This privacy policy applies to the Alex application at alex-hq.com, published by The AI Shop ("we", "us"). Alex is a decision-memory service for companies. This policy explains what personal information we collect when you use Alex, why we collect it, who we share it with, and the choices you have. We process personal information in line with South Africa's Protection of Personal Information Act (POPIA) and, where it applies, other data protection law.
Who is responsible for your information
When your account is created or you sign in, we are the responsible party for your account information. The company that added you to Alex (our customer) is the responsible party for the business information it records in Alex, such as decisions, notes, and connected data. We process that information as an operator on the company's instructions, under the agreement we have with it. Questions about how your company uses Alex should go to your company first.
Information we collect
Account information
Your name, work email address, and the name of your company, and, if you sign in with Google or Microsoft, the basic profile those services share with us: your name, email address, and profile picture. We create your company's workspace and your account within it, on the instruction of the company's account with us, and use this information to sign you in and show who recorded or changed something in Alex. If you choose a password, our sign-in provider, WorkOS, stores only a salted hash of it. We never see or store a password for your Google or Microsoft account.
Company information
The decisions, reasoning, documents, conversations, and data that your company records in Alex or connects to it. This may include personal information about colleagues, customers, or suppliers where your company chooses to include it.
What you tell Alex about yourself
When you set Alex up, or later in Settings, you can tell it your job title, your function, who you report to, what you are accountable for, what has to go right for you this year, what worries you, and how you like answers. Your title, function, manager and what you are accountable for are visible to colleagues in your company, as your place on the committee always has been. Your priorities, your worries and how you like answers are used only in the answers Alex gives you, and no colleague can see them. Alex saves none of this from a conversation until you press Save on what it proposes.
You can also give Alex your mobile number. It is used only to recognise you when you phone Alex, and no colleague or administrator of your company can see it. You can change or remove it in Settings at any time.
An administrator of your company can ask Alex to read the company's own public website and draft a short company profile. What it reads is shown to that administrator to check and correct, and reaches nobody else's Alex until an administrator confirms it; once confirmed, the profile is read by everyone's Alex in that company.
Your private notes
When you ask Alex to remember something in chat, WhatsApp or a call, it saves a private note in your account. A longer account may be saved as a draft while you finish it. These notes are available to your own Alex across those channels; colleagues and company administrators cannot open them. You can read, edit, restore earlier versions and move them to your private Trash. Sharing a record is a separate step that you confirm.
Voice input
If you choose to dictate a chat message, your browser sends microphone audio directly to ElevenLabs to turn it into text. The text appears in your draft for you to review before sending. Alex does not store an audio recording for this feature. Once you send the message, its text is handled like any other chat message.
If you send a voice note to Alex's WhatsApp number, our servers fetch the recording and send it to ElevenLabs to turn it into text. ElevenLabs processes it in the United States, which means this audio leaves the region where the rest of your data is processed. We do not keep the recording: only the text of what you said is stored, and it is then handled like any other message you send Alex. If you would rather not have a recording leave the region, type the message instead.
Talking to Alex
If you start a call with Alex from the chat, ElevenLabs carries the call in the United States: your browser streams your microphone to ElevenLabs, which turns what you say into text and reads Alex's answers aloud. ElevenLabs passes that text to our servers, and Alex writes its answer on our side from the information you can already see in Alex. Your files, decisions and notes are not sent to ElevenLabs, only the sentences Alex speaks back, which may repeat what those files say. ElevenLabs does not keep a recording of the call. It does keep the text of the call, and an index it uses to search that text, until it deletes them on its own schedule. We have switched off the call analysis ElevenLabs lets us switch off, such as evaluations and topic and sentiment analysis. When you hang up, the text of the call is saved in your chat conversation and handled like any other message. If you would rather your words did not leave the region, type instead.
You can also phone Alex on its own number. Alex answers only a call from a mobile number that one of its users has given it in their profile or has linked to Alex on WhatsApp, and answers as that person; a call from any other number is not answered at all. Twilio, our telephone provider, carries the call and passes the audio to ElevenLabs, which handles it as described above, including keeping the text of the call until it deletes it on its own schedule. We do not record the call and we do not give ElevenLabs your number. On our side we keep when the call was made and how long it lasted, and the private notes and drafts you ask Alex to capture. The full phone transcript is not saved to your conversations. Retrieved passages may be held briefly during a call so follow-up answers do not repeat the same search. Because a phone network can be made to show a false number, keep the number you give Alex to the phone you actually use, and if you lose that phone remove the number from your profile and unlink it from WhatsApp in Settings.
