Alapon — Privacy Policy
DRAFT. Not reviewed by a lawyer. Do not publish this as-is.
Every [SQUARE BRACKET] is a fact only the owner can supply. Bangladeshi
counsel must review this against PDPA 2026 before launch, and a native Bangla
speaker must produce the Bangla version — machine translation is not acceptable
for a document people rely on.
Draft prepared: 2026-09-13 · Last updated: [PUBLISH DATE] · Effective: [PUBLISH DATE]
Alapon is operated by LeadRescue LLC, [REGISTERED ADDRESS — required; a policy
without a real address is not a valid notice], contactable at
saul@sitesbysaul.com .
The short version
- We store your email, your conversations, and anything you explicitly save.
- Memory is off unless you turn it on. If you never touch it, we remember
nothing about you between conversations.
- We do not train AI models on your conversations. That setting exists, it
is off, and it cannot default to on.
- Uploaded documents are deleted automatically after 30 days.
- You can delete your account from inside the app, and it takes effect
immediately.
- Two things survive deletion: security logs and safety records. They are
described in full below rather than buried, because you should not discover
them after asking us to delete your data.
What we collect
You give us
| What | Why | How long |
|---|---|---|
| Email address | To identify your account and let you sign in | Until you delete your account |
| Password | To sign you in. Stored as an Argon2id hash — we cannot read it or recover it, only check it | Until you delete your account |
| Your messages and Alapon's replies | To show you your conversation history and to answer your next question in context | Until you delete the conversation or the account |
| Saved memories | Only what you explicitly add. Off by default | Until you delete them |
| Uploaded documents | So Alapon can answer questions about them and cite them | 30 days, then deleted automatically |
| Language and script preference | So replies come back in the script you write in | Until you delete your account |
Created as you use it
| What | Why | How long |
|---|---|---|
| Usage records (token counts, timestamps, which model) | To enforce your plan's daily limit and to control cost. Contains no message content | 12 months, then deleted [OWNER: confirm — long enough for a billing dispute, short enough to be defensible] |
| Subscription status and a Google Play purchase token | To know which plan you are on | While the subscription exists, plus 24 months for billing and tax records [OWNER: confirm against your accountant] |
| Security events (sign-ins, failed sign-ins, session reuse) | To detect someone attacking your account | See "what survives deletion" |
| Safety records | Only when a message is blocked or specially handled. Ordinary messages are never recorded here | See "what survives deletion" |
What we never collect
- Payment details. Subscriptions are handled entirely by Google Play. We
never see your card, and we cannot charge you — only Google can.
- Your contacts, location, photos, or other apps.
- Advertising identifiers. There is no advertising and no third-party tracking
in the app.
What survives account deletion, and why
When you delete your account we immediately remove your conversations, your
messages, your memories, and your uploaded documents; we sign out every device;
and we scramble your email address so it is not kept in readable form and so you
can sign up again with it.
**Two records remain, attached to an account number that no longer identifies
anyone:**
1. Security logs — sign-ins, failed sign-ins, and session-token reuse. If
these could be erased by deleting an account, someone who broke into your
account could erase the evidence of having done so. That would make you less
safe, not more private.
2. Safety records — only for messages that were actually blocked or
specially handled, never ordinary conversation. Each holds a short excerpt
(at most 300 characters) so that a person reviewing an appeal has enough to
judge it fairly.
Neither holds your conversations. We consider this the honest trade: a small,
named exception in exchange for logs that cannot be tampered with. If you object
to it, please do not create an account.
Where your data goes
Alapon uses an AI model to generate replies. **Your messages are sent to that
model provider to produce an answer.**
- Provider: [PROVIDER NAME]
- Where they process it: [COUNTRY / REGION]
- What they do with it: [RETENTION AND TRAINING TERMS — this must be quoted
from the provider's own published terms, not summarised from memory]
This means your messages leave Bangladesh for processing. Bangladeshi
counsel must confirm what PDPA 2026 requires us to tell you and to obtain from
you before this is switched on. [COUNSEL TO CONFIRM — blocking.]
Apart from that provider and Google Play (for subscriptions), we do not share,
sell, rent, or trade your data with anyone. There are no advertisers and no data
brokers involved in this product.
Training
We do not use your private conversations to train or tune AI models.
There is a setting for contributing conversations to improvement. It is off. It
cannot be on by default, and turning it on has to be a deliberate act by you,
with a plain explanation of what it means at the moment you do it.
Your rights
From inside the app, at any time:
- See everything we hold — Settings gives you a full export of your data.
- Delete your account — Settings → Delete my account. It takes effect
immediately.
- Delete individual items — any conversation, any memory, any document.
- Turn memory off — and clear everything already remembered.
You do not need to email us or wait for us to act. If you would rather write to
a person, saul@sitesbysaul.com.
Under PDPA 2026 you may have further rights, including correction and complaint
to a regulator. **[COUNSEL TO COMPLETE — the specific rights and the regulator's
name and contact.]**
Security
- Passwords are hashed with Argon2id and are never stored in a readable form.
- Sign-in sessions expire and rotate; reusing an old session token invalidates
the whole chain, which is what makes a stolen token useless.
- All traffic between the app and our servers is encrypted (HTTPS). The app
refuses to send anything over an unencrypted connection.
- Uploaded files are scanned for malware before being processed.
- No AI provider key is ever stored on your phone.
We do not claim to be unbreakable. If you find a security problem, please write
to saul@sitesbysaul.com — we would much rather hear from you than not.
Children
Alapon is not intended for children under 18. [OWNER/COUNSEL: 18 is the
conservative choice and the one to default to. Going lower pulls the app into
Play's Families policy and adds parental-consent duties under PDPA 2026 — more
obligation, for an audience that is not the paying market.] We do not knowingly collect data from
them. If you believe a child has created an account, contact saul@sitesbysaul.com and
we will delete it.
Important: Alapon is not a professional
Alapon is an AI assistant. It can be confidently wrong. It is not a doctor,
a lawyer, an accountant, or a counsellor, and nothing it says is professional
advice.
If you are in danger or thinking about harming yourself, please contact local
emergency services or a crisis line. Alapon will try to point you to one, but
it is software and it is not a substitute for a person.
Alapon is an independent product. It is not made by, affiliated with, or
endorsed by OpenAI, Google, Anthropic, or any other AI company, whichever model
happens to be generating a reply.
Changes
If we change this policy we will update the date at the top and tell you in the
app before the change takes effect. We will not quietly widen what we collect.
Contact
LeadRescue LLC, [REGISTERED ADDRESS] · saul@sitesbysaul.com