We do not sell personal data. We do not use workspace content to train AI models.
3. Controller and processor roles
For account, authentication, operational, security, and service-administration data, Odd Solutions Ltd acts as controller.
For CRM records, schemas, saved views, form submissions, webhook-derived data, and other workspace content, you decide what to store and why. In many cases you are the controller and we process that data to provide the service. If you need a formal data processing agreement, production support commitment, or regulated-data arrangement, contact us before using SmallCRM for that purpose.
You are responsible for having a valid legal basis and appropriate notices for any personal data you or your agents put into SmallCRM or disclose to a user-chosen agent/model provider, including data submitted through forms, sent by webhook providers, or returned from a connected mailbox.
SmallCRM remains responsible for its own processing, for enforcing the mailbox-access boundary it presents, and for obligations that apply to SmallCRM. It is not responsible for deciding whether a user's external agent or model provider is suitable for the user's purpose.
4. Cookies and similar technologies
SmallCRM uses the scrm_session cookie for logged-in browser sessions. This cookie is necessary for authentication. It is HttpOnly, SameSite=Lax, expires after 30 days, and is marked Secure on the production HTTPS deployment.
SmallCRM does not currently use analytics, advertising, or tracking cookies.
The browser app uses localStorage and sessionStorage for interface state, as described above.
5. Third parties
SmallCRM may share data with service providers that help us operate the service, such as hosting, domain, network, storage, logging, security, and infrastructure providers.
Other third-party interactions include:
- npm, when the installer downloads the published CLI package.
- Resend, for passwordless authentication and invitations and when a workspace connects Resend email.
- Google, when you use Google sign-in or connect Gmail. Those are separate authorizations.
- Microsoft, when you connect Outlook.
- Google Fonts on public marketing, auth, and legal pages.
- External sites you click from rendered CRM records or public pages.
- External services you configure to send webhook deliveries to SmallCRM.
- External coding-agent, model, plugin, tool, logging, or telemetry providers selected by the user.
Those third parties may receive ordinary network metadata such as IP address, user agent, requested URL, and time of request. Email providers receive data needed for the capability you authorize. User-chosen agent/model providers may receive data returned to the CLI. External services and websites have their own terms and privacy practices.
SmallCRM's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only for the visible SmallCRM email features the user authorizes. We do not sell it, use it for advertising, or use it to train general AI models.
6. Retention
Workspace data is retained while the workspace exists. Session records expire after 30 days unless renewed and may be revoked earlier on logout. Event logs are part of workspace data and may retain before/after record values. Mailbox research grants expire on the approved schedule or remain active until revoked. Disconnecting a provider stops future provider access but does not silently delete CRM messages already recorded in the workspace.
SmallCRM does not yet provide self-service account or workspace deletion. Contact us to request deletion. We may retain limited information where required for security, abuse prevention, legal obligations, or dispute handling.
Unless we separately agree otherwise in writing, SmallCRM does not provide a backup, disaster recovery, uptime, or data-retention guarantee.
7. Your privacy rights
If UK GDPR or another applicable privacy law gives you rights over personal data we control, you may contact us to request access, correction, deletion, restriction, objection, portability, or other applicable rights.
Some workspace data is controlled by the workspace owner or the person/organisation that collected it. If your data was submitted into another user's SmallCRM workspace, we may need to refer your request to that workspace owner or act on their instructions.
You may complain to the UK Information Commissioner's Office at ico.org.uk.
8. Sensitive and regulated data
Do not use SmallCRM for special-category personal data, health data, criminal-offence data, children's data, payment card data, government identifiers, regulated financial records, or other high-risk regulated data unless we have separately agreed suitable terms and controls in writing.
9. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above reflects the most recent change.
Terms of Service
Last updated: 20 August 2026
These Terms of Service ("Terms") govern your use of the SmallCRM website, hosted service, CLI, APIs, public form endpoints, webhook endpoints, browser views, and related services (together, the "Service") operated by Odd Solutions Ltd (company number 16186575, registered in England and Wales).
By using the Service, you agree to these Terms. If you do not agree, do not use the Service.
1. The Service
SmallCRM is an agent-first CRM and structured persistence layer. It lets you and your coding agents create schemas, store records, query data, render browser views, create public form and webhook receivers, connect email providers, send and synchronize CRM conversations, and request user-approved mailbox research.
SmallCRM is currently an early prototype made available for personal projects and experiments. We may modify, limit, suspend, discontinue, charge for, or remove any part of the Service at any time.
2. Accounts and security
You are responsible for the security of your account, devices, local CLI credentials, transitional password if used, agents, scripts, and integrations.
You must not share account access with people who are not authorised to use the workspace. You must tell us promptly if you believe your account, workspace, form endpoint, webhook endpoint, session file, or integration has been compromised.
3. Your content and responsibilities
You retain your rights in data you or your agents submit to SmallCRM. You grant us the rights needed to host, process, transmit, render, secure, back up where applicable, and otherwise operate the Service.
You are solely responsible for:
- The records, schemas, notes, files, queries, forms, webhook mappings, metadata, and other content you or your agents create or submit.
- Ensuring you have the right to collect, store, process, and disclose that content.
- Providing privacy notices and obtaining consents or other legal bases where required.
- Selecting and configuring any external coding agent, model provider, plugins, tools, logging, or telemetry used with the CLI.
- Reviewing agent instructions, proposed mailbox access, outputs, and actions before relying on them in important workflows.
- Ensuring you have the right to disclose CRM or mailbox data to SmallCRM and to any external agent/model provider you use.
- Exporting or backing up important data outside SmallCRM.
