This Privacy Policy explains how Lin Youheng (sole proprietor) (“Alter,” “we,” “us”) collects, uses, and shares information when you use the Alter mobile application and related services (the “Service”). It also explains your rights and how to exercise them.
Read this alongside our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.
This document is written to align with findings from our 2026-04-18 Apple App Review research regarding Apple App Store Review Guideline 5.1.2(i) (third-party AI data sharing), California SB 243, New York S3008C, and related statutes.
1. Data controller
The controller of your personal data is Lin Youheng (sole proprietor), contactable at:
- Email: [email protected]
For privacy matters specifically, you may write “Privacy Request” in the subject line. We do not yet have a formal Data Protection Officer; where a DPO is legally required, we will appoint one before launching in that market.
2. What we collect
We collect the categories of data below. Some are required to use the Service; others you provide voluntarily.
2.1 Account data
- Email address — used for login, verification, and service notices.
- Handle, nickname / display name, and bio — used for your profile and shown in relevant social/conversation surfaces.
- Full date of birth — submitted at registration, stored on the citizen record, and used to enforce the 18+ age gate. The current app does not integrate an Apple age-range API.
- Authentication and session data — password hash, access/refresh-token state, verification/reset records, and related security state.
- Push token — stored when you enable push delivery and sent through Expo/APNs with notification content as disclosed in Section 4.1.
- IP and request context — may appear in server/security logs for rate limiting, fraud, and abuse prevention; a verified fixed retention limit is not stated in this code-only review.
2.2 Content you create
- Messages you send and receive, including in direct messages, group chats, and rooms.
- Profile content — handle, display name, bio, and avatar URL/seed. The current app does not provide a general profile-photo or interest-list upload field.
- Alter-instance personality data — answers to the personality questionnaire, plus the personality traits we derive from your conversations, for the purpose of running your own Alter instance.
2.3 Interaction metadata
- Who talked to whom, and when — friendships/relationship state, conversation and room membership, message timestamps, read state, and supported reaction/feedback events. The current app does not claim a time-spent-in-room metric.
- Moderation events — reports you submit, reports submitted about you, enforcement actions applied to your account.
2.4 Inferred data
- Personality, memory, summary, and relationship signals extracted from conversations to run Alter instances/resident replies and maintain conversation or relationship context. The current Service does not use these to personalize a user-facing feed.
- Moderation and security signals — report, ban, blocklist, rate-limit, and related state used to detect or respond to spam, fraud, scraping, underage use, and similar abuse.
2.5 Technical data
- Crash and error events via Sentry. These may include stack traces, device, OS, request context, identifiers, or content fragments. The server removes fields whose keys look like credentials or secrets, but that is not a general message-content or personal-data scrubber; the mobile Sentry client currently has no structural before-send scrubber. See Section 11.
- API and server logs — endpoint, timestamp, response code, user ID, and, on some current paths, raw user or AI content snippets and error context. Credential/header/email-key redaction does not reliably remove arbitrary content embedded in strings.
- In-app-purchase receipts via Apple and subscription-state events via RevenueCat.
We do not collect precise location data. We do not deploy web cookies or ad trackers in our native app. We do not store your LLM API keys — you never provide them, and the Service uses platform-owned keys for all AI routing.
2.6 User-initiated diagnostic log upload
You may tap “Report a problem log” in Alter Settings to actively upload debugging information so we can diagnose an issue you encountered.
Trigger condition: Upload requires explicit tap + consent-checkbox acknowledgement + tap “Submit” by you. Never uploaded automatically or in the background.
What we collect:
- App build info (EAS update group ID / runtime version / channel / built at)
- Device info (OS + version + device model; no advertising identifier / IDFA)
- Current app screen path + last 5 navigation pathnames
- Last 100 console log entries (production: warn / error level only; no debug / info)
- Last 10 network request failure records (URL + status code + error message; no request body / response body)
- Optional free-text description you typed (≤500 chars)
- Linked Sentry event ID (if available, to enable cross-system forensics)
Structural limits and current risk:
- The collector does not intentionally attach request bodies, response bodies, images, videos, audio, IDFA, or other advertising identifiers.
