Our Privacy Policy is the plain-language statement of what we collect and the choices you have. This page is the operational and technical detail behind it: the data lifecycle, the access model, and our vendor flows. Where this page says “audit,” it means an operational and financial profit diagnostic — not a statutory or GAAP financial-statement audit or attestation.
On this page
Data classification
We handle several kinds of data at different sensitivity levels. The most sensitive material is business data our clients entrust to us; the least sensitive is marketing data captured on our funnel pages, which is kept apart from the application.
Business-sensitive
Operational & financial data
Engagement metadata, checklist responses, automated check verdicts and findings. Treated as confidential and scoped to the owning organization.
Most sensitive
Uploaded documents
Business and financial documents a client uploads. Held in private storage, processed server-side, and never sent to the AI assistant.
Lower sensitivity
Account & marketing data
Account and profile details for portal access, and — separately — funnel lead data captured on marketing pages, kept apart from the application.
What data we hold
This map shows each category of data, where it lives, whether AI processes it, and whether a person reviews it.
| Category | Where it lives | AI processed? | Human reviewed? | Notes |
|---|---|---|---|---|
| Account / profile name, email, role, org | Profiles + Supabase Auth | Organization name only | Staff manage | — |
| Organization info | Organizations | Name only to assistant | Yes | — |
| Engagement metadata status, dates, day target | Engagements | Yes (status / timeline) | Yes | — |
| Audit intake / checklist | Checklist items | Labels + status to assistant | Yes | The questionnaire. |
| Uploaded documents business / financial | Documents + private Storage | Contents not sent; engine processes server-side | Validated + staff review | Sensitive. |
| Document check verdicts | Document checks | Verdict label to assistant | Yes | Deterministic checks. |
| Audit findings leak zones, ranges, confidence | Findings | Engine-produced, zone-agent scored | Publish gate + audit-team estimate | Only source of client-facing numbers. |
| Deliverables / reports | Deliverables (private bucket) | No | Published by staff | — |
| Messages | Messages | — | Staff / client | — |
| Activity events | Events (append-only) | — | — | Auditability. |
| Funnel lead data name, email, phone, company, revenue bracket, trucks | Typeform → webhook → Meta (hashed) | No | — | Marketing only, separate from the app. |
Data lifecycle
Business data follows the same path from the moment it is submitted to the moment it is removed.
- 1CollectionYou submit account details, checklist responses and documents through the portal, or lead details through a marketing form.
- 2UseData is used to run your engagement: to prepare, analyze and deliver your profit diagnostic.
- 3AccessReads are constrained by row-level security and role separation, so data is reachable only within its own organization and role.
- 4AI processingOnly minimized metadata is included in model requests; document contents and financial figures are not sent.
- 5Human reviewThe audit team reviews analysis and controls the publish gate before any finding or number reaches a client.
- 6StorageRecords are held in a managed database; uploaded files sit in private storage reachable only through short-lived signed URLs.
- 7RetentionData is kept for as long as it is needed for the engagement and our record-keeping, within the framework below.
- 8DeletionData can be soft-deleted or purged through the mechanisms described below, on request or at end of life.
Access model
Access follows a least-privilege principle: a request can reach only the data its owner and role permit, and privileged operations run on the server rather than in the browser.
- Row-level security, enabled and forced on every table, default-deny. Reads are scoped by the caller’s identity and organization, so another tenant’s data is simply invisible.
- Role separation. Client and staff / auditor roles are distinct, with staff-only operations and staff-only contexts.
- Private file storage, signed-URL only. Document and deliverable buckets are not public; files are reached only through short-lived signed URLs.
- Controlled writes through server-side routines. Sensitive writes go through defined, security-checked server routines rather than open table access.
AI processing
AI is applied to a deliberately minimized slice of engagement data, and never to document contents. Model requests carry labels and statuses — for example the organization name, the engagement stage, checklist labels, uploaded file names and their check verdicts — not the underlying documents or financial figures. Findings are engine output, and the portal assistant is barred from stating any numbers.
The controls around model use — the publish gate, data minimization, the metadata-only assistant, provider governance, auditability and usage caps — are described in full on our AI Governance page.
Human review & controlled writes
The step that puts a number in front of a client is a human, server-side action — not something a model or a browser session can do on its own.
- The publish gate. A client can read only their own organization’s published findings; unpublished rows are invisible even inside the right tenant. Publishing is a server-side step that also records an audit event.
- Findings are service-role writes. Findings are engine output; no signed-in session — staff included — can insert, update or delete them directly. Those privileges are revoked.
- Append-only auditability. Significant actions are recorded in an append-only event log, with client-visible events whitelisted.
Vendor data flows
We share the minimum necessary data with the service providers that process it on our behalf. The table below is a summary; the authoritative, current list is our Subprocessors page.
| Provider | Purpose | Data | Class |
|---|---|---|---|
| Vercel | Web + serverless hosting | Requests, funnel API payloads | Critical |
| Supabase | Database, Auth, file Storage, Edge Functions | All application data | Critical |
| Anthropic | AI model provider (Claude Haiku 4.5) | Minimized engagement metadata | Critical (AI) |
| Meta (Facebook) | Pixel + Conversions API — ad measurement | Hashed contact data + technical ids | Marketing (funnel) |
| Typeform | Funnel lead form | Lead form responses | Marketing (funnel) |
| Calendly | Funnel call scheduling | Name / email / time on booking | Marketing (funnel) |
| Google Fonts | Serves the Inter webfont | Visitor IP (no cookie) | CDN |
Core application data is hosted with Supabase in the United States (AWS us-east-1); other processing locations are provider-dependent — see our Subprocessors page. Marketing providers apply to the funnel pages only and are separate from the client application.
Ownership & export
You own the data you provide. The documents you upload and the information you submit remain yours; we process them to deliver your engagement, and we do not sell your personal information.
Published deliverables and reports are provided to you as part of the engagement. Where applicable, you can request a copy of the information we hold about you by contacting us. A self-serve export tool is not offered today, so we handle these requests directly.
Encryption & transport
- In transit: data is encrypted in transit (TLS) across the website, database and APIs.
- At rest: encryption at rest is provided by our infrastructure providers (the managed database, storage and hosting platforms).
We describe transport protection at this level deliberately and do not claim specific ciphers or key lengths.
Retention
We keep information for as long as it is needed to run your engagement and to meet our record-keeping and advertising-measurement needs. Rather than publish fixed day counts we cannot yet commit to, we describe retention as a framework with the mechanisms that enforce it:
- Soft delete for documents, which removes a file from active use while preserving auditability;
- Organization purge, which removes an organization’s data at end of life.
Retention periods vary by data category and business requirement. Alpha Scaling is formalizing category-specific retention schedules.
Deletion
Two deletion mechanisms exist in the platform:
- Soft delete of a document marks a file as deleted through a server-side routine, taking it out of active use and out of the assistant’s context while keeping the audit trail intact.
- Organization purge removes an organization’s data. A purged organization resolves to no identity, so deactivated members lose access to findings and everything else along with it.
To request access to, correction of, or deletion of your data, email edward@alpha-scaling.com.
Contact & legal details
Data questions, access & deletion
Contact edward@alpha-scaling.com for data, privacy, vendor or subprocessor questions.
Alpha Scaling’s corporate legal details — including our registered legal entity name, address, and governing-law jurisdiction — are being finalized and will be stated in our Terms of Service once confirmed.