4. Email connections and external agents
Email-provider authorization is separate from SmallCRM sign-in. You authorize the provider capabilities shown during connection and in Email settings. A connection may allow SmallCRM to send email, synchronize replies, receive delivery events, or access mailbox data, depending on the provider and scopes you approve.
General Gmail research requires a separate SmallCRM approval tied to a named CLI installation. The mailbox owner can change or reject the proposed content level, history window, and duration. A grant is read-only, excludes attachments, and can be revoked. It does not prevent an authorized agent from using returned information in later CRM commands or from sending that information to the external services the agent itself uses.
SmallCRM does not provide, operate, or supervise the coding agent or model service selected by the user. Once SmallCRM provides data to an authorized CLI process at the user's direction, the external provider's own terms, privacy policy, retention settings, security, and training choices may apply. We do not promise that external agents will follow instructions, produce accurate output, preserve confidentiality, or avoid unintended actions.
You are responsible for choosing and trusting the agent/model provider, limiting access to what is necessary, reviewing its actions, and maintaining the rights and legal basis needed to disclose relevant data. SmallCRM remains responsible for its own service, including honoring the permissions and revocations it presents and any liability that cannot lawfully be excluded.
5. Public forms and webhooks
SmallCRM public form and webhook URLs are public write-only receivers. Anyone with the URL can submit data to the configured workspace endpoint. The endpoints do not expose existing workspace data, but they can create records or, for webhooks, update matching records.
You are responsible for where you publish those URLs, what data you ask people or services to submit, and whether the endpoint is appropriate for the workflow. SmallCRM webhooks currently do not provide provider-specific signature verification.
Do not put API keys, secrets, credentials, or other sensitive tokens in public HTML, form fields, webhook mappings, trusted metadata, CRM records, or event reasons unless you have separately agreed appropriate production controls with us.
6. Acceptable use
You must not use the Service:
- For unlawful, harmful, fraudulent, defamatory, harassing, abusive, invasive, or rights-infringing activity.
- To send spam, phishing, malware, credential-harvesting, or deceptive content.
- To probe, overload, scrape, disrupt, damage, or bypass the Service or related infrastructure.
- To submit content you are not authorised to collect or process.
- For high-risk, emergency, safety-critical, medical, legal, financial, regulated, or compliance-critical decisions without separate written agreement.
- To store special-category, children's, payment card, government identifier, criminal-offence, or other high-risk regulated data without separate written agreement.
We may suspend or remove accounts, workspaces, endpoints, or data that we reasonably believe violate these Terms, create legal or security risk, or threaten service stability.
7. Availability, backups, and data loss
Unless we separately agree otherwise in writing, the Service is provided without uptime, availability, support, backup, disaster recovery, retention, or data-restoration commitments.
You are responsible for maintaining independent copies of important data. We are not responsible for lost, corrupted, deleted, overwritten, unavailable, or inaccessible data.
8. No professional advice
SmallCRM is a software tool. It does not provide legal, financial, tax, medical, security, sales, compliance, or professional advice. Records, views, scores, automations, webhook updates, and agent outputs may be incomplete or wrong. You are responsible for checking outputs before relying on them.
9. CLI package and licence
The SmallCRM CLI package is licensed under the licence stated in the package. Package availability does not create any warranty, support commitment, or obligation to continue operating the hosted Service.
10. Third-party services
SmallCRM may depend on third-party providers such as hosting, network, domain, package registry, font, authentication, and email providers. Your use of npm, Google, Microsoft, Resend, external websites, webhook providers, agents, model providers, browsers, operating systems, plugins, tools, logging, telemetry, email tools, messaging tools, or other integrations is governed by their terms and privacy policies.
We are not responsible for third-party services, data they collect, outages they cause, or actions they take.
11. The Service is provided "as is"
The Service is provided on an "as is" and "as available" basis, without warranties of any kind, whether express or implied, including warranties of merchantability, fitness for a particular purpose, title, non-infringement, availability, security, accuracy, or reliability.
We do not warrant that the Service will be uninterrupted, error-free, secure, complete, current, or free of harmful components.
12. Limitation of liability
To the fullest extent permitted by applicable law, Odd Solutions Ltd, its directors, employees, contractors, and suppliers will not be liable for any indirect, incidental, consequential, special, exemplary, or punitive damages, or any loss of profits, revenue, business, opportunities, data, goodwill, or other intangible losses, arising out of or relating to the Service or these Terms, even if we have been advised of the possibility of such damages.
Unless a separate written agreement says otherwise, our total aggregate liability to you in connection with the Service, in contract, tort, negligence, breach of statutory duty, or otherwise, will not exceed the greater of: (a) the amount you paid us for the Service in the three months before the event giving rise to the claim; or (b) GBP 0 if you used the Service for free.
Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law, including liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation.
13. Indemnification
You agree to indemnify and hold harmless Odd Solutions Ltd, its directors, employees, contractors, and suppliers from any claim, demand, loss, liability, damage, cost, or expense, including reasonable legal fees, arising out of or relating to:
- Your content, records, forms, webhook mappings, integrations, agents, or submissions.
- Your use or misuse of the Service.
- Your violation of these Terms.
- Your violation of any law or third-party right, including intellectual property, privacy, data protection, confidentiality, publicity, or consumer-protection rights.
14. Changes
We may update these Terms from time to time. The "Last updated" date above reflects the most recent change. Continued use of the Service after changes constitutes acceptance of the revised Terms.
15. Governing law
These Terms are governed by the laws of England and Wales. Any dispute arising out of or in connection with these Terms or the Service will be subject to the exclusive jurisdiction of the courts of England and Wales.
16. Contact
Questions about these Terms may be directed to hi@sdocs.dev.
Odd Solutions Ltd - registered in England and Wales, company number 16186575.