- Console arguments, error objects, network-error URLs/messages, and your optional description are converted to strings without a structural personal-data or secret sanitizer. They may therefore incidentally contain identifiers, message fragments, passwords, tokens, API keys, or other sensitive text if those values appeared in an error or console entry.
- Review your optional description and do not include secrets or sensitive personal information. We do not promise that the automatically captured diagnostic strings are free of such data.
Use: solely to diagnose the issue you raised.
Retention: automatically deleted after 30 days (see Section 5).
Sub-processors: the diagnostic bundle is stored in Alter’s primary database. If it contains a linked Sentry event ID, that ID points to a separate event already processed by Sentry; the bundle itself is not forwarded to Sentry as part of this upload. See Section 4.1 for Sentry’s independent crash/error processing.
Your rights: you may request deletion at any time (see Section 6 for your rights).
3. How we use your data
We use your data for the purposes below.
3.1 Running the Service
- Delivering your messages to the intended recipient (human or AI).
- Generating AI responses and feeding them through the human filter pipeline before delivery.
- Running your Alter instance, including updating it from your new content over time.
- Enabling the current profile, room, contact, conversation, read-receipt, and reaction features.
3.2 Moderation and safety
- Running automated word/blocklist and model-based checks on relevant message and AI-output paths; these checks may allow, repair, drop, or block output and may miss harmful content.
- Creating operator-review records for submitted reports and hard-ban appeals. Not every automated message-level decision is escalated to a person.
- Detecting spam, fraud, scraping, underage use, impersonation, and similar abuse.
- Enforcing the Terms of Service through current 24-hour/7-day message mutes, 72-hour shadow bans, hard bans, and report handling.
3.3 Billing
- Processing Alter+ and private-room purchases via Apple In-App Purchase.
- Reconciling subscription state via RevenueCat.
- Responding to refund, chargeback, and receipt-validation workflows.
3.4 Product improvement
- Aggregate analytics — we look at totals, distributions, and trends across the user base, not at named individuals, to improve the Service.
- Quality evaluation of AI outputs on sampled content, traces, decision reports, and operator reports. Some paths de-identify data, but others retain citizen/resident identifiers, source utterances, raw/final replies, or content previews; anonymization is not universal and authorized operators may see identifiable snippets.
3.5 Legal and compliance
- Responding to lawful requests (subpoenas, court orders, regulator requests).
- Maintaining moderation records for appeal windows.
- Meeting tax, accounting, and corporate-governance obligations.
4. How we share your data — and with whom
We share data only with the parties below, for the purposes below. This list constitutes the third-party AI data-sharing disclosure required by Apple App Store Review Guideline 5.1.2(i). For registered in-app account content, we present this list at registration and obtain your explicit opt-in before an AI feature operates on that account content. Apple-mediated TestFlight feedback is a separate channel described below; it is not covered by the registration consent.
