Private beta -- real-time chain data is still being wired up.

Privacy Policy

Last updated: August 2026

This policy is adapted from a standard SaaS privacy-policy structure to describe what Chainlake actually collects and does today. It has not been reviewed by a lawyer. If you need this for compliance purposes, get it reviewed before relying on it.

Chainlake is an on-chain data analytics platform, run independently by a single developer. This policy covers both the marketing site (chainlake.io) and the console application (console.chainlake.io).

1. Information we collect

On the console (once you have an account), via our identity provider (Zitadel):

  • Name, email address, and authentication data (password hash, passkey/MFA registration -- we never see your raw password)
  • Organization and project membership, and the role/permission level assigned to you
  • Queries you run, agent sessions, dashboards and charts you create, and related usage metadata (timestamps, duration, which tables/connections were touched)

On the marketing site, only if you submit the "Request access" or Contact form:

  • Name, email, company (optional), and whatever you write in the message field
  • IP address and user agent, kept only to prevent spam submissions

We don't run ad-tracking or third-party analytics pixels on chainlake.io.

2. How we use it

  • To operate the product -- authenticate you, enforce permissions, run and store your queries/dashboards
  • To respond to access requests and support messages
  • To keep the service secure -- rate limiting, fraud/abuse prevention on the leads form
  • To understand product usage in aggregate, to prioritize what to build next

We do not sell personal information, and we do not use your data to train third-party models without your knowledge.

3. Who we share it with

Data is shared only with the infrastructure providers needed to run the service:

  • Zitadel (self-hosted) -- handles authentication, so your credentials never touch Chainlake's own database directly.
  • Cloudflare -- hosts the marketing site and fronts the console/gateway with a tunnel.
  • Our database provider -- stores console application data (queries, dashboards, organization/permission records, and marketing-site leads).
  • AI model providers -- when you use the AI Agent, your query text and relevant schema context are sent to the model provider powering that session, to generate the response.

We may also disclose information if legally required to, or in connection with a sale or transfer of the business.

4. Security

All traffic is encrypted in transit (HTTPS/TLS). Authentication supports passkeys (WebAuthn) and TOTP-based MFA, and organizations can require MFA for all members. Access to console data is scoped by an organization/project permission model, not a single shared account.

We don't claim a specific third-party security certification (e.g. SOC 2) -- none exists today. If that changes, this section will be updated to reflect it, not before.

5. Data retention

Account and application data is retained for as long as your account is active. Marketing-site leads are retained to follow up on your request and are deleted on request. If you delete your account, console application data is removed on a schedule described in-product at the time of deletion.

6. Your rights

You can ask to:

  • See what personal information we hold about you
  • Correct inaccurate information
  • Delete your account and associated data
  • Export your data

Email the address below to make any of these requests.

7. Contact

Questions about this policy: hello@chainlake.io