Legal
Privacy policy
Effective September 15, 2026
This Privacy Policy explains how Schemalink collects, uses, and protects information when you use the Schemalink dashboard, hosted MCP service, website, and Payload plugin (collectively, the “Service”).
Information we collect
We collect account information such as your name, email address, authentication details, and profile image when you create or sign in to an account. We also collect the project names, Payload URLs, connection settings, permissions, OAuth client details, and audit events that you choose to configure.
When an AI client uses Schemalink, we record operational metadata such as the client, project, operation, outcome, and time of the request. The Payload plugin may return schema information, locale information, and content requested by an authorized operation so Schemalink can complete that request. Schemalink does not intentionally copy an entire Payload database into the Service.
How we use information
We use information to provide and secure the Service, authenticate users, route authorized requests to Payload, enforce project and operation permissions, maintain audit logs, troubleshoot failures, and communicate about the Service. We do not sell personal information.
Data location and control
Your Payload content, database, and media remain in the systems you connect. Schemalink acts as a control and request-routing layer. You are responsible for the data, users, and access rules in your Payload installation and database provider.
Sharing
We share information only with service providers needed to operate the Service, when required by law, or when necessary to protect the Service, users, or others. An AI client receives only the results of operations allowed by the OAuth grant and project permissions you approve.
Security and retention
We use reasonable administrative, technical, and organizational safeguards. No online service can guarantee absolute security. We retain account, connection, and audit information for as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements, unless a shorter period is required by law or agreed with you.
Your choices
You may update your account, disable or revoke AI connections, rotate project credentials, and delete projects where those controls are available. To request access, correction, or deletion of personal information, contact the Schemalink operator using the support address provided with your account or deployment.
Changes
We may update this policy as the Service changes. We will update the effective date when we do. Continued use after an update means you acknowledge the revised policy.
Contact
Questions about this policy should be sent to the Schemalink operator through the support contact associated with your account.