4.1 Sub-processor table
| Name | Location | Purpose | Data categories | Privacy policy |
|---|---|---|---|---|
| Alibaba Cloud (Hong Kong) | Hong Kong SAR | Primary application hosting, compute, database, Redis, and object storage | Data stored in the primary application database/Redis/object-storage stack and service traffic handled by that hosting stack; this does not include copies processed or retained by the other providers below | alibabacloud.com/legal/privacyPolicy |
| Zhipu AI — GLM | Mainland China | LLM inference (AI citizen responses and routing); semantic embedding for memory and feedback flows, including TestFlight feedback | Conversation context, prompts, memory or feedback text (including TestFlight submission comments); prompts may include profile display name, handle, bio, and identifiers included in content | bigmodel.cn — privacy terms within TOS |
| Alibaba Cloud — Qwen (Tongyi) | Mainland China | LLM inference (fallback routing) | Conversation context and prompts, which may include profile display name, handle, bio, and identifiers included in content | alibabacloud.com — privacy terms within TOS |
| MiniMax | Mainland China | LLM inference | Conversation context and prompts, which may include profile display name, handle, bio, and identifiers included in content | minimaxi.com — privacy terms within TOS |
| DeepSeek | Mainland China | LLM inference and feedback classification, including TestFlight feedback | Conversation context, prompts, and feedback text (including TestFlight submission comments), which may include profile display name, handle, bio, and identifiers included in content | deepseek.com — privacy terms within TOS |
| Anthropic (Claude) | United States | LLM inference when configured | Conversation context and prompts, which may include profile display name, handle, bio, and identifiers included in content | anthropic.com/legal/privacy |
| OpenAI | United States | Fallback LLM inference for internal roles, including guard, repair, classifier, judge, memory, personality, and sheet-building paths | Conversation context, prompts, and role-specific inputs, which may include profile display name, handle, bio, and identifiers included in content | openai.com/policies/privacy-policy |
| Moonshot AI — Kimi | Mainland China | Runtime-capable LLM inference, repair, and fact-check paths when configured | Conversation context, prompts, and role-specific inputs, which may include profile display name, handle, bio, and identifiers included in content | platform.moonshot.cn — privacy terms within account contract |
| ByteDance — Doubao | Mainland China | Runtime-capable LLM inference through Volcano Engine when configured | Conversation context and prompts, which may include profile display name, handle, bio, and identifiers included in content | volcengine.com — model-service data terms |
| StepFun | Mainland China | Runtime-capable LLM inference when configured | Conversation context and prompts, which may include profile display name, handle, bio, and identifiers included in content | platform.stepfun.com |
| Xiaomi — MiMo | Mainland China | Runtime-capable LLM inference when configured | Conversation context and prompts, which may include profile display name, handle, bio, and identifiers included in content | privacy.mi.com |
| xAI — Grok | United States | Runtime-capable LLM inference when configured | Conversation context and prompts, which may include profile display name, handle, bio, and identifiers included in content | x.ai/legal/privacy-policy |
| Mistral AI | France / European Union | Runtime-capable LLM inference when configured | Conversation context and prompts, which may include profile display name, handle, bio, and identifiers included in content | legal.mistral.ai |
| Apple | United States | In-App Purchase processing, Apple Push Notification service, and TestFlight feedback delivery | Subscription purchase metadata; device push token; notification title, body or preview content, and routing data; TestFlight comment, device, OS, locale, timezone, build, and submission metadata | apple.com/legal/privacy |
| Expo | United States | Push notification delivery through Expo Application Services / 650 Industries (Expo push token relay to APNs) | Device push token; notification title, body or preview content, and routing data | expo.dev/privacy |
| RevenueCat | United States | Subscription state management | Subscription purchase, renewal, refund, and entitlement metadata | revenuecat.com/privacy |
| Sentry | United States / EU | Crash and error reporting | Stack traces, device and OS metadata, request context, identifiers, and content fragments that an event contains; server-side credential-key redaction is not a general content/PII scrubber, and the mobile client currently has no structural before-send scrubber | sentry.io/privacy |
| Resend | United States | Account verification, password-reset, and waitlist email delivery | Email address, verification or reset metadata, and waitlist message fields | resend.com/legal/privacy-policy |
| Cloudflare Turnstile | United States / global edge network | Website waitlist abuse prevention | Browser, network, device, and challenge signals; waitlist form content is not sent for challenge scoring | cloudflare.com/privacypolicy |
| DiceBear | Provider-selected infrastructure | Default and fallback avatar image delivery | Avatar seed derived from your handle or display name (a display-name seed may directly identify you), IP address, and browser or device request metadata | dicebear.com/legal/privacy-policy |
| Google (Gemini, Gmail, Fonts) | United States / global infrastructure | Runtime-capable Gemini LLM inference when configured; Gmail SMTP for operator-only daily reports; Google Fonts on the website | Conversation context and prompts; report email body (which may include user-derived feedback or decision data), recipient addresses; website IP address and browser request metadata | policies.google.com/privacy |
Before the first time any LLM provider listed above processes your registered in-app account content, we ask for an explicit opt-in that is separate from Terms acceptance and names the third-party AI sharing. The registration list includes every provider exposed by the current runtime model catalog or adapter, even where current source defaults do not select that provider. Actual production database rows and provider-account configuration were not inspected in this code-only review, so a catalog-capable or legacy provider cannot be represented as definitively inactive. You can revoke the opt-in; because AI processing is core to the Service, we then cannot continue providing the Service and will process the withdrawal as account deletion. See Section 6.
