← Intake CRM

Privacy Policy

Last updated 6 September 2026

What this system is

Intake CRM is an inbound enquiry handling system operated by Storyworks Consulting. It receives email sent to a dedicated intake address, researches the sender’s organisation, and presents the resulting record on a login-gated dashboard so enquiries can be prioritised and answered.

It is also a portfolio and demonstration project. Most of the contacts currently visible in the dashboard are synthetic records created during development, not real people. Where a record is genuine, it is because that person emailed the intake address.

What we collect, and how

We do not operate trackers, advertising pixels or third-party analytics on this site, and the public pages set no cookies. There are two ways data reaches this system:

1. You email the intake address

Everything in the message you sent is stored: your name and email address as they appear in the headers, the recipients, the subject, the full message body, the time it was sent, and the technical transport headers your mail server attached. If you did not email us, we hold nothing about you.

2. We look up your organisation

From the domain of your email address, we research the organisation using publicly available web sources and store a short profile of it. This is deliberately limited to the organisation. We do not build a profile of you as an individual, and we do not buy, enrich from, or cross-reference third-party personal data brokers.

Signing in to the dashboard sets a session cookie. That cookie is strictly necessary for authentication and is used for nothing else.

How the data is used

Your message is passed to Anthropic’s Claude API, which writes a one-sentence summary, assigns a priority with written reasoning, and flags messages showing a concrete sign of impersonation. Those outputs are advisory. No reply is ever sent automatically: a person reviews the record and decides what to do, and a human being clicks send on every outbound email.

Under Anthropic’s commercial terms, data sent through the API is not used to train their models.

Who processes it, and where

  • Mailgun — receives and sends the email. United States region.
  • Vercel — hosts the application. Requests are served from Singapore.
  • Supabase — stores the database. Singapore region (ap-southeast-1).
  • Anthropic — processes message text to produce the summary and priority. United States.

Using these services means your message is transferred outside Singapore, to the United States. We rely on each provider’s contractual data protection terms for that transfer.

Who can see it

One operator. Access requires a confirmed account and a valid session; the database enforces this itself through row-level security rather than relying on the application to check. An unauthenticated request returns no rows even when it presents the public API key that ships in the browser, and accounts that can sign in are granted read and update only — they cannot insert or delete records. Records are created solely by the mail webhook, which accepts a message only after verifying its cryptographic signature.

We do not sell your data, share it with advertisers, or disclose it to anyone outside the processors listed above, except where we are legally required to.

How long it is kept

Enquiries are retained while the enquiry is live and for as long as the business relationship makes it useful to keep them. There is currently no automated deletion schedule; records are reviewed and removed manually. If you want your record removed sooner, ask and we will delete it.

Your rights

Under Singapore’s Personal Data Protection Act you may ask what personal data we hold about you and how it has been used, ask us to correct anything inaccurate, ask us to delete it, and withdraw consent for further processing.

To make any of those requests, or to raise a concern about how this system has handled your data, email intake@mg.storyworks.asia. A person reads that address and will respond.

Automated decisions

The priority rating and the impersonation flag are produced by a language model and can be wrong. They are shown to a human alongside the reasoning behind them, and they do not by themselves decide anything about you: no message is deleted, rejected or replied to on the strength of a model output alone. If you believe a rating about your enquiry is wrong, tell us at the address above and a person will look at it.

Security

The application was scanned by an independent automated security service (ZeroThreat) on 6 September 2026, which reported no critical and no high severity findings, and an A+ grade for the TLS certificate. The medium and low findings were missing HTTP security headers; those have been added. The access controls described above were separately verified by direct testing.

If you find a security issue in this application, please report it to the address above rather than disclosing it publicly, and we will respond.

Intake CRM is operated by Storyworks Consulting. This policy describes the system as it actually behaves today; where something is not yet automated, it says so.