Privacy
What the website does now
This is a static website. It sets no advertising cookies, runs no third-party analytics, and does not track visitors across sites. Theaccess chooser has no form and sends no access request by email. It does not collect a name, email address, LinkedIn profile, password, or access key.
One cookie exists, and only on the closed-beta path below. It is named__session, it is set when you choose LinkedIn verification, and it carries two purposes in sequence and never both at once: first an opaque handle for the sign-in flow, consumed and deleted when you return, lasting ten minutes; then a download grant lasting thirty minutes, which carries a one-way handle derived from your LinkedIn identifier rather than the identifier itself. Both are HttpOnly,Secure and SameSite=Lax. A download link issued from a grant lasts an hour, which is a separate and later clock than the grant that produced it. No cookie is set for anyone who does not start verification.
The site is served by Google Firebase Hosting, which may process standard request information such as IP address, user agent, requested URL, and timestamp for delivery, security, and operations. Alelyon does not receive that request log as a separate record and does not join it to any account.
Following an external link, including theopen-toolkit repository, takes the visitor to a separate service whose operator may process the request under its own terms.
Open beta
The open-beta path covers the local Terminal interface and Lattice, plus the separately published alelyon-os toolkit. It does not use LinkedIn verification, issue an access key, or connect the visitor to a hosted DQC-OS backend.
The installer and portable artifact links are not configured, so the current page renders them as unavailable controls. There is no email fallback and no download request record.
Alelyon Terminal (desktop)
Alelyon Terminal is a desktop application. A local account, workspace layout, watchlists, research artifacts, history store, and any position data are stored on the user's machine by the desktop application. Running the application alone does not send those records to Alelyon. The packaged preview's local sign-in is not remote identity.
The application can make requests to third-party market, economic, filing, and model providers when the user selects and configures those features. Content sent to a selected provider is processed under that provider's own terms and privacy practices. Alelyon does not publish a provider-by-provider inventory for the desktop application, because which providers are contacted depends on which features the user configures; the application names the provider at the point of configuration.
Closed beta — what is collected
The closed-beta service processes only the data required for identity, review, issuance, and audit:
- LinkedIn OpenID Connect assertions within the
openid,profileandemailscopes: the LinkedIn subject identifier, name, email address, and whether LinkedIn asserts that address as verified. OIDC establishes control of that LinkedIn account; it does not prove every statement on a profile. Alelyon does not scrape public LinkedIn profiles. - The access-request state, operator decision, timestamps, actors, and reasons needed to reconstruct the decision rather than silently alter it after the fact.
- For an issued key, a one-way digest of the key and a keyed commitment to the identity it was issued against. The plaintext bearer key is shown once and must be saved before leaving that response. It is not emailed and is not retrievable after refresh; a lost or compromised key is revoked and reissued.
The static browser page does not generate or simulate that key and never receives an OIDC client secret, issuer secret, or stored key material. Server-side OIDC state and nonce validation, rate limiting, non-disclosive refusals, revocation, and operator authorization are properties of the hosted service, not of this page.
Purposes and legal bases
- Verifying who is asking. Processed on your consent: the LinkedIn sign-in is a control you choose, and declining it leaves the rest of the site fully usable.
- Reviewing and deciding the request, and issuing a key.Processed to take steps at your request before providing the beta.
- Keeping a decision record, preventing abuse, and securing the service. Processed under Alelyon's legitimate interests in operating access control it can account for. An approval that cannot be reconstructed is one that cannot be audited or reversed.
Personal data is not sold, not used for advertising, not used to train models, and not disclosed to anyone outside the processors named below except where the law requires it.
Processors and where processing happens
- LinkedIn (Microsoft) — the identity provider. You authenticate on LinkedIn's own pages under LinkedIn's terms; Alelyon receives only the assertions listed above and contacts no other LinkedIn endpoint.
- Google Cloud — Cloud Run runs the access service in the
us-central1region (United States); Firebase Hosting serves this website from a global content network; Secret Manager holds the service's credentials; Artifact Registry holds its container image. Cloud Storage would hold the private artifact bucket, and is not configured today. - An Alelyon-operated workstation — the operator copies the request queue off the hosted service to a local database, andthat local copy is the system of record. Requests leave Google's infrastructure and land on a machine, by design. This is the row easiest to leave out of a notice, and the one that most changes where your data actually lives.
Alelyon's own service logs record no email address, no name and no LinkedIn identifier; a download is logged against the one-way handle described above. Google keeps its ordinary infrastructure request logs — IP address, user agent, URL, timestamp — under its own terms.
Alelyon Quantitative Services is established in the United States, and access-request records are processed there. If you are outside the United States, using the closed-beta control transfers the fields above to the United States.
Retention and deletion
An access-request record is deleted no later than12 months after its access decision, and an undecided request no later than 12 months after it was submitted. Deletion removes the request and its decision history together.
This is enforced by a retention pass over the record store rather than by anybody remembering: the pass reports what is overdue before it removes anything, so a period that has silently stopped being honoured is visible as a number rather than as an absence. A digest of an issued key outlives the request only while that key is still valid; revoking or reissuing a key removes it.
The hosted side is shorter than that, and in a way worth stating plainly rather than in the flattering direction: the access service keeps requests in scratch storage, so a request is lost when the service is next redeployed. That bounds retention on Google's infrastructure to days rather than months. It also means a request can be destroyed before anybody reads it, if a redeployment lands between your sign-in and the operator's next export. That is one of the reasons no response time is promised anywhere on this site.
You can ask for your record to be deleted sooner, and it will be, unless a specific legal obligation requires Alelyon to keep it — in which case you will be told which.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or port personal data Alelyon holds about you, to withdraw consent, and to object to or restrict certain processing. Withdrawing consent does not affect processing already carried out.
Write to contact@alelyon.com to exercise any of them. The same address is the security contact for reporting a vulnerability or a suspected exposure of personal data. It is not a beta-access intake route — theaccess chooser is.
No response time is promised for either route. If you are in a jurisdiction with a supervisory authority for data protection, you may also complain to it.
Changes
Material changes are reflected in the date below. Alelyon is a small company and this notice describes a beta; where it is silent, treat the silence as a gap to ask about rather than as a permission.
Last updated: 12 August 2026.