Short version
We collect what we need to run AlignCube. We do not sell your data. We do not run advertising. Your tool stack data belongs to you and can be exported or deleted.
AlignCube LLC ("AlignCube", "we", "us", "our"), a Colorado limited liability company, provides AI-assisted software stack governance for spend decisions. This Privacy Policy explains how we collect, use, and protect information when you use aligncube.ai and the AlignCube web application (together, the "Service").
What we collect
We collect the minimum data needed to authenticate your account, run audits, generate recommendations, route decisions, and maintain the service.
Account Data
- Email address: used to identify your account and communicate with you.
- Password: sent to AlignCube only over HTTPS, never logged, and stored only as a salted PBKDF2-HMAC-SHA256 hash.
- Subscription tier: free or monitor, managed via Stripe.
Stack and Audit Data
- Tool names, costs, categories, and team usage information you enter during audits.
- Audit results, recommendations, and accept or reject decisions in your Decision Log.
- Company name, industry, and headcount you provide during intake.
Product Usage and Operational Events
- First-party product usage events (for example signups, audit runs, decisions) used to understand activation and improve the Service.
- Security events (login attempts, rate-limit and abuse signals) and delivery/API-cost events used to operate and protect the Service.
- Token counts for AI API calls made on your behalf, used for billing and internal cost monitoring.
Team, Sharing, and Drafts
- Organization membership and invitations when you create or join a team; shared stack records are visible to organization members.
- Public share links you choose to create for an audit: anyone with the link can view that report until it expires or you revoke it.
- Unsaved drafts kept locally in your browser (not on our servers) as you work.
Applications and waitlist
- If you apply at /apply for a done-for-you record: your name, work email, company, LinkedIn URL if given, headcount, who signs off on renewals, the tools you list, and the IP address and browser details of the submission.
- If you join a waitlist: your email address, when you joined, and which page you joined from.
- Neither creates an account. Retention is in the table below, and account deletion also removes applications and waitlist entries under your account email.
Session Data
- A session cookie issued on login to authenticate your requests. This cookie is required for signed-in use.
- A 30-day referral cookie is set only when you open a referral link, so we can credit that referral; it is cleared once you sign up.
- No advertising or third-party analytics cookies are used at launch. AlignCube records limited first-party product, security, billing, and delivery events to operate and protect the Service.
How we use your data
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing and operating the Service | Performance of contract |
| Processing payments via Stripe | Performance of contract |
| Sending account-related emails such as receipts and alerts | Performance of contract |
| Improving the Service using aggregated, non-identifiable insights | Legitimate interests |
| Complying with legal obligations | Legal obligation |
We do not use your data for advertising. We do not sell your data. We do not share individual stack or audit data with any third party except as described below.
Third-party processors
These providers help run the service. We share only the data needed for the listed purpose.
Your tool stack and chat messages are sent to Anthropic's commercial API when you invoke AI-powered AlignCube features. Anthropic does not use commercial API inputs or outputs to train models by default.
anthropic.com/privacyEmail and payment details are processed by Stripe. We never see or store your full card number.
stripe.com/privacyApplication data and the database are hosted on Railway-hosted servers in the United States. Railway's infrastructure handling is governed by its own privacy and security practices.
railway.com/legal/privacyTransactional and lifecycle emails are sent through Resend, which processes your email address and the messages we send you.
resend.com/legal/privacy-policyOur support and founder inboxes run on Google Workspace, so messages you send us are processed by Google. Our pages load fonts from Google Fonts, which receives your IP address and browser details. If our backup email route is ever used, Google also processes your email address and the messages we send you.
policies.google.com/privacyDNS, TLS, and CDN are provided by Cloudflare, which processes request metadata (such as IP address) needed to route and secure traffic.
cloudflare.com/privacypolicyDatabase backups are stored as private GitHub Actions artifacts for disaster recovery. Backups are retained for up to 90 days and then expire.
github.com privacyAnalytics are off at launch. If first-party product analytics are enabled, PostHog processes only explicit, allowlisted, non-content events with autocapture, session recording, and persistent cookies disabled. No advertising or cross-site tracking.
posthog.com/privacyWe also enable you to share data at your direction: organization members you invite can see your shared stack records, and public share links you create can be viewed by anyone who has the link. Referral credits between AlignCube users are account credits; AlignCube does not receive commissions or referral payments from software vendors.
Data retention
| Data type | Retention |
|---|---|
| Account data | Retained while your account exists. When you delete your account we remove it from active AlignCube systems after billing is safely closed. Cancelling a subscription does not delete data. |
| Audit and decision data | Retained while your account exists and removed from active systems on account deletion. |
| Database backups | Kept for up to 90 days for disaster recovery, then they expire. Restoring a backup re-applies recorded account deletions, removing the deleted account and the records it owned. |
| Applications and waitlist | Applications flagged as spam are deleted after 30 days. Other applications are deleted after 12 months unless the applicant became a customer. Waitlist entries are deleted after 12 months. Either is deleted sooner on request or when you delete your account. |
| Billing and tax records | Stripe retains payment records as required for financial and tax compliance, independent of account deletion. |
| Security and abuse records | Kept as needed to protect the Service and meet legal obligations. |
| Session tokens | Expire 30 days from issuance. |
Deletion removes your data from active AlignCube systems after billing is safely closed; limited backups and legally required records (such as billing/tax and security records) expire under the retention schedule above rather than being erased at the same instant. Provider retention: under Anthropic's commercial API terms your inputs and outputs are not used to train models by default, and Anthropic may retain API content for up to 30 days for trust-and-safety purposes. Where a submission is flagged under Anthropic's Usage Policy, inputs and outputs may be retained for up to 2 years and trust-and-safety classification scores for up to 7 years.
Cookies
A session cookie keeps you signed in. A 30-day referral cookie is set only when you open a referral link. No advertising or cross-site tracking cookies.
The session cookie is a strictly necessary cookie required for you to stay logged in and use the Service; it expires after 30 days. The referral cookie is cleared once you sign up or after 30 days, whichever comes first, and is set only if you arrive via someone's referral link.
We do not use Google Analytics, Facebook Pixel, or any third-party tracking cookies. We do not serve advertising.
Your rights
GDPR (EU/UK residents)
CCPA (California residents)
To exercise these rights, email [email protected]. We will respond within 30 days.
International data transfers
AlignCube is operated from the United States and data is hosted in the United States. We do not have Standard Contractual Clauses (SCCs) in place today, and we currently contract only with U.S.-based organizations. If your review requires a signed data processing agreement or a transfer mechanism, email [email protected].
Data security
All data is transmitted over HTTPS/TLS. Passwords are hashed with salted PBKDF2-HMAC-SHA256. Session tokens are stored in httpOnly, Secure cookies. We do not store payment card details; payment processing is handled by Stripe's PCI-DSS compliant infrastructure.
In the event of a data breach affecting personal data, we will notify the relevant supervisory authority within 72 hours where required by law, and affected users without undue delay.
Children
The Service is not directed to anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We will notify you by email and post a notice on the Service at least 30 days before material changes take effect. Continued use after the effective date constitutes acceptance.
Contact
Data controller: AlignCube LLC, a Colorado limited liability company.
Questions, export requests, and deletion requests go to the founder inbox. You can also export and delete your data yourself, without emailing us, from Usage & Plan.
[email protected]AlignCube LLC
1500 N Grant St # 7091
Denver, CO 80203
United States