Privacy policy
This Privacy Policy explains how Alusia (“we”) handles personal data when you visit alusia.net, create an account, or use the Alusia service. We design for data minimization: we collect what the Service needs to work, store customer documents in the EU, never use them to train models, and keep everything non-essential switched off until you opt in.
1. Two roles: our site and your documents
For data about visitors and account holders (registration details, billing records, product telemetry) we act as the data controller. For the documents your organization uploads and the questions it asks over them (“Customer Content”), the organization is the controller and we process the data only on its instructions as a processor under our Data Processing Agreement. If you are an employee using an Alusia workspace, your organization decides what is uploaded and who can access it.
2. Data we collect as controller
Account data: name, work email, password hash (or your Google sign-in identity), organization membership and role. Operational data: audit events (who did what and when, per organization), usage counters against plan quotas, and support correspondence. Contact-form leads: the details you submit on the contact page. Technical data: server logs with request identifiers and, for rate-limiting on the contact form, a salted daily hash of your IP address - the raw address is not stored and hashes are deleted within 48 hours.
3. Customer documents
Uploaded documents, their extracted text, search indexes, embeddings, conversations, and citations are stored in a private, access-controlled environment in Frankfurt, Germany (EU), isolated per organization and additionally restricted by collection-level permissions. We access Customer Content only to provide the Service, to prevent abuse, or as instructed by the customer, and never to train machine-learning models.
4. AI processing
To answer questions, the relevant document passages and the question are sent to OpenAI’s API, acting as a subprocessor. Under OpenAI’s API terms this data is not used to train OpenAI’s models; it may be retained briefly for abuse monitoring under OpenAI’s API data-usage policy and is then deleted. Answers are generated only from passages the asking user is authorized to see.
5. Legal bases
We process account and billing data to perform our contract with you; security logging, abuse prevention, and service improvement rest on our legitimate interests in operating a safe service; optional cookies and marketing rest on consent; and some records are kept to meet legal obligations such as accounting rules. Where we rely on legitimate interests you can object as described under your rights below.
6. Cookies and local storage
The Service uses strictly necessary storage to keep you signed in and to remember your cookie decision. Nothing else - no analytics, functional, or marketing storage - runs unless you opt in through the cookie banner, and your choice is stored for at most 12 months before we ask again. You can change your decision at any time via “Cookie settings” in the footer.
7. Sharing and subprocessors
We do not sell personal data. We share it only with the subprocessors needed to run the Service - currently Supabase (database, storage, and authentication hosting in Frankfurt, EU), Vercel (web hosting and content delivery), OpenAI (AI answer and embedding generation), and Resend (transactional email) - and with authorities where the law requires it. The current list, purposes, and locations are maintained on the Subprocessor List page.
8. International transfers
Customer Content is stored in the EU. Where a subprocessor processes limited data outside the EU/EEA (for example, US-based API infrastructure), the transfer is protected by the European Commission’s Standard Contractual Clauses and, where applicable, an adequacy decision such as the EU-US Data Privacy Framework.
9. Retention
Account data is kept while your account exists. When an organization is deleted - or a trial lapses without conversion - its content remains recoverable for a 30-day grace period and is then permanently removed from documents, indexes, conversations, and storage. Audit logs are retained per plan limits, contact-form leads for as long as the enquiry is active, and IP-derived rate-limit hashes for at most 48 hours.
10. Security
All traffic is encrypted in transit and data is encrypted at rest. Every organization’s data is isolated by database-level row security, enforced again at retrieval time before any AI processing; access within a workspace follows the roles and collection permissions its administrators configure. Administrative actions are recorded in an audit log, API endpoints are rate-limited, and secrets never reach the browser.
11. Your rights
Under the GDPR you can request access to, correction of, deletion of, or a portable copy of your personal data, restrict or object to certain processing, and withdraw consent at any time without affecting prior processing. Requests concerning data inside a customer workspace should go to that organization (the controller); we support them in responding. You can also lodge a complaint with your supervisory authority. Requests concerning data for which Alusia acts as controller (for example accounts and billing contacts) can be sent to privacy@alusia.net.
12. Changes and contact
We will update this policy as the Service evolves and give notice of material changes in the product or by email; the “last updated” date always reflects the current version. Requests and questions about data protection can be sent to privacy@alusia.net or through the contact page at alusia.net/contact.
Questions about these documents can be sent through the contact page while the dedicated legal address is being set up. alusia.net/en/contact