ALETHEIA Privacy Policy

Last updated: 2026-04-20 · Aligns with HQ Data Policy v2.0 · Effective immediately

API-served technical companion. This is the technical companion document for API consumers. For the primary, canonical, human-readable Privacy Policy for the Holistic Quality ecosystem, see holisticquality.io/data-policy. The ALETHEIA product-level Privacy Notice is at aletheia.holisticquality.io/privacy. Where this page and those pages describe the same practice, the canonical pages govern.

1. Data Controller

Holistic Quality LLC ("we", "us") operates the ALETHEIA Safety Database API at api.aletheia.holisticquality.io.

Privacy contact: privacy@holisticquality.io · General inquiries: Enterprise Inquiry Form · Security/vulnerability reports: security@holisticquality.io

2. Data We Collect

Collection PointDataPurposeLegal Basis
API key trial signupEmail addressKey delivery, trial managementContract (Art. 6(1)(b))
Stripe checkoutEmail, payment info (via Stripe; we never receive card numbers)Subscription billingContract (Art. 6(1)(b))
Enterprise inquiryName, email, company, messageSales inquiry responseLegitimate interest (Art. 6(1)(f))
API request metadataTimestamp, endpoint, HTTP status, one-way hashed API key, IP truncated to /24 subnetRate limiting, abuse prevention, security auditLegitimate interest (Art. 6(1)(f))
API request/response bodies and query parametersNever logged or stored (processed transiently in memory only)N/AN/A — not collected

3. How We Use Your Data

4. Data Retention

Full canonical retention matrix with GDPR Art. 6 legal basis per category: HQ Data Policy §Data Retention. Summary:

DataRetentionMechanism
Email + hashed API key (active)Duration of active trial/subscription (max 24 months idle on paid keys)Contract (Art. 6(1)(b))
Email + hashed API key (post-cancellation)90 days baseline; up to 120 days if open Stripe chargeback/dispute appliesAuto-TTL + chargeback extension
Trial signup flag30 daysAuto-TTL
Enterprise inquiry data30 daysAuto-TTL
Request metadata (endpoint, timestamp, key hash, /24-truncated IP, status)90 days active logs; no identifiable archival tierAuto-TTL
Rate limit counters24 hoursAuto-TTL
Security audit logs (hashed/minimized identifiers only)90 daysAuto-TTL (Art. 6(1)(f))
Encrypted backups (Upstash snapshots)Roll off within 35 days of source-record deletionUpstash-managed
Verified erasure requestsProcessed without undue delay (typically within 30 days)Art. 17
Aggregated or anonymized analyticsMay be retained longer (no longer identifies a person)Not personal data once anonymized
Stripe billing dataPer Stripe's retention policyManaged by Stripe

5. Sub-Processors

Canonical list (mirrors the HQ Data Policy v2.0 exactly):

ServiceJurisdictionPurposeData Transferred
CloudflareUS (global edge)DNS, CDN, edge security, DDoS protection, bot managementIPs, security cookies, TLS session metadata
UpstashEU (eu-west-1, Ireland)Serverless Redis — hashed API key storage, rate limitingHashed API keys, email, usage counters, metadata
VercelUSServerless compute, hosting, infrastructure logsRequest logs (IP /24-truncated), function execution metadata
ResendUSTransactional email deliveryEmail address, email content (28-day retention)
StripeUSPayment processing (direct-issued only)Email, payment info (we never receive card numbers)

RapidAPI is an independent data controller (not a subprocessor) for users who access ALETHEIA through the RapidAPI marketplace.

Per-processor DPA status and international transfer documentation (2021 EU SCCs, DPF participation): /api/compliance.

6. Your Rights (GDPR / CCPA)

You have the right to:

How to Exercise Erasure

  1. Send POST /api/keys/erasure with {"email": "your@email.com"}
  2. Check your email for a 6-digit verification code
  3. Send POST /api/keys/erasure with {"email": "your@email.com", "code": "123456"}
  4. All API keys, usage data, and personal records will be permanently deleted

Note: Security audit logs (containing hashed identifiers only) are retained for 90 days under legitimate interest for fraud prevention (Art. 6(1)(f)).

7. Cookies & Tracking

The ALETHEIA API does not use cookies. The dashboard uses localStorage to remember your API key for convenience (opt-in, client-side only). No third-party trackers, pixels, or advertising SDKs are used.

8. Security

We implement: HTTPS-only transport, AES-256-GCM encryption for webhook secrets, SHA-256 admin authentication with timing-safe comparison, rate limiting, audit hash chains with tamper detection, and CSP headers on all pages.

Security issues: security@holisticquality.io (see security.txt)

9. Changes

We may update this policy. Material changes will be noted in the API changelog (GET /api/changelog).

ALETHEIA Safety Database · Holistic Quality LLC · API Root · Terms of Use