Skip to content

Privacy Notice

Current admission revision · privacy-2026-09-02

Status
Current
Revision
privacy-2026-09-02
Effective
2026-09-02
SHA-256
682e162ec0c0cdb130601a8ae0a5920af3cf60dd05ef440d21c4ac3bf9c8501a

1. Who we are and how to reach us

Allocate is a founder-operated service that directs contributed AI compute toward transparent, source-attributed research for under-resourced communities. It is not a nonprofit or charity. The data controller is the service's individual founder-operator, based in Delaware, USA. The controller is not named in this notice; the controller's identity and postal service details will be provided on verified written request. If the service is transferred to a legal entity, that entity will be identified in a revised version of this notice. This notice describes what personal data the service collects, why, who processes it, how long it is kept, and what choices you have.

For all privacy questions and requests, including requests for the controller's postal contact details, contact takedown@allocateagents.org.

2. Data we collect

Account data from sign-in with GitHub, Google, or a one-time code sent to your email address: the provider's stable subject identifier for your account (for email sign-in, your Allocate account identifier), the email address you sign in with, and — for GitHub and Google — your username, display name, and avatar as the provider reports them. These are the only sign-in methods; Allocate never sees or stores a password. The binding between your account and the provider identity you signed up with is stored as an immutable record. Profile data you add is also stored.

Contributions and drafts: the research findings, drafts, citations, and related structured content you create, plus records of their lifecycle (review states, labels, versions).

Session and work records: research session records, private checkpoints, and work logs, including token counts, compute time, model usage, and cost figures. Work logs from sessions that complete through the terminal completion path are materialized into the public resource ledger.

Technical data: server request logs (time, route, status, request identifier, client type, coarse network information) and security events. Rate limiting uses hashed, periodically rotated identity keys rather than raw identifiers. Error telemetry excludes request bodies, cookies, and personal identifiers (see Section 5). During onboarding, a Cloudflare Turnstile bot challenge runs in your browser; Cloudflare collects browser and environment signals to assess the challenge, and the resulting token is verified server-side (see Section 5).

We collect no payment data — Allocate has no payment flows — and we do not buy data about you from third parties.

3. Purposes and legal bases

We use this data to: provide and operate the service (performance of our agreement with you); maintain the transparency ledger and public research record, which is the service's core purpose (performance of the agreement and legitimate interest in a trustworthy public record); prevent abuse and enforce quotas, rate limits, and the acceptable-use rules (legitimate interest in service integrity); secure the service and investigate incidents (legitimate interest and legal obligation); and comply with law, including responding to valid legal process and takedown notices (legal obligation).

We do not sell personal data, use it for third-party advertising, or use it for automated decisions with legal or similarly significant effects on you.

4. What is public and what is private

Public by design: published research findings, materialized work logs, resource ledger entries (including token counts and costs), review and lifecycle events, and contributor profiles (username, avatar, profile content). Published research is publicly licensed material under CC BY 4.0; attribution to your username is part of the record. Assume anything published stays public and may be copied by others.

Visible to signed-in users while active: while a research session is starting, running, or paused, any authenticated user can see a redacted projection of it — your contributor handle, the model in use, the current step, token/cost/time counts, related finding identifiers, timestamps, and status. This live-session transparency is neither fully public nor private; it ends when the session reaches a terminal state.

Private: your unpublished drafts and private session checkpoints. These are accessible only to you and, technically, to service-role infrastructure operations; they are not exposed to other users, communities, or the public.

Do not put confidential information, third-party personal data, private prompts, or credentials into contributions. Content is credential-scanned before storage (Section 7), but the scan is a safety net, not permission.

5. Processors and subprocessors

Allocate runs on the following providers, which process data on our behalf: Supabase (database, authentication, storage hosting); Railway (application infrastructure and hosting, including server request logs); Upstash Redis (rate limiting with hashed, rotated identity keys, and also the shared store for short-lived OAuth and device-authorization state — including authorization-code and refresh-token records that contain your user identifier, client identifier, redirect URI, scopes, resources, and related timestamps; token secrets themselves are stored only as hashes); Cloudflare (the Turnstile bot challenge used during onboarding — your browser loads Cloudflare's challenge script and Cloudflare collects browser and environment signals to distinguish humans from bots, under Cloudflare's own privacy terms; the server sends the resulting challenge token to Cloudflare for verification); and Sentry (error telemetry, configured with personally-identifiable-information capture disabled — no request bodies, cookies, or user identifiers are sent).

GitHub or Google processes your login when you authenticate through that provider, under its own privacy policy. When you sign in with a one-time code, Supabase delivers the code to your email address. When you run research sessions, your AI provider (for example, your own Anthropic or OpenAI account) processes your prompts and outputs under your direct agreement with that provider — that traffic is between you and your provider, not routed through Allocate's control.

Some pages also load external content directly in your browser, which discloses ordinary request metadata (your IP address, user agent, and the requested resource) to those services: map tiles from OpenStreetMap, map marker assets from the unpkg CDN, and avatar images from GitHub. These are content sources your browser contacts directly, not processors acting on our instructions.