Photos, videos and 3D models
When you upload a photo, a video or a 3D model, Alex reads a few facts off the file itself so they can be shown beside it: its size in pixels, how long a video runs, when a photo or video was taken, the camera model, and what a 3D model is made of. These come from the file's own metadata and are visible to whoever can see the file. Alex does not read the location a photo or video was taken at, and it does not watch or describe what a photo or video shows. A 3D model is drawn in your own browser; it is not sent anywhere else to be rendered.
Documents Alex makes for you
If you ask Alex for a document — a PDF, a Word file, or a spreadsheet — or to work something out from a file, such as totalling a spreadsheet or drawing a chart, it writes a short program and runs it on a temporary machine provided by E2B, in the United States. The program contains the figures and wording that go into your document, and when Alex names one of your files as the input, a copy of that file (at most four, and only files you could already open) is placed on the machine too, so this information leaves the region where the rest of your company's data is processed. The machine has no access to the internet and reaches no other file; it is destroyed after the run, and nothing is kept there. The finished file is saved to your private files, where only you can see it.
Models Alex builds for you
If you ask Alex to build a 3D model from your drawings, it first shows you which files it would use and asks you to confirm, and nothing is sent until you do. If you go ahead, a copy of the files you confirmed (only files you could already open) and a description of what you asked for are sent to OpenAI, in the United States, where one of its AI models works on them on a temporary machine for up to an hour, so this information leaves the region where the rest of your company's data is processed. A file that reached Alex as an email attachment is sent only if you attached it to your message yourself. For a project, the programme and the bill of quantities you tick when you build or refresh its model go the same way, so its dates and costs can be matched up with the model. The machine has no access to the internet and reaches no other file, and it is deleted when the work ends or when you cancel it. OpenAI does not use this information to train its models and does not keep it once the work is done. A model you asked for yourself is saved to your private files, where only you can see it. A model built for a project is saved in that project's folder in the company library, where everyone at your company can see it, along with its dates and costs.
Technical information
Standard server logs (IP address, browser type, timestamps, pages requested), the one-time codes we email you to sign in, and security events such as sign-ins and sign-outs. We use browser storage to keep you signed in. We do not use advertising trackers or third-party analytics cookies.
How we use information
- To provide Alex: signing you in, recording and retrieving decisions, and checking them over time.
- To keep the service secure: detecting abuse, verifying sign-ins, and investigating incidents.
- To support you and your company when you contact us.
- To improve Alex, using aggregated information that does not identify individuals.
- To meet legal obligations and enforce our agreements.
We do not sell personal information, and we do not use company information to market to third parties.
Google user data
This section applies if you sign in to Alex with Google. It describes how Alex accesses, uses, stores, and shares Google user data.
- What we access. Alex requests only your basic Google profile: your name, email address, and profile picture. We do not request access to Gmail, Drive, Calendar, Contacts, or any other Google data.
- How we use it. We use your name and email address to create your Alex account, sign you in, and show colleagues who recorded or changed something in Alex. We use your profile picture only to display it in Alex. We do not use Google user data for advertising, and we do not use it for any purpose other than providing and improving Alex.
- How we store and protect it. Your Google profile details are held by our sign-in provider, WorkOS, and within Alex, encrypted in transit and at rest. Access is restricted to the people who need it to run the service.
- Who we share it with. We do not sell Google user data, and we do not transfer or disclose it to third parties for purposes other than providing Alex. It is processed only by the providers listed below that help us run Alex, and disclosed otherwise only where the law requires, or as part of a merger or acquisition, with notice to you.
- No AI training, no Workspace APIs. We do not use Google user data, or any data obtained through Google APIs, to develop, improve, or train generalised or non-personalised artificial intelligence or machine learning models, and we do not allow our AI model providers to do so. Alex does not use Google Workspace APIs and does not request access to any Google Workspace data.
- People reading it. No person at The AI Shop reads your Google user data except with your consent, for security purposes such as investigating abuse, to comply with the law, or in aggregated form that cannot identify you.
- Retention and deletion. We keep it for as long as your account exists and delete it when your account is deleted, as described under "Deleting your information". You can also revoke Alex's access at any time from your Google Account permissions page.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Signing in with Microsoft works the same way, using only your basic Microsoft account profile.
Who we share information with
We share information only with providers that help us run Alex, each bound by contract to protect it:
- WorkOS, which handles sign-in and holds account records.
