Alpha legal
Privacy Notice
This notice covers the Alpha mobile apps, web app, public site, authentication service, and related support and safety operations.
Alpha is a social home for founders and builders. This notice explains how personal data is collected and used when you browse our public pages, create an account, publish or send content, join communities, contact support, or use related Alpha services. It should be read together with the Notice at Collection,Terms of Use, and Community Guidelines.
1. Controller and contact
Ahmed Mansour, an individual developer operating Alpha from Egypt, determines the purposes and means of the processing described here and is the data controller. Privacy requests may be sent to privacy@alpha-app.online. General support is available at support@alpha-app.online.
Alpha's principal establishment is in Egypt. Egypt's Personal Data Protection Law No. 151 of 2020 and Executive Regulations No. 816 of 2025 form part of the applicable local framework. Information about that framework and complaints is available from theEgyptian Personal Data Protection Center.
2. Data we collect
Account and identity data
- Name, email address, handle, profile image, biography, interests, country selection, links, and other profile fields you choose to provide.
- A password hash when you use email and password. Alpha does not store your readable password.
- Google or Apple provider identifiers, verified email/name information returned by the provider, and account-linking records when you choose social sign-in.
- Session identifiers, signed authentication tokens, creation and update timestamps, and the versions and time of the legal terms accepted at registration.
Content, social activity, and communications
- Threads, replies, polls, reactions, reposts, saves, follows, community memberships, invitations, and reports.
- Direct messages and message-request relationships needed to deliver private conversations.
- Images, video, audio, PDFs, filenames, dimensions, file size, and technical metadata associated with files you choose to upload.
- Moderation results, reports, appeal correspondence, strikes, and records reasonably required to investigate abuse or prevent ban evasion.
Device, network, and diagnostic data
- IP address, request time, referrer/origin, browser or app version, operating system, device type, and server logs generated when systems communicate.
- Push-notification tokens and delivery status if notifications are enabled.
- Crash context, connectivity checks, and error details submitted through support or generated when diagnosing failures. We ask that users avoid placing confidential information in bug reports.
- A local theme preference on the public site. See the Cookie Notice.
Permission-based data
Camera, photo-library, file, microphone, or notification access is requested only when a feature needs it. Choosing a file or taking a photo causes that selected item to be processed; Alpha does not receive an unrestricted copy of your entire library. Operating systems may provide limited or selected-library access. Permissions can be changed in device settings.
Purchase information
Alpha is currently free. If paid features are introduced, Apple, Google, or another disclosed processor may handle payment credentials. Alpha would normally receive product, receipt, entitlement, renewal, cancellation, and refund status—not a full card number.
3. Sources of data
Most data comes directly from you or is generated by your use of Alpha. Identity data may come from Google or Apple when you select those providers. Other members provide data when they mention, follow, message, invite, block, or report an account. Security and delivery providers generate network and service logs. Alpha does not purchase marketing profiles or enrich member accounts with data-broker records.
4. Why we process data and our legal bases
- Provide the contract: create and secure accounts; publish requested content; provide feeds, profiles, communities, messages, uploads, notifications, settings, support, and deletion.
- Legitimate interests: protect accounts and infrastructure; prevent spam, fraud, and abuse; enforce community rules; troubleshoot; understand aggregate reliability; defend legal claims; and improve product safety. We balance these interests against member rights.
- Consent: activate optional device permissions, push notifications, and any future non-essential analytics or marketing. Consent can be withdrawn without affecting earlier lawful processing.
- Legal obligations and rights: comply with binding law, court orders, regulatory duties, and valid requests, and establish, exercise, or defend legal claims.
- Vital interests: in exceptional circumstances, address a credible and imminent threat to life or physical safety.
Account identifiers and authentication data are contractually necessary. Without them, Alpha cannot provide an authenticated profile. Optional profile fields, uploads, push notifications, and permission-based features may be declined.
5. Visibility and audiences
Public or community content is visible according to the audience and privacy settings selected in the product and may be copied, quoted, indexed, or shared by recipients. Private profiles limit ordinary in-product visibility but do not make information invisible to people you approve, service providers, or Alpha's safety and support operations. Direct messages are delivered to their participants and are not routinely subjected to pre-publication moderation; they may be accessed when reported, required for support, necessary for security, or legally compelled.
6. Automated moderation and decisions
Text submitted for public threads and replies may be evaluated before or after publication by deterministic rules and third-party machine-learning safety services. Current integrations may include Groq and Hugging Face models. The text under review and limited technical context may be sent to those providers; account credentials are not sent as part of the moderation prompt.
Screening can flag, delay, label, or block material against categories such as threats, harassment, hate, sexual content, self-harm encouragement, scams, spam, prohibited goods, and attempts to manipulate the screening system. Material decisions may be reviewed and appealed under the Community Policy andStrikes & Appeals. Automated systems can be wrong; an appeal may request human reconsideration.
