Legal

Privacy Policy

Last updated: April 18, 2026

Overview

ScaleBop ("we," "us," or "our") provides tools that help you plan and generate cloud delivery assets from software projects you choose to connect or upload. Project content you import is handled only to operate your workspace and deliver the Services—not to build a standalone archive of customer code or to train generalized machine learning models. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use our website and services (collectively, the "Services").

By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.

Information we collect

  • Account and contact data. When you register or sign in (including through an identity provider such as GitHub), we collect information such as your name, email address, and authentication identifiers associated with your account.
  • Project and repository content. When you import a project, we process the files you provide (for example from a linked repository) so we can analyze the stack and generate outputs you request. We retain this content only as needed to operate the Services for your account (for example, to power analysis, regeneration, and project history). We do not use your application source code to train machine learning models or for any similar model-learning purpose.
  • Billing. If you purchase a paid plan, payment details are processed by our payment provider; we typically receive limited billing metadata (such as subscription status) rather than full card numbers.
  • Usage and diagnostics. We may collect technical and usage information such as device type, browser, approximate region, log data, and product analytics events to operate, secure, and improve the Services.
  • Deployment diagnostics. When you ask ScaleBop to diagnose a failed deployment, we may store a bounded, redacted excerpt of your AWS CloudWatch logs and ECS service state (for example, the stopped-task reason) for that deployment attempt. Excerpts are size-capped, stripped of terminal control characters, and filtered through automated secret-redaction patterns before storage; they are deleted with the project and are never collected automatically — only when you request diagnostics or export a support bundle.
  • Communications. If you contact us (for example support or feedback), we retain those messages and related metadata as needed to respond and improve support.

How we use information

We use the information above to:

  • Provide, maintain, and improve the Services and generated outputs;
  • Authenticate users, enforce limits associated with your plan, and prevent abuse;
  • Process transactions and communicate about your account or the Services;
  • Analyze aggregated or de-identified usage to understand product performance (not to train models on your proprietary source code);
  • Comply with law, respond to lawful requests, and protect our rights and users.

Machine learning and your source code

We do not use your application source code, repository contents, or uploaded project files for training, fine-tuning, or improving generalized machine learning models. Processing may use third-party AI or cloud services strictly to deliver features you invoke (for example, analysis or generation steps within the product), subject to our agreements with those providers and this policy.

Sharing of information

We do not sell your personal information. We may share information with:

  • Service providers who assist us (for example hosting, analytics, payment processing, email, or AI inference), bound by contractual obligations;
  • Professional advisors where appropriate (for example auditors or lawyers);
  • Authorities when required by law or to protect safety and rights.

If we are involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction; we will provide notice where required.

Retention

We retain information for as long as your account is active and as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete a project or your account (where available), we delete or de-identify associated data within a reasonable period, except where retention is required by law or legitimate business needs such as security logs. Deployment diagnostic excerpts (GitHub, repository drift, and AWS) are stored with the deployment attempt and are deleted with the project through the same cascade.

Security

We use administrative, technical, and organizational measures designed to protect information. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

International transfers

We may process and store information in the United States and other countries where we or our providers operate. Those countries may have different data protection rules than your place of residence.

Children

The Services are not directed to children under 16. We do not knowingly collect personal information from children under 16.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or restrict certain personal information, or to object to or limit certain processing. You may exercise these rights through your account settings where available, or by contacting us. You may also unsubscribe from marketing emails using the link in those messages.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may be communicated through the Services or by email where appropriate.

Contact

Questions about this Privacy Policy or our data practices may be directed through support channels listed on the ScaleBop website or within the product.

Back to home