Cross Link — Privacy Policy
Effective date: September 14, 2026 · Previous version: July 25, 2026 Independent Technologies Limited — [email protected]
This policy covers the Cross Link applications: the desktop viewer/editor for Windows, the Cross Link mobile viewer for Android, and the project web viewer (PWA). It describes what data the apps handle, what little of it ever reaches us, and your choices.
The short version
- Using the apps never sends us your drawings. Cross Link projects live in storage your organization controls, and opening, viewing or editing a project talks directly to that storage — never through us.
- Sending us drawings to be scanned is the exception, and it is deliberate. Building a Cross Link project means you give us the source drawings. We receive and store those files to do the work. See Drawings you send us for scanning.
- No ads, no analytics, no trackers. The apps contain no advertising or analytics SDKs and do not profile usage.
- We only see what licensing needs: your work email address plus a device identity (device name and a derived device ID) used to bind your seat to your devices.
- Support data is opt-in and user-initiated. Diagnostic logging is off by default; nothing is sent unless you press send.
Data we collect
Sign-in and licensing
When you unlock the app with Microsoft sign-in or an activation code, the app sends your email address (and, for Microsoft sign-in, the signed identity token issued by Microsoft) to our licensing service to confirm your organization's seat entitlement. Because seats are bound to devices, activation also sends a device identity: the device name, the operating-system username on that device, a derived device identifier, the platform type, and — from the Windows app — a one-way fingerprint of the computer's Windows machine identifier (the identifier itself never leaves the computer), so that every Windows profile on one computer counts as one machine. We store the email address, seat assignment, device identity, activation records, and per-device last-seen timestamps needed to administer your organization's license, for the life of the seat. Authentication itself is performed by Microsoft; we never see or store your password.
Support requests (optional)
If you use About › Report a problem or idea… or send a diagnostics log, we receive what you chose to send: your description, optionally your email address for follow-up, and — if a diagnostic log exists on your device from a session where you enabled logging — a redacted technical log. The Android app also adds one line about the phone's screen (its size, scale and text size) so we can tell whether the app fitted it, and shows you that line before you send. Diagnostic logging is off by default. Logs never include your drawings or their contents. From version 1.7.77 of the Windows and Android apps (build 110 on Android), the apps remove the names of your drawings, files, folders, projects and storage sites from the log before it is sent. They keep only the host name of the storage service involved (for example yourcompany.sharepoint.com or youraccount.blob.core.windows.net), which can itself contain your organization's or storage account's name, and the domain of the account you signed in with. An error message returned by Microsoft sign-in, SharePoint or Azure is kept as received apart from addresses, paths and file names, so it may contain your email address, your organization's name or a name that service repeats back. Logs from earlier versions may include names. Credentials and access tokens are removed. Your description is sent as you wrote it. Support data is kept only as long as needed to resolve the issue.
Update checks
The desktop app — and the Android app when installed outside Google Play — checks for signed application updates by fetching version metadata. No personal data is included in update checks. On Google Play, app updates are delivered by Google Play itself.
Drawing submissions (Windows desktop, Admin seats only)
If an Admin uses Submit Drawings for Scanning, we receive the drawing files plus one record of the submission. That record is set out field by field under Drawings you send us for scanning below — including the contact details and the pack's own descriptive fields, the application version, the facility it is filed under and the Admin seat that authorised the upload. The list there is generated from the columns of the database table itself, so it is the whole of the record rather than a summary of one, and this page deliberately keeps no second, shorter copy of it here. This is the one path by which drawing content reaches us, it is never automatic, and it is not available in the Android app or the web viewer.
Nothing else
The apps collect no location data, no contacts, no device identifiers for advertising, and no usage analytics. The apps use the camera for two things. Scanning a QR code to open a project (on a phone, or on a Windows computer that has a camera): the image is processed on your device and is never stored or transmitted. Take a photo, in the Android app's PDF editor: the photo is shrunk and stored inside the PDF you are marking up — it goes wherever you save or share that PDF — with its location, camera and time details left out, and the full-size copy the camera saved is deleted once the app has read it. While the editor has unsaved changes it also keeps a copy of your markups, photos included, in its own crash-recovery file on the phone, and that copy stays there until a later editing session replaces it. Photos are never sent to us. If you deny camera permission on a phone you can still open projects by other means, and choose a picture instead of taking one — only QR-code scanning and Take a photo are affected.
