Privacy

Privacy Policy

Alicorn is built so that most of your work never reaches us: agents run on your own machines and call models through your own gateway. This policy covers the rest: what our hosted service and this website hold, why, and what you can ask of us.

Effective date: 2 October 2026 · Last updated: 2 October 2026

1. Who we are

Alicorn is made by 8Seneca, a company based in Vietnam ("8Seneca", "we", "us"). This policy applies to the Alicorn service that 8Seneca hosts (the web app, desktop app, mobile app, CLI and the control plane behind them) and to this website.

If your organisation runs Alicorn on its own infrastructure, your organisation operates that installation and its own privacy notice applies to it, not this one.

2. Our role under the GDPR

The EU General Data Protection Regulation (GDPR) is the main framework for this policy.

  • 8Seneca is the controller for account and sign-in data, billing data and this website. We decide why and how that data is used.
  • 8Seneca is a processor for the content your organisation puts into Alicorn: projects, tasks, comments, requirements, workflow and gate data, knowledge, time and cost data. Your organisation is the controller of that content, and we process it only on its instructions, under our Data Processing Addendum.

If your question is about content inside an organisation, for example a task that mentions you, ask that organisation first. It decides what happens to that content.

3. What we collect and why

Account and sign-in. We use this to give you an account and keep it safe.

  • Your email address, name, an account identifier, and which sign-in method you use. You sign in with an email link, or with Google or Microsoft if you choose to. If you use Google or Microsoft, we receive your name, email address and an identifier from them. None of these methods gives us a password.
  • Sign-in events: when a sign-in link is sent and used, and the network address that asked for it. We use these to limit how many links can be sent, against abuse.
  • Your organisations, your role in each (Owner, Admin, Member or client guest), your seat, and any role you have been given on a project or stage.

Organisation and billing. We use this to run and bill the plan.

  • The organisation's name and address in Alicorn (its slug), plan, number of seats, billing country, and, if given, a VAT or tax ID and purchase-order number.
  • If you pay online, Paddle takes the payment. We receive subscription and transaction references and the payment status; we never see or store card details.

Content your organisation adds. We process this for your organisation, to provide the service it uses.

  • Projects, tasks, comments, requirements, workflow state, gate decisions, sign-offs and invitations.
  • Knowledge: facts, decisions and glossary entries, the search index built from them, and documents you upload for extraction.
  • Time entries, and cost and rate data where your organisation records them.
  • Assistant conversations, where your organisation keeps their history.
  • Runner records: which machines are enrolled, their status, and basic health such as memory and disk use.
  • The settings of the connections your organisation makes (for example its git host, chat or work tracker). We store the name of each secret, never the secret's value.
  • If you use the mobile app with notifications on, a device token to deliver them.

Records of what happened.

  • The measurement ledger: an append-only record of what ran, what verified it and what was decided, used for reports and to measure how often people are interrupted.
  • An audit log of access changes, connection changes and every look at people-cost data.

What we do not receive.

  • Agent work runs on your organisation's own machines (runners). Your source code is worked on there, not on our servers.
  • We host no AI model and hold no model key. Model calls go from your machines through a gateway your organisation runs, to model providers your organisation contracts with. Prompts and model answers do not pass through us.
  • An agent run's transcript stays on the runner that ran it.

This website.

  • This website sets no cookies and runs no analytics or advertising scripts. Our network provider sees the standard request data (your IP address, browser and the page asked for) to deliver the page and protect it from attacks.

4. Cookies and browser storage

  • This website: no cookies.
  • The web app: the sign-in service sets cookies that keep you signed in, and the app keeps your session and a few preferences (such as the organisation you last opened) in your browser's storage. These are strictly necessary for the service you asked for, so they need no consent. We use no analytics, advertising or tracking cookies.

5. Legal bases

Where 8Seneca is the controller, we rely on these GDPR legal bases (Art. 6(1)):

  • Contract: to create your account, sign you in, run your organisation's service and bill for it.
  • Legitimate interests: to keep the service secure (rate limits, sign-in events, the audit log), to keep a reliable record of decisions, and to answer you when you contact us. We weigh these against your rights, and you can object (section 10).
  • Legal obligation: to keep billing and tax records, and to answer lawful requests.

For content your organisation adds, your organisation chooses the legal basis as controller.

6. Sub-processors and other recipients

We share personal data only with the providers below, only for the purpose shown, and never sell it. Your organisation's own connections (its git host, chat, work tracker, finance system and model gateway) are chosen and contracted by your organisation, not by us.

ProviderPurposeDataLocation
RailwayHosting of the control plane: database, sign-in service, API, relay, web app and file storageAll data the service holdsSingapore (Railway region asia-southeast1); Railway is a United States company
ResendSending sign-in links and invitationsEmail address, organisation name, the email's contentUnited States
PaddleOnline payment, as merchant of record (Paddle is the seller and handles tax)Billing contact, billing address, payment details, tax IDUnited Kingdom
CloudflareDelivering and protecting this website (network, DNS, TLS)IP address and request dataGlobal network; United States company
GitHubStoring desktop app releases, which downloads and updates are served fromIP address and request dataUnited States
Google (optional)Sign-in, only if you choose Continue with GoogleName, email address, account identifierUnited States
Microsoft (optional)Sign-in, only if you choose Continue with MicrosoftName, email address, account identifierUnited States

Paddle, Google and Microsoft also act as independent controllers for the accounts you hold with them, under their own privacy policies. We may also disclose data where the law requires it. If 8Seneca's business is sold or merged, data would pass to the new owner under this policy.