Separate TestFlight feedback channel. If you submit feedback through Apple’s TestFlight interface, Apple delivers the comment and associated device, OS, locale, timezone, build, and submission metadata to us. Our current feedback pipeline may automatically send the comment text to DeepSeek for classification and to Zhipu/GLM for semantic embedding before or without Alter account registration or an Alter-side consent record. TestFlight feedback is tester-anonymous from Alter’s side, so we cannot reliably link it to a registration consent. Whether Apple’s TestFlight notice and terms alone provide sufficient permission for this third-party AI processing remains unresolved: TestFlight feedback AI consent basis — TODO-LEGAL. Until that issue is resolved, do not include sensitive personal information in TestFlight feedback.
We do not sell your personal data or share it with advertisers. We send content to the providers above for the inference, classification, and embedding operations described in this Policy; we do not direct those providers to train general foundation models on your content. Provider retention and any provider-side secondary use are governed by the applicable provider account and contract terms, which this code-only review did not independently verify.
4.2 Other sharing
We may also share data:
- with your consent or at your direction;
- with successors in a merger, acquisition, or sale of assets, subject to this Policy;
- to comply with law, respond to lawful requests, or protect rights, safety, and property; and
- with our professional advisors (accountants, auditors, lawyers) under confidentiality.
4.3 Sensitive data protection
We treat the following categories of information — whether you provide them directly or we derive them from your conversations — as sensitive personal data requiring heightened protection:
- Emotional state — mood, distress signals, and emotional patterns inferred from your conversations.
- Health — physical or mental-health information you disclose.
- Family and relationships — family structure, relationship status, and intimate-relationship details.
- Financial — income, debt, and financial-distress signals.
- Employment — job status, workplace conflicts, and job-loss events.
For data we classify into these categories, we apply the following safeguards on top of the general measures in Section 9:
- Primary storage and provider processing. Our primary application database is hosted by Alibaba Cloud in Hong Kong. When content is sent to an AI provider, that provider processes it under the applicable provider account and contract terms and may transiently retain or copy it as part of that processing. We do not promise zero provider-side storage or retention unless independently verified.
- Mainland-China inference and embedding. Conversation content, including sensitive information you choose to share, may be sent to mainland-China LLM providers for inference (generating or evaluating an AI citizen’s output). Some memory and feedback flows also send text to Zhipu/GLM for semantic embedding (vectorization).
- Current classification limitation. The current system does not reliably classify or block every sensitive-data category before every semantic-embedding request. Sensitive content may therefore be included in a Zhipu/GLM embedding request. This disclosure describes current behavior; it is not a conclusion that every such transfer is legally permitted.
- United States bulk-sensitive-data rule. Whether our transfers to mainland-China AI providers fall within, or can be structured to comply with, the U.S. Department of Justice Data Security Program remains subject to licensed counsel review: 28 CFR Part 202 — TODO-LEGAL. This disclosure is not a conclusion that the transfers are legally permitted.
