Privacy Policy
This policy describes what Ravenwood Capital Management, LLC collects when you use AlphaLode, and how it is used. Short version: we collect what is needed to run the Service, we use cookieless analytics, and we do not sell personal information.
What we collect
- Account data — your email address and a bcrypt hash of your password (we never store the password itself). If you sign in with Google or GitHub, we receive your email address from them.
- Billing data — payments are processed by Stripe. We store your Stripe customer and subscription identifiers; full card numbers never reach our servers.
- API keys — stored as SHA-256 hashes; the key itself is shown to you once and cannot be recovered by us.
- Server logs — standard web-server access logs (IP address, request path, timestamp) kept for security and debugging.
- Account activity logs — for signed-in members we record, per account, the API and terminal requests you make, including request paths and query parameters (for example search terms and filters), with timestamps. We keep these for security, abuse prevention, support and product improvement.
- Usage analytics — we run a self-hosted, cookieless analytics instance (GoatCounter at stats.alphalode.com). It records the page viewed, referrer, browser and screen class, and country. It sets no cookies and does not store your IP address; a short-lived salted hash is used only to distinguish unique visits within a day. No data is shared with any third-party analytics or advertising company.
Cookies
We use only strictly necessary cookies: s (your signed
session, 14 days, HttpOnly/Secure) and os (a transient
anti-forgery value used only during Google/GitHub sign-in). Because we use no
advertising or cross-site tracking cookies, no cookie consent banner is
required. The research terminal also saves preferences (theme, layouts,
watchlists) in your own browser's local storage; that data stays on your
device.
Text messages
If you add a mobile number and opt in to text alerts, we store the number with your account together with a record of your consent (timestamp and IP address), kept to honor and document your preference. Messages are service updates only. You can opt out at any time by replying STOP or by unchecking the option on your account page. Texts are delivered by Twilio, acting as our processor, which handles your number solely to deliver them.
Member chat
Members can send direct messages to other members inside the terminal.
- Encryption: Messages are end-to-end encrypted in your browser using keys generated on your device. AlphaLode's server stores only encrypted message bytes and routing metadata: sender, recipient, and timestamp. AlphaLode cannot read message contents.
- Your key: Your private key never leaves your device. If you clear browser storage or switch devices without exporting your key, no one, including AlphaLode, can decrypt messages you previously received.
- Deletion: You can permanently delete any message you sent or an entire conversation. This removes the encrypted bytes from the server for both participants and cannot be reversed.
- Routing metadata: Information about who messaged whom and when is kept while the messages exist. The operator can see this metadata for abuse handling. Message contents are not readable, but the fact and timing of a conversation are.
- What this protects against, and what it does not: Encryption happens in your browser, so the stored messages are unreadable to the server and to anyone who obtains them from it. Because the messaging code is delivered to your browser by AlphaLode, this protection assumes AlphaLode serves honest code; it is not a defense against a compromised operator who alters that code. There is no message-history forward secrecy yet: if your private key is ever stolen, past messages you received could be decrypted. Chat is intended for personal and community use, not for records-retained regulated communications.
Member mail
Each member receives an email address in the form handle@mail.alphalode.com. You can use it to send and receive ordinary email with any outside address.
- Storage: Ordinary email is not end-to-end encrypted. AlphaLode's server stores addresses, subject, and body text for sent and received messages so you can read them in the terminal. Messages remain until you delete them.
- Deletion: Deleting a message permanently removes it from AlphaLode's server. Copies held by the outside party's mail provider are beyond AlphaLode's control.
- Delivery: Outbound mail is delivered through Twilio SendGrid, a third-party email delivery provider that processes the message in transit. Attachments are not supported.
- Use: Sending limits apply to prevent abuse. Using the address for unsolicited bulk mail is grounds for account termination under the terms of service.
How we use it
To provide and secure the Service, process subscriptions, prevent abuse, and understand aggregate usage. Legal bases: performance of a contract and legitimate interest.
Sharing
Service providers only: Stripe (payments), Twilio (text-message delivery, if you opt in), and our cloud infrastructure provider (hosting). We do not sell or rent personal information, and we do not share it with advertisers or data brokers.
Retention and backups
Account data is kept while your account is active and deleted on request. Encrypted-in-transit daily backups of account data are retained for up to 30 days, after which they roll off automatically.
Your rights
You may request access to, correction of, or deletion of your personal data at any time from your account page, and we will honor the request within 30 days.
Children
The Service is not directed to anyone under 18.
Changes; contact
Material changes will be posted here with a new effective date. Contact: Ravenwood Capital Management, LLC, via your account page.