Privacy Policy

Last updated: July 5, 2026

Introduction

This Privacy Policy explains how ARDOR 0608 OOD ("we") collects, uses, and protects your personal data when you use alphai at alphai.io (the "Service") — an AI-curated financial news platform that aggregates market-moving stories from public sources, enriches them with AI, and serves them via our website, REST API (api.alphai.io), and MCP server (mcp.alphai.io). We act as the data controller under the GDPR and applicable Bulgarian law.

  • Company: ARDOR 0608 OOD
  • Address: Azman Dere 423-3, Priselci village, 9131, Bulgaria
  • Email: info@alphai.io

Information We Collect

  • Account data: email, full name, and (if provided) a profile avatar. Passwords are hashed if you register directly.
  • Google sign-in: if you use Google OAuth, we receive your Google name, email, and profile picture.
  • Technical data: IP address, browser and device information, and server logs.
  • Payment data: handled entirely by Stripe — we never store card details, only your Stripe customer and subscription IDs.
  • Saved preferences: the tickers you add to your watchlist or subscribe to for news alerts (paid tiers). Stored with your account; not shared publicly.
  • Sales inquiries: if you submit the /contact form, we keep your name, email, use case, expected volume, and referral source to respond. Not used for marketing.

Legal Basis for Processing

  • Contract: to provide the news platform, REST API, and MCP server.
  • Legitimate interests: to secure, maintain, and improve the Service.
  • Consent: for analytics/marketing trackers and any future marketing email (opt-in only).
  • Legal obligation: to comply with applicable law.

How We Use Your Information

  • Create and manage your account and authenticate access.
  • Provide AI-curated financial news and developer access (REST API, MCP server).
  • Process subscriptions and payments via Stripe.
  • Send service emails (verification, password reset, receipts) and respond to support requests.
  • Maintain security, prevent abuse, and improve the Service.

We do not run marketing newsletters today. If we introduce them, they will be opt-in only.

News Sources & AI Enrichment

Our feed is built from publicly available sources and enriched with AI: articles come from GDELT (a public, openly accessible news index), and summaries, categories, and relevance scores (1–10) are generated using OpenAI's API. Original article links and publisher attribution are preserved on every article.

Note: news content comes from public publishers via GDELT and is processed by OpenAI. We do not guarantee its completeness, timeliness, or accuracy, and we retain the article text only for a short window needed to produce and quality-check each enrichment, after which it is removed.

Developer Surfaces (REST API & MCP)

If you use our REST API or MCP server, we also process:

  • API keys: stored only as an SHA-256 hash plus a masked prefix (e.g. ak_live_xxxx…). The plaintext is shown once at creation and never persisted; revoked keys are kept inactive for audit.
  • MCP OAuth credentials: short-lived client metadata and rotating refresh tokens (chain-reuse detection revokes the grant on replay), held in Redis with a TTL.
  • IP address: used for short-lived rate-limit buckets in Redis; not written to long-term logs except by Sentry when error tracking is enabled.

Data Sharing

We share data only with providers needed to run the Service:

  • Stripe — payment processing (handles all card data directly).
  • Google — sign-in via Google OAuth / One Tap.
  • Mailgun (EU) — transactional email (verification, password reset, sales-lead notifications).
  • OpenAI — news enrichment from public articles; no personal account data is sent.
  • GDELT — public news index we ingest from; receives no personal data from us.
  • Cloud hosting — application hosting and storage.
  • Analytics & monitoring — PostHog (EU, first-party usage) and Sentry (optional error tracking). Consent-gated trackers (Google Analytics, Tag Manager, Ads, Facebook Pixel, Yandex Metrica) load only after you accept analytics cookies.

We may also disclose data when required by law, and may transfer it as part of a merger, acquisition, or sale of assets.

International Data Transfers

Where data is processed outside the European Economic Area (EEA), we rely on appropriate safeguards — Standard Contractual Clauses or European Commission adequacy decisions.

Data Retention

  • Account data: kept while your account is active; deleted within 30 days of a deletion request (aggregated, non-identifying analytics may remain).
  • Payment data: retained as required by financial law (typically 7 years).
  • Technical logs: up to 12 months.

Your GDPR Rights

You have the right to access, rectify, erase, restrict, or port your data, to object to processing based on legitimate interests, and to withdraw consent at any time. To exercise any of these, email info@alphai.io with the subject "Data Protection Request"; we respond within 30 days. You may also lodge a complaint with the Bulgarian Commission for Personal Data Protection (cpdp.bg) or your local supervisory authority.

Data Security

We protect your data with encryption in transit and at rest, need-to-know access controls, bcrypt password hashing, and JWT-based sessions with rotating refresh tokens. Two-factor authentication is not currently offered.

Minors

The Service is not intended for anyone under 16. We do not knowingly collect data from minors and will delete it if we become aware of it.

Changes to This Policy

We may update this policy periodically and will post the revised version here, updating the date above. Continued use after changes take effect constitutes acceptance.

Contact

ARDOR 0608 OOD

  • Address: Azman Dere 423-3, Priselci village, 9131, Bulgaria
  • Email / DPO: info@alphai.io

Supervisory Authority

Commission for Personal Data Protection (Bulgaria)

  • Website: www.cpdp.bg
  • Email: kzld@cpdp.bg