Login Get a Demo
01 Legal

Your privacy, respected.

We only collect and use personal data in the ways described here — consistent with our obligations and your rights under the law.

Effective Date: June 29, 2026  ·  Last Updated: July 23, 2026

Cranium AI, Inc. (“Cranium,” “we,” “our,” or “us”) respects your privacy and is committed to handling personal data responsibly. This Privacy Policy explains what personal data we collect through our websites at cranium.ai and related Cranium properties (the “Site”) and our SaaS platform and services (together, the “Services”), how we use and share it, and the rights and choices available to you.

This Policy is provided alongside our Cookie Policy, our AI & Automated Decision-Making Notice, and our Terms of Service. If you do not agree with this Policy, please discontinue use of the Site.

Quick links

Exercise your data rights: Privacy Request Form  ·  Email: privacy@cranium.ai  ·  Opt out of sale/sharing & targeted advertising: Do Not Sell or Share My Personal Information

1. About Cranium

Cranium AI, Inc. provides an end-to-end AI security and governance platform that helps enterprises discover, secure, monitor, and govern their AI models, agents, and AI supply chain. Our registered office is 1200 Morris Tpke, Suite 3005, Short Hills, NJ 07078, United States. Cranium is the controller responsible for the personal data described in this Policy. Following Cranium’s acquisition of Aiceberg, Aiceberg products and properties are operated by Cranium and are covered by this Policy.

2. Scope of This Policy

This Policy applies to personal data we process as a controller in connection with the Site and our marketing, sales, events, and support activities, and to account and usage data we process in operating the Services. Where we process personal data on behalf of a business customer as a processor / service provider under that customer’s instructions (for example, content our customers load into the platform), the customer’s own privacy notice and our agreement with them govern that processing, not this Policy. The Site may link to third-party sites we do not control; their privacy practices are their own.

3. Personal Data We Collect

The categories of personal data we collect depend on how you interact with us:

Information you provide

  • Identifiers & contact data — name, business email, phone number, job title, employer/company name, and account username and password.
  • Communications — the contents of forms, demo and contact requests, support tickets, event registrations, survey responses, and correspondence with us.
  • Commercial & marketing data — your interests, preferences, and the products, content, or events you engage with.

Information collected automatically

  • Device & connection data — IP address, device and browser type, operating system, and language settings.
  • Usage & analytics data — pages viewed, links clicked, referring URLs, session activity, and approximate (city/region-level) location derived from IP address.
  • Cookies & similar technologies — as described in our Cookie Policy.

Information from third parties

  • Marketing & enrichment partners — business contact details and firmographic data from lead-generation, event, and data-enrichment providers.
  • Visitor identification providers — we use business visitor-identification technology (RB2B) that matches certain anonymous Site visitors against third-party identity graphs to tell us the company and, in some cases, the business individual visiting our Site (such as name, professional profile, and business email). We do not run this visitor-identification technology on visitors we identify as California residents.
  • Advertising & social platforms — engagement data when you interact with our ads or content on third-party platforms.

We do not seek to collect special categories of data (such as race or ethnicity, religious beliefs, health, sexual orientation, political opinions, trade-union membership, or genetic or biometric data) through the Site, and we ask that you do not submit them. We do not knowingly process the personal data of children (see Section 13).

4. How and Why We Use Personal Data

We use personal data to operate, secure, and improve our Site and Services; to respond to your inquiries; to provide demos, support, and customer engagements; to send communications and marketing you have asked for or that are relevant to your business role; to host and follow up on events; to conduct analytics and research; to personalize your experience; to detect, prevent, and respond to fraud and security threats; and to comply with law and enforce our agreements.

Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract (operating your account and Services); legitimate interests (running, securing, and growing our business, including B2B marketing and analytics, balanced against your rights); consent (certain cookies, marketing, and optional processing, which you may withdraw at any time); and legal obligation or the establishment, exercise, or defense of legal claims.

5. Cookies, Analytics, Visitor Identification & Advertising

We and our partners use cookies and similar technologies for essential site functionality, analytics, visitor identification, and advertising. Our current tools include HubSpot (forms, website analytics, and CRM), Google Analytics and Hotjar (website analytics and on-page behavior), Crazy Egg (click, scroll, and heatmap analytics), RB2B (business visitor identification), and LinkedIn Ads (advertising and campaign measurement). As described in Section 3, RB2B identifies the companies and business individuals visiting our Site; we do not run RB2B on visitors we identify as California residents. The specific tools and your controls are described in our Cookie Policy. Where required, we obtain consent before setting non-essential cookies, and you can change your preferences at any time through our cookie banner or your browser settings.

6. How We Share Personal Data

We do not sell your personal data for money. We may share personal data as follows:

  • Service providers / processors — vendors that host our infrastructure, process payments, deliver email and CRM, provide analytics and support, and run events, bound by contract to use the data only to provide services to us.
  • Advertising & analytics partners — we may share online identifiers and usage data with advertising and analytics partners to measure and deliver relevant ads. Under some US state laws, this activity may be considered a “sale” or “sharing” for cross-context behavioral advertising even though no money changes hands. You can opt out via our Do Not Sell or Share form or by enabling a recognized opt-out preference signal (see Section 8).
  • Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • Legal & safety — to comply with law, respond to lawful requests and legal process, enforce our terms, and protect the rights, property, and safety of Cranium, our users, and the public.

