Skip to content
alderson
Terms Privacy Data use

Legal

Alderson Product Privacy Policy

How Alderson handles personal information across the Free and Enterprise services.

On this page
  1. 1. Personal information we collect
  2. 2. How we use personal information
  3. 3. When we disclose personal information
  4. 4. Retention
  5. 5. Data controls
  6. 6. Your rights
  7. 7. Children and teens
  8. 8. Security
  9. 9. Additional Canadian and United States disclosures
  10. 10. International processing
  11. 11. Changes to this Policy
  12. 12. Who controls personal information
  13. 13. Contact and useful resources

Draft version: 2026-07-22
Proposed effective date: on publication after counsel approval
Status: counsel approval copy; not yet effective

This Privacy Policy explains how 17333790 Canada Inc., carrying on business as Alderson (Alderson, we, us, or our) collects, uses, discloses, retains, and protects personal information when you visit our product pages, create an account, use our desktop software and agents, connect another service, contact us, or otherwise use the Alderson product and related services (together, the Service).

This Policy covers personal information handled by Alderson. It also distinguishes personal information from Customer Content, operational data, and information used to improve agents and models.

This Policy does not apply to content that Alderson processes solely on behalf of an Enterprise customer. That processing is governed by the customer's agreement, data processing addendum, configuration, and privacy notice. This Policy still applies to the limited account, security, billing, legal, and service-health information that Alderson controls for its own purposes.

For more detail about product improvement, see How Alderson uses service data to improve agents. That page supplements this Policy but does not authorize additional collection or use.

1. Personal information we collect

The information we collect depends on the plan, feature, connected services, and choices involved in your use.

Information you provide

Account and organization information. When you create or use an account, we may receive your name, email address, email-verification status, profile image, identity-provider subject, organization, membership, role, plan, entitlements, account status, and policy-acceptance records. We create an Alderson account identifier and may record installation registrations and organization settings.

WorkOS currently provides social and email authentication and organization features. Alderson does not receive your social-provider password. WorkOS and the social identity provider may process sign-in information under their own notices.

Customer Content. You may provide prompts, instructions, files, images, source material, model-visible context, connected-application content, tool inputs and results, model outputs, agent execution or reasoning traces, edits, corrections, validation information, outcomes, and feedback (together, Customer Content).

Customer Content is processed when needed to perform the action you request. Depending on your configuration, it may remain on your device, be sent to a model provider or connected application you select, or be handled for an Enterprise customer under its agreement. Alderson does not intentionally scan unopened files on your device.

Communications and support information. If you contact us, we collect the contact details, message, account identifiers, and diagnostic material you choose to provide. Do not send credentials or unrestricted project files through support email.

Business and transaction information. Enterprise purchasing and support may involve business contact details, title, employer, approval or signature status, Order Form details, invoices, tax information, payment status, and procurement or security-review correspondence. If a payment processor is introduced, we will identify it before use.

Other information you choose to provide. We collect information you submit through an event, survey, privacy request, security report, or other voluntary interaction.

Information we receive from use of the Service

Log and network information. Browsers, devices, and network services send information such as IP address, browser type, requested route, request time, referrer category, security signals, and session information. Cloudflare and internet providers necessarily process connection information to route and protect traffic. Alderson's ordinary application telemetry is designed not to store raw IP addresses.

Minimum Operational Data. The signed-in Free Service produces limited technical and usage information needed to provide, protect, meter, maintain, and troubleshoot the Service. Depending on the feature, this may include:

  • an opaque account, organization, installation, session, run, or action identifier;
  • app, agent, schema, feature, component, tool, model, and provider identifiers and versions;
  • operating-system family and version, device architecture, locale, time zone, and bucketed device-capability information;
  • start and end times, duration or latency ranges, queue time, retries, counts, completion status, and validation status;
  • reviewed static error, recovery, security, capability, and compatibility codes; and
  • plan, destination, retention, and policy identifiers needed to enforce the correct data mode.

