Privacy Policy

Last updated:
The short version: ALYGN analyses text you paste or import. That text is sent to the AI and kept in your private account — your decode history, plus excerpts and summaries of any conversation you import — so future analyses remember the relationship. It's visible only to you, you can delete it anytime, it's never sold or shared, and it's never used to train AI models.

1. Who We Are

ALYGN ("we", "our", "us") is a communication intelligence tool operated by Alice Pascoletti. You can reach us at privacy@alygn.me.

2. What Data We Collect

We collect the minimum required to provide the service:

3. What We Do NOT Collect

4. How We Use Your Data

5. Where Your Data Is Stored

All stored user data lives in Google Firebase Realtime Database, Europe West 1 (Belgium) region — storage stays in the EU. AI analysis is performed via the Google Gemini API (paid tier), whose processing infrastructure is Google's and may be located outside the EU for the duration of the request. Conversations you import — a chat export, a pasted email exchange, or an email you forward to your personal ALYGN import address — are processed the same way, only at your request, and stored only in your own space: your text is sent to Google only to generate the analysis, is not used to train or improve Google's models, and may be retained by Google only briefly for abuse monitoring under the Gemini API terms.

End-to-end encrypted decodes and imported-chat memory (signed-in accounts). If you save your profile with an account (Google or email), the full text and the full analysis of each decode — including the name of the person it is filed under and the text preview — and the memory of every conversation you import (the chat export or email text you chose to keep, the period summaries and the relationship scan derived from it, and its history of scans) and the relationships themselves (the name you give a relationship, its goal, and for each person their name, the other names you told us they go by, how you describe the relationship and every note you wrote about them) are encrypted on your device (AES-256-GCM) with a key that is created on your device and never sent to us. What reaches our database is the encrypted blob plus a few numbers in clear: for a decode, its id and date, the perception-gap value, the communication flags, the EQ delta, the intent type and the relationship it belongs to; for an imported chat, only the relationship it belongs to and the time of the last write; for a relationship, its id, its type (romance, work, family, friends, self), its EQ score and trend, how many decodes are filed under it and how many people it holds — a count, never a name. We store your decodes, your imported chats and your notes about people in a way that only you can read them back — not even us. A 12-word recovery code, shown to you once, can recreate the key on a new phone; if you lose both the device and the code, the full texts and the notes cannot be recovered by anyone, and the shape of your profile and relationships remains.

Without an account, nothing about other people leaves your phone. If you have not saved your profile with an account, this app has no key to encrypt with, so it does not send anything that could identify or describe another person. The names of the people you write about, the other names they go by, how you describe the relationship, your notes about them and the full text and analysis of every decode stay in your browser's storage on that device. What is synced under your anonymous id is the shape of the history only: for each decode its id and date, the perception-gap value, the flags, the EQ delta, the intent type and which relationship it belongs to; for each relationship its id, type, EQ score, trend, the number of decodes and the number of people. That is what a restore link can bring back, and it is all we hold. Data written in clear by an earlier version of the app is overwritten with this reduced form, and the fields that are no longer synced are deleted from our database, the first time your device loads the app after this change. An imported chat saved before this encryption existed is moved into the encrypted form the first time your signed-in device opens it, and its clear copy is deleted.

What still sits in clear, and for how long. Two short queues are not covered by the sentence above: an email you forward (or import from Gmail) waits in your private space in clear until your device picks it up and adds it to a person's memory, and the payload of a compare-decode link you choose to share is kept in clear for 30 days, because sharing it is the point. Ids, dates and numbers are always in clear. We say this plainly so the encrypted sentence covers exactly what it covers.

5a. Gmail (optional connection)

If you choose to connect your Gmail account ("Connect Gmail" on a person's page), ALYGN asks Google for read-only access to your mailbox (gmail.readonly) and imports only the messages exchanged with the people you pick, for the period you choose (30, 90 or 365 days). Nothing else in your mailbox is read, listed, or kept. The imported text lands in your private space exactly like an email you forward to your ALYGN import address (see §5) — it is queued under your own account until you add it to that person's memory, then processed and stored only for you. The Google refresh token that allows the import is kept server-side, is never shown to you or to anyone else, and is used for nothing but fetching those messages when you ask.

