
bh
Privacy Policy
h
1. Who we are
Alta Labs, Inc. (“Alta,” “we,” “us,” or “our”) operates the Alta website, web application, and any associated services (collectively, the “Service”) available at https://altalabs.co.
Contact
Email (all privacy matters): support@altalabs.co
Mailing address: [Alta Labs, Inc., 251 Little Falls Dr., Wilmington, DE 19808, USA]
Privacy Officer / DMCA Agent: [Full name] - [phone]
2. Information we collect
CategoryExamplesSourceLegal Basis (GDPR)Typical RetentionAccount dataName, email, username, password hash, auth-provider IDsYouContract Art. 6 (1)(b)While account active + 30 daysUser-generated content (UGC)Stories, prompts, images, commentsYouContract / Legit. interestUntil deleted by you or 24 months after account closureDevice & usage dataIP address, browser type, OS, interaction events, cookiesYour deviceLegit. interest26 months (Google Analytics default)Payment dataCard last-4, billing address (processed by Stripe)You / StripeContract / Legal obligation7 years (IRS)AI model inputs/outputsPrompt text, generated story segmentsYou / ServiceContract / Legit. interest90 days; then aggregated & de-identified
We do not knowingly collect data defined as “sensitive” under CCPA/CPRA, GDPR, or HIPAA.
3. How we use your information
Provide, maintain, and secure the Service (authentication, fraud prevention, load balancing).
Generate collaborative content via third-party large language model (LLM) APIs (e.g., OpenAI, Anthropic). Prompts are transmitted to those processors.
Improve and debug our models and algorithms using de-identified logs.
Communicate with you (transactional emails, feature updates, newsletters if you consent).
Comply with applicable laws, regulations, and legal process.
We will request your consent before using your data for any purpose not covered above.
4. Sharing and disclosure
RecipientPurposeSafeguardsCloud infrastructure (AWS us-east-1)Hosting, storageSOC 2, ISO 27001, SCCsAI vendorsText generationData Processing Addenda; prompts excluded from vendor model trainingPayment processor (Stripe)Billing & refundsPCI-DSS Level 1Analytics services (Google Analytics 4, PostHog)Product analyticsIP masking; opt-out via cookie bannerLaw enforcement or regulatorsLegal complianceDisclosure only on valid subpoena or court orderSuccessor entityMerger, acquisition, bankruptcyPrior notice + opt-out (EU/UK)
We do not “sell” or “share” personal information as those terms are defined by the California Consumer Privacy Act (CCPA/CPRA).
5. Cookies & tracking
We use first-party cookies for session integrity and preferences, plus third-party cookies for analytics. You can manage cookies via the banner shown on first visit and in your browser settings.
6. Your rights
JurisdictionYour rightsEU/EEA & UKAccess, rectification, erasure, restriction, portability, objection, complain to supervisory authorityCalifornia (CCPA/CPRA)Know, delete, correct, opt-out of “sale/share,” limit sensitive PI, non-discriminationVirginia, Colorado, Connecticut, UtahAccess, correct, delete, opt-out of targeted ads / profiling
Submit requests by emailing support@altalabs.co or via Settings → Privacy. We will verify your identity before processing.
7. Security
TLS 1.3 encryption in transit
AES-256 encryption at rest (RDS & S3)
Role-based access controls and MFA for staff
Annual third-party penetration tests + continuous vulnerability scanning
Bug-bounty program (launching soon at hackerone.com/alta)
8. International transfers
We are headquartered in the United States. When transferring personal data from the EEA, UK, or Switzerland, we rely on:
Standard Contractual Clauses (SCCs);
Encryption and pseudonymisation; and
Risk assessments consistent with Schrems II guidance.
9. Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect their data. If you are a parent or guardian and believe a child has provided us personal information, email support@altalabs.co to request deletion.
10. Data retention
We keep personal data only as long as necessary for the purposes described above, unless a longer retention period is required by law (e.g., tax, accounting, or audit obligations).
11. Changes to this policy
If we make material changes, we will notify you by email and/or a banner at least 30 days before the new policy takes effect. Minor textual updates will be logged at the top of this page.
12. Contact us
Questions or concerns? Email support@altalabs.co or write to [Alta Labs, Inc., address above].