Legal

Privacy

Last updated September 2026. This page is a plain-language summary of how Scaleup-in-a-Box handles your data while the product is in its invite-only phase. It is written to be read, not to be lawyered — if you need contractual terms for a procurement or compliance review, ask us and we will send them.

What we collect

  • Account details you give us at signup: your name, email address and the referral code you used.
  • The startup information you enter during onboarding — company name, product description, stage and business model — which is what your agents are briefed with.
  • Everything your AI team produces and everything you send it: chat messages, documents, decks and the files in each agent's workspace.
  • Ordinary operational records: sign-in times, errors, and which parts of the product were used.

Where it lives

  • Account data and your chat history are stored in our Supabase database, protected by row-level security so one account cannot read another's rows.
  • Each startup runs in its own isolated container with its own agent workspaces. Those workspaces are not shared between customers.
  • API keys and tokens you add in the credentials vault are encrypted at rest and are only ever decrypted to be handed to your own container.

Who else sees it

  • Your agents run on third-party AI model providers. Prompts and the content your agents work on are sent to whichever provider your startup is configured to use.
  • We use service providers for hosting, database, email delivery and error reporting. They process data on our behalf, not for their own purposes.
  • We do not sell your data, and we do not use your company's content to advertise to you.

Your choices

  • You can pause a startup at any time from its settings, which stops its container.
  • You can remove any credential you have stored from the credentials vault.
  • You can ask us to delete your account and its data — see the contact page.

Questions about any of this, or a request to delete your data? Get in touch.