Your projects stay in your storage
Cross Link is client-hosted by design. Project packages are stored in your organization's own SharePoint, Azure storage, or network drives, governed by your organization's permissions and policies. When an app opens a project, it talks directly to your organization's storage — that traffic never passes through Independent Technologies.
Packages may additionally be encrypted at rest with a company key (AES-256). Company keys are never transmitted to us, and neither is the recovery phrase that locking a package shows the person who locks it (the twelve words that open the package if its company key is lost): we hold neither the company key nor the recovery phrase. Locked packages are decrypted entirely on your device.
Drawings you send us for scanning
A Cross Link project is produced by our scanning service, which means you send us the source drawings. This is a deliberate, admin-initiated action — the Submit Drawings for Scanning feature in the Windows desktop app, available only to holders of an Admin seat. The Android app cannot submit drawings at all, and neither can the web viewer.
When a drawing pack is submitted, we receive and store on infrastructure we control (Cloudflare):
- the drawing files themselves; and
- one record of the submission, holding: the queue number, the status of the job, the company name the pack is filed under, as that name stood when the pack was submitted, the project name, the submitting person's name, the contact email address for the job, the contact telephone number, where one is given, the free-text notes on the submission, the version of the application that submitted the pack, the list of file names and sizes that were in the pack, with each file's pixel dimensions and the category it was filed under, the company name exactly as typed into the submission form, which is recorded on every submission whether or not it matches the seat's company, which of the customer's facilities the pack was submitted under, where one is assigned, the email address of the authenticating seat — the Admin seat the submission was actually made from, which may not be the contact above, the retention term agreed for the pack, where a term has been agreed, a record of the finished deliverable that was handed back — its file name, size, checksum and the time it was released, the identifier the submitting project carries, so a delivered package can be matched back to the project it came from, the purchase-order number, where one is given on the submission, the time the finished deliverable was first downloaded, the time the download was confirmed complete and verified on your device, which is when the retention period starts, and the times the pack was created, queued, closed out and last updated.
That record is the whole of it. It is generated from the columns of the table it is stored in, so it is the complete list rather than a summary of one.
Three entries deserve a note. Pixel dimensions are recorded so we can flag a scan that is too low resolution to read before it reaches the scanning team. The email address of the Admin seat that authenticated the submission is recorded separately from the contact email above, because the person who submits a pack may legitimately be someone other than the contact for the job. The company name as typed is recorded on every submission, not only on the ones where it differs from the company that owns the authenticating seat: the pack is always filed under the seat's company, and the typed value is kept verbatim so that a division rename can be told apart from work queued in another company's name.
Scanning runs on offline models on our own workstations. Your drawings are never sent to a third-party or cloud AI service.
What you get back is a reading of your drawings, not a replacement for them. Data accuracy — read this. Processed data is generated by automated, AI-assisted recognition and is reviewed by a person before delivery. It can still contain errors, omissions, or misidentifications, and it is provided for reference and navigation convenience only. It is not a substitute for the original engineering documents or for review by qualified personnel: verify against the original documents before any operational, safety-related, regulatory, or compliance decision. We report what each drawing says; we do not decide which drawing is right.
