alexandria.

Privacy Policy

Last updated: August 4, 2026

What Alexandria is

Alexandria provides instructions that your own AI uses to build and read a detailed mirror of your thinking. The private mirror is stored as plain files on your computer. An optional hosted connector lets compatible loops use the Library, Marketplace, membership, and publishing features.

Your private mirror stays private

Your private files — including your constitution, vault, marginalia, transcripts, and notes — stay on your device. Alexandria has no endpoint that accepts them and cannot read or retrieve them. Backups are optional and go only to accounts you control if you choose to enable them.

This promise covers the private mirror. Information you deliberately publish, feedback you submit, and the connector records described below do reach services we operate.

What the hosted connector stores

Account and billing records. Your GitHub ID and login, email address, billing status, and Stripe customer or subscription identifiers. Account records are encrypted at rest.

Authentication records. A SHA-256 hash of your Alexandria API key; the raw key stays on your machine. Short-lived browser session and onboarding tokens are also stored when those flows are used.

Service activity. A 60-day log of which Alexandria endpoints your account used and when; module IDs your loop calls, with any notes you explicitly attach; Library publishing, access, purchase, and account events; and install-status or feedback text you explicitly submit.

Content you publish. Files, works, quizzes, profile details, and other material you deliberately send to the Library, together with their titles, access settings, prices, and file metadata.

Website analytics

We use Vercel Web Analytics for aggregate page views, referrers, country or region, browser, operating system, and device type. Vercel says this service uses no cookies, stores anonymised data, and resets its visitor-identification hash every 24 hours. We do not use advertising trackers or cross-site fingerprinting. Read Vercel’s analytics privacy documentation.

Payments

Stripe processes payments. Alexandria does not receive or store complete card numbers. Stripe receives the information needed to process the payment and keeps it under Stripe’s privacy policy.

Retention

Account records stay while your account is active. Endpoint event logs expire after 60 days. Mobile-onboarding records expire after 90 days. Module-call, Library activity, transaction, and submitted-feedback records do not currently expire automatically. Published content stays until you unpublish it or delete your account; unpublishing cannot recall copies someone already downloaded or shared. We may retain records when required for security, fraud prevention, payments, disputes, or law.

Your choices and rights

Your private mirror is already portable: ordinary files you can read, edit, move, or delete. Deleting ~/alexandria/ removes the local loop but does not delete an optional hosted account.

Depending on where you live, you may have rights to know or access personal data, correct it, delete it, receive a portable copy, restrict or object to processing, and appeal a decision. We do not sell personal information or share it for cross-context behavioural advertising.

To exercise a right, delete an account, or ask us to remove submitted feedback, email benmowinckel@gmail.com. We may need to verify your identity. We will answer within the period required by applicable law.

Contact

Benjamin a. Mowinckel — benmowinckel@gmail.com

Terms of Service