PRIVACY
Privacy Policy
Product-policy effective date: 2026-08-17 · Last updated: 2026-08-28
The currently distributed SCALAR Atelier public alpha consists of local-first, BYOK macOS and Windows desktop apps. The source repository also contains an internal iOS chat app and Remote Beta work, but those surfaces are not currently publicly distributed or available through TestFlight. The conditional iOS and Remote Beta disclosures below apply only if we expressly provide an internal build.
1. No automatic collection or tracking
The app has no product analytics, behavior tracking, crash-reporting service, or automatic error upload. Conversations, prompts, AI responses, files, projects, API keys, and OAuth credentials are not automatically sent to us.
2. What stays on your device
- Provider credentials remain in local credential/app storage.
- Conversations, sessions, projects, attachments, audit/execution records, and local cost estimates remain in local app data.
- The current free alpha requires no license key or activation.
We do not make a server backup of these local contents. Removing app data or the app can remove them, subject to your operating-system backup settings.
3. Requests you choose to send to third parties
- AI providers: Desktop requests send selected prompts and attachments to your connected provider. If you use an expressly supplied internal iOS build, each send shares the recent conversation needed for that reply with OpenRouter and the selected AI model provider; older content in a long chat stays only on the device. Retention, logging, and training rules can differ by provider. SCALAR Atelier does not proxy or retain that chat traffic.
- iOS OAuth callback: If you use an expressly supplied internal iOS build, OpenRouter returns a short-lived, PKCE-bound authorization code through a fixed page on `atelier.scalar-inc.com`. The page makes no additional network request and forwards the code to the App. The hosting provider may process ordinary request metadata under its own policy.
- Remote Beta: If an internal Remote Beta is expressly enabled for you and you pair an iPhone with a Mac, the Cloudflare relay can process IP addresses, connection times, random channel identifiers, and encrypted frame sizes. Conversations and transferred files remain end-to-end encrypted between the paired devices; the relay does not provide plaintext storage or an offline queue.
- Historical payments: Lemon Squeezy may retain earlier purchase, refund, and entitlement records under its policy. The current free alpha has no checkout or license validation, and we do not receive card details.
- Public pages and update hosting: During the hosting transition, Netlify and Cloudflare may process ordinary request metadata such as IP address, request time, requested URL, and response size when serving public pages, update metadata, or an installer. Those requests are not designed to contain prompts, source files, credentials, or usage analytics.
- Optional support: An error card can prepare a minimal mail summary or local diagnostics ZIP, but nothing leaves until you copy, attach, or send it yourself.
4. Voluntary alpha check-in
The alpha check-in is addressed to `l0architect@scalar-inc.com` only when you choose Open email. It is routed into a dedicated alpha-check-in label, not automatic upload or app-use tracking.
- The aggregate contains only checkpoint, device category, result, help status, and whether a note or reply contact was supplied.
- Notes remain in the email body and an optional reply address remains in a separate restricted area. Neither appears in the default dashboard.
- We do not request or aggregate coupons, license keys, API keys, prompts, file names, full conversations, or source files. Invalid input or content that looks like a secret is quarantined rather than aggregated.
- 90 days after alpha ends, we delete successfully processed raw messages and restricted Raw/Contacts rows, retaining only non-identifying daily aggregates. Invalid-format messages are not automatically deleted.
5. Your controls and local device transfer
- You can remove provider credentials in the app's connection settings. In an expressly supplied internal iOS build, disconnect removes only the key on that device; revoke the issued key separately in OpenRouter settings to invalidate it remotely.
- In an expressly supplied internal iOS build, Settings → Delete all data removes local chats, provider consent, and the device key. It does not revoke an already issued OpenRouter key remotely.
- You can export selected desktop outcomes and diagnostics from settings. To delete all desktop data, remove the App's local app-data folder yourself.
- The alpha check-in is optional and does not affect access to the app or support.
- Under Settings → Permissions & Data → Device transfer, you can export selected settings and work records to a local ZIP and inspect it before import. You move the file yourself; it is not uploaded to us.
- The transfer ZIP excludes license keys and activation records, API keys and OAuth tokens, always-allow tool grants, caches, logs, audit streams, original media, and absolute paths. Re-enter credentials and relink original files and workspace folders on the destination. A source file is linked only after its hash matches.
- Keep the original data until you verify the import. Do not delete the source device's data until independent macOS-to-Windows transfer acceptance is complete.
6. Contact
For general support or questions about this policy: l0architect@scalar-inc.com
This public-alpha notice reflects the product-policy source updated on 2026-08-28. It is not legal advice and has not been attorney-reviewed. Counsel review remains required before a future paid public launch.