Minimum Operational Data is designed not to include prompt text, file contents, model-visible context, output text, exact commands, exact tool inputs or results, credentials, secret environment variables, or free-form error text. It may still be personal information when linked or reasonably linkable to an account, device, or person.

Free Actions and Training Data. While Improve Alderson for everyone is on, Alderson may create detailed Actions from eligible Free product journeys and agent episodes. Depending on the feature and activity, Free Actions may include:

  • prompts, instructions, model inputs, model-visible context, and outputs made available to Alderson;
  • the ordered steps of an agent episode, including agent execution or reasoning traces, branches, retries, and state changes;
  • tool identifiers, calls, arguments, results, and errors;
  • portions of files or connected-application content actually read or created by an agent or model;
  • edits, corrections, human feedback, labels, validation results, and observed outcomes;
  • model, token, timing, runtime-health, and coarse device information; and
  • source, policy, consent, provenance, and dataset-edition records needed to govern later review and training.

Free Actions do not intentionally include passwords, access or refresh tokens, API keys, authentication cookies, authorization headers, keychain values, secret environment variables, raw IP addresses in the ordinary Actions store, unopened host files, unrestricted keystrokes or clipboard history, or a model provider's private hidden chain-of-thought that is not returned to Alderson. Credential removal, field validation, and filtering reduce risk but do not guarantee that eligible Customer Content contains no personal, confidential, or sensitive information.

An Action selected for evaluation or training may be disassociated from direct account identifiers, filtered, labelled, transformed, or combined with other examples in a governed Training Edition. Disassociation or tokenization does not necessarily make information anonymous under applicable law.

Device and location information. We may receive the operating-system and browser information described above and infer a coarse country or region from a connection for security, localization, legal compliance, or service availability. The general Service does not collect precise device location.

Cookies and similar technologies. We use cookies or similar technologies that are necessary for authentication, security, session continuity, and user preferences. The initial product launch does not use third-party advertising tags, session replay, or optional cross-site behavioural tracking. If non-essential analytics are introduced, they will not begin until we provide the notice and choice required in the applicable location.

Information from other sources

We may receive information from:

  • an authentication or social identity provider;
  • an Enterprise administrator or organization directory;
  • a model provider or connected application you authorize;
  • cloud, security, email, support, and payment providers;
  • another user who invites you to an organization or reports a shared action; and
  • public or professional sources used for Enterprise sales, fraud prevention, or legal compliance where permitted.

We do not purchase consumer profiles from data brokers for model training or targeted advertising.

Enterprise information

An Enterprise customer's configuration may permit more detailed activity records, including Customer Content and exact tool activity, to be routed to a customer-controlled destination. The customer may use those records for its own audit, evaluation, fine-tuning, or model-development program under its own authority and policies. By default, detailed Enterprise records are not sent to Alderson's Free Actions store and are not used to train shared Alderson agents or models.

Alderson may process Enterprise data transiently to perform a requested action or route it to the configured destination. Alderson-hosted retention of detailed Enterprise data occurs only when a signed Order Form or data processing addendum expressly specifies the destination, purpose, and retention period. Authorized administrators may access, export, retain, or delete customer-controlled information according to the customer's policies and agreement.

If you use an organizational account, direct questions about customer-controlled information to that organization. Alderson will assist the organization as required by its agreement and applicable law.

2. How we use personal information

We use personal information for the following purposes:

  • Provide and maintain the Service. Authenticate users, maintain accounts and organizations, deliver software and agents, perform requested actions, provide storage and exports, enforce entitlements, and provide support.
  • Protect the Service. Prevent fraud, abuse, malware, unauthorized access, policy violations, and threats to users, Alderson, connected systems, or the public.
  • Analyze, troubleshoot, and improve. Measure reliability, compatibility, capacity, latency, failures, and workflow completion; diagnose problems; conduct research; and improve features and documentation.
  • Evaluate and train Alderson agents. Review, filter, annotate, score, and use eligible Free Actions for supervised fine-tuning, preference or reinforcement learning, evaluation, routing, tool-use, safety, and other shared agent or model development.
  • Administer Enterprise relationships. Provision organizations, apply customer settings, route customer-controlled data, support administrators, administer contracts, and provide audit and deletion assistance.
  • Communicate. Respond to requests and send authentication, security, download, support, billing, policy, and other Service messages.
  • Administer business operations. Process orders and payments, maintain accounting and tax records, conduct vendor and security review, protect legal rights, and manage corporate transactions.
  • Comply with law. Respond to valid legal process, meet regulatory and recordkeeping requirements, and establish, exercise, or defend legal claims.
  • Send marketing where permitted. Send marketing only through a separate permission or opt-out process appropriate to the recipient's location.

