Skip to content
AlpineDataWorks.AI
Legal

Privacy Policy

Last updated: July 20, 2026

1. Overview

AlpineDataWorks.AI ("we," "us," or "our") respects your privacy. This policy explains what information we collect when you visit our website, use our API Services, or connect AlpineDataWorks.AI as an AI connector (for example, through Claude or another Model Context Protocol client), how we use it, and your rights with respect to it. It applies to all AlpineDataWorks.AI products.

2. Information We Collect

2a. Information you provide

When you sign up, request API access, or fill out the contact form, we collect your name, work email address, company name, and any use-case description you submit.

2b. Usage and technical data

Our servers log API and connector requests including the data product called, timestamp, response latency, and HTTP status code, so we can meter usage, bill accurately, and detect abuse. We do not log the substance of the data we return beyond what is necessary for debugging and billing.

Agent and connector discovery traffic (unauthenticated calls that list what tools exist) is logged with a coarse country and a truncated user-agent string only — not a raw IP address. Standard website visits may generate ordinary web server logs (including IP address, user-agent, and referring URL) retained for up to 90 days for security and abuse prevention. Where we retain an IP for audit purposes, it is stored as a salted, non-reversible hash rather than in the clear.

2c. Cookies

We use a single functional cookie to remember your light/dark theme preference. We do not use third-party advertising cookies or cross-site tracking cookies.

3. AI Connectors & OAuth Authorization

When you connect AlpineDataWorks.AI as a connector inside an AI client such as Claude, you authorize the connection through OAuth 2.1 (with PKCE). We store an authorization grant — an access token and a refresh token — bound to your account, encrypted at rest.

  • We receive only the tool calls your AI agent makes on your behalf — which data product was requested and its parameters (for example, a ZIP code or ticker). We do not receive the content of your conversations with the AI client, and we do not access the client's memory or chat history.
  • Connector usage is metered against your plan, the same as direct API usage.
  • You can revoke a connection at any time from your User Hub or by emailing us; revoking immediately invalidates the stored tokens. Revoked and expired grants are deleted.

4. How We Use Your Information

  • To provision and maintain your API and connector access.
  • To meter usage and bill accurately.
  • To respond to support requests and legal inquiries.
  • To monitor service health, detect abuse, and enforce the Acceptable Use Policy.
  • To send product updates, only to users who have requested them. You may unsubscribe at any time.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

5. Data Sharing & Subprocessors

We may share information with subprocessors who help us operate the Services (cloud hosting and edge compute, email delivery, and payment processing). Each subprocessor is bound by a data-processing agreement with at least equivalent protections. A current list of subprocessors is published on our Security page. We may also disclose information when required by law, regulation, or valid legal process.

6. International Transfers & Legal Basis

We operate on globally distributed edge infrastructure, so your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers. Our legal bases for processing include performance of our contract with you, our legitimate interest in operating and securing the Services, and your consent where applicable. Business customers who require a Data Processing Addendum (DPA) may request one at [email protected].

7. Data Retention

We retain account information for as long as your access is active, plus 12 months after termination to resolve disputes and comply with legal obligations. Web server logs are purged on a rolling 90-day cycle. OAuth connector grants are retained until you revoke them or they expire, then deleted. You may request deletion of your personal data at any time; see Section 9.

8. Security

We use TLS for all data in transit. API keys are hashed at rest and OAuth grants are encrypted at rest. Access to production systems is restricted to named personnel. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security. See our Security page for details and how to report a vulnerability.

9. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, port, or delete the personal information we hold about you. To exercise any of these rights, contact us at the address below. We will respond within 30 days.

10. Children's Privacy

The Services are not directed at individuals under 18. We do not knowingly collect personal information from minors. If we learn that we have done so, we will delete it promptly.

11. Changes to This Policy

We may update this policy as the Services evolve. We will post the revised policy on this page and update the "Last updated" date. For material changes, we will notify active users by email.


Privacy questions? Contact us and we will respond within 5 business days.