7. Your US State Privacy Rights

Depending on your state of residence, you may have some or all of the following rights with respect to personal data we hold about you: the right to know/access the categories and specific pieces of personal data we process; the right to correct inaccurate data; the right to delete your data; the right to a portable copy; the right to opt out of (i) the sale of personal data, (ii) sharing/processing for targeted (cross-context behavioral) advertising, and (iii) certain profiling that produces legal or similarly significant effects; the right to limit the use of sensitive personal data; the right to appeal a denied request; and the right to be free from discrimination for exercising these rights.

These rights are provided under comprehensive consumer privacy laws now in effect in states including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, among others as such laws take effect. The specific rights available to you, and any exceptions, depend on your state’s law.

How to exercise your rights. Submit a request through our Privacy Request Form or email privacy@cranium.ai. We will verify your request, typically respond within the timeframe required by your state’s law (often 45 days, with an extension where permitted), and will not discriminate against you for exercising your rights. If we deny your request, you may appeal by replying to our decision or emailing privacy@cranium.ai with “Appeal” in the subject line.

Authorized agents. You may use an authorized agent to submit a request. We may require the agent to provide proof of authorization and may ask you to verify your identity directly.

8. Opt-Out Preference Signals (Global Privacy Control)

We honor recognized universal opt-out mechanisms, including the Global Privacy Control (GPC). When we detect a GPC signal from your browser, we treat it as a request to opt out of sale/sharing for targeted advertising for that browser or device. Because such signals are typically not tied to your identity, this may not affect data linked to your account; to apply an opt-out to your account, please also submit our Do Not Sell or Share form.

9. California Notice at Collection & Additional Disclosures

This section provides additional detail for California residents under the CCPA/CPRA.

Categories of personal information collected in the past 12 months: identifiers; customer records (name, contact, employment information); commercial information; internet/network activity; approximate geolocation; and professional/employment information. We collect these from you, automatically through the Site, and from the third-party sources described in Section 3.

Purposes: as described in Section 4. Disclosure for a business purpose: we disclose the categories above to service providers and, for analytics/advertising, to the partners described in Section 6.

Sale/Sharing: we do not sell personal information for money. We may “share” internet/network identifiers for cross-context behavioral advertising; you can opt out via our Do Not Sell or Share My Personal Information form or GPC. Sensitive personal information: we do not use or disclose sensitive personal information for purposes that require offering a “Limit the Use” right. Retention: see Section 11. Shine the Light: California Civil Code § 1798.83 lets California residents request information about disclosures to third parties for their direct-marketing purposes; email privacy@cranium.ai.

10. AI & Automated Decision-Making

We do not use automated decision-making technology (ADMT) to make decisions that produce legal or similarly significant effects about you without human involvement on the Site. Where we use AI to support marketing, lead routing, analytics, or security, a human remains responsible for material decisions. For details on our use of AI, automated processing, and your related rights — including under the California CCPA ADMT regulations, the Colorado AI Act, the Texas Responsible AI Governance Act, and the EU AI Act — see our AI & Automated Decision-Making Notice. Where applicable law gives you the right to opt out of, or obtain human review of, automated processing, you may contact us using the details in Section 16.

11. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy — to provide the Services, maintain our business records, comply with legal obligations, resolve disputes, and enforce our agreements — after which we delete or de-identify it. Retention periods vary by data type and context; for example, marketing data is retained until you unsubscribe or become inactive, and account data is retained for the life of the account plus any legally required period.

12. International Data Transfers

Cranium is headquartered in the United States, and our Site is hosted in the United States. If you access the Site or Services from outside the US, your personal data will be transferred to and processed in the US and other countries whose laws may differ from yours. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful transfer mechanism. You may request a copy of the relevant safeguards by contacting us.

13. Children’s Privacy

The Site and Services are intended for business users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

14. Security

As an AI security company, we take data protection seriously. We maintain administrative, technical, and organizational safeguards designed to protect personal data appropriate to its sensitivity. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

15. Europe, UK & Switzerland

If you are in the EEA, UK, or Switzerland, you have the rights to access, rectify, erase, restrict, and object to processing of your personal data, to data portability, and to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority, though we ask that you contact us first so we can try to help. To exercise these rights, use the details in Section 16. [Where required, our EU/UK representative and Data Protection Officer contact details will be listed here — see LEGAL-REVIEW-NOTES.md.]

16. Contact Us & Changes

For privacy questions or to exercise your rights, use our Privacy Request Form or email privacy@cranium.ai. You can also write to: Cranium AI, Inc., Attn: Privacy, 1200 Morris Tpke, Suite 3005, Short Hills, NJ 07078, USA.

We may update this Policy from time to time. We will post the updated version here with a new “Last Updated” date and, where required, provide additional notice. Your continued use of the Site after an update means you accept the revised Policy.