Privacy Policy
Scalink processes the information needed to authenticate users, run workspaces, connect external services, store architecture and chat content, provide AI assistance, meter usage, measure aggregate public page visits, and operate optional Product Telemetry.
Data Scalink processes
Account and workspace data
Clerk user ID, email address, name, workspace name, membership, role, and invitation records used to authenticate people and enforce workspace access.
Product content
Projects, architecture diagrams, graph content, selected repository metadata, prompts, responses, and creator-private conversation transcripts saved for sandbox-independent chat history.
Connected-service data
Connection status, provider account identifiers and display metadata, and the authorization credentials needed to access services that a workspace chooses to connect.
Billing and operational data
Plan and subscription status, billing-provider references, sandbox and model usage, token and cost totals, session state, and controlled failure information used to operate and meter the service.
Cookieless public analytics
A public page path, referring domain, and the utm_source, utm_medium, and utm_campaign values supplied in a marketing link. Query strings, URL fragments, full referrers, and person profiles are excluded.
Optional Product Telemetry
Completed product events, content-free AI generation metadata, opaque correlation identifiers, controlled event properties, and an approximate country code are collected only after affirmative consent.
How Scalink uses data
- Create and secure accounts and workspaces.
- Store diagrams, projects, and creator-private chat history.
- Connect services and fetch the data a workspace asks Scalink to display or use.
- Run isolated AI-assisted architecture workflows and return model responses.
- Process subscriptions, meter usage, enforce plan limits, and maintain service reliability.
- Measure aggregate public-page visits and campaign attribution using cookieless analytics.
- Improve product workflows and understand AI cost, performance, and reliability using limited Product Telemetry when a user has consented.
Scalink does not use workspace content to train models or for advertising. Connected services are accessed only when a workspace authorizes a connection or requests a provider-backed feature.
AI requests and chat history
When an agent runtime is started, selected repository content may be cloned into an isolated, ephemeral sandbox. Prompts and relevant context are sent through Scalink's model gateway to OpenRouter and a selected model provider to generate a response.
The gateway forces Zero Data Retention routing and denies provider data collection. Eligible model providers do not retain prompts or responses or use them for training. OpenRouter may retain operational metadata such as token counts, latency, model choice, and a pseudonymous Scalink user and workspace reference.
Zero Data Retention applies to upstream AI processing; it does not mean Scalink discards chat history. Scalink durably stores the root project conversation transcript so its creator can read it without starting another sandbox. Archiving hides a conversation but does not delete its stored transcript.
Cookieless public analytics
Public marketing pages send a limited PostHog page-view event so Scalink can understand aggregate traffic and campaign attribution. The event contains only the public page path, the referring domain, and controlled utm_source, utm_medium, andutm_campaign values when they are present. Query strings, URL fragments, full referrers, page content, and form values are removed before sending.
This stream runs in PostHog's always-cookieless mode, creates no person profile, stores no PostHog cookie or browser identifier, does not use GeoIP enrichment, and is not linked to a later account or sign-up. PostHog derives only a short-lived server-side hash for aggregate audience measurement. Because that hash changes daily, public analytics is not used for multi-day unique-user or retention reporting.
Loading your public analytics preference…
Optional Product Telemetry
Product Telemetry remains off until an authenticated user gives affirmative consent. Declining does not block Scalink, and the preference can be changed later in Settings. Withdrawal stops future Product Telemetry collection.
With consent, Scalink may record that a project graph was successfully loaded and visible, using only an opaque project ID, and may send PostHog content-free metadata for each AI generation: model and provider identifiers; token, cache, reasoning, and web-search counts; exact provider-reported cost; response latency and time to first token; HTTP status, streaming state, stop reason, and controlled error category; and opaque user, Workspace, conversation, assistant-turn, and generation identifiers. Scalink uses this metadata to understand product activity, AI cost, performance, and reliability. PostHog is not Scalink's billing source of truth.
Within authenticated Product Telemetry, Scalink disables session replay, autocapture, generic page views, URL and path collection, and referrer tracking. All Product Telemetry uses fixed property allowlists and must not contain prompts, responses, transcripts, tool definitions, tool arguments or results, reasoning text, diagrams, repository names or URLs, workspace names, email addresses, provider account data, arbitrary request or response payloads, or raw error messages.
For eligible browser events, PostHog derives an approximate country code from the browser IP address and then discards the IP. City, subdivision, postal code, coordinates, and other precise location properties are not retained.
Cookies and browser storage
Scalink uses Clerk's browser storage for authenticated sessions and a seven-day cookie to remember whether the application sidebar is open. Cookieless public analytics does not use PostHog cookies, local storage, or session storage; Scalink stores only the local opt-out preference if a visitor disables it. PostHog browser identity and Product Telemetry opt-in state are initialized only for authenticated users whose Product Telemetry consent is granted.
Service providers and connected services
Scalink uses the following services for the stated operational purposes. A workspace may also connect GitHub, Vercel, AWS, Clerk, Stripe, or Lemon Squeezy; Scalink exchanges data with those services only to perform the actions the workspace requests.
- Clerk
- Account authentication and identity management.
- Vercel and managed database infrastructure
- Application hosting, API execution, and durable product storage.
- AWS
- SecureString storage for provider credentials and supporting cloud infrastructure.
- Modal
- Ephemeral, workspace-scoped sandboxes used for repository and agent workflows.
- OpenRouter and selected model providers
- AI inference with Zero Data Retention routing and provider data collection denied.
- PostHog Cloud EU
- Cookieless public-page analytics plus consent-gated product analytics and content-free AI generation observability.
- Resend
- Transactional workspace invitation email.
- Lemon Squeezy
- Subscription checkout, billing, and customer portal access.
Current security controls
Scalink verifies Clerk authentication on API requests and uses workspace membership and roles as the tenancy boundary. Provider secrets are stored as AWS Systems Manager SecureString parameters scoped by connection rather than embedded in workspace records. GitHub sandbox access uses short-lived installation tokens, and stored conversation transcripts remain private to their creator.
Contact
Questions about these current data practices can be sent to hello@scalink.app.