Privacy Policy
Last updated: July 2, 2026
Align ("Align," "we," "us," or "our") provides an AI personal assistant called Tracy. This policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have — including under the EU/UK General Data Protection Regulation (GDPR/UK GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). It applies to the Align website and application (the "Service").
1. Who We Are (Data Controller)
The Service is operated by [LEGAL ENTITY NAME], [BUSINESS ADDRESS] ("Align," "we"). For the purposes of GDPR/UK GDPR, [LEGAL ENTITY NAME] is the data controller responsible for your personal data. See Section 13, Contact for how to reach us.
2. Information We Collect
Align uses Firebase Authentication to manage sign-ins. We collect your email address (and, if you sign in with Google, your Google account name and avatar) solely for authentication. Beyond your account credentials, we collect the content you choose to give Tracy — tasks, calendar events, notes, information about people in your life, and your chat messages — because that content is what makes the Service work. We do not run advertising or third-party tracking, and we do not sell or share your data for cross-context behavioral advertising.
3. Where Your Data Is Stored
Your tasks, events, people, notes, and related entities are stored in Google Cloud Firestore, protected by security rules that make your data readable and writable only by your authenticated account. Other users cannot access it; our operators can access data only where necessary to run, secure, or support the service. In guest mode (no sign-in), your data stays on your device only — in your browser's local storage or IndexedDB — and is never sent to our servers.
4. AI Processing
When you talk to Tracy (our AI assistant), your message and limited relevant context — task titles, schedule entries, people names, and profile details you have added — are relayed through Align's own server proxy to the AI provider you have selected (Google Gemini by default; optionally OpenAI, Anthropic, Groq, or a self-hosted model you run yourself). We use our proxy so that requests can be authenticated and routed without exposing infrastructure secrets to your browser. These providers process the data under their own terms and may retain logs per their own policies. We do not store your AI conversations on our servers; your chat history is saved in your own Firestore space (or on your device only, in guest mode).
5. Your API Keys
If you supply your own AI API key, it is stored encrypted in your browser's local storage. It is sent over an encrypted (TLS) connection to our proxy endpoint with each AI request so the request can be forwarded to your chosen provider; it is never logged or stored on our servers. Treat API keys like passwords and rotate them periodically.
6. Optional Integrations
Google Calendar and Gmail import are opt-in. When connected, calendar events and email metadata are read with your permission to populate your own Align data. We request the minimum scopes needed for these features, and you can disconnect them at any time. Push notifications use your browser's push service and can be disabled in Settings or in your browser.
7. Cookies & Local Storage
We use only essential, first-party storage — Firebase Authentication keeps you signed in via IndexedDB/localStorage. We do not use advertising cookies, cross-site tracking, or third-party analytics scripts.
8. Legal Bases for Processing (GDPR)
Where GDPR/UK GDPR applies, we rely on the following legal bases:
- Performance of a contract— processing your account data and content is necessary to provide the Service you've signed up for (Art. 6(1)(b)).
- Consent — for optional features such as connecting Google Calendar/Gmail, choosing a third-party AI provider, or enabling push notifications (Art. 6(1)(a)). You may withdraw consent at any time, as described in Section 9.
- Legitimate interests — securing the Service, preventing abuse, debugging, and operating our infrastructure (Art. 6(1)(f)), balanced against your rights and interests.
9. Your Privacy Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Port your data to another service — you can export your Align data as JSONL directly from the app;
- Withdraw consent at any time for processing based on consent, without affecting processing before the withdrawal.
You can exercise most of these rights directly in the app (You → Privacy), including data export and account deletion. For anything else, contact us at [PRIVACY CONTACT EMAIL]. If you are in the EEA, UK, or Switzerland and believe we have not adequately addressed your concern, you also have the right to lodge a complaint with your local data protection supervisory authority.
10. International Data Transfers
Align and its sub-processors may process and store your data outside your country of residence, including in the United States, currently in [FIRESTORE DATA REGION]. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (or equivalent UK addendums) with our sub-processors, or the sub-processor's own adequacy / certification mechanisms.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the CCPA/CPRA gives you additional rights over your personal information:
- Categories collected: identifiers (email, account ID); and content you provide (tasks, events, notes, people information, chat messages). We do not collect sensitive personal information for profiling purposes beyond what you voluntarily enter as task/note content.
- Sale or sharing: we do not sell or share (as defined by the CPRA, including for cross-context behavioral advertising) your personal information, and have not done so in the past 12 months.
- Right to know what personal information we collect, use, and disclose;
- Right to delete your personal information;
- Right to correct inaccurate personal information;
- Right to non-discrimination for exercising any of these rights.
You can exercise these rights in-app (You → Privacy) or by emailing [PRIVACY CONTACT EMAIL]. We will verify your request using your authenticated account before acting on it.
12. Sub-processors
We rely on the following sub-processors to operate the Service. Optional sub-processors are only engaged if you choose to use the related feature.
- Google — Firebase Authentication, Cloud Firestore, and Gemini (AI provider);
- Cloudflare — hosting and edge network;
- OpenAI, Anthropic, and/or Groq — only if you select one of these as your AI provider;
- Your browser vendor's push service (e.g., Google FCM, Apple, Mozilla) — only if you enable push notifications.
13. Children's Privacy
The Service is not directed to children under [MINIMUM AGE — default 16], and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us at [PRIVACY CONTACT EMAIL] and we will delete it.
14. Security
We use industry-standard safeguards, including TLS encryption for data in transit, encryption at rest for stored data, and per-account access rules that isolate your Firestore data from other users. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
15. Data Retention & Deletion
We keep your data for as long as your account exists. Deleted items are soft-deleted for approximately 7 days to allow undo, then permanently purged. You can delete your entire account and all associated data at any time from the You → Privacy section; this permanently erases your Firestore data and your authentication account. We do not retain your data after account deletion, except where we are required to by law.
16. Changes to This Policy
We may update this policy from time to time. Material changes will update the "Last updated" date above and will be announced in-app. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
17. Contact
Questions about this policy, your data, or to exercise any of the rights described above, contact us at [PRIVACY CONTACT EMAIL] and we will respond as quickly as we can.
Data Controller: [LEGAL ENTITY NAME]
Address: [BUSINESS ADDRESS]
Email: [PRIVACY CONTACT EMAIL]
This policy is governed by the laws of [GOVERNING-LAW JURISDICTION].