Privacy Policy
Effective Date: 2026-05-26
AlignMe LLC (“AlignMe,” “we,” “our,” “us”) is a behavioral intelligence platform. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
1. Introduction
AlignMe LLC is committed to handling your personal and behavioral information with care and transparency. This Privacy Policy describes the categories of data we collect through the AlignMe app and website (the “Service”), the purposes for which we use it, the third-party processors that help us deliver the Service, and the rights you have under applicable data protection laws. By using AlignMe, you acknowledge that you have read and understood this Privacy Policy.
2. Data We Collect
We collect the following categories of information:
- Account data — name, email address, date of birth (used for Life Path and optional Cosmic features), and authentication metadata.
- Assessment responses — answers to behavioral questions used to generate your Signal, RootType, and MindMap profile.
- Conversation data — AI Guide session content, themes, and insights generated during sessions.
- Voice diary entries — audio recordings, transcribed and analyzed for behavioral insights. Source audio is deleted within 24 hours of processing.
- Check-in data — daily check-ins, emoji entries, morning pulse responses, and reaction-button inputs.
- Passive data (with permission) — health-app data (sleep, activity) and calendar event metadata (count and timing only, never event names or attendees).
- Usage and device data — browser type, device type, general location (country and region only), and usage patterns.
- Payment information — processed by Stripe. AlignMe does not store full payment card details.
3. How We Use Your Data
- Generate, display, and update your behavioral profile.
- Personalize your AI Guide sessions with relevant behavioral context.
- Improve our assessment accuracy and AI response quality (subject to your AI-training opt-out under §8).
- Send you product updates, insights, and notifications only if you have opted in.
- Process payments and manage your subscription.
- Ensure platform safety, prevent abuse, and detect fraud.
- Comply with legal obligations and respond to lawful requests.
4. Legal Bases (GDPR)
If you are located in the European Union, European Economic Area, United Kingdom, or Switzerland, we process your personal data on the following legal bases under the GDPR / UK GDPR:
- Consent (Art. 6(1)(a)) — for optional functionality such as voice diary processing, passive health-app / calendar metadata, AI-training participation, and marketing communications. You may withdraw consent at any time.
- Contract performance (Art. 6(1)(b)) — to provide the core Service you subscribed to: generating your behavioral profile, delivering AI Guide sessions, and processing payments.
- Legitimate interest (Art. 6(1)(f)) — for product improvement, security monitoring, abuse prevention, and aggregated analytics that do not identify individual users.
- Legal obligation (Art. 6(1)(c)) — to retain certain billing and compliance audit records as required by tax, consumer-protection, and financial regulations.
5. AI Processing
AlignMe uses artificial intelligence to generate behavioral insights, AI Guide session responses, and compatibility analyses. By default, AI inference is performed by Anthropic (Claude API), processed on United-States-based infrastructure. Anthropic does not train its models on AlignMe customer data under our API terms.
For gov-tier and isolated-enterprise deployments (see §7), AI inference may instead be performed by one of the alternate processors listed below. The choice of AI processor for a given deployment is determined at provisioning time and is disclosed to the deploying organization; it is never silently switched at runtime.
6. Data Retention
- Voice diary source audio — deleted within 24 hours of processing. Only the derived transcript and behavioral insights are retained.
- Conversation screenshots shared with AlignMe — deleted within 24 hours of processing.
- Account and profile data — retained for as long as your account is active to support the Living Profile system.
- Session content — retained while your account is active so AI Guide sessions remain context-aware.
- Compliance audit logs (per Spec 18 retention tiers) — security and admin-action logs retained for 1 year; billing and subscription audit logs retained for 3 years; regulated-tier (HIPAA / SOC 2) audit logs retained for 3 years or longer as required by the applicable regulation or BAA.
- On account deletion, we delete your account and associated data within 30 days, subject to the compliance retention obligations above.
7. Third-Party Processors
AlignMe relies on the following sub-processors to deliver the Service. This list is sourced from our verified production stack (AlignMe.AppHost) and updated whenever the stack changes.
- Microsoft Azure — infrastructure (compute, database, storage, key vault, voice transcription)
- Anthropic — AI model inference (Claude API)
- Stripe — payment processing
- Resend — transactional email
- Typesense — search index
- Sentry — error monitoring
The following alternate AI processors may be substituted in gov-tier or isolated-enterprise deployments (see §5). These are not active on the standard service tier:
- Azure OpenAI — AI inference (alternative)
- AWS Bedrock — AI inference (alternative)
- LocalLlama (self-hosted) — AI inference (air-gap)
We do not sell, rent, or trade your personal information to any third party for their own purposes.
8. Your Rights
Depending on your location, you may have some or all of the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion of your account and associated data. We complete verified deletion requests within 30 days, subject to the compliance retention obligations described in §6.
- Portability — receive your data in a machine-readable, portable format.
- Opt-out of AI training — request that your data not be used to improve our AI models.
- California residents (CCPA) — AlignMe does not sell personal information. You may request to know what data we collect and request deletion at any time.
- EU / UK residents (GDPR / UK GDPR) — you may lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact our Data Protection Officer at privacy@alignme.app. We respond to verified requests within 30 days.
9. Children
AlignMe is intended for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we discover we have collected information from someone under 18, we will delete it immediately. If you believe a minor has provided us with personal information, please contact privacy@alignme.app and we will investigate and delete the data promptly.
10. Security Practices
We use industry-standard technical and organizational controls to protect your data:
- Encryption in transit — TLS 1.2 or higher for all client-to-server and server-to-processor traffic.
- Encryption at rest — AES-256 for stored data, including the database, object storage, and key vault.
- Access controls — least-privilege access to production systems, with audit logging on administrative actions.
- HIPAA posture — AlignMe is not a HIPAA-covered entity on the standard service tier and must not be used to process Protected Health Information without a separately executed Business Associate Agreement. See Terms of Service §10 for the full HIPAA posture.
- Gov-tier hardening — for gov-tier and isolated-enterprise deployments, infrastructure is configured to DISA STIG baselines, administrative access is gated by PIV / CAC smart-card authentication, and audit logs are streamed to a customer-controlled SIEM.
No system is perfectly secure. We will notify affected users of a confirmed personal-data breach within 72 hours of discovery, as required by GDPR Art. 33.
11. International Transfers
AlignMe’s standard service is hosted in United States Azure regions. If you access AlignMe from the European Union, European Economic Area, United Kingdom, or Switzerland, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses approved by the European Commission as the legal basis for such transfers. By using AlignMe from these regions, you consent to this transfer.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before they take effect. The “Effective Date” at the top of this page indicates when the current version took effect. Your continued use of AlignMe after the effective date of the updated Policy constitutes acceptance of the updated Policy. If you do not agree to the updated Policy, you must stop using the Service.
13. Contact (DPO)
For privacy questions, data-subject requests, or concerns, contact our Data Protection Officer at dpo@alignme.app. For general support, contact AlignMe LLC at support@myalignme.com or visit myalignme.com.