Legal

Privacy Policy

Last updated: April 2026

CostLynx ("CostLynx," "we," "us," or "our") is an Australian-registered company operating globally, including in the United States. We operate the CostLynx platform at costlynx.com (the "Service"). This Privacy Policy explains what information we collect, how we use it, and your choices and rights regarding that information.

1. Information We Collect

We collect information you provide directly, information generated through your use of the Service, and limited technical information necessary to operate and secure the platform.

a) Account and identity information

When you sign up or sign in, we collect your name, email address, and profile information through our authentication provider, Clerk, Inc. This includes any OAuth or SSO identity tokens used to authenticate your session. Authentication credentials and session state are managed by Clerk on our behalf.

b) Organization and workspace data

We store organization names, member roles and permissions, project names, environment labels, feature attribution tags, and invitation records that you configure within the Service.

c) AI usage metadata

When you send usage events to CostLynx via the ingestion API or an SDK, we receive and store the metadata you submit: provider name, model identifier, input and output token counts, estimated cost, attribution labels (project, environment, feature), a caller-supplied request identifier, and the timestamp of ingestion.

Important: CostLynx does not receive, process, or store your AI prompts or AI-generated responses. We receive only the usage metadata you explicitly send.

d) Provider connection data

If you configure a provider connection (for example, to enable automatic usage sync from OpenAI), we store the provider name and the API key you supply. Provider API keys are encrypted at rest using AES-256-GCM before storage; we do not retain the plaintext key after the initial credential test.

e) Billing and payment information

Subscription and billing management is handled by Stripe, Inc. We store your subscription status, plan tier, Stripe customer identifier, and subscription identifier. We do not receive or store payment card numbers; card data is collected and retained exclusively by Stripe.

f) Configuration and notification data

We store budget amounts and thresholds, alert rule configurations, and notification preferences you set within the Service. Slack webhook URLs, if provided, are encrypted at rest using AES-256-GCM.

g) Technical and operational data

We collect IP addresses, request metadata, and limited error telemetry to operate, secure, and maintain the Service. This data is used for rate limiting, abuse prevention, and diagnosing service issues. We do not build individual user profiles from this data.

2. How We Use Information

We use the information we collect to:

  • Provide, operate, and maintain the Service and its features
  • Authenticate users and enforce workspace access controls
  • Process billing events and manage subscription state
  • Deliver organization invitation emails and alert notifications
  • Evaluate spend anomaly rules and trigger configured notifications
  • Enforce API rate limits and request idempotency
  • Monitor for and respond to security threats and abuse
  • Improve the Service using aggregate, non-identifying usage patterns
  • Respond to support requests and account inquiries
  • Comply with applicable legal obligations

3. Privacy Framework

Our privacy practices are designed around generally recognized privacy principles, including core concepts reflected in the Australian Privacy Act (such as transparency, data minimization, security safeguards, and access/correction rights), together with local legal requirements where we operate.

  • We collect and use personal information that is reasonably necessary to provide and secure the Service.
  • We seek to keep information accurate, up to date, and protected against unauthorized access or misuse.
  • We use information for service delivery, account administration, security, support, billing, and legal compliance.
  • Where required by applicable law, we rely on consent or another valid legal basis for specific processing activities.

4. How We Share Information

We do not sell your personal data. We do not share your data with third parties for advertising purposes.

We share data with the following service providers ("subprocessors") who process data on our behalf to operate the Service:

ProviderPurpose
Clerk, Inc.User authentication and identity management
Stripe, Inc.Billing and payment processing
Vercel Inc.Cloud hosting and deployment infrastructure
Upstash, Inc.Rate limiting and ephemeral caching
ClickHouse, Inc.Event data storage and metrics processing
Resend, Inc.Transactional email delivery (organization invitations)

All subprocessors are contractually required to handle data in accordance with applicable law and maintain appropriate security safeguards. We may update this list as our service providers change; material updates will be reflected in this policy.

We may disclose information if required by law, court order, or valid legal process, or where necessary to protect the rights, safety, or property of CostLynx, its users, or the public.

In the event of a merger, acquisition, or sale of assets, customer data may be transferred as part of that transaction, subject to equivalent or greater privacy protections.

5. Data Retention

  • Account and organization data is retained while your account is active and for a reasonable period after account closure to fulfill legal obligations and resolve disputes.
  • AI usage event data is retained while your organization is active. You may request deletion upon account closure.
  • Billing records are retained as required by applicable financial, tax, and regulatory obligations.
  • Transient operational data (rate limit counters, idempotency records) is short-lived and not retained beyond its operational purpose.

6. Security

We use industry-standard security measures to protect information under our control, including:

  • TLS encryption for all data in transit
  • AES-256-GCM encryption for sensitive credentials (provider API keys, webhook URLs) at rest
  • HMAC-based hashing for ingestion and API key storage (plaintext keys are not retained after issuance)
  • Role-based access controls within the platform
  • Security headers on all HTTP responses

No method of transmission or storage is completely secure. We do not guarantee absolute security, and we are not responsible for the acts of third parties. If you believe you have discovered a security issue, please report it to security@costlynx.com.

7. International Data Transfers

CostLynx is operated from Australia and through service providers that may operate in other regions. If you use the Service, your information may be processed in Australia, the United States, and other countries where we or our subprocessors run infrastructure and support operations.

Privacy laws in those regions may differ from the laws in your location. Where required, we take reasonable contractual and operational steps to safeguard information transferred across borders.

8. Your Rights and Choices

Depending on your location and applicable law, you may have rights to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete personal data
  • Request deletion of your personal data, subject to legal retention requirements
  • Restrict or object to certain processing activities
  • Request portability of your data in a structured, machine-readable format
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at privacy@costlynx.com. Enterprise customers may also submit requests through their account team. We will respond within a reasonable timeframe and in accordance with applicable law.

9. Cookies and Tracking

We use session and authentication cookies necessary to operate the Service. These are managed by our authentication provider, Clerk. We do not deploy third-party advertising cookies or behavioral tracking technologies.

Because authentication cookies are functionally necessary to use the Service, they cannot be disabled without preventing sign-in.

10. Children's Privacy

The Service is intended for business use and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently received data from a child, contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide notice by email or in-app notification before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date of any change constitutes your acceptance of the updated policy.

12. Contact Information

If you have questions or concerns about this Privacy Policy or our data practices, please contact:

CostLynx (Australian-registered company)

Privacy inquiries: privacy@costlynx.com

Security disclosures: security@costlynx.com