We may aggregate or de-identify information so that it no longer identifies you. We maintain de-identified information in de-identified form and do not attempt to reidentify it except where permitted or required by law to verify our processes.

Product improvement and model training

Minimum Operational Data is used to run and protect the Service. It is not placed into a content-bearing Training Edition merely because it reports that an action succeeded or failed.

Alderson may use eligible Free Customer Content and Actions to evaluate, train, and improve shared Alderson agents, models, routing, tool-use policies, safety systems, and related product features. Methods may include human review and labelling, automated filtering, benchmarking, supervised fine-tuning, preference optimization or reinforcement learning, scoring, retrieval and routing experiments, and red-team or safety evaluation. Only selected Actions are expected to enter a Training Edition; selection may be based on quality, failure mode, novelty, validation, or research need.

This training use occurs only while Improve Alderson for everyone is on. New personal Free accounts start with the setting on. You can change it at any time in the Data Controls section of your account without closing the account. After you turn it off, Alderson will not collect new content-bearing Free Actions for shared training. The change does not automatically remove Actions collected while the setting was on or information already used to train a model. Previously collected Actions remain subject to the retention, deletion, rights, and remediation provisions below. If applicable law requires express consent or another choice before this use, Alderson will not activate the affected collection or use in that jurisdiction until the required mechanism or another lawful product rule is in place.

Enterprise Customer Content and detailed Enterprise activity are excluded from shared Alderson training by default. They may be used by the Enterprise customer for its own models through its configured destination. Alderson may use them for shared training only under a separate, express written agreement signed by an authorized customer representative.

No sale or behavioural advertising

Alderson does not sell personal information, share it for cross-context behavioural advertising, operate as a data broker, or use Customer Content for third-party targeted advertising.

3. When we disclose personal information

We disclose personal information only for the purposes described in this Policy and according to the applicable data mode.

Vendors and service providers. We use providers that perform services for us under appropriate contractual restrictions:

  • WorkOS for authentication, identity-provider integration, organization membership, and related account functions;
  • Cloudflare for edge delivery, security, compute, queues, databases, object storage, and related infrastructure; and
  • Resend for requested account, security, policy, support, and download email.

Our current provider list and roles are described above. A dedicated Subprocessor List will be linked here after it is approved for publication.

Model providers and connected applications. They receive Customer Content and instructions when you or your organization selects them or requests an action that requires them. Their independent processing is governed by their own terms and privacy notices.

Enterprise customers and administrators. An organization and its authorized administrators receive information controlled through its workspace, configuration, and agreement.

People you direct us to share with. We disclose information when you request an export, sharing action, connected-service action, or other transfer.

Professional advisers and security responders. We may disclose limited information to authorized support personnel, incident responders, auditors, insurers, lawyers, and accountants where reasonably necessary and subject to confidentiality duties.

Authorized reviewers and training service providers. A limited number of authorized Alderson personnel and service providers may review selected Free Actions to filter, label, evaluate, or prepare Training Editions. Access is need-to-know, logged where supported, and subject to confidentiality and use restrictions.

Legal and safety recipients. We may disclose information when we reasonably believe disclosure is required by valid law or legal process, or is narrowly necessary to protect rights, safety, or security. Where lawful, we assess, narrow, document, and notify the affected person or customer.