How long we keep the files. Submitted drawing files are retained until the pack has been scanned and the finished project has been accepted, or sooner on your written request. Closing out the job deletes those files from our storage. You do not have to do anything to accept a delivery. Where you have a signed services agreement, acceptance is as that agreement defines it. Under the current form that is a 30-day review period after each delivery, in which you can ask at no charge for correction or re-scan of ANY drawing in the package, so that you can satisfy yourself the processed data is right — you do not have to show that anything is wrong. If you ask for nothing in that window the package is deemed accepted, and corrections requested after it are billed at the per-drawing revision rate. A revision re-scan, or drawings added to an existing project, is itself a delivery and starts its own review period. There is no button to press. Two backstops apply automatically so that an unfinished job cannot hold drawings indefinitely. They apply to the transfer shelf — the copy of your files sitting on our side waiting to be scanned or collected — and to nothing else. A delivered project that is never accepted has its source files deleted 90 days after your download completes and is verified on your device — or 90 days after the pack is downloaded where that confirmation never reaches us, or 90 days after delivery for a pack that is never downloaded — and an upload that is interrupted and never completed is discarded after 7 days. A scheduled job applies both once a day, so a file is deleted on the first daily run after its window ends rather than at the instant it ends. What this does not touch: the copy you downloaded is yours, the record of the job is kept with no end date, and nothing we host for you is on a timer of any kind.
The submission record outlives the drawings. Closing out a job deletes the drawing files but not the record of the job. Every entry in the list above is kept, with no end date — closing out a job clears none of them, and nothing else deletes them on a clock. We keep it so a customer who loses their originals can be told exactly what to re-send, and so we can identify past work. It is a business record, not drawing content — the drawings themselves are gone. You can ask us to erase the record as well, and we will.
Using drawings to improve recognition
Our tag-recognition models are trained on drawings that have been through the scanning service.
Retention for model improvement is opt-in: no drawing is retained for model improvement unless you authorize it for your project, which matches Section 7.3(d) of the services agreement. Declining does not affect the quality of your own project, though we may decline work where retention is not permitted.
Two points are worth stating plainly rather than burying:
- What we keep for model improvement is a redacted copy, never your original. Before any drawing enters the training set, a fixed band across the bottom 15% of the sheet and a 2% strip along all four edges are blanked out of the image. On a standard landscape P&ID that band is where the title block, the revision table, the company logo and the border drawing number sit. It is a band, not a detector — nothing outside it is removed, so an identifying region lying outside it, such as a notes block placed high on the sheet, is not removed by the automated step — and a sheet that is not a standard landscape sheet is not retained at all. Nothing outside that band is removed — there is no second, manual pass and no recognition-based scrubbing of title blocks, company names or logos, and we make no commitment to re-scrub material already retained. Your original drawing files are separate, and are deleted when the job is closed out or on your written request.
- It is never sold, and it does not leave our systems. Retained material is used for one purpose — training and evaluating the models that read your drawings — on vendor-controlled workstations, with no third-party or cloud AI service involved. It is never published, distributed, sold, or provided to any third party.
- Tag text cannot be removed, because recognizing tag text is exactly what the model is being taught to do. We therefore describe retained material only as having direct identifiers removed. We do not call it anonymized or anonymous, because it is neither — a retained copy can still contain your equipment and line numbers.
You may request deletion of your project's retained training material at any time by emailing us.
Sharing
We do not sell, rent, or trade personal data — ever. The limited data above is processed by the sub-processors we run on:
- Cloudflare (USA) — the licensing and update service, and the drawing-submission queue, which holds submitted pack files as ciphertext it cannot decrypt plus the pack metadata in clear
- Microsoft Entra ID (your own Microsoft tenant, under your organization's existing Microsoft agreements) — sign-in, where your organization uses it
- Microsoft Azure Key Vault (vendor subscription) — custody of the private key that unwraps submitted packs; Independent Technologies also holds a backup copy of that key, used when the vault cannot be reached or no one is signed in to it
That list is maintained in full, with a 30-day change-notice commitment, in Sub-processors — see The documents this refers to below. We disclose data only if required by law.
Security
All traffic between the apps and our services uses HTTPS. Application updates are cryptographically signed and verified before install. Optional package-at-rest encryption uses AES-256-GCM. Licensing records are stored on Cloudflare's infrastructure with access limited to Independent Technologies.
Retention and deletion
Licensing records are kept for the life of your organization's license. Support submissions are deleted once resolved.
