Introduction
This Privacy Policy explains how Scalcraft (“we”, “us”, or “our”) collects, uses, stores, and shares information when you use our website, applications, and related services (collectively, the “Services”).
We believe privacy should be the default, not a setting. We only collect what we need to run the Services, keep them secure, and improve them over time. We don’t sell your personal data. Ever.
Information We Collect
We collect information in three ways: you give it to us, it’s generated through your use of the Services, or it comes from trusted third parties you authorize.
- Account information — your name, email address, password (hashed), profile photo, and any optional profile details you add.
- Authentication data — if you sign in with Google or another provider, we receive a unique identifier and the basic profile fields you approve.
- Content you create — architecture diagrams, saved problems, notes, comments, blog posts, and chat messages you send to our AI assistant.
- Usage data — pages visited, features used, timestamps, and approximate location derived from IP, collected to understand product performance.
- Device and log data — browser type, OS, referrer URLs, and error logs needed to debug issues and keep the Services secure.
- Payment information — handled directly by Stripe and Razorpay. We never see or store your full card number.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Services.
- Personalize your experience, including AI feedback tailored to your designs.
- Process payments, manage subscriptions, and issue receipts.
- Send transactional emails — account verification, receipts, security alerts, and product updates you opt into.
- Detect, prevent, and respond to fraud, abuse, or security incidents.
- Improve model quality, product flows, and documentation.
- Comply with legal obligations and enforce our Terms.
We process your data only for the purposes listed here. If we ever need to use it for something new, we’ll ask first or update this page with clear notice.
AI and Your Content
When you interact with our AI tutor or design reviewer, we send the relevant prompt and any attached architecture context to our AI providers (currently Google Generative AI). We keep prompts and responses associated with your account so you can see your history.
Your private designs, notes, and chats are not used to train third-party foundation models. Providers may process requests ephemerally to generate responses under their own terms, but we do not grant them rights to train on your private content.
If you publish content publicly — such as a public blog post or a shared problem solution — that content is visible to others and may appear in search engines.
Data Retention
We keep your account data for as long as your account is active. You can export or delete your data at any time from your account settings. When you delete your account, we remove personal data within 30 days, except where we’re required to retain it for legal, accounting, or fraud-prevention reasons.
Backups are retained for a maximum of 90 days before being permanently purged.
Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your account and associated data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent you previously granted.
- Lodge a complaint with a supervisory authority.
You can exercise most rights directly from your account settings, or by emailing privacy@scalcraft.com.
Security
We use industry-standard safeguards: TLS encryption in transit, encryption at rest for sensitive fields, scoped access controls, and regular security reviews. No system is perfect — if we ever experience a breach that affects you, we’ll notify you promptly and transparently.
Children
The Services are not directed to children under 13 (or the relevant minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact us and we’ll delete it.
International Data Transfers
We process data in the regions where our infrastructure providers operate, which may include the United States, European Union, and India. When transferring data internationally, we rely on Standard Contractual Clauses and other approved safeguards.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced on this page and, where appropriate, by email. The “Effective” date at the top always reflects the most recent version.
Contact Us
Questions, complaints, or data requests? Email privacy@scalcraft.com or write to us at Scalcraft, Attn: Privacy. We aim to respond within 7 business days.
Questions?
We’re human. Reach out any time.
If anything on this page is unclear, email us and a real person will reply. We’ll update this page in plain English whenever policies change.
hello@scalcraft.com