Skip to content

Legal

Privacy Policy

Last updated: August 1, 2026

The short version: accounts are optional. Without one, your ideas live only in your browser. If you make an account we store your email and sign-in details and sync your ideas to our database so you can reach them across devices. What you type is sent to Anthropic's API (our AI provider) to generate results, never to train AI models by default. Brand-image generation also uses Google's Gemini API. We use necessary sign-in storage, cookieless aggregate and funnel analytics, error monitoring, and an internal alert when someone signs up, contacts support, or buys so we can run the service.

1. What you give us to generate ideas

Alxoria is operated by ALX Ventures LLC ("we", "us"), the controller of the data described in this policy. The wizard asks about your skills, interests, budget, and available time. When you generate an idea or a dossier section, those inputs are sent to our server and forwarded to Anthropic's API (our AI provider) to produce the result. Your inputs are not used to train AI models.

If you are signed out, Alxoria does not save the submitted idea or result to an Alxoria account database. The result returns to your browser. If you are signed in, your ideas and dossiers are saved to your account so they follow you across devices. Standard Anthropic API inputs and outputs are deleted from Anthropic's backend within 30 days, subject to limited exceptions for legal obligations, usage-policy enforcement, or a different contractual setting. Anthropic does not use commercial API inputs or outputs to train models by default.

If you choose to generate a brand image, the brand name, description, visual direction, and palette are sent to Google's Gemini API. A candidate image and related business context are then sent to Anthropic for an automated quality check. The selected image is stored with your account in Supabase Storage. Do not submit confidential personal information that is unnecessary for the business task.

2. Accounts (optional)

You can use Alxoria without an account. If you create one, we store the details needed to operate it: your email address, a securely hashed password (if you choose one), or the identifier shared by Google or GitHub if you sign in with them, plus sign-in timestamps. This data lives in our database, hosted by Supabase in the United States.

Account and service emails (such as verification, password reset, requested results, and progress reminders you enable) are delivered through Resend, our email provider, which processes your email address for that purpose. We send occasional product updates only when you explicitly opt in, and every update includes a way to unsubscribe. We never sell your data.

If you buy a report or subscribe to a paid plan, payments are processed by Stripe. Your card details go to Stripe directly and never touch our servers. We store only the information needed to provide your purchase: your subscription plan, remaining report credits, Ask Alxoria access window, and Stripe's reference identifiers.

3. Where your ideas live

Without an account, generated ideas, dossiers, and your progress checkmarks are stored in your browser's local storage, on your device. Clearing your browser data deletes them permanently; we have no copy and cannot restore them.

With an account, your ideas sync to our database (hosted by Supabase) so they survive browser clears and follow you across devices. They are protected by row-level security. We do not review account content as a routine business practice or use it to train AI models. Limited authorized access may occur when you request support, when needed to investigate security or reliability problems, or when required by law. Support requests are stored so we can answer them.

4. Browser storage, cookies, and analytics

Alxoria uses browser storage for local-only ideas, progress, and interface preferences. Signed-in sessions use storage or cookies that are necessary for authentication and security. Stripe may use necessary cookies on its hosted checkout and billing pages under Stripe's policy.

We use Vercel Analytics for aggregate site usage. We also use PostHog for a small set of manually defined product-funnel events, such as starting validation or reaching checkout. These events pass through an Alxoria endpoint without tracking cookies or persistent analytics identifiers. Autocapture, session recording, pageview tracking, person profiles, and analytics GeoIP processing remain disabled, and we do not send idea text, email addresses, customer identifiers, or report slugs as event properties. Neither service is used for cross-site advertising. Alxoria does not use advertising cookies.

5. Rate limiting and background work

To keep the service available and prevent abuse, our servers count recent requests per IP address. These counters are stored in Upstash, a hosted cache, expire within an hour, and are used only for limiting, never for profiling or advertising.

Long-running report generation can use Upstash QStash to deliver signed background tasks. Those tasks contain the account and report identifiers needed to resume the work, while the report content remains in the Alxoria database.

6. Error monitoring and operational alerts

We use Sentry, a hosted error-monitoring service, to capture technical errors so we can fix them. Sentry receives error details and technical context (such as the page and browser), not the contents of your dossiers; it is configured for errors only, with no session recording.

When someone creates an account, submits the support form, asks us to email a result, or makes a purchase, our servers post a short internal notification to a private team channel (Slack) so a solo team can respond. That notification can include the email address involved and the fact of the event; it is not shared outside our team and never used for advertising.

If you ask us to email you a dossier or name-check results, or opt in to occasional updates, we store your email address (in our database, Supabase) to send what you requested and, with consent, those updates.

7. Third-party links

Recommended services (formation, banking, design, and similar tools) are independent companies. Following a link takes you to their site under their privacy policy. Some links may become referral links, in which case the partner may know you arrived from Alxoria. Nothing about your generated ideas is shared with them.

8. How long we keep data

Local-only ideas remain on your device until you clear the browser data. Account content remains until you delete the account or ask us to delete it. Short-lived rate-limit counters expire within an hour. Anthropic's standard commercial API retention is described above.

We keep operational, support, security, and billing records only as long as reasonably needed for the purpose collected, to resolve disputes, prevent abuse, or meet legal, tax, and accounting obligations. Deleting an Alxoria account removes active product content, but Stripe and legally required transaction records can remain under the relevant retention obligations and provider policies.

9. Security

We use encrypted connections, managed service providers, authentication controls, row-level database access rules, and multi-factor authentication options to reduce risk. No online system can guarantee absolute security. If you believe your account or data is at risk, contact hello@alxoria.com and change your password promptly.

10. Your choices and rights

From Account, you can update account details, export your product data, turn weekly progress email on or off, and delete your account. Account deletion cancels any subscription and permanently erases your ideas, dossiers, journal, Ask Alxoria history, and credits from the active product database. Signing out removes the active session from the device; clearing browser data removes local-only ideas.

You may also email hello@alxoria.com to request access, correction, export, or deletion of personal data. We may need to verify that you control the account before acting. Some information can be retained when required for security, fraud prevention, billing, tax, legal claims, or other legal obligations.

11. Children

Alxoria is not directed at children under 16 and we do not knowingly process their data.

12. Changes and contact

If our data practices change, this policy will be updated and the date below revised before the change takes effect. Questions: hello@alxoria.com.