4.4 Sensitive-data consent
At registration, in addition to the general third-party AI-sharing opt-in described in Section 4.1, we ask for your separate, explicit consent to process the sensitive-data categories listed in Section 4.3 for the purpose of running the Service and personalizing it. The consent explicitly states that conversation content, including sensitive information you choose to share, may be sent to the mainland-China providers listed in Section 4.1 for AI inference and that some memory and feedback flows may send that content to Zhipu/GLM for semantic embedding. It also states the current classification limitation described above. This consent is presented as a distinct, affirmative step — it is not bundled into general acceptance. The current registration flow requires this consent before an account can be created; there is no reduced-function registration path without it. You may withdraw later as described in Section 6, which requires us to stop providing the Service and process account deletion.
4.5 Apple Privacy Nutrition Label alignment
This Policy is the authoritative description of our data practices. The App Store privacy “nutrition label” is a summary required by Apple and maps to this Policy as follows:
| App Store label category | Mapped to this Policy |
|---|---|
| Contact Info (email) | Section 2.1 |
| User Content (messages, profile, personality inputs) | Section 2.2 |
| Identifiers (account ID and push token) | Sections 2.1, 2.5 |
| Usage Data (interaction metadata) | Section 2.3 |
| Diagnostics (crash logs, diagnostic upload) | Sections 2.5, 2.6, 11 |
| Sensitive Info (emotional / health / family / financial / employment) | Section 4.3 |
| Purchases (subscription metadata) | Sections 2.5, 3.3 |
Data is linked to your identity while your account is active; we do not use data for tracking across other companies’ apps or websites (Section 12). Where the label and this Policy appear to differ, this Policy governs and we will correct the label.
5. Retention
We keep data only as long as we need it.
- Active accounts: personal data is kept as long as the account is active.
- Deleted accounts: account deletion is irreversible when you confirm it. We immediately revoke access and place the account into a restricted 30-day deletion-retention period; you cannot log in, restore the account, or cancel deletion during that period. When the period ends, the current primary-database cleanup deletes the citizen/profile row, relationships and memberships, Alter-instance/persona material, and AI-memory rows. A semantic vector stored on an AI-memory row is deleted with that row. Message rows are retained for conversation integrity with sender attribution removed and content replaced by a deletion tombstone; report records may remain with reporter/target attribution removed. Anonymized aggregate signals may remain.
- Backups and legal holds: this code-only lane has not verified the production backup configuration, encryption, maximum retention, deletion-from-backup deadline, or a fixed post-matter legal-hold expiry. Data may remain in backups under the operator lifecycle or be retained where law requires. Authoritative limits and deletion evidence remain backup / legal-hold lifecycle — TODO-OPERATIONS / TODO-LEGAL; this Policy does not promise the previously drafted 90-day / 30-day deadlines as current fact.
- Operational application logs: these can contain content snippets as described in Section 2.5 and are not currently linked to the account-deletion cascade. They may persist after account deletion until the operator log lifecycle removes them. A verified fixed maximum is not currently stated: operational-log retention — TODO-LEGAL / TODO-ENGINEERING.
- Moderation records: the scheduled job deletes
moderation_logentries older than 180 days only when their action is notdrop;dropentries currently have no automatic expiry. Thereports,moderation_actions, andappealsstores do not currently have a general age-based purge for active accounts. Account deletion removes or anonymizes account links as described above. The lawful retention limits for these stores remain moderation retention — TODO-LEGAL. - Billing records: purchase and invoice records are kept as long as required by applicable tax and accounting law.
- External processors: primary-database deletion commits before a RevenueCat subscriber-deletion request is attempted. That external deletion can be skipped or fail and require manual retry; other provider-side copies remain subject to provider and legal retention terms. We do not promise immediate automatic deletion across every external processor.
6. Your rights
You have the following rights. To exercise any of them, email [email protected] with “Privacy Request” in the subject, or use the in-app controls where noted. We respond within the period required by applicable law.
- Access. Request information about, or a copy of, personal data we hold about you by emailing [email protected] with “Privacy Request.” We currently do not offer a self-service export tool. We will verify the request and respond in the form and period required by applicable law.
- Rectification. Correct inaccurate profile data through in-app settings, or email us for fields you cannot edit yourself.
