Privacy Policy
This policy describes how The Mad Botter INC ("we") handles personal information when you use Alice Pro. Short version: we collect what's needed to run the Service, your business data stays in your own cloud wherever possible, and we don't sell or rent personal information. Ever.
1. What we collect
- Account information: your name, work email, password (stored as a salted hash), and workspace/company name.
- Connection credentials: credentials you provide for data sources and destinations (database passwords, storage keys, OAuth tokens for Microsoft). These are encrypted at rest with keys held separately from the database, and used only to operate your pipelines.
- Configuration and usage: pipelines, schedules, SQL, run logs and metrics, Alice AI requests and generated SQL (with token counts for metering).
- Your business data during direct-connector runs: pipeline runs read from authorized sources and write results to serving storage. Result data lives in your cloud storage account or your single-tenant managed container; we do not keep additional copies of your row data beyond capped preview samples and temporary processing memory.
- Uploaded source files: files you upload are stored in private application storage so scheduled runs can process them.
- Technical data: server logs and error reports (including IP address and request metadata) for security and debugging.
- Acquisition context: a random visitor ID plus bounded first- and last-touch fields such as landing page, referring site, campaign tags, click ID, promotion/referral code, and the Alice CTA selected. We discard arbitrary query strings, fragments, credentials, email-like values, and private capability paths.
- Billing: processed by Stripe. We never see or store full card numbers.
2. What we use it for
Operating the Service you asked for, securing it, metering plan usage, providing support, and sending service email (receipts, alerts about your pipelines, material changes). No advertising, and no sale of personal data. Our public marketing pages use a visitor-identification service (see Cookies below); the application itself, and public shared-view pages, carry no third-party trackers.
3. Alice AI
When you use Ask Alice, your request text and the schema of the tables involved (names and types) are sent to Anthropic's Claude API to generate SQL. Under Anthropic's commercial API terms, API inputs and outputs are not used to train their models. Generated SQL and your prompt are stored in your workspace history for metering and audit.
4. Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| DigitalOcean | Application hosting and database | United States |
| Microsoft Azure | Managed serving storage; Power BI/Fabric APIs in your tenant | United States (your tenant per your config) |
| Anthropic | Alice AI SQL generation | United States |
| Stripe | Payment processing | United States |
| Sentry | Error monitoring | United States |
| RB2B | Marketing-site visitor identification (marketing pages only) | United States |
5. Cookies & visitor identification
The application uses an essential session cookie to keep you signed in. Public acquisition pages and registration use alice_acq, an encrypted, HTTP-only first-party cookie containing a random visitor ID and the sanitized acquisition fields described above. It expires 90 days after the first recorded touch and is used to understand aggregate conversion cohorts, not to serve advertising. Visiting the Coder Radio offer also sets a 30-day promo cookie so the offer can be applied at checkout.
Our public acquisition and campaign pages also use RB2B, a service that attempts to identify business visitors from the United States (e.g., matching your IP address and device signals to a work profile) so we can follow up with companies researching Alice. It does not run inside the application, on legal and payment-support pages, or on public shared-view pages. Our first-party acquisition measurement does not gate, delay, or replace RB2B. To opt out or request deletion of RB2B data, contact us below or see RB2B's own policy.
6. Retention & deletion
Account and configuration data are kept while your account is active and for 30 days after termination, then deleted. A completed workspace keeps its sanitized acquisition snapshot while the account exists so later activation and billing outcomes stay attached to the original cohort. Raw first-party funnel events are pruned after 13 months. The acquisition context on an uncompleted signup is scrubbed after 90 days, and inquiry contact records are deleted after 90 days. Run logs are pruned on a rolling basis. You may request export or deletion of your data at any time at the contact below; we respond within 30 days.
7. Security
TLS everywhere; connector credentials encrypted at rest (application-level encryption with separately held keys); single-tenant serving containers with scoped, minimal-privilege credentials; firewalled infrastructure; least-privilege access. No method of transmission or storage is 100% secure, but this is what we'd want as a customer, so it's what we build.
8. Your rights
Depending on where you live (e.g., EEA/UK GDPR, California CCPA), you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Contact us and we'll honor them. We do not discriminate for exercising them.
9. Changes & contact
We'll announce material changes by email or in-app before they take effect. Data questions or requests: michael@themadbotter.com. The Mad Botter INC, Florida, USA.