7. Service providers and disclosures
Alpha uses providers for defined operational purposes. Depending on the feature, these include:
- Convex and Convex components — application database, realtime backend, authentication storage, chat, presence, counters, notifications, and server functions.
- Vercel — web and API hosting, content delivery, request logging, and reliability/security controls.
- UploadThing — upload, storage, and delivery of media selected by members.
- Expo, Apple, and Google — app delivery, secure device services, push-notification routing, and platform functionality.
- Google and Apple sign-in — authentication when selected by the member.
- Groq and Hugging Face — automated safety classification when configured.
- Linked websites — Alpha may fetch public metadata from a URL included in a post to generate a preview. The destination server can receive the fetching server's IP and request metadata.
Providers process data under their own security and contractual obligations. We disclose data to the minimum categories reasonably necessary for the selected feature. Alpha does not sell personal information, rent member lists, or share personal information for cross-context behavioral advertising. We may disclose data in a business reorganization, but any successor must honor this notice or give legally required notice before materially changing the purpose.
8. Legal, safety, and rights-related disclosures
We may preserve or disclose information when reasonably and lawfully necessary to respond to binding legal process; protect members or the public from credible harm; investigate fraud, security incidents, or rule violations; protect Alpha's rights; or respond to a rights request. We review requests for scope and authority and disclose only what is reasonably required. We notify the affected person when legally permitted and operationally appropriate.
9. Retention and deletion
- Account and profile: while the account is active, then deleted or de-identified after a verified deletion request, subject to the exceptions below.
- Published content and messages: while retained by the member or needed to provide the conversation, then removed through content/account deletion workflows. Copies made independently by recipients are outside Alpha's control.
- Sessions and security logs: for the session lifetime and a limited period afterward based on security, incident-response, and provider-log rotation needs.
- Support, reports, and appeals: for as long as needed to resolve the request and maintain an appropriate audit trail.
- Backups and caches: until overwritten on normal protected rotation schedules; they are not returned to active use except for disaster recovery.
- Enforcement and legal records: a narrowly scoped record may be retained when necessary to prevent serious abuse or ban evasion, meet a legal obligation, or resolve a dispute.
We review retention based on purpose, sensitivity, legal requirements, safety risk, and technical necessity. Start deletion in Settings or use theexternal deletion route. Where a provider holds data solely on our behalf, we instruct it to delete or allow its normal deletion/rotation process to complete.
10. Security
Measures include encrypted transport, password hashing, signed and expiring tokens, restricted secrets, provider access controls, scoped endpoints, rate limits, and deletion workflows. No system is perfectly secure. If a breach creates a legally reportable risk, Alpha will notify the competent authority and affected people as required. Report suspected security issues tosafety@alpha-app.online without publicly exploiting them.
11. International transfers
Alpha is operated from Egypt and service providers may process data in the United States, Europe, or other locations. Those locations may have different privacy laws. Where required, Alpha relies on provider contractual commitments, recognized transfer mechanisms such as standard contractual clauses, adequacy decisions, consent, or another lawful basis. Transfers involving Egyptian personal data are handled subject to the PDPL and applicable permits or safeguards.
12. Your choices and rights
Subject to applicable law and exceptions, you may request confirmation and access; correction; deletion; a portable copy; restriction; objection; withdrawal of consent; and review of a significant automated decision. You may also change profile visibility, permissions, push settings, and certain content directly in the app. Exercising a right does not result in unlawful discrimination.
Email privacy@alpha-app.online. Describe the request and the account involved. We may verify identity proportionately. We respond within the period required by the applicable law; for GDPR requests this is ordinarily one month, subject to a permitted extension. Authorized agents must show authority to act.
13. Egypt, EEA/UK, and California supplements
Egypt
Eligible data subjects may exercise the rights provided by the Egyptian PDPL and complain to the Personal Data Protection Center. Valid consent and opt-out records are retained when the law or its regulations require them.
European Economic Area and United Kingdom
The legal bases in Section 4 apply. Where Alpha has no establishment in the EEA/UK, local representative obligations are assessed as the service and user base develop. You may complain to the supervisory authority where you live or work. Guidance is available from theEuropean Data Protection Boardand the UK ICO.
California
If the California Consumer Privacy Act applies to Alpha or to a particular processing activity, California residents may request to know, delete, or correct covered personal information and may exercise applicable opt-out and non-discrimination rights. Alpha does not sell covered personal information or share it for cross-context behavioral advertising. The categories collected and disclosed are listed in Sections 2 and 7. Information about CCPA rights is available from the California Attorney General.
14. Age requirement
Alpha is intended only for people aged 18 or older. We do not knowingly create accounts for children. If you believe a person under 18 has provided personal data, contactprivacy@alpha-app.online so we can investigate and remove it where appropriate.
15. Changes to this notice
The effective date and version appear above. Material changes will be announced through the app, account email, or another prominent method when required. A change does not retroactively create consent for a new purpose. Archived versions may be requested fromlegal@alpha-app.online.