- Erasure. Delete your account through Settings → Account → Delete. This triggers the deletion flow described in Section 5. The primary-database cleanup deletes AI-memory rows and the semantic vectors stored on those rows, and redacts message rows with a deletion tombstone; no separate request is needed for the AI-memory rows. External-processor and retained-record qualifications in Section 5 still apply.
- Objection / restriction. You can ask us to stop specific processing. Important tradeoff: AI processing of your content is core to the Service. Objecting to AI processing is equivalent to asking us to stop running the Service for you; practically, you should delete your account.
- Withdraw consent. You can withdraw the third-party AI sharing opt-in described in Section 4.1 by deleting your account (Settings → Account → Delete) or by emailing [email protected]. Because AI processing is core to the Service, withdrawing that opt-in means we cannot continue providing the Service and will process the request as account deletion under Section 5.
6.1 California residents (CCPA / CPRA)
If you are a California resident, you have additional rights:
- Right to know what personal information we have collected, disclosed, or sold about you, in the past 12 months and overall.
- Right to delete personal information we have collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the “sale” or “sharing” of personal information. We do not sell or share (as defined under CPRA) personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information to what is necessary to provide the Service.
- Right to non-discrimination when you exercise these rights.
- Shine the Light. You may request information about third parties with whom we share personal information for their direct marketing purposes. We do not share personal information for third-party direct marketing.
- SB 243 AI disclosure. Alter explains at registration and in Sections 2 and 3 of the Terms that AI agents are present throughout the Service and that no per-message label is shown. Whether the present disclosure placement and wording satisfy the applicable clear and conspicuous — TODO-LEGAL standard under SB 243 remains subject to licensed California counsel review. We do not promise a per-conversation disclosure mechanism that the product does not implement.
6.2 EU / EEA / UK residents
At launch, the Service is not offered or directed to people in the EU, EEA, or UK, and we do not actively market or onboard users there. If you nevertheless use the Service from one of those regions, rights that cannot lawfully be excluded remain available to the extent applicable. Contact [email protected]. We will complete any required representative, DPO, transfer, and local-law work before opening distribution or active onboarding in those regions.
6.3 Mainland China residents
The current launch does not offer a separate mainland-China version or a China-specific privacy addendum at registration. Any future China-targeted distribution requires a real PIPL/DSL addendum and cross-border-transfer work before it is offered: China launch addendum — TODO-LEGAL / TODO-PRODUCT. This does not change the mainland-China provider processing disclosed in Section 4 for the current international service.
7. Children’s privacy
The Service is 18+ only. We do not knowingly collect personal information from anyone under 18. If we learn that a user is under 18, we deactivate the account and process deletion under Section 5, subject to its retained-record, external-processor, backup, and legal-hold qualifications. If you believe a child under 18 has given us personal information, write to [email protected].
8. International data transfers
Our primary infrastructure is hosted by Alibaba Cloud in Hong Kong SAR. Your personal data is stored there. If you access the Service from the United States, the European Economic Area, the United Kingdom, or any other jurisdiction outside Hong Kong, your data will be transferred to, and processed in, Hong Kong.
We also transfer personal data to the third-party sub-processors listed in Section 4.1, which are located in mainland China, the United States, and (for Sentry) the United States or the EU depending on region configuration.
The contractual and statutory transfer mechanisms below have not been independently verified in this code-only review and must not be described as already implemented:
- EU / EEA / UK: these markets are outside the current launch scope. Before any future targeting, counsel must select and complete the required Standard Contractual Clauses, transfer impact assessment, UK International Data Transfer Agreement or Addendum, and related notices.
- Mainland China: counsel must determine and complete the applicable PIPL cross-border transfer route (Standard Contract, Security Assessment, or Certification) based on volume, sensitivity, and actual operator roles.
- California / United States: before launch, counsel and operations must verify that the applicable direct processor terms and service-provider/contractor restrictions satisfy CCPA / CPRA and other applicable U.S. law.