Submitted drawing files are kept until the pack is scanned and accepted, or until you ask for them in writing. Two backstops apply automatically so that an unfinished job cannot hold drawings indefinitely. They apply to the transfer shelf — the copy of your files sitting on our side waiting to be scanned or collected — and to nothing else. A delivered project that is never accepted has its source files deleted 90 days after your download completes and is verified on your device — or 90 days after the pack is downloaded where that confirmation never reaches us, or 90 days after delivery for a pack that is never downloaded — and an upload that is interrupted and never completed is discarded after 7 days. A scheduled job applies both once a day, so a file is deleted on the first daily run after its window ends rather than at the instant it ends. What this does not touch: the copy you downloaded is yours, the record of the job is kept with no end date, and nothing we host for you is on a timer of any kind. The submission record — the queue number, the company and project names, the submitting person's name, email address and telephone number, the notes, the list of file names and sizes, and 15 further fields, listed in full under "Drawings you send us for scanning" above — is kept after the drawings are deleted, with no end date, as the record of work performed. Retained training material is covered above and can be deleted on request.
Nothing you keep with us is on a clock. Where we host a deployment for you, your packages and project data stay until you tell us otherwise: no automatic process and no time limit ever deletes them, and there is no scheduled sweep on that side at all. The only deletions that happen are ones someone asks for — you ask us in writing, or the hosting arrangement ends, in which case we hand you a current copy and delete ours within thirty days as the agreement provides. The 90-day and 7-day windows described above are about the transfer shelf: the copy of a drawing set sitting on our side waiting to be scanned or collected. They have never applied to anything else.
Two things on your own devices depend on reaching us now and then. A device that has not reached our licensing service for 30 days falls back to the free viewer: paid Editor and Admin features stop until it connects again. Nothing is deleted, nothing is changed on disk, and one successful connection restores it. Separately, a device that opens a company-key-locked package remembers that key so nobody retypes it, and that memory is good for 7 weeks from the last time the device reached us — every check-in renews it, so a device in regular use never lapses, and a device that has never reached us holds no key at all. Past 7 weeks the stored key stops opening the package and the app asks for it again. It is a check-in rule, not a countdown from when you locked anything.
One rule on the device deletes anything, and it is not a timer on use. If our licensing service refuses a device outright — the seat has been revoked, its sign-in pool deleted, the credentials are dead — and goes on refusing it for the same 7 weeks, the Windows desktop app clears the working data it manages for you on that device: its cached copies of packages downloaded from your cloud storage, the files it staged for upload, the temporary files it wrote for emailing, the editor's crash-recovery copy, the recent-projects list, the saved links to your storage locations, the keys it had stored for opening locked packages, and (from 1.7.89) the history it keeps for those cloud copies — their baselines, backups and revisions — even for a project already taken off its list of projects on this computer. Files you saved yourself are never touched — your packages, exports, drawings and anything else you chose where to put stays exactly where you put it, and so do the baselines, backups and revisions the app keeps beside a project you opened from your own disk or network folder. Being offline never starts that clock, a licence simply running out never starts it, and a device sitting unused never starts it: only an answer that says this device should not hold the data, and any successful sign-in or heartbeat clears it. The 7 weeks are measured across launches, so a device that is rarely opened reaches the mark later than the calendar alone would say. It runs on the device and is best-effort by construction — a device that is never switched on again is beyond anyone's reach — and it is not a remote wipe. The Android app has no such mechanism and deletes nothing on a clock.
To request access to or deletion of your data, email [email protected] — deletion requests are honored within 30 days, except records we must keep for license administration your organization has contracted for.
Two companion annexes carry the detail behind this section, and are versioned so you can see when they change: Sub-processors (SUBPROCESSORS.md) lists in full every third party that processes data on our behalf, with a 30-day change-notice commitment; Data Retention and Deletion (DATA_RETENTION.md) sets out how long each category of data is kept and what deletes it. Both are published as Sub-processors & Data Retention in the Cross Link documentation set, and are available on request from the address in "Contact" below.
Children
Cross Link is a professional/industrial tool and is not directed at children under 13. We do not knowingly collect data from children.
Changes
If this policy changes materially, we will update this page and the effective date above. Continued use after a change means acceptance of the updated policy.
Contact
Independent Technologies Limited [email protected] https://independenttechnologies.io