Altiora LLC (Republic of Armenia) is the data controller for personal data processed through app.aialtiora.com and Altiora Desktop.
1. What we collect
| Data | Why | Basis |
|---|---|---|
| Email address, password (stored only as a PBKDF2 hash) | To create and secure your account | Contract |
| Organisation name, team membership | To separate your workspace from other customers' | Contract |
| Prompts, files and generated output | To run the work you asked for | Contract |
| Usage records: model, token counts, cost, timestamps | To bill accurately and show you what you spent | Contract |
| API keys you add (BYOK) | To call providers on your behalf; encrypted at rest | Contract |
| IP address and login events | To detect brute-force attempts and abuse | Legitimate interest |
| Payment details | Handled entirely by Paddle — we never receive card numbers | Contract |
2. What we do not do
- We do not sell personal data.
- We do not use your content to train models — ours or anyone else's.
- We do not run advertising or third-party tracking pixels on the application.
- We never see your full payment card details.
3. Who we share it with
Only the processors needed to run the Service:
| Processor | Purpose | Data reaching them |
|---|---|---|
| Model providers you use (e.g. Anthropic, OpenAI, Google, Mistral, DeepSeek, xAI, Groq, Perplexity) | To generate the output you requested | The prompt and files you submit for that request |
| Paddle.com Market Ltd | Merchant of Record: payment, invoicing, tax | Billing details you enter at checkout |
| DigitalOcean | Hosting and storage | Data at rest on our servers |
| Our email provider | Transactional email (password resets, billing notices) | Your email address |
Requests go only to the provider whose model you or your routing configuration selected. In BYOK mode the request is made with your own credentials.
We may disclose data where legally required, and will inform you unless prohibited from doing so.
4. International transfers
Our servers are in the European Union. Model providers and Paddle may process data in the United States and elsewhere. Where personal data leaves the EEA or the UK, transfers rely on Standard Contractual Clauses or an adequacy decision.
5. How long we keep it
- Account data — while the account exists, then deleted within 30 days of closure.
- Projects, prompts and output — until you delete them, or 30 days after account closure.
- Usage and billing records — retained as long as tax and accounting law requires, typically several years.
- Security logs — up to 12 months.
- Password-reset tokens — one hour, single use, stored only as a hash.
6. Security
- All traffic is served over TLS.
- Passwords are stored as salted PBKDF2 hashes; we cannot read them.
- Provider API keys are encrypted at rest.
- Each organisation's data is isolated, and access is checked on every request against the requester's organisation.
- Login and password-reset endpoints are rate-limited and lock out after repeated failures.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant supervisory authority as required by law.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, export or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. Write to hello@aialtiora.com and we will respond within 30 days. If you are in the EEA or the UK you may also complain to your local data-protection authority.
8. Cookies
The application sets one strictly necessary cookie: your session identifier, which keeps you signed in. It is HttpOnly and SameSite=Lax. We use no advertising or analytics cookies, so there is no consent banner to click.
9. Children
The Service is not intended for anyone under 18, and we do not knowingly collect their data.
10. Changes
We will announce material changes by email or in the app at least 14 days before they take effect.
11. Contact
Altiora LLC
Republic of Armenia
Email: hello@aialtiora.com
Phone: +374 41 888 911