ALYGN's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice: Gmail data is used only to provide this user-facing feature; it is never used for advertising, never sold, never used to train or improve AI models (general or ALYGN's own), and no human at ALYGN reads it, except with your explicit consent for support, where required by law, or for security investigations.

To disconnect: tap "Disconnect" in the same card — ALYGN revokes the token at Google and deletes the connection record immediately; anything you already imported stays in your space until you delete it, like any other imported conversation. You can also remove ALYGN's access at any time from your Google Account → Security → Third-party apps & services. During the initial wave the Google project is in "testing" mode: only invited test accounts can connect, and Google shows an "app not verified" screen before consent.

In italiano. Se colleghi Gmail, ALYGN chiede a Google un accesso in sola lettura e importa solo le email scambiate con le persone che scegli tu, per il periodo che indichi. Il resto della casella non viene letto né conservato. Il testo importato finisce nel tuo spazio privato, come un'email inoltrata al tuo indirizzo ALYGN. L'uso e il trasferimento ad altre app delle informazioni ricevute dalle API di Google rispettano la Google API Services User Data Policy, inclusi i requisiti di Uso Limitato: i dati di Gmail servono solo a questa funzione, mai per pubblicità, mai per addestrare modelli, e nessuna persona di ALYGN li legge. Per scollegare: "Scollega" nella stessa scheda (il token viene revocato subito) oppure dalla pagina delle autorizzazioni del tuo Account Google.

6. Data Retention

Your data is retained as long as your account is active. You can delete your account and all associated data at any time from the app's Settings screen. Deletion is permanent and takes effect within 24 hours.

7. Your Rights (GDPR / UK GDPR)

If you are in the EU or UK, you have the right to:

8. Cookies and Local Storage

ALYGN uses browser localStorage (not cookies) to store your preferences and UI state (dismissed banners, language) and a local copy of your decodes and relationship data. Your preferences and UI state stay on your device. With an account, your decodes, your notes about people and your imported-chat analyses are also synced to your own private account in our Firebase database (EU region — see §9) so they are available across your devices — encrypted on your device before they are sent (see §5); they are private to you, and we never sell or share them. Without an account only the numbers described in §5 are synced, and nothing about another person leaves your phone. Message text you choose to decode is sent to our AI provider (Google Gemini API) solely to produce your analysis — it is not used to train models, and the provider keeps only a brief abuse-monitoring retention under its terms (see §9). ALYGN never connects to your messaging apps or reads anything in the background — only what you paste or import. Firebase Authentication uses a session token stored in IndexedDB.

9. Third-Party Services

What the encryption does and does not hide. For signed-in accounts the decode texts and analyses, the memory of the conversations you import, and the names of and notes about the people in your relationships reach Firebase only as encrypted blobs. The size of each blob still reveals roughly how long the message, its analysis, the imported conversation or a relationship's notes are (to within a few bytes), and the database also sees when a blob is written, which relationship it belongs to, how many there are, and how many people each relationship holds. The encryption key lives on your device (IndexedDB, with a localStorage fallback) and is readable by anyone who holds your unlocked phone, like everything else in the app; it does not leave your device, so we do not hold it. When you ask for an analysis, the text is sent in clear over an encrypted connection to our proxy and on to Google Gemini for the duration of that request only; it is not kept there beyond Google's brief abuse-monitoring retention and is not used to train models.

10. Children

ALYGN is not directed at children under 16. We do not knowingly collect data from children.

11. Changes to This Policy

We will update this page if our practices change and notify you via the app for material changes.

12. Contact

Questions? Email privacy@alygn.me.

← Back to ALYGN Privacy Policy Terms of Service Security & Data Architecture