Astrolinks: who else can receive data
Draft for review by a lawyer. Not in force yet.
In this file, "Astrolinks" and "we" mean the company; "the app" means the software.
The short answer
The app's activity log never leaves the person's computer. Only these companies can ever receive anything, and each only after a click (or, for the store and payment rows, outside the app):
| Company | Role | What they receive | When | Where | Terms to check |
|---|---|---|---|---|---|
| Anthropic, PBC (or Anthropic Ireland, Limited for customers in the EEA, Switzerland and the UK) | AI model provider. For the AI included with Pro: our processor. With the person's own key: the person's own provider, not ours. | The day's summary, profile, client context, report text, recent chat and the new message, with web addresses cut to site names and emails and phone numbers masked by default. Never the raw log, never private clients, never crisis messages. With Pro, also a pseudonymous code per license (an HMAC of the license fingerprint); never a name, email, key or the person's network address. With the person's own key, Anthropic also sees their network address and the SDK's platform details. | Write with AI, each chat message, Test it (no content) | United States, and other regions Anthropic uses | Commercial Terms of Service, Data Processing Addendum, Usage Policy, Privacy Center (anthropic.com/legal). Anthropic's Privacy Center (1 July 2026) says API inputs and outputs are deleted within 30 days, flagged content kept up to 2 years. |
| Cloudflare, Inc. | Hosting for our AI service (Cloudflare Workers), its license store (Workers KV), its per-license counters (Durable Objects) and rate limiter; and for the Team service (Workers, the D1 database, a rate limiter, a nightly Cron Trigger). Possibly the website. | AI requests in transit (not stored by our code); the connection's network address (Cloudflare sees it; our code counts only a keyed fingerprint of the network, for rate limits); license records (fingerprint, plan, status, end date, daily limit); each license's counter (the latest day's request count, spending, running requests, this month's AI writes and edits, and when last used; deleted after 35 days unused); for a team seat, which workspace it belongs to; for a Team or Business subscription, the Paddle customer and subscription ids of the workspace it pays for. With Team: the reports workers send, workers' names, managers' emails, names, password fingerprints and sealed two-step secrets, recovery code fingerprints, sessions (with a browser label and the country Cloudflare gives), the activity log, invites and throttle counts. | Each AI request with the AI included with Pro; Team use | Global network; Cloudflare is a US company. D1 keeps a restore history ("Time Travel") of the Team database. | Cloudflare Data Processing Addendum and Self-Serve Subscription Agreement. |
| Slack (Slack Technologies, LLC, a Salesforce company) | Not our processor. The client's or company's workspace provider. | The report the person chose to send | Only Send to Slack, after a confirm, to that client's Slack link | Per the workspace's own Slack setup | The workspace owner's agreement with Slack. Astrolinks has no account relationship here. |
| The person's own email app and email provider | Not our processor. The person's own tools. | A draft with the report | Only Email draft; nothing is sent until the person sends it | The person's provider | The person's own terms with their provider |
| Paddle.com Market Limited (Paddle) | Merchant of record: Paddle sells the plans and handles payment, tax, receipts and refunds. | From the buyer at checkout: name, email, country, billing and card details. From our service: a license's Paddle customer id (to open the customer portal) and, for prices, the network address of whoever opens the Plan page (passed on, never kept). The website's pricing page loads Paddle.js, which sees visitors' network addresses and may set Paddle's cookies. | Checkout, renewals, refunds, Manage plan, prices on the Plan page and the pricing page | Paddle's Buyer Terms, Seller Terms, DPA and privacy notice. | |
| Microsoft (Microsoft Store), if the app is listed there | Not our processor. The store the person downloads from, under Microsoft's own terms and privacy statement. | Nothing from the app. Microsoft has the person's download and any Store purchase. | Download and Store purchases | Microsoft's | Microsoft App Developer Agreement and Store Policies. |
Not used, on purpose
- No analytics or usage tracking in the app or (by default) on the website
- No crash reporting or error tracking services
- No advertising networks, pixels or data brokers
- No fonts, scripts or images loaded from other companies' servers: the app's fonts are bundled, and every window's content security policy allows only its own files
- No update service: the app doesn't check for updates by itself
- No customer accounts or cloud sync for the activity log
- No email sending service: the Team service sends no email today (a manager's forgotten password is reset by hand)
Involved, but not receiving data from the app
- The operating system. On a Mac the key that unlocks saved secrets is in the Keychain ("Astrolinks Safe Storage"); on Windows it is protected with DPAPI and kept in the app's own folder. Both stay on the computer.
- Dictation. On a Mac, the mic button starts Apple's Dictation, which may process audio under Apple's terms. The app never receives audio.
- The person's web browser. Links open there. On a Mac, the app asks supported browsers for the front tab's address through Apple Events, on the computer. On Windows, the app's own small helper reads the address bar of Chrome, Edge, Brave and Firefox through Windows' accessibility interface, on the computer; it makes no connections.
- Apple and Microsoft download checks. macOS may check a download's notarization with Apple, and Windows SmartScreen or the Microsoft Store may check an installer with Microsoft. These are the operating system's own connections.