← Back

Privacy Policy

Effective date: August 20, 2026

This Privacy Policy explains what information ALPHA collects, how it is used, who we share it with, and your rights regarding that information. We try to keep this plain-English. If anything is unclear, email us.

1. Information We Collect

When you create an account and use ALPHA, we collect:

  • Account information: your username, email address, and password (stored as a secure hash — we cannot read your password).
  • Financial records you enter: split calculations, budget entries, royalty logs, deductions, invoices, and collaborator contacts.
  • Bank data (only if you connect a bank account via Plaid): account name, account mask (last four digits), and transaction history. Your bank login credentials are entered directly into Plaid and never reach ALPHA; we store an encrypted access token that lets us pull transactions.
  • Subscription data (only if you subscribe to a paid plan): a customer identifier and subscription status from Stripe. We do not store your card details — those stay with Stripe.
  • Error diagnostics: when something breaks in the app, we may capture your user ID and email along with the technical error so we can identify and fix it.

We do not collect your real name, mailing address, or anything beyond what you explicitly enter or connect.

2. How We Use Your Information

Your data is used to operate ALPHA for you. Specifically:

  • To authenticate your account and keep your data private from other users.
  • To display your logged entries, calculations, history, and (if connected) imported bank transactions.
  • To categorize imported bank transactions automatically (see Section 3 — Anthropic).
  • To send you account-related emails: signup verification, password reset, and notifications you've opted in to (such as 1099 watch alerts).
  • To send an invoice, an invoice reminder, or a split payout notification to the client or collaborator you addressed it to, on your behalf.
  • To diagnose errors and improve reliability.

We do not sell your data, target ads at you, or use your financial entries for behavioral analytics.

3. How We Share Your Information

We do not sell or rent your data. We share it in two situations only: with the service providers necessary to operate ALPHA, as listed in Section 7 — Service Providers, and with a person you have told us to send something to. Each provider receives only the data they need for their specific function, and is bound by their own privacy obligations.

There are two places where you direct us to send something to someone else. When you send an invoice or an invoice reminder, we email it to the client address you entered, and that email carries your name, the invoice and what it is for. When you record paying a collaborator their share of a song, we email that collaborator to tell them, using the address you saved for them. Both go out because you asked for them, to the address you supplied, and nowhere else.

We may also disclose information if required by law (e.g., a valid subpoena), or to protect against fraud or abuse.

People who are not ALPHA users. If you enter a client or a collaborator, we hold what you typed about them — usually a name, an email address, and the invoice or payment record you attached them to. That came from you, not from them, and they may never have heard of us. We use it only to send the messages described above and to show you your own records. We do not market to them, sell their details, or add them to any mailing list. Anyone who wants to know what we hold about them, or would rather not be emailed again, can write to support@alphaos.studio.

When someone asks us to stop, we keep their email address on a do-not-send list. That means holding on to the one thing they asked us not to use — there is no other way to recognize the address and leave it alone. It is used for that and nothing else.

4. Data Storage and Security

Your data is stored on a secured server (Railway, US region). Passwords are hashed using industry-standard algorithms and are never stored in plain text. Bank access tokens are encrypted at rest. Two-factor authentication is available for your account.

We take reasonable steps to protect your information, though no system is completely immune to risk.

5. Your Rights

You have the right to:

  • Access all data associated with your account (visible within the app, and exportable via the Settings > Data tab).
  • Correct any information you have entered by editing or deleting entries in the app.
  • Delete your account and all associated data at any time from within the app or by emailing us.
  • Disconnect Plaid at any time from Settings > Data, which revokes our access token and stops further bank syncs.

6. Cookies and Tracking

ALPHA does not use advertising cookies or behavioral analytics. Your browser stores your authentication token to keep you logged in.

Our error monitoring service (Sentry) tags errors with your user ID and email so we can connect a bug report to your account. It does not perform page-view tracking or behavioral analytics.

7. Service Providers

We use the following third-party services to run ALPHA. Each receives only the data it needs to do its job.

  • Railway — backend hosting. Stores all of your account data, financial entries, and (if connected) encrypted Plaid tokens.
  • Vercel — frontend hosting. Serves the ALPHA app to your browser; does not store account data.
  • Plaid — bank connection (only if you connect a bank). Receives your bank login (entered directly into Plaid), and returns your account metadata and transactions to ALPHA.
  • Stripe — payment processing (only if you subscribe). Receives your payment information; ALPHA stores only your customer ID and subscription status.
  • Anthropic (Claude) — AI categorization for imported bank transactions. Receives the merchant name and amount of each transaction to suggest a category; does not receive your name, account number, or other identifying information.
  • Sentry — error monitoring. Receives your user ID and email along with technical error details when an error occurs in the app.
  • Resend — outbound email delivery. Receives the recipient address, subject, and body of every email ALPHA sends: both the mail we send you (verification, password reset, 1099 alerts) and the mail we send on your behalf to a client or collaborator (invoices, invoice reminders, split payout notifications).
  • ImprovMX — inbound email forwarding for our support@ address. If you email support, ImprovMX forwards your message to our team inbox.

If we add or change a service provider, we will update this section.

8. Children's Privacy

ALPHA is not intended for users under the age of 13. We do not knowingly collect information from children.

9. Changes to This Policy

We may update this Privacy Policy as the service evolves. We will update the effective date at the top of this page when changes are made.

10. Contact

For any privacy-related questions or to request deletion of your data, contact us at support@alphaos.studio.