Corporate transactions. Information may be transferred in connection with a merger, financing, reorganization, insolvency process, acquisition, or sale. A successor must handle it consistently with this Policy and applicable law, including any notice or choice required for a materially new purpose.

4. Retention

We retain personal information only for as long as reasonably needed for the purpose described in this Policy, subject to the intended maximums below. We may delete or de-identify it sooner.

Information Intended maximum retention
Necessary public-site session information Session duration; ordinary security and fraud-prevention records up to 30 days
Optional public-site analytics, if later introduced lawfully Up to 90 days
Free Minimum Operational Data Up to 365 days from collection
Encrypted raw Free Actions and content objects Up to 365 days from collection
Selected governed Training Editions Until deleted or revoked under the edition manifest; reviewed at least annually
Derived de-identified statistics, evaluations, and trained model parameters For the useful life of the relevant product or model, subject to applicable deletion, correction, suppression, and model-remediation duties
Enterprise Customer Content and detailed activity No Alderson Actions retention by default; customer-controlled retention, or the period expressly selected in a signed Order Form or DPA
Active account and organization information While active, then up to 90 days for ordinary wind-down
Support correspondence and voluntarily supplied diagnostics Up to 24 months after closure
Ordinary security and administrative audit records Up to 12 months from the event
Contract, transaction, tax, material acceptance, and consent records Up to seven years after the relevant account, transaction, contract, or fiscal year
Breach and material incident records At least 24 months after a determined breach and up to seven years where reasonably required
Backups Rolling expiry within 90 days

A legal hold, active security investigation, unresolved request, dispute, or other legal requirement may require a limited record to be retained longer. We document the reason, restrict the record's use, and delete it when the exception ends.

When you delete eligible account information, we remove it from active systems or place it into a deletion process. For Free Actions, the intended deletion process destroys the account's server-side content-encryption key, schedules physical deletion of raw objects, revokes associated active Training Editions, and prevents those editions from entering future training runs. Information may remain temporarily in isolated backups until they expire. If a backup is restored, applicable deletion requests are re-applied.

Account deletion may not reverse statistical changes already incorporated into a model that completed training. Where applicable law requires more, we will evaluate reasonable correction, output suppression, dataset exclusion, retraining, fine-tuning, or other model-remediation measures.

Account deletion does not delete local projects, user-created exports, information an Enterprise customer lawfully controls, or copies sent to a connected provider under your direction. Those copies must be managed separately.

5. Data controls

Depending on the feature and your location, you may be able to:

  • view or update account information;
  • export eligible account and Service information;
  • delete or archive information and request account deletion;
  • disconnect a model provider or connected application;
  • turn Improve Alderson for everyone on or off for a personal Free account;
  • choose whether to receive marketing;
  • manage optional cookies or analytics if they are introduced; and
  • submit a privacy request through the methods in Section 6.

The Minimum Operational Data described in Section 1 is required for the Free Service. Alderson collects eligible content-bearing Free Actions for shared training only while Improve Alderson for everyone is on. Turning it off does not prevent ordinary Free use. After you turn it off, Alderson will not collect new content-bearing Free Actions for shared training. You may also request account deletion. Enterprise uses a separate, customer-controlled data model under a signed agreement. Enterprise Customer Content and detailed activity are excluded from shared Alderson training by default.

Customer Content may still be processed by a model provider or connected application when you direct the Service to use it. Disconnecting that provider does not automatically delete information already sent to it.

Because Alderson does not currently sell personal information or share it for cross-context behavioural advertising, there is no current sale or targeted- advertising activity for an opt-out to stop. We nevertheless recognize a legally applicable Global Privacy Control or other universal opt-out signal for processing to which it applies.

6. Your rights

Depending on where you live and subject to identity verification, exceptions, and applicable law, you may have the right to:

  • confirm whether we process personal information about you;
  • access that information and learn about its purposes, sources, uses, and recipient categories;
  • correct inaccurate or incomplete information;
  • receive eligible information in a portable, commonly used format;
  • delete personal information;
  • withdraw consent where processing relies on consent;
  • limit or object to certain processing;
  • use an authorized agent where applicable;
  • opt out of covered sale, targeted advertising, or profiling if Alderson ever performs those activities; and
  • appeal a denied request where applicable.

