Legal

Privacy

What the website does now

This is a static website. It sets no advertising cookies, runs no third-party analytics, and does not track visitors across sites. Theaccess chooser has no form and sends no access request by email. It does not collect a name, email address, LinkedIn profile, password, or access key.

One page is an exception, and it is the only one. Theaccount page carries a form. Submitting it sends the email address and password you type there directly from your browser to Supabase, which operates the account service; they are not routed through Alelyon and Alelyon never receives the password. Supabase stores the address and a hash of the password, and sends the confirmation email that activates the account. Nothing is sent until you submit, and simply opening the page collects nothing. An Alelyon account is separate from LinkedIn verification and is not required to download the build.

One cookie exists, and only on the closed-beta path below. It is named__session, it is set when you choose LinkedIn verification, and it carries two purposes in sequence and never both at once: first an opaque handle for the sign-in flow, consumed and deleted when you return, lasting ten minutes; then a download grant lasting thirty minutes, which carries a one-way handle derived from your LinkedIn identifier rather than the identifier itself. Both are HttpOnly,Secure and SameSite=Lax. A download link issued from a grant lasts an hour, which is a separate and later clock than the grant that produced it. No cookie is set for anyone who does not start verification.

The site is served by Google Firebase Hosting, which may process standard request information such as IP address, user agent, requested URL, and timestamp for delivery, security, and operations. Alelyon does not receive that request log as a separate record and does not join it to any account.

Following an external link, including theopen-toolkit repository, takes the visitor to a separate service whose operator may process the request under its own terms.

Open beta

The open-beta path covers the local Terminal interface and Lattice, plus the separately published alelyon-os toolkit. It does not use LinkedIn verification, issue an access key, or connect the visitor to a hosted DQC-OS backend.

The access page currently links to configured installer and portable artifacts. Requesting an artifact may give its hosting provider the same ordinary delivery metadata described above. A configured link is not, by itself, evidence that the binary is signed or that its digest was checked; those release facts must accompany the artifact.

Alelyon Terminal (desktop)

Alelyon Terminal is a desktop application. A local account, workspace layout, watchlists, research artifacts, history store, and any position data are stored on the user's machine by the desktop application. Running the application alone does not send those records to Alelyon. The packaged preview's local sign-in is not remote identity.

The application can make requests to third-party market, economic, filing, and model providers when the user selects and configures those features. Content sent to a selected provider is processed under that provider's own terms and privacy practices. Alelyon does not publish a provider-by-provider inventory for the desktop application, because which providers are contacted depends on which features the user configures; the application names the provider at the point of configuration.

Closed beta — what is collected

The closed-beta service processes only the data required for identity, review, issuance, and audit:

  • LinkedIn OpenID Connect assertions within the openid,profile and email scopes: the LinkedIn subject identifier, name, email address, and whether LinkedIn asserts that address as verified. OIDC establishes control of that LinkedIn account; it does not prove every statement on a profile. Alelyon does not scrape public LinkedIn profiles.
  • The access-request state, operator decision, timestamps, actors, and reasons needed to reconstruct the decision rather than silently alter it after the fact.
  • For an issued key, a one-way digest of the key and a keyed commitment to the identity it was issued against. The plaintext bearer key is shown once and must be saved before leaving that response. It is not emailed and is not retrievable after refresh; a lost or compromised key is revoked and reissued.

The static browser page does not generate or simulate that key and never receives an OIDC client secret, issuer secret, or stored key material. Server-side OIDC state and nonce validation, rate limiting, non-disclosive refusals, revocation, and operator authorization are properties of the hosted service, not of this page.

  • Verifying who is asking. Processed on your consent: the LinkedIn sign-in is a control you choose, and declining it leaves the rest of the site fully usable.
  • Reviewing and deciding the request, and issuing a key.Processed to take steps at your request before providing the beta.
  • Keeping a decision record, preventing abuse, and securing the service. Processed under Alelyon's legitimate interests in operating access control it can account for. An approval that cannot be reconstructed is one that cannot be audited or reversed.

Personal data is not sold, not used for advertising, not used to train models, and not disclosed to anyone outside the processors named below except where the law requires it.

Processors and where processing happens

  • LinkedIn (Microsoft) — the identity provider. You authenticate on LinkedIn's own pages under LinkedIn's terms; Alelyon receives only the assertions listed above and contacts no other LinkedIn endpoint.
  • Google Cloud — Cloud Run runs the access service in the us-central1 region (United States); Firebase Hosting serves this website from a global content network; Secret Manager holds the service's credentials; Artifact Registry holds its container image. Cloud Storage holds the private artifact bucket the desktop build is served from, and receives the durable mirror of the request queue.
  • Supabase — operates the account service. If you create an account it holds your email address, a hash of your password, and the session records that keep you signed in, and it sends the confirmation email that activates the account. Your password goes from your browser to Supabase directly; Alelyon does not receive it and cannot read it. This processor applies only if you use the account page — downloading the build through LinkedIn verification involves no account and does not reach Supabase.
  • An Alelyon-operated workstation — the operator copies the request queue off the hosted service to a local database, andthat local copy is the system of record. Requests leave Google's infrastructure and land on a machine, by design. This is the row easiest to leave out of a notice, and the one that most changes where your data actually lives.

