Privacy Policy
Last updated: August 4, 2026
What Alexandria is
Alexandria provides instructions that your own AI uses to build and read a detailed mirror of your thinking. The private mirror is stored as plain files on your computer. An optional hosted connector lets compatible loops use the Library, Marketplace, membership, and publishing features.
Your private mirror stays private
Your private files — including your constitution, vault, marginalia, transcripts, and notes — stay on your device. Alexandria has no endpoint that accepts them and cannot read or retrieve them. Backups are optional and go only to accounts you control if you choose to enable them.
This promise covers the private mirror. Information you deliberately publish, feedback you submit, and the connector records described below do reach services we operate.
What the hosted connector stores
Account and billing records. Your GitHub ID and login, email address, billing status, and Stripe customer or subscription identifiers. Account records are encrypted at rest.
Authentication records. A SHA-256 hash of your Alexandria API key; the raw key stays on your machine. Short-lived browser session and onboarding tokens are also stored when those flows are used.
Service activity. A 60-day log of which Alexandria endpoints your account used and when; module IDs your loop calls, with any notes you explicitly attach; Library publishing, access, purchase, and account events; and install-status or feedback text you explicitly submit.
Content you publish. Files, works, quizzes, profile details, and other material you deliberately send to the Library, together with their titles, access settings, prices, and file metadata.
Website analytics
We use Vercel Web Analytics for aggregate page views, referrers, country or region, browser, operating system, and device type. Vercel says this service uses no cookies, stores anonymised data, and resets its visitor-identification hash every 24 hours. We do not use advertising trackers or cross-site fingerprinting. Read Vercel’s analytics privacy documentation.
Payments
Stripe processes payments. Alexandria does not receive or store complete card numbers. Stripe receives the information needed to process the payment and keeps it under Stripe’s privacy policy.
Retention
Account records stay while your account is active. Endpoint event logs expire after 60 days. Mobile-onboarding records expire after 90 days. Module-call, Library activity, transaction, and submitted-feedback records do not currently expire automatically. Published content stays until you unpublish it or delete your account; unpublishing cannot recall copies someone already downloaded or shared. We may retain records when required for security, fraud prevention, payments, disputes, or law.
Your choices and rights
Your private mirror is already portable: ordinary files you can read, edit, move, or delete. Deleting ~/alexandria/ removes the local loop but does not delete an optional hosted account.
Depending on where you live, you may have rights to know or access personal data, correct it, delete it, receive a portable copy, restrict or object to processing, and appeal a decision. We do not sell personal information or share it for cross-context behavioural advertising.
To exercise a right, delete an account, or ask us to remove submitted feedback, email benmowinckel@gmail.com. We may need to verify your identity. We will answer within the period required by applicable law.
Contact
Benjamin a. Mowinckel — benmowinckel@gmail.com