Legal
Privacy Policy
Last updated: April 2026
CostLynx ("CostLynx," "we," "us," or "our") is an Australian-registered company operating globally, including in the United States. We operate the CostLynx platform at costlynx.com (the "Service"). This Privacy Policy explains what information we collect, how we use it, and your choices and rights regarding that information.
1. Information We Collect
We collect information you provide directly, information generated through your use of the Service, and limited technical information necessary to operate and secure the platform.
a) Account and identity information
When you sign up or sign in, we collect your name, email address, and profile information through our authentication provider, Clerk, Inc. This includes any OAuth or SSO identity tokens used to authenticate your session. Authentication credentials and session state are managed by Clerk on our behalf.
b) Organization and workspace data
We store organization names, member roles and permissions, project names, environment labels, feature attribution tags, and invitation records that you configure within the Service.
c) AI usage metadata
When you send usage events to CostLynx via the ingestion API or an SDK, we receive and store the metadata you submit: provider name, model identifier, input and output token counts, estimated cost, attribution labels (project, environment, feature), a caller-supplied request identifier, and the timestamp of ingestion.
Important: CostLynx does not receive, process, or store your AI prompts or AI-generated responses. We receive only the usage metadata you explicitly send.
d) Provider connection data
If you configure a provider connection (for example, to enable automatic usage sync from OpenAI), we store the provider name and the API key you supply. Provider API keys are encrypted at rest using AES-256-GCM before storage; we do not retain the plaintext key after the initial credential test.
e) Billing and payment information
Subscription and billing management is handled by Stripe, Inc. We store your subscription status, plan tier, Stripe customer identifier, and subscription identifier. We do not receive or store payment card numbers; card data is collected and retained exclusively by Stripe.
f) Configuration and notification data
We store budget amounts and thresholds, alert rule configurations, and notification preferences you set within the Service. Slack webhook URLs, if provided, are encrypted at rest using AES-256-GCM.
g) Technical and operational data
We collect IP addresses, request metadata, and limited error telemetry to operate, secure, and maintain the Service. This data is used for rate limiting, abuse prevention, and diagnosing service issues. We do not build individual user profiles from this data.
2. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Service and its features
- Authenticate users and enforce workspace access controls
- Process billing events and manage subscription state
- Deliver organization invitation emails and alert notifications
- Evaluate spend anomaly rules and trigger configured notifications
- Enforce API rate limits and request idempotency
- Monitor for and respond to security threats and abuse
- Improve the Service using aggregate, non-identifying usage patterns
- Respond to support requests and account inquiries
- Comply with applicable legal obligations
3. Privacy Framework
Our privacy practices are designed around generally recognized privacy principles, including core concepts reflected in the Australian Privacy Act (such as transparency, data minimization, security safeguards, and access/correction rights), together with local legal requirements where we operate.
- We collect and use personal information that is reasonably necessary to provide and secure the Service.
- We seek to keep information accurate, up to date, and protected against unauthorized access or misuse.
- We use information for service delivery, account administration, security, support, billing, and legal compliance.
- Where required by applicable law, we rely on consent or another valid legal basis for specific processing activities.
4. How We Share Information
We do not sell your personal data. We do not share your data with third parties for advertising purposes.
We share data with the following service providers ("subprocessors") who process data on our behalf to operate the Service:
| Provider | Purpose |
|---|---|
| Clerk, Inc. | User authentication and identity management |
| Stripe, Inc. | Billing and payment processing |
| Vercel Inc. | Cloud hosting and deployment infrastructure |
| Upstash, Inc. | Rate limiting and ephemeral caching |
| ClickHouse, Inc. | Event data storage and metrics processing |
| Resend, Inc. | Transactional email delivery (organization invitations) |
All subprocessors are contractually required to handle data in accordance with applicable law and maintain appropriate security safeguards. We may update this list as our service providers change; material updates will be reflected in this policy.
We may disclose information if required by law, court order, or valid legal process, or where necessary to protect the rights, safety, or property of CostLynx, its users, or the public.
In the event of a merger, acquisition, or sale of assets, customer data may be transferred as part of that transaction, subject to equivalent or greater privacy protections.
5. Data Retention
- Account and organization data is retained while your account is active and for a reasonable period after account closure to fulfill legal obligations and resolve disputes.
- AI usage event data is retained while your organization is active. You may request deletion upon account closure.
- Billing records are retained as required by applicable financial, tax, and regulatory obligations.
- Transient operational data (rate limit counters, idempotency records) is short-lived and not retained beyond its operational purpose.
6. Security
We use industry-standard security measures to protect information under our control, including:
- TLS encryption for all data in transit
- AES-256-GCM encryption for sensitive credentials (provider API keys, webhook URLs) at rest
- HMAC-based hashing for ingestion and API key storage (plaintext keys are not retained after issuance)
- Role-based access controls within the platform
- Security headers on all HTTP responses
No method of transmission or storage is completely secure. We do not guarantee absolute security, and we are not responsible for the acts of third parties. If you believe you have discovered a security issue, please report it to security@costlynx.com.
7. International Data Transfers
CostLynx is operated from Australia and through service providers that may operate in other regions. If you use the Service, your information may be processed in Australia, the United States, and other countries where we or our subprocessors run infrastructure and support operations.
Privacy laws in those regions may differ from the laws in your location. Where required, we take reasonable contractual and operational steps to safeguard information transferred across borders.
8. Your Rights and Choices
Depending on your location and applicable law, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete personal data
- Request deletion of your personal data, subject to legal retention requirements
- Restrict or object to certain processing activities
- Request portability of your data in a structured, machine-readable format
- Withdraw consent where processing is based on consent
To exercise these rights, contact us at privacy@costlynx.com. Enterprise customers may also submit requests through their account team. We will respond within a reasonable timeframe and in accordance with applicable law.
9. Cookies and Tracking
We use session and authentication cookies necessary to operate the Service. These are managed by our authentication provider, Clerk. We do not deploy third-party advertising cookies or behavioral tracking technologies.
Because authentication cookies are functionally necessary to use the Service, they cannot be disabled without preventing sign-in.
10. Children's Privacy
The Service is intended for business use and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently received data from a child, contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide notice by email or in-app notification before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date of any change constitutes your acceptance of the updated policy.
12. Contact Information
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
CostLynx (Australian-registered company)
Privacy inquiries: privacy@costlynx.com
Security disclosures: security@costlynx.com