Security
Last updated: July 26, 2026
Crewio holds two sensitive things: your CRM and a live connection to your Telegram account. Here is how we treat both.
Infrastructure
- Production runs at Hetzner in Falkenstein, Germany (EU), servers and object storage alike.
- All traffic is encrypted in transit with TLS: browser to app, app to Telegram, service to service.
- Workspaces are isolated from each other; every request is checked against your workspace membership and role.
- Access to production is limited to the people who operate it.
Your Telegram connection
- The mirror connects over Telegram's own MTProto protocol, like one of your devices. There is no password sharing; you authorize the session yourself.
- You can see and revoke Crewio's session from Telegram's settings at any time, independently of us.
- You choose which chats the mirror sees. Excluded chats are never stored.
- Campaign sending is paced with randomized intervals and daily caps, and pauses automatically when Telegram signals trouble.
Payments
Checkout and billing run through Paddle as merchant of record. Card numbers never reach our servers.
Deletion
Deleting a workspace deletes its data immediately, mirrored conversations included. Residual copies in encrypted backups expire on a rolling basis shortly after.
Reporting a vulnerability
Found something? Email hello@crewio.xyz with the details. We read every report, respond quickly, and will credit you if you want us to. Please give us a reasonable window to fix the issue before disclosing it publicly.