Privacy Policy
Last updated: August 2026
Alembic is operated by James McArthur as a sole proprietorship. This policy explains how we collect, use, and protect your information when you use Alembic ("the Service").
What We Collect
When you create an account, we collect:
- Account information — your name, email address, and a hashed password (or Google OAuth credentials)
- Documents you upload — PDFs, DOCX files, and images submitted for extraction
- Extracted data — structured fields, values, and metadata produced by our AI pipeline
- Usage data — which features you use, document counts, and processing metrics (for billing and service improvement)
- Push notification subscription data — endpoint URLs and encryption keys, stored solely for delivering web push notifications to your device
How Your Documents Are Processed
When you upload a document — or submit one via email — it is sent to a third-party AI provider (Anthropic, Google, OpenAI, or xAI, depending on the job) over HTTPS for AI-powered extraction and assistance. These providers do not use API data for model training. Your document content is not retained by the provider beyond the processing window (xAI retains API logs for 30 days for abuse monitoring unless Zero Data Retention is enabled). We never use your documents to train our own models.
Where Your Data Is Stored
- Database — Neon Postgres, hosted in the US, encrypted at rest
- File storage — Vercel Blob, hosted in the US, encrypted at rest
- All data transmitted over HTTPS (TLS encryption in transit)
How Long We Keep Your Data
Your documents and extracted data remain in the system for as long as your account is active. You can delete individual documents or entire spaces at any time from the app — deleted data is permanently removed from our systems. If you delete your account, all associated data is permanently removed.
Third-Party Services
We use the following services to operate Alembic:
- Anthropic — AI document processing and conversation (US)
- Google — AI document processing (Gemini), when used for high-volume jobs (US)
- OpenAI — AI processing during provider outages (US)
- xAI — AI assistance for the hardest judgment jobs (US)
- Vercel — application hosting and file storage
- Neon — managed Postgres database
- Stripe — payment processing and billing
- Resend — transactional email delivery
- Fastmail — email inbox management for inbound document emails (AU)
We do not sell your data to advertisers, data brokers, or any other third parties.
Cookies & Analytics
We use session cookies (via BetterAuth) to keep you signed in. We do not use third-party tracking cookies or advertising cookies, and website analytics data is stored in our own database — it is never shared with a third-party analytics service.
Website analytics work in two tiers, and which tier you are in depends on your choice in the consent banner.
If you accept. We set a first-party analytics cookie holding a random identifier, which lets us recognise your browser across visits. Alongside the pages you view we record the referring site, any campaign tags in the link you arrived by, your device type, browser, operating system, and an approximate location — country and region only, never your city, your coordinates, or your IP address. If you later create an account, this browsing history is linked to your account.
If you decline, or have not yet chosen. We still count your visit. This is what the consent banner means by "we count visits either way". Nothing is stored on your device and no cookie is set. Instead, our server derives a short identifier by hashing your IP address and browser user-agent string together with a random key that changes every day. The IP address and user-agent are used to compute that hash and are then discarded — neither is written to our analytics records. We keep each day's random key for two days and then delete it, after which the identifiers made with it cannot be recomputed or traced back by anyone, including us.
In that tier we record the same page, referrer, campaign, device, browser, operating system, country and region information described above. The identifier is pseudonymous, not anonymous: within a single day, visits made by one browser are linked to each other. Across days they are not, and they are never linked to an account.
Global Privacy Control. We respect the GPC signal. If your browser sends GPC we do not track you at all — no cookie is set and no visit is counted, in either tier.
The cookies involved:
- alembic_consent (365 days) — records whether you accepted or declined, so you are not asked again.
- alembic_vid (365 days) — the analytics identifier described above. Set only if you accept.
- alembic_ft (180 days) — remembers how you first arrived, meaning the referring site and any campaign tags, so we can tell which channel led to a signup. Set only if you accept.
- alembic_internal — read by this website, but never set by it. Our own staff set it by hand on their own machines so that their visits can be excluded from our figures.
Declining, or turning analytics off later in your account settings under Preferences, deletes the alembic_vid and alembic_ft cookies from your device and moves you to the cookieless tier described above. It stops an identifier being stored on your device. It does not stop your visits being counted, and it does not delete records already collected.
How long analytics data is kept. Individual visit records — the page-by-page log and the sessions built from it — are retained for 400 days and then permanently deleted. Some analytics records are kept indefinitely and are not covered by that deletion:
- Daily totals — visit counts aggregated by day, page, channel, campaign, country and device type. These carry no visitor identifier.
- First-touch attribution — for accounts, a record of the referring site and campaign tags associated with the first visit that led to the signup.
- Consent records — the identifier the choice was made for, the choice itself, the IP address it was made from, and when. We keep these as the record that a consent decision was actually made.
- Internal summaries — periodic written summaries of the aggregate figures above.
To request deletion of analytics records associated with you, email us at james@alembictransform.com.
Your Rights
- Delete any document or space from the app at any time
- Delete your entire account from Settings
- Export your extracted data
- Request information about what data we hold — email us at james@alembictransform.com
Contact
For questions about this policy or your data, contact james@alembictransform.com.