Back home

Legal

How Scalink handles your data.

This page documents the privacy controls and data flows implemented in the product today. Last updated August 13, 2026.

Terms of Service

Scalink's customer-facing Terms of Service are being finalized separately from this implementation-focused privacy statement.

Privacy Policy

Scalink processes the information needed to authenticate users, run workspaces, connect external services, store architecture and chat content, provide AI assistance, meter usage, measure aggregate public page visits, and operate optional Product Telemetry.

Data Scalink processes

Account and workspace data

Clerk user ID, email address, name, workspace name, membership, role, and invitation records used to authenticate people and enforce workspace access.

Product content

Projects, architecture diagrams, graph content, selected repository metadata, prompts, responses, and creator-private conversation transcripts saved for sandbox-independent chat history.

Connected-service data

Connection status, provider account identifiers and display metadata, and the authorization credentials needed to access services that a workspace chooses to connect.

Billing and operational data

Plan and subscription status, billing-provider references, sandbox and model usage, token and cost totals, session state, and controlled failure information used to operate and meter the service.

Cookieless public analytics

A public page path, referring domain, and the utm_source, utm_medium, and utm_campaign values supplied in a marketing link. Query strings, URL fragments, full referrers, and person profiles are excluded.

Optional Product Telemetry

Completed product events, content-free AI generation metadata, opaque correlation identifiers, controlled event properties, and an approximate country code are collected only after affirmative consent.

How Scalink uses data

  • Create and secure accounts and workspaces.
  • Store diagrams, projects, and creator-private chat history.
  • Connect services and fetch the data a workspace asks Scalink to display or use.
  • Run isolated AI-assisted architecture workflows and return model responses.
  • Process subscriptions, meter usage, enforce plan limits, and maintain service reliability.
  • Measure aggregate public-page visits and campaign attribution using cookieless analytics.
  • Improve product workflows and understand AI cost, performance, and reliability using limited Product Telemetry when a user has consented.

Scalink does not use workspace content to train models or for advertising. Connected services are accessed only when a workspace authorizes a connection or requests a provider-backed feature.

AI requests and chat history

When an agent runtime is started, selected repository content may be cloned into an isolated, ephemeral sandbox. Prompts and relevant context are sent through Scalink's model gateway to OpenRouter and a selected model provider to generate a response.

The gateway forces Zero Data Retention routing and denies provider data collection. Eligible model providers do not retain prompts or responses or use them for training. OpenRouter may retain operational metadata such as token counts, latency, model choice, and a pseudonymous Scalink user and workspace reference.

Zero Data Retention applies to upstream AI processing; it does not mean Scalink discards chat history. Scalink durably stores the root project conversation transcript so its creator can read it without starting another sandbox. Archiving hides a conversation but does not delete its stored transcript.

Cookieless public analytics

Public marketing pages send a limited PostHog page-view event so Scalink can understand aggregate traffic and campaign attribution. The event contains only the public page path, the referring domain, and controlled utm_source, utm_medium, andutm_campaign values when they are present. Query strings, URL fragments, full referrers, page content, and form values are removed before sending.

This stream runs in PostHog's always-cookieless mode, creates no person profile, stores no PostHog cookie or browser identifier, does not use GeoIP enrichment, and is not linked to a later account or sign-up. PostHog derives only a short-lived server-side hash for aggregate audience measurement. Because that hash changes daily, public analytics is not used for multi-day unique-user or retention reporting.

Loading your public analytics preference…

Optional Product Telemetry

Product Telemetry remains off until an authenticated user gives affirmative consent. Declining does not block Scalink, and the preference can be changed later in Settings. Withdrawal stops future Product Telemetry collection.

With consent, Scalink may record that a project graph was successfully loaded and visible, using only an opaque project ID, and may send PostHog content-free metadata for each AI generation: model and provider identifiers; token, cache, reasoning, and web-search counts; exact provider-reported cost; response latency and time to first token; HTTP status, streaming state, stop reason, and controlled error category; and opaque user, Workspace, conversation, assistant-turn, and generation identifiers. Scalink uses this metadata to understand product activity, AI cost, performance, and reliability. PostHog is not Scalink's billing source of truth.

Within authenticated Product Telemetry, Scalink disables session replay, autocapture, generic page views, URL and path collection, and referrer tracking. All Product Telemetry uses fixed property allowlists and must not contain prompts, responses, transcripts, tool definitions, tool arguments or results, reasoning text, diagrams, repository names or URLs, workspace names, email addresses, provider account data, arbitrary request or response payloads, or raw error messages.

For eligible browser events, PostHog derives an approximate country code from the browser IP address and then discards the IP. City, subdivision, postal code, coordinates, and other precise location properties are not retained.

Cookies and browser storage

Scalink uses Clerk's browser storage for authenticated sessions and a seven-day cookie to remember whether the application sidebar is open. Cookieless public analytics does not use PostHog cookies, local storage, or session storage; Scalink stores only the local opt-out preference if a visitor disables it. PostHog browser identity and Product Telemetry opt-in state are initialized only for authenticated users whose Product Telemetry consent is granted.

Service providers and connected services

Scalink uses the following services for the stated operational purposes. A workspace may also connect GitHub, Vercel, AWS, Clerk, Stripe, or Lemon Squeezy; Scalink exchanges data with those services only to perform the actions the workspace requests.

Clerk
Account authentication and identity management.
Vercel and managed database infrastructure
Application hosting, API execution, and durable product storage.
AWS
SecureString storage for provider credentials and supporting cloud infrastructure.
Modal
Ephemeral, workspace-scoped sandboxes used for repository and agent workflows.
OpenRouter and selected model providers
AI inference with Zero Data Retention routing and provider data collection denied.
PostHog Cloud EU
Cookieless public-page analytics plus consent-gated product analytics and content-free AI generation observability.
Resend
Transactional workspace invitation email.
Lemon Squeezy
Subscription checkout, billing, and customer portal access.

Current security controls

Scalink verifies Clerk authentication on API requests and uses workspace membership and roles as the tenancy boundary. Provider secrets are stored as AWS Systems Manager SecureString parameters scoped by connection rather than embedded in workspace records. GitHub sandbox access uses short-lived installation tokens, and stored conversation transcripts remain private to their creator.

Contact

Questions about these current data practices can be sent to hello@scalink.app.