← ALIVE

Privacy notice — draft

Draft for legal review. Not approved for external pilot data collection.

The current v0.1 service handles account and workspace details; server and Linux-agent inventory and heartbeat metadata; user-entered billing, usage, renewal, and currency data; audit/security events; notification preferences and delivery history; webhook destination URLs and encrypted signing keys; and early-access form details (name, email, optional company, server-count range, use case, and consent time).

ALIVE uses these data to provide the requested workspace service, authenticate accounts, deliver configured alerts, maintain audit/security history, respond to early-access requests, and prevent abuse. Workspace access is role-scoped; configured platform administrators can review early-access requests. Do not submit server credentials, agent tokens, billing account secrets, or other sensitive infrastructure details.

The current development service runs on a single VPS failure domain. A separate pilot database and secrets, hosting/subprocessor list, data-location statement, retention schedule, deletion process, and monitored privacy contact must be established before external pilot collection. There is no self-service account deletion today.

The application is designed for secure HTTPS cookies and encrypts webhook signing keys at rest; public HTTPS behavior has not yet been verified. There is no payment processor in v0.1. The current product has no data-sale feature; any formal no-sale commitment requires operator and legal confirmation.

Read the Early Access Terms Draft. The full review copy is in docs/PRIVACY_DRAFT.md.

Privacy contact: not configured.