Submit a request through https://alderson.ai/account/privacy or email privacy@alderson.ai. Our operating target is to respond within 30 calendar days. If applicable law permits or requires a different period, we will follow that period and provide an extension notice when required.

We verify requests in proportion to their risk. A signed-in user may be asked to re-authenticate. We avoid collecting new identifiers when existing account information is sufficient and delete additional verification information when it is no longer needed.

We do not charge for an ordinary request or discriminate against you for exercising a right. If we deny all or part of a request, we will explain the basis and available appeal or regulator path where required. To appeal, reply to the decision or email privacy@alderson.ai with Privacy appeal in the subject line.

For information controlled by an Enterprise customer, we may direct the request to that customer and assist it. An administrator may have lawful reasons to retain a limited record after an individual account is removed.

7. Children and teens

The Service is intended for adults and is not directed to people under 18. Alderson does not knowingly create accounts for people under 18 or knowingly select a child's or teen's personal information for shared model training, targeted advertising, or sale.

If we learn that a person under 18 provided personal information through the general Service, we may suspend the account, stop collection, delete the information, and contact a parent or guardian where required. Contact privacy@alderson.ai if you believe a child has provided information.

A school, education, family, or youth deployment requires a separate product, privacy, and legal review.

8. Security

We use technical, administrative, and organizational safeguards appropriate to the sensitivity and data mode. The proposed launch controls include:

  • encryption in transit and encryption for hosted Actions storage;
  • signed, short-lived authorization capabilities that identify the account, plan, destination, and permitted data mode;
  • access separation appropriate to the account or Enterprise tenant;
  • least-privilege administrative access, multi-factor authentication for privileged systems, and logged support access;
  • server-side validation of data mode and destination;
  • secure development, dependency, change, backup, vulnerability, and incident processes; and
  • tested export, retention, and deletion procedures.

No storage system, network, or automated filter is perfectly secure. Select plans, providers, destinations, and inputs appropriate to the information. Do not submit credentials or restricted information merely because a filter is present.

If an incident reaches the legal threshold for notification, we will notify affected people, customers, and regulators in the required form and time. Enterprise incident obligations are addressed in the applicable data processing addendum.

9. Additional Canadian and United States disclosures

Canada

Alderson is accountable for personal information under its control and has designated the Privacy Lead identified in Section 13. Canadian users may ask about the existence, use, disclosure, location, retention, protection, and accuracy of their information and may challenge our compliance.

Where Canadian law requires meaningful consent, we identify the information, purpose, consequences, and available controls at or before collection. The Free sign-in notice links this Policy and the Data Use explanation. Personal Free accounts also have an Improve Alderson for everyone control under Data Controls. If Canadian law requires a separate express choice before a particular collection or use, Alderson will not activate that collection or use for affected Canadian accounts until a compliant mechanism or location-specific product rule has been approved. Consent withdrawal applies going forward where processing relies on consent.

Canadian information may be processed outside a province or outside Canada as described in Section 10 and may be subject to lawful access under foreign law.

You may complain to the Office of the Privacy Commissioner of Canada or an applicable provincial privacy authority. We invite you to contact the Privacy Lead first, but doing so does not remove a regulator right or deadline.

The general signup is not currently offered in Quebec. Before Quebec launch, Alderson will complete the required privacy assessments and make the complete French Policy and collection notices available through an equal French path.

United States

State privacy rights and coverage vary. Alderson intends to provide the request path in Section 6 across the United States even where a particular omnibus state-law threshold has not been met, subject to reasonable verification and legal exceptions.

The table below uses common U.S. statutory categories to summarize information that may be collected, used, and disclosed for a business purpose.

