
Privacy policy
This policy explains what data we collect on scalingos.co and diagnostico.scalingos.co, what we use it for, and how to ask us to delete it. It is written to be understood, not to cover ourselves.
Updated on
What data do we collect?
When you request access to the community on scalingos.co: your first name, last name, email address, WhatsApp number and the language you used the site in. Nothing else — it is four fields.
When you take the AI Diagnostic on diagnostico.scalingos.co: your answers to the questionnaire —including your company name and whatever you write in the open questions—, your email address and, if you provide them, your WhatsApp, city and country. Any public profiles you share are optional.
When you register for an event (an in-person workshop) or ask us to tell you about the next one: your name, email, WhatsApp, city and your answers to the registration form — your role in the company, how old it is, how many people work with you, approximate revenue and margin, the currency you are paid in, where your business stands and your last training.
In every case we also store your IP address and your browser identifier (user-agent). This is not for profiling: it is what lets us stop automated form submissions, which would otherwise burn through our email quota and fill the database with fake applications.
We do not ask for or store card details, bank accounts, identity documents or passwords.
What do we use this data for?
Three specific things: sending you what you asked for (your application confirmation, or your diagnostic), reviewing whether your profile meets the community access criteria, and contacting you by email or WhatsApp about that application.
For events, your answers are also used to select attendees: seats are limited and are assigned according to each company’s profile. Part of that selection is automatic and the rest is reviewed by a person on our team; either way, the decision reaches you by email.
We also use the data in aggregated, anonymous form to understand how the site is used. Aggregated and anonymous means without your name, your company name or your individual answers.
To write your diagnostic we also look up public information about your company online: its website, if you share it, and whatever a search for the company name returns. We only read public pages, we do not access anything private, and what we find is used to write your diagnostic and nothing else.
We do not sell your data. We do not pass it to advertisers. We do not use it to train third-party AI models.
Who do we share data with?
Only the providers that make the service work, and only with what each one needs: Supabase and Railway to host the database and the applications, Resend to send emails, DeepSeek to write your diagnostic from your answers, and Google Analytics for site usage metrics.
Each of those providers acts on our instructions and under their own data processing commitments. None of them is authorised to use your data for their own purposes.
Beyond that there is one case where your data reaches other people, and it only happens if you ask for it: a campaign’s business directory. The checkbox to join is at the end of Ecosistem — the second form, the one that returns your connections — and it is off by default. If you tick it, the other participants in that same campaign who also ticked it can see your name, company, sector, city, email and mobile number, and you can see theirs. If you do not tick it, you do not appear and you do not see anyone either. You can ask us to remove you at any time by writing to info@scalingos.co. Until August 2026 that checkbox lived in Scan, the first form; anyone who ticked it back then is not in the current directory, because consent does not carry over on its own.
How long do we keep your data?
Your access application and your diagnostic are kept as long as the relationship remains relevant, and in any case until you ask us to delete them.
The IP address and user-agent are erased after 90 days. They are not anonymised or archived: they are overwritten with an empty value in the same row, which is otherwise kept. An automated job does this every night inside the database, so it does not depend on anyone remembering.
Why 90 days and not longer? Because stopping automated submissions does not depend on storing your IP —a separate counter does that, and it empties within hours— so the only thing that justifies keeping it is being able to investigate abuse that already happened. And that investigation has a shelf life: if a pattern of abuse went unnoticed for three months, an IP from a year ago will not resolve it. Keeping data longer than you can justify is not prudence, it is accumulated risk.
What rights do you have over your data?
Wherever you live, we give you the same rights: to know what we hold about you, to request a copy, to correct anything wrong, to ask us to delete it, and to ask us to stop contacting you. We do not ask you to justify the request, and we do not treat you differently for making it: access to the community does not depend on you waiving any of this.
We respond within 45 days at most. To confirm the request is yours, it is enough that you write from the email address you registered with; we do not ask for identity documents for this. If you write on someone else’s behalf, we need them to confirm it from their own address.
scalingOS is a new, small company, and it does not currently meet the thresholds that make California’s consumer privacy law apply —USD 25 million in annual revenue, or the data of 100,000 California residents a year, or deriving half its revenue from selling data—. We give you those rights anyway, because it is the right thing to do and because thresholds get crossed by growing.
If there were ever unauthorised access to your personal data, we will tell you by email within 45 days of detecting it, with what we know and what we are doing about it.
How do I request access to my data or its deletion?
Write to info@scalingos.co from the same email address you registered with and tell us what you want: a copy of what we hold, a correction, or full deletion. You do not need to justify the request.
If you ask for deletion, we remove your record and your diagnostic answers. Emails we already sent you stay in your inbox — that part is not ours to control.
Do we use cookies?
The site works without session cookies: there are no accounts and no login. The only third-party technology that may write cookies is Google Analytics, which we use to measure how many people visit the site and where they come from.
If you would rather not be measured, any tracker blocker or your browser’s do-not-track mode is enough to remove that collection. Nothing on the site stops working if you do.
Do you collect data from minors?
No. The site is aimed at business owners with proven revenue, so the question should not arise, and we do not knowingly collect data from minors. If we learn that someone under 18 registered, we delete the record without waiting to be asked.
What if this policy changes?
When it changes substantially, the date on this page is updated. If a change widens what we do with data you already gave us —rather than just clarifying it— we will tell you by email before applying it.
For any question about this policy, write to info@scalingos.co.