Privacy Policy
Last updated
Name the data controller (legal entity, registered address) and a contact for privacy requests. If a representative or DPO is required in your jurisdiction, name them here.
1. What this policy covers
The albirint web app and API, and the relationship to the Terms of Service.
2. What we collect
Split this three ways, because the categories carry different obligations:
- Account data — email address, password hash, plan and billing status, session and login timestamps.
- Data you connect — uploaded files and the credentials for connected sources, plus the artifacts analysis produces from them. Say where they are stored and that credentials are encrypted at rest.
- Usage data — queries run, tokens and cost consumed, errors, and request logs. Say what is retained and what is redacted.
3. Why we process it
Purpose and lawful basis per category: performing the contract, legitimate interest in security and abuse prevention, legal obligations for billing records, consent where it applies.
4. Sub-processors
The third parties that receive data and what each receives — the hosting provider, the managed database, object storage, the payment processor, the email sender, and the LLM provider. This last one is the disclosure users most need: prompts and data structure are sent to a model provider in order to plan and run an analysis. Be specific about what leaves and what does not.
5. Where data is stored, and transfers
Hosting region, and the transfer mechanism for anything that leaves it.
6. How long we keep it
Retention per category, what deleting a notebook or data source actually deletes, and what closing an account removes and when.
7. Security
Encryption in transit and at rest, credential vaulting, access controls, and the breach notification commitment.
8. Your rights
Access, correction, deletion, portability, objection and complaint — and how to exercise each, with the response window.
9. Cookies and local storage
The session cookie and the browser storage the app uses to keep you signed in and to remember interface preferences. State whether any analytics or tracking cookies are set.
10. Children
The minimum age, and what happens if an underage account is found.
11. Changes to this policy
How changes are announced and how much notice material ones get.
12. Contact
Privacy questions and requests: hello@albirint.com.