Legal
Privacy Policy
Slynkz is built local-first: your conversations, files, and API keys stay encrypted on your device. This policy explains the small amount of data we do handle, why we handle it, and the rights you have over it.
Who we are
Slynkz is operated by [Company legal name], [Company address](“Slynkz”, “we”, “us”). We are the data controller for the personal data described in this policy. You can reach us about anything privacy-related at privacy@slynkz.com.
Local-first by design
The Slynkz desktop app keeps your working data on your own Mac. Chats, projects, files you open in the app, and secrets for connectors you set up are stored in a local database encrypted with SQLCipher, with the most sensitive items held in the macOS Keychain. This data does not leave your device unless you choose a feature that requires it.
If you enable optional cloud sync, your device encrypts the data before upload and our servers store only the resulting ciphertext. We do not hold the keys and cannot read the content — a zero-knowledge design. Deleting synced data removes the ciphertext from our storage.
What happens when you use managed model credits
This is the most important disclosure in this policy.When you use your plan’s managed credits, the prompt content you submit (and any context you attach to it) is transmitted through our managed gateway to the AI model provider selected for that request, so that provider can generate a response. This only applies to managed-credit requests; when you run local models, your prompts do not pass through our gateway. Connector or capability secrets stay behind their local/native boundary and are not stored in web UI state.
Data we collect
We keep the account-side data small and purposeful:
- Account data — your email address and the profile details you choose to add, used to operate your account and portal.
- Billing data — your plan, subscription state, and invoice history. Payments are processed by Stripe; your card details go directly to Stripe and never touch Slynkz systems.
- Usage and credit metering — counts of managed-credit usage (amounts, timestamps, which model tier), so we can enforce plan limits and show you your balance. We meter usage; we do not build content profiles from your prompts.
- Trusted-device records — identifiers for the desktop devices you link to your account, so you can review and revoke them from the Security page.
- Notification preferences — which account and billing notifications you want to receive.
Service providers (processors)
We use a short list of providers to run the service, each only for its stated purpose:
- Supabase — hosting, authentication, and our account database.
- Stripe — payment processing and subscription billing.
- Vercel — hosting of this website and the account portal.
- Sentry — error reporting to help us fix crashes and bugs, where enabled.
- AI model providers — receive prompt content only for managed-gateway requests, as described above, to generate the responses you asked for.
Your rights (GDPR)
If you are in the EU/EEA (and in many other places), you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to receive a copy in a portable format, and to object to or restrict certain processing. You also have the right to complain to your local data protection authority.
To exercise any of these rights, email privacy@slynkz.com from your account email address. We respond within one month.
Deleting your account
You can delete your account yourself from the Security page of your account portal, or by emailing privacy@slynkz.com. Deletion removes your account data and any synced ciphertext from our systems. Data on your own device stays on your device and remains under your control.
Retention
We keep account data for as long as your account exists. After deletion, we remove personal data promptly, keeping only what the law requires us to retain — for example, invoice and tax records, which are kept for the statutory retention period and nothing longer. Usage ledgers are anonymised rather than kept in identifiable form.
Cookies
We use essential cookies only: the authentication cookies needed to keep you signed in to your account portal. We do not use advertising or tracking cookies, and we do not sell or share your personal data for advertising.
Children
Slynkz is not directed at children. You must be at least 16 years old (or the age of digital consent in your country) to create an account.
Changes to this policy
If we make material changes to this policy, we will notify you by email or through the account portal before they take effect.
Last updated: 12 July 2026
This document is a draft prepared for launch and is under legal review.