- Railway, which hosts the Alex application and database.
- Cloudflare, which provides DNS and network security for alex-hq.com.
- Resend, which delivers our transactional emails such as sign-in codes.
- Unipile, which connects Alex to a mailbox you link. Existing WhatsApp connections may also use Unipile. Unipile is hosted in the European Union.
- LlamaIndex, whose LlamaParse service reads the documents you add to Alex, such as PDFs, Word files, presentations, spreadsheets, scans and pictures, and turns them into text Alex can search and quote. LlamaIndex receives a copy of each of those files and processes it in the United States. It may keep the file and the text it produced for a limited time, on its own schedule, before deleting them. Plain text files and spreadsheets saved as CSV are read on our own servers and are not sent to it. Excel and OpenDocument spreadsheets are read on our own servers too, and are sent to LlamaIndex only when we cannot read them that way.
- ElevenLabs, which transcribes microphone audio when you choose voice input and voice notes you send to Alex's WhatsApp number, and carries calls with Alex: it hears what you say, turns it into text, and speaks Alex's answers. ElevenLabs processes this audio, and the text of a call, in the United States.
- Twilio, which provides Alex's telephone number and carries a call you make to it: the number you are calling from and the audio of the call, which it passes to ElevenLabs. It also carries messages and voice notes sent to Alex's own WhatsApp Business number and Alex's replies, including phone numbers and delivery information. Twilio processes this messaging data in the United States and may process calls there. Alex does not connect to or read your personal WhatsApp account.
- Exa, which searches the web and reads public web pages when Alex looks something up for you. It also reads your company's own public website: when Alex is set up for your company, when an administrator asks, and once a month after an administrator has confirmed the website is yours. Alex uses what it reads to draft the company profile and, once confirmed, keeps a copy of those public pages in your shared library. Exa receives only the search terms or the page addresses Alex sends it, not your files, and processes them in the United States.
- E2B, which runs the program Alex writes when you ask it to make a document or to work something out from a file you name. E2B processes the program, and a copy of any file Alex names as its input, in the United States on a temporary machine that is destroyed after each run.
- OpenAI, which builds a 3D model from your drawings when you ask Alex for one and confirm it. OpenAI processes a copy of the files you agreed to send, and a description of what you asked for, in the United States on a temporary machine that is deleted when the work ends, and does not use them to train its models.
- AI model providers, which process company information to produce Alex's summaries and checks, under agreements that limit their use of that information to providing the service and prohibit using it to train their models.
We may also disclose information when the law requires it, to protect the rights and safety of people, or as part of a merger or acquisition, with notice to you, in which case this policy continues to apply to it.
Where information is stored
Alex is hosted with providers in the United States and other countries outside South Africa. Where we transfer personal information across borders we do so under POPIA section 72, relying on contracts that require the recipient to protect it to a standard comparable to POPIA.
How long we keep information
We keep account information for as long as your account is active and for a short period afterwards to handle disputes and legal requirements. Company information is kept for as long as the company's agreement with us runs, and is deleted or returned within 30 days of the agreement ending unless the law requires us to keep it longer. Server logs are kept for a limited period for security purposes.
Security
Information travels between you and Alex over encrypted connections. Our providers encrypt stored data. Access to production systems is restricted to the people who need it, and sign-in never relies on passwords held by us. No system is perfectly secure, and we will notify affected people and the Information Regulator of a breach as POPIA requires.
Your rights
Under POPIA you may ask us to:
- confirm whether we hold personal information about you, and give you access to it;
- correct or delete personal information that is inaccurate, out of date, or no longer needed;
- object to processing in certain circumstances; and
- stop sending you direct marketing, which we do not send in any case.
To exercise these rights, email our Information Officer at hello@smart-alex.ai. Where your request concerns information your company recorded in Alex, we may refer it to your company as the responsible party. You may also lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.
Deleting your information
You can ask us to delete your account and the personal information we hold about you at any time by emailing hello@smart-alex.ai from the address on your account. We confirm deletion within 30 days. Company information is deleted when the company's agreement with us ends, as described above, or earlier on the company's instruction. If you signed in with Google or Microsoft you can also revoke Alex's access from your Google Account permissions or your Microsoft account settings at any time.
Children
Alex is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children.
Changes to this policy
We will post any changes here and update the date at the top. If a change materially affects how we use personal information, we will tell account holders by email before it takes effect.
Contact
The AI Shop, operator of Alex. Email hello@smart-alex.ai or visit smart-alex.ai.
