Privacy
What we collect, and what we do with it.
Last updated 17 August 2026.
This page
If you join the waitlist we store the email address you give us, the sentence you write about what you are working on, and the optional answers on the confirmation screen. We also store the UTM parameters and referring domain of the link you arrived through, so we know which channels are worth our time.
We do not store your IP address, and we set no advertising or tracking cookies. Traffic measurement, where enabled, is cookieless and aggregate. Bot protection is handled by Cloudflare Turnstile, which was chosen over the alternatives specifically because it does not require cookies.
There is exactly one cookie. If you sign up with JavaScript turned off, we store the address you just typed for one hour so the follow-up questions can be attached to the right signup — the alternative would be putting your email address in the page URL, where it would end up in your browser history and in server logs. It is first-party, it expires on its own, and nothing else reads it.
Your email
We use it to tell you when it is your turn for an audit, and to ask the questions we need to do one. That is the whole list of uses. We do not sell it, rent it, share it with anyone, or swap it with another newsletter. Reply to any message with “remove” and you are off the list — there is no form to complete.
If you send us an archive
Nothing on this page requires you to send us anything. If you later choose to, these are the commitments that apply, and they are the same ones stated on the home page:
- Revoke the connection from your own X settings, without asking us
- Your raw archive is deleted within 24 hours of being processed
- Only the signals and the specific quoted lines are kept — not your whole inbox
- Message text is encrypted with a key unique to you
- Delete everything, instantly, and get written confirmation
- Delete a message on X and it goes from here too
- Your messages never appear in logs or analytics
We hold no security certification — not SOC 2, not ISO 27001, and we have not had a penetration test. We are not going to pretend otherwise. What is above is concrete and you can hold us to it.
What this product does not do
- It never sends anything. Read-only, and that is enforced by the permission itself, not just by us: the access you grant cannot post, cannot message and cannot follow. No sequences, no replies fired on your behalf. You copy a draft and send it yourself, in X, as yourself.
- It only looks at people you already talk to. It does not find strangers, build lists, or pull in anything about someone from outside your own conversation with them.
- Your data is never pooled with anyone else’s. There is no shared graph of who responds to what. Not as a policy we promise to keep — it is structurally impossible in how the system is built.
- No training on your messages. Your conversations are used to answer your question and nothing else.
Processors
We keep this list short deliberately, and it will be kept current. Today: a hosting provider serving this page, a database holding waitlist rows, an email provider sending confirmation messages, and a cookieless analytics provider counting visits. If that list changes in a way that touches your data, we will say so here before it takes effect.
Your rights
Ask us what we hold about you and we will tell you. Ask us to delete it and we will, then confirm in writing. Both requests go to founder@alakoda.com and neither requires a reason.
Contact
founder@alakoda.com reaches a person, not a ticket queue.