Alelyon's own service logs record no email address, no name and no LinkedIn identifier; a download is logged against the one-way handle described above. Google keeps its ordinary infrastructure request logs — IP address, user agent, URL, timestamp — under its own terms.

Alelyon Quantitative Services is established in the United States, and access-request records are processed there. If you are outside the United States, using the closed-beta control transfers the fields above to the United States.

Retention and deletion

An access-request record is deleted no later than12 months after its access decision, and an undecided request no later than 12 months after it was submitted. Deletion removes the request and its decision history together.

This is enforced by a retention pass over the record store rather than by anybody remembering: the pass reports what is overdue before it removes anything, so a period that has silently stopped being honoured is visible as a number rather than as an absence. A digest of an issued key outlives the request only while that key is still valid; revoking or reissuing a key removes it.

The hosted side is shorter than that, and in a way worth stating plainly rather than in the flattering direction: the access service keeps requests in scratch storage, so a request is lost when the service is next redeployed. That bounds retention on Google's infrastructure to days rather than months. It also means a request can be destroyed before anybody reads it, if a redeployment lands between your sign-in and the operator's next export. That is one of the reasons no response time is promised anywhere on this site.

You can ask for your record to be deleted sooner, and it will be, unless a specific legal obligation requires Alelyon to keep it — in which case you will be told which.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or port personal data Alelyon holds about you, to withdraw consent, and to object to or restrict certain processing. Withdrawing consent does not affect processing already carried out.

Write to contact@alelyon.com to exercise any of them. The same address is the security contact for reporting a vulnerability or a suspected exposure of personal data. It is not a beta-access intake route — theaccess chooser is.

No response time is promised for either route. If you are in a jurisdiction with a supervisory authority for data protection, you may also complain to it.

Changes

Material changes are reflected in the date below. Alelyon is a small company and this notice describes a beta; where it is silent, treat the silence as a gap to ask about rather than as a permission.

Last updated: .

Choose your beta

One build. Two tiers.

The Windows build downloads with no sign-in, no LinkedIn and no key. Which tier you are in is decided when the app signs in: without a beta key you run everything locally, and a key — issued automatically to a signed-in, LinkedIn-verified account — is what adds Alelyon’s hosted DQC-OS.

Open beta

Run the app without a beta key.

There is one build, and this is the same one the closed beta uses — the tiers differ at sign-in, not at download. Sign in without a beta key and you get the local tier: Terminal UI, Lattice workspace, local calculator, and visible tool traces. A beta key is what adds hosted DQC-OS issuance.

  • Local-first Windows interface
  • Open Alelyon toolkit and source
  • No hosted backend entitlement

Windows 10 / 11, 64-bit · 0.6.1

Closed beta

Verify identity with LinkedIn to unlock hosted DQC-OS.

LinkedIn OpenID Connect verifies control of the LinkedIn account; Alelyon does not scrape your profile. It records a verified access request, and when you verify from your signed-in account page, your hosted DQC-OS key is issued automatically— no review, no queue, nobody to wait for. It does not create or sign you into an Alelyon account, and an anonymous verification issues no key: the key needs a signed-in account to attach to.

  • Everything in the open beta
  • Hosted deterministic DQC-OS calculations, unlocked by your key
  • Signed envelopes and certified answer paths

Signing up uses Alelyon’s own email-and-password account flow, which is separate from LinkedIn verification below. One Alelyon account signs you in to every Alelyon application, and it keeps working until you delete it. Verifying with LinkedIn comes next and links that identity to this account.

Verify with LinkedIn

Verify from your signed-in account page and your hosted DQC-OS key is issued automatically — it appears on that page the moment verification completes. Copy it into a password manager and enter it when Alelyon Terminal asks during sign-in; if it expires, opening your account page issues a fresh one.

Available now

Ask, and a person reads it.

Prefer to talk to someone first, or need access sooner than the self-serve paths allow? Ask directly.

Nothing about access waits on a person. The build downloads with no sign-in and no key; a hosted DQC-OS key is issued automatically when a signed-in account verifies with LinkedIn, and it appears on that account’s page. This address is for everything else — questions, problems, deletion requests, and anything a page cannot answer. It is read by a person, so no response time is promised.

Do not include credentials, account numbers, API keys, or position data in the message.