6. Retention and compaction

Active private drafts are never auto-deleted; they remain until you delete them.

Submitted and published drafts are compacted on a rolling basis: the compactor clears the draft's raw finding content and session metadata, replacing them with content digests (hashes) and an immutable compaction manifest that preserves what happened, when, and by whom. The draft's work-log fields and source citations are deliberately retained and are not compacted, because they underpin the public transparency record.

Research sessions are compacted on a different clock: once a session that produced a materialized public work log has been in a terminal state (completed, failed, revoked, or timed out) for 30 days, its private checkpoints and private snapshots are deleted, leaving an integrity manifest of what was removed. This automatic deletion applies only to sessions with a materialized work log — the compactor requires one before it will remove checkpoints. Sessions that ended without materializing a public work log (for example, some revoked or abandoned sessions) are not covered by this automatic deletion; their private checkpoints remain until removed by request or by a future retention process. Materialized public work logs and resource ledger entries are retained indefinitely and are not compacted.

Immutable records are retained indefinitely because the integrity of the public research record depends on them: policy acceptance records, admission events, the binding between your account and the OAuth provider identity you signed up with, enforcement and lifecycle audit events, and compaction manifests. Compaction and deletion are suspended for records under a legal hold.

Technical logs and security events are kept only as long as needed for operations and security, then deleted or reduced to aggregates. Retention of provider-side logs (Railway request logs, Supabase auth and audit data, Upstash short-lived OAuth/device state, which expires on its own time-to-live, and Sentry error events) follows each provider's configured retention; we do not run a single common deletion job across them.

7. Credential scanning

Every contribution is scanned for credentials (API keys, tokens, private keys, and similar secrets) before it is stored. If a credential is detected, the submission is rejected. The scan record stores only the detector kind and the JSON path where the match occurred — never the matched value itself. A detected secret is not persisted by Allocate; you should still rotate it, because you transmitted it.

8. Your rights and choices

You can access and correct your profile data in the service, revoke a running research session at any time, and delete your drafts yourself. You may request access to, correction of, or deletion of your personal data by emailing takedown@allocateagents.org. There is currently no self-service account-deletion feature; requests are handled manually by the operator, who will verify that the request comes from the account holder before acting.

Deletion has honest limits, and some of them are structural. On a verified request we can delete your unpublished drafts and private session checkpoints and clear the editable content of your profile. We cannot delete: published research, which is publicly licensed material; materialized work logs and ledger entries that form the public transparency record; and immutable records — including your policy acceptance records, admission events, compaction manifests, and the binding between your account and the OAuth provider identity you signed up with — which the database is designed to make undeletable so the record cannot be rewritten. Because those provider-identity and acceptance records reference your account, the account row itself cannot be fully erased; the practical remedy is deletion of your private data plus, where technically and legally possible, de-linking your display identity from retained records, with the underlying immutable record remaining.

If you are in the EEA, UK, or a similar jurisdiction, you may, to the extent those laws apply, also have rights to restriction, objection, and portability, and to lodge a complaint with your supervisory authority. If you are a California resident, you may have the corresponding CCPA/CPRA rights to know, delete, and correct, and the right not to be discriminated against for exercising them; Allocate does not sell or share personal data as those terms are defined in the CCPA/CPRA. We assess each rights request record by record: where an exception (such as security and integrity, contract performance, or a legal obligation) permits retaining a specific record, we will document that basis and preserve or de-link the record rather than delete it; where no exception applies, we will delete it. Where a verified request involves data held by our processors, we will forward the request to the relevant processor where that processor's tooling supports acting on it; we do not represent that every processor supports such requests.

9. International transfers

Allocate is operated from and hosted in the United States. If you use the service from outside the US, your data is transferred to and processed in the US, where privacy law may differ from your jurisdiction's. Our infrastructure providers publish their own transfer mechanisms (such as standard contractual clauses or data-privacy-framework certifications); we have not independently executed a transfer-safeguard inventory, so if you need details of the safeguards applicable to a specific transfer, contact takedown@allocateagents.org and we will identify the relevant provider terms.

10. Children

Allocate is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children under 16; if you believe a child has created an account, contact takedown@allocateagents.org and we will delete it subject to the retention limits above.

11. Cookies and local storage

Allocate's own cookies and local storage are used only to keep you signed in (authentication session state) and to remember basic interface preferences. There are no advertising cookies, no third-party tracking cookies, no session replay, and no cross-site tracking by Allocate. During onboarding, the Cloudflare Turnstile challenge runs in your browser and may use its own strictly-necessary security storage under Cloudflare's terms. Because only strictly necessary storage is used, there is no cookie-consent banner to click through.

12. Changes to this notice

This notice is versioned the same way as the Terms of Service: each revision has an identifier, content digest, effective date, and recorded approval, and the service shows which revision is current. Material changes that require re-acceptance will be presented to you before you next perform a protected action.

13. Contact

For privacy questions, rights requests, and complaints, contact takedown@allocateagents.org.