Legal
Privacy
Last updated September 2026. This page is a plain-language summary of how Scaleup-in-a-Box handles your data while the product is in its invite-only phase. It is written to be read, not to be lawyered — if you need contractual terms for a procurement or compliance review, ask us and we will send them.
What we collect
- Account details you give us at signup: your name, email address and the referral code you used.
- The startup information you enter during onboarding — company name, product description, stage and business model — which is what your agents are briefed with.
- Everything your AI team produces and everything you send it: chat messages, documents, decks and the files in each agent's workspace.
- Ordinary operational records: sign-in times, errors, and which parts of the product were used.
Where it lives
- Account data and your chat history are stored in our Supabase database, protected by row-level security so one account cannot read another's rows.
- Each startup runs in its own isolated container with its own agent workspaces. Those workspaces are not shared between customers.
- API keys and tokens you add in the credentials vault are encrypted at rest and are only ever decrypted to be handed to your own container.
Who else sees it
- Your agents run on third-party AI model providers. Prompts and the content your agents work on are sent to whichever provider your startup is configured to use.
- We use service providers for hosting, database, email delivery and error reporting. They process data on our behalf, not for their own purposes.
- We do not sell your data, and we do not use your company's content to advertise to you.
Your choices
- You can pause a startup at any time from its settings, which stops its container.
- You can remove any credential you have stored from the credentials vault.
- You can ask us to delete your account and its data — see the contact page.
Questions about any of this, or a request to delete your data? Get in touch.