Privacy
Policy
This Privacy Policy explains how Alloyqa collects, uses, stores, and shares information when you use Alloyqa.
Alloyqa is available on the web and as a macOS app for software work. It lets you connect GitHub repositories, create and collaborate on Projects, Ideas, Tasks, reviews, and feedback, and run Tasks through the Alloyqa agent and Cloud execution. The Service is available at alloyqa.com ("Service"). This policy applies when you access or use the Service.
Information We Collect
We collect information in three ways:
A — Directly from You
- Account and profile information — your email address, display name, avatar where provided, and account session information used to operate the Service. Sign-in is provided through Supabase Auth.
- Workspace and collaboration information — workspace names, memberships, roles, invitations, and collaboration activity.
- Product content — Projects, Ideas, Tasks, feedback, reviews, comments, attachments, workflow status, and related context that you create or receive in Alloyqa.
- Repository and pull-request information — connected repository names and settings, branches, commits, pull requests, diffs, reviews, and status information used to work with GitHub repositories.
- Execution information — Cloud execution status, Task status, attempts, checks, command output or summaries, errors, changed-file information, pull-request details, and results used to show work history and support review.
- Billing information — workspace plan and subscription status, Cloud balance and purchase records, and Alloyqa agent usage records. Paddle processes checkout and payment transactions.
- GitHub credentials — where GitHub access requires Alloyqa to retain a credential, the application stores it separately from normal product records.
B — Automatically
- Service and diagnostic data — feature use, Task and workflow activity, request timing, and error information used to operate and troubleshoot the Service.
- Session data — authentication session information managed by Supabase Auth.
C — From Third-Party Integrations
When you connect GitHub or use the Alloyqa agent and Cloud execution, Alloyqa processes the information needed for that action:
- GitHub — repository metadata, branches, commits, pull requests, diffs, comments, reviews, and status checks needed to work with selected repositories and return or merge changes according to workspace policy.
- Alloyqa agent and Cloud execution — Alloyqa's managed Cloud worker receives the Task instructions, feedback, and selected repository workspaces needed to perform Cloud execution. Google Cloud provides managed worker infrastructure. Depending on the execution path, selected Task content may be processed by OpenAI services or Google Cloud Vertex AI Gemini, as needed.
How We Use Your Information
We use the information we collect to:
- Explore connected repositories to understand codebase architecture, configuration, and patterns.
- Help you investigate reported issues and verify expected behaviour.
- Generate and modify code to implement requested changes and bug fixes.
- Run and record checks and execution results from work performed through the Alloyqa agent and Cloud execution.
- Create branches, commits, and pull requests in connected GitHub repositories.
- Produce Task history, review context, and results for you and your workspace.
- Authenticate your identity and maintain your session securely.
- Monitor Service performance, diagnose errors, and prevent abuse.
- Communicate with you about your account or material changes to this policy.
Data Storage & Retention
Alloyqa keeps workspace, Task, review, repository, execution-result, and billing records in order to operate the Service and show workspace history. Task attachments, feedback screenshots, and supported execution evidence may be stored with the related product record.
Temporary workspaces used for Alloyqa agent and Cloud execution are cleaned up after execution. Alloyqa does not currently publish a fixed retention period for temporary execution data.
Workspace owners can delete a workspace through the product. For account or personal-data deletion requests, contact privacy@alloyqa.com.
Third-Party Services
The Service integrates with and relies on the following third-party providers:
- Supabase — database, authentication, and file storage used by the Service.
- Netlify — public application and serverless API hosting.
- GitHub — repository, version-control, and pull-request operations for connected repositories.
- Google Cloud — managed worker infrastructure and Vertex AI Gemini processing used as needed for supported Alloyqa agent and Cloud execution paths.
- OpenAI — AI processing used as needed for supported Alloyqa execution paths.
- Paddle — Team Workspace subscription billing, Cloud balance purchases, and payment processing.
- PostHog — product analytics.
- Resend — transactional email, including workspace invitations.
Each provider processes information under its own terms and privacy notice. The information sent depends on the feature, GitHub connection, or Cloud execution you use.
Data Sharing
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- With GitHub, at your direction, to read selected repository information and to create branches, commits, pull requests, reviews, and other authorized repository actions.
- With Supabase, Netlify, Paddle, PostHog, Resend, and other providers that operate the Service, as needed for the service they provide.
- With Google Cloud as needed to operate managed worker infrastructure and Vertex AI Gemini processing for supported Alloyqa agent and Cloud execution paths.
- With OpenAI as needed for supported AI processing paths. The provider used depends on the execution path; not every Task is processed by every provider.
- With service providers who help us operate the platform, under confidentiality obligations.
- If required by law, regulation, or valid legal process, or to protect the rights and safety of Alloyqa and its users.
- In connection with a merger, acquisition, or sale of assets — we will notify you before your data is transferred.
Integration Credentials
Alloyqa uses GitHub App installation credentials for repository operations. A Cloud Task requests access only for its selected repositories before GitHub work is performed.
Where Alloyqa stores an integration secret, the application encrypts it before application storage.
You can disconnect GitHub from Alloyqa. You may also revoke access through GitHub's own settings.
Your Rights & Choices
Depending on your jurisdiction and applicable law, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request that we correct inaccurate or incomplete data.
- Deletion — request that we delete your account and associated data.
- Portability — request your saved data in a machine-readable format.
- Objection — object to certain processing activities.
These rights may vary depending on your location and applicable law. To make a privacy request, contact us at privacy@alloyqa.com.
Children's Privacy
The Service is not designed for use by children under 16. If you believe a child has provided personal information through the Service, contact us at privacy@alloyqa.com.
Security
For a current description of Alloyqa's implemented controls for Cloud execution, credentials, GitHub access, and logging, see Security at Alloyqa.
No internet service can guarantee complete security. If you suspect unauthorized GitHub access, disconnect GitHub in Alloyqa and revoke access through GitHub's own settings.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a revised effective date. Your continued use of the Service after changes are posted constitutes acceptance. For significant changes, we will make reasonable efforts to notify you by email.
Contact Us
For privacy questions or requests, contact us at privacy@alloyqa.com.