Privacy
What we collect, and what we do with it.
Last updated 21 August 2026.
This page
If you join the waitlist we store the email address you give us, the sentence you write about what you are working on, and the optional answers on the confirmation screen. We also store the UTM parameters and referring domain of the link you arrived through, so we know which channels are worth our time.
We do not store your IP address, and we set no advertising or tracking cookies. Traffic measurement, where enabled, is cookieless and aggregate. Bot protection is handled by Cloudflare Turnstile, which was chosen over the alternatives specifically because it does not require cookies.
There are no cookies at all. There used to be exactly one, holding the address you typed for an hour so that a second set of questions could be attached to the right signup. Those questions are gone, so the cookie went with them. This site stores nothing on your device.
Your email
We use it to tell you when it is your turn for an audit, and to ask the questions we need to do one. That is the whole list of uses. We do not sell it, rent it, share it with anyone, or swap it with another newsletter. Reply to any message with “remove” and you are off the list. There is no form to complete.
If you ever connect an inbox
Nothing on this page requires you to connect anything, and today nothing can be connected. The email side is waiting on Google's security review and the X side on developer approval from X. If that changes and you choose to, these are the commitments that apply, and they are the same ones stated on the home page:
- Revoke either connection yourself, in your own X or Google settings, without asking us
- Your raw archive is deleted within 24 hours of being processed
- Newsletters, receipts and alerts are discarded before anything reads them, and never stored
- Only the signals and the specific quoted lines are kept, not your whole inbox
- Message text is encrypted with a key unique to you
- Delete everything, instantly, and get written confirmation
- Delete a message on X and it goes from here too
- Your messages never appear in logs or analytics
We hold no security certification: not SOC 2, not ISO 27001, and we have not had a penetration test. We are not going to pretend otherwise. What is above is concrete and you can hold us to it.
Email specifically
A mailbox is a bigger thing to hand over than a DM archive, and it is worth being exact about the difference. Reading mailbox contents is what Google calls a restricted scope: it requires their verification and an annual independent security assessment before any real account can be connected. We have not been through it. Until we have, the Gmail option on the home page is a description of intent and nothing more.
The access we would ask for is read-only. It cannot send a message, delete one, or mark anything as read. Most of what is in a mailbox is not from a person at all. Newsletters, receipts, deploy alerts and calendar noise are discarded on sight, by ordinary pattern matching rather than a model, before anything reads it and without being stored. What survives is the mail an actual human wrote to you.
Any Google user data we received would be handled in line with the Google API Services User Data Policy, including its Limited Use requirements. In practice that means the same thing the rest of this page says: it answers your question, it trains nothing, it is never sold, and it is never pooled with another customer's.
What this product does not do
- It never sends anything. Read-only, and that is enforced by the permission itself, not just by us: the access you grant cannot post, cannot message and cannot follow. No sequences, no replies fired on your behalf. You copy a draft and send it yourself, in X, as yourself.
- It only looks at people who reached you first. It does not find strangers or build lists. Everyone it can show you already wrote to you, on X or by email, and it pulls nothing about them from outside that conversation. The one thing that would is down the pipeline, and it would only ever read what someone published under their own name and handed you the link to.
- Your data is never pooled with anyone else’s. There is no shared graph of who responds to what. Not as a policy we promise to keep. It is structurally impossible in how the system is built.
- No training on your messages. Your conversations are used to answer your question and nothing else.
Processors
We keep this list short deliberately, and it will be kept current. Today: a hosting provider serving this page, a database holding waitlist rows, an email provider sending confirmation messages, and a cookieless analytics provider counting visits. If that list changes in a way that touches your data, we will say so here before it takes effect.
Your rights
Ask us what we hold about you and we will tell you. Ask us to delete it and we will, then confirm in writing. Both requests go to founder@alakoda.com and neither requires a reason.
Contact
founder@alakoda.com reaches a person, not a ticket queue.