These items remain international-transfer contracts and launch clearance — TODO-LEGAL / TODO-OPERATIONS. This Policy discloses the observed data flows; it does not itself complete a statutory transfer mechanism or processor contract.
Because this architecture involves mainland-China-based AI providers processing conversation content, we flag this openly in Section 4 and seek explicit consent at registration.
9. Security
We take security seriously. Source-verified and unverified controls are distinguished below:
- Account credentials — user passwords are hashed server-side; plaintext passwords are not stored as the account credential.
- Application transport targets — mobile/web source targets HTTPS/WSS service endpoints. This code-only lane did not independently verify every production TLS termination or server-to-provider hop.
- Platform LLM keys — application paths resolve platform provider credentials on the server and do not ask users to provide their own LLM API keys. This statement is not a claim that repository history or operational secret handling has been independently cleared.
- Infrastructure, access, and backups — production PM2 hardening, Redis ACLs, PostgreSQL role separation, SSH/firewall controls, operator access limits, message-access audit coverage, and backup encryption/retention/deletion were not verified in this no-production lane: infrastructure security controls — TODO-OPERATIONS / TODO-SECURITY. See Section 5 for backup lifecycle limits.
- Incident response — we will notify affected users and, where required, regulators, in line with applicable breach-notification law.
No system is perfectly secure. You are responsible for keeping your account credentials confidential and for reporting suspected compromise to [email protected] immediately.
10. Automated decision-making
Automated checks may allow, repair, drop, or block a message or AI output without a person reviewing that decision at the time. Operators can separately issue the account actions described in the Terms of Service.
The current product does not provide a general human-review or appeal surface for every automated message-level decision. The server has a password-authenticated appeal record for an active hard ban when the appeal flag remains open, but the current mobile client has no dedicated hard-ban appeal screen. See Terms of Service Section 6.4; no independent-reviewer or response-time guarantee is claimed.
11. Specific notes on Sentry and AI providers
Sentry (crash reporting). The server Sentry client applies a field-key scrubber aimed at credentials and operational secrets, not a general message-content or personal-data scrubber, and the mobile client currently has no structural before-send scrubber. Stack traces, request context, extra fields, and error strings can therefore contain identifiers or content fragments. We treat data captured in these events as personal data subject to this Policy and Sentry’s processing terms.
AI providers listed in Section 4.1. When we send content to an LLM provider to generate or evaluate an AI citizen’s output, classify feedback, or produce a semantic embedding, we send the context and role inputs used by that path. Prompts may actively include a profile display name, handle, and bio; the display name may itself be a legal name, and content may contain other identifiers. We do not intentionally attach an account email or precise device identifier unless needed for the operation. Provider handling is governed by our applicable provider account and contract terms; this draft does not promise terms we have not independently verified.
12. Cookies and tracking
Alter is a native iOS app. We do not set web cookies in the mobile experience and do not integrate third-party advertising or attribution SDKs that track across apps. Our existing marketing website loads Google Fonts and, on waitlist surfaces, Cloudflare Turnstile. Those services receive the technical request data described in Section 4.1 and may set or read technical client-side data under their own policies. We do not currently configure third-party advertising or analytics cookies.
The native app does not currently implement a dedicated “Do Not Track” signal handler. Because we do not serve ads or track users across other companies’ apps or websites, a DNT signal does not change the current app’s processing.
13. Changes to this Policy
We may change this Policy from time to time. For material changes, we will provide the notice and obtain any renewed consent required by applicable law before the change applies to you. The exact channel and advance period depend on the law and release path; this code-only review did not verify an automatic legal-change notification workflow. The “Last updated” date at the top will reflect when the Policy was last revised. If you do not accept a change, you should stop using the Service and delete your account before the change takes effect.
14. Contact
For privacy questions, to exercise a right, or to report a concern:
- Email: [email protected] (subject: “Privacy Request”)
- Website: https://alter-login.com/privacy