7. International transfers

The service is hosted in Singapore, 8Seneca is based in Vietnam, and several providers above are in the United States or the United Kingdom. When personal data from the European Economic Area leaves it, we rely on:

  • an EU adequacy decision, for the United Kingdom;
  • the EU–US Data Privacy Framework, for a US provider certified under it;
  • otherwise, the European Commission's Standard Contractual Clauses (2021), with the safeguards they require. This covers our hosting in Singapore and transfers to 8Seneca in Vietnam, since neither country has an EU adequacy decision.

You can ask us for a copy of the safeguards that apply (section 15).

8. How long we keep data

  • A sign-in link works once, for 10 minutes. An invitation link works once, for 7 days.
  • An account whose email address nobody proved is deleted after a day.
  • A document uploaded for knowledge extraction is deleted when its extraction ends, and in any case after 7 days.
  • Assistant conversations nobody has added to for 90 days are deleted with their messages. Unreviewed facts drawn from conversations are blanked after 90 days. Your organisation's admin can change this period.
  • Your account and your organisation's content are kept while the organisation uses Alicorn. If a paid plan ends, the organisation moves to the free plan and nothing is deleted.
  • When someone is removed from an organisation, their access ends at once: their sessions end, their runners are revoked and their agents retired. The content they added stays with the organisation, which controls it.
  • The measurement ledger and the audit log are append-only: entries are never edited or removed while the organisation exists, because their value is that nobody can rewrite them.
  • Database backups are kept for up to 12 months, then deleted.
  • Billing records are kept as long as tax law requires.

Deleting an account or a whole organisation is not yet a button in the product. Ask us at the address in section 15 and we will do it, and tell you what, if anything, the law requires us to keep.

9. Security

  • Every row in the database carries the organisation it belongs to, and the database itself enforces row-level security, so one organisation's queries cannot read another's.
  • Connections to the service are encrypted with TLS.
  • AI agents act with short-lived tokens that are always narrower than their owner's: an agent can never do more than the person it works for.
  • Merge, release and money always need a person in the named role. No agent passes these gates.
  • No model key and no connection secret is stored in our database. Agent work runs on your organisation's own machines.
  • Access changes and looks at people-cost data are written to an append-only audit log.

The annex to our Data Processing Addendum describes these measures in more detail.

10. Your rights under the GDPR

If you are in the EEA, the UK or Switzerland, you have the right to:

  • Access (Art. 15): get a copy of your personal data.
  • Rectification (Art. 16): correct data that is wrong.
  • Erasure (Art. 17): have your data deleted.
  • Restriction (Art. 18): ask us to pause using it.
  • Portability (Art. 20): receive data you gave us in a machine-readable format.
  • Objection (Art. 21): object to uses based on legitimate interests.
  • No solely automated decisions (Art. 22): we make no decision about you with legal or similarly significant effects by automated means alone.

How to use them. Email[email protected] from the address on your account, and say which right you are using. We may ask you to confirm your identity. We answer within one month, or tell you within that month why we need up to two more. Using your rights is free.

Requests about content inside an organisation go to that organisation, as its controller. If you send one to us, we pass it on and help the organisation answer it.

You can also complain to a data protection supervisory authority, in particular where you live or work. The European Data Protection Board keeps thelist of authorities.

11. EU representative

8Seneca has no establishment in the European Union. We have not yet appointed a representative in the Union under Article 27 GDPR; when we do, we will name them here. Until then, send every privacy question and request to[email protected].

12. Other privacy laws

California (CCPA, as amended by the CPRA).

If you live in California, you can ask to know what personal information we collect, use and disclose, to delete it, to correct it, and to limit the use of sensitive information. We do not sell or share personal information for cross-context behavioural advertising, and we do not treat you differently for using your rights. The categories we collect are in section 3, and the businesses we disclose them to are in section 6. Send requests to the address in section 15; an authorised agent may send one for you.

Vietnam (Decree 13/2023/ND-CP on personal data protection).

If Decree 13 applies to you, you have the rights it gives, including to be informed, to consent and withdraw consent, to access, correct and delete your data, to restrict or object to its processing, and to complain. 8Seneca acts as a personal data controller for its own data and as a processor for data it processes for an organisation. Send requests to the address in section 15.

13. Children

Alicorn is a tool for work, for people aged 16 and over. We do not knowingly collect data from children. If you think a child has given us data, tell us and we will delete it.

14. Changes to this policy

When we change this policy, we update the date at the top. If a change materially affects how we use your data, we tell organisation owners by email before it takes effect. Changes to our sub-processors are announced as theData Processing Addendum sets out.

15. Contact

8Seneca, Vietnam. Privacy contact:[email protected].