Category Alderson examples Main purposes and recipients
Identifiers Email, identity-provider subject, account or organization ID, opaque installation or session ID, business contact, connection IP processed for delivery and security Authentication, account operation, security, support; WorkOS, Cloudflare, Resend, customer administrators
Customer-record and commercial information Business contact, plan, entitlement, Order Form, invoice, payment and support status Contracts, billing, support; infrastructure, payment provider if introduced, advisers
Internet or electronic activity Feature and component identifiers, timing, completion, retry, agent episode steps, tool activity, static error, validation, and security status Delivery, compatibility, reliability, troubleshooting, and shared agent evaluation and training for Free accounts; Cloudflare, authorized reviewers, and customer destination where applicable
Coarse geolocation Country or region inferred from a connection, locale, and time zone Security, localization, availability; infrastructure and security providers
Audio, visual, or electronic content Prompts, model-visible context, model inputs and outputs, reasoning or execution traces, images, files actually read, and tool inputs or results Requested processing; for Free accounts, shared agent evaluation and training; selected model or connected provider; Enterprise customer destination where applicable
Professional information Employer, title, organization role, and customer-controlled work activity Enterprise administration; customer and account providers
Inferences Customer-controlled validation or workflow assessments Requested evaluation or Enterprise use; customer destination
Sensitive personal information Authentication information handled within secured authentication systems; restricted sensitive content only in a separately approved Enterprise use Authentication and security or approved customer processing

Alderson does not sell these categories, share them for cross-context behavioural advertising, or use or disclose sensitive personal information to infer characteristics through the general Service. Free training is not a sale of personal information or permission for targeted advertising. If Alderson later offers a price or service difference tied to participation, it will first provide any Notice of Financial Incentive or other terms required by applicable law.

Where an applicable state law provides access, correction, deletion, portability, authorized-agent, opt-out, sensitive-data, or appeal rights, use the methods in Section 6. Alderson will honor an applicable legally recognized universal opt-out mechanism.

Washington consumer health data and Illinois biometric information are not approved categories for the general Service. A future product that processes them requires a separately reviewed notice, authorization, retention, security, rights, and contract design before collection begins.

10. International processing

Alderson operates from Ontario, Canada. Cloud, authentication, email, support, model, and connected-application providers may process information in Canada, the United States, or another location disclosed for the applicable feature. Information may be subject to the laws of those locations, including lawful access by courts, law enforcement, or national-security authorities.

We use contractual restrictions, access limits, encryption, minimization, provider review, and other safeguards appropriate to the information and destination. Enterprise residency, transfer, and government-request commitments must be stated in the applicable signed agreement; a marketing statement does not create a data-residency guarantee.

11. Changes to this Policy

We may update this Policy as the Service, providers, technology, or law changes. We will post the current version and effective date.

We will provide prominent notice before a material change to the categories, purposes, recipients, retention, sale or sharing, sensitive-information use, Enterprise role, or training practice. Where required, we will request a new acknowledgement, agreement, or consent before the change applies.

An updated Policy does not retroactively authorize a materially different use of previously collected information. A formatting or explanatory correction that does not change the processing may take effect when posted without a new account gate.

12. Who controls personal information

For Free accounts and the public product website, 17333790 Canada Inc., carrying on business as Alderson is responsible for the personal information described in this Policy.

For an Enterprise workspace, the customer organization generally controls its Customer Content and detailed activity, and Alderson acts as a processor or service provider under the customer's instructions. Alderson separately controls limited account, security, billing, legal, abuse-prevention, and service-health information for its own necessary purposes.

13. Contact and useful resources

Max Berry, Privacy Lead
17333790 Canada Inc., carrying on business as Alderson
1608-2760 Carousel Crescent
Ottawa, Ontario K1T 2N4
Canada

Privacy requests and complaints: privacy@alderson.ai
Account and general support: support@alderson.ai
Security reports: security@alderson.ai
Privacy request page: https://alderson.ai/account/privacy

Useful resources:

  • How Alderson uses service data to improve agents
  • Alderson Terms of Service

Related policies

Review the other documents in Alderson's legal and data-use policy set.

Terms Data use
alderson

© 2026 17333790 Canada Inc.

Terms Privacy Data use