Draft — not yet in force. This document has not been reviewed by a lawyer and is published here for review only.

Alapon — Privacy Policy

Last updated: 2026-09-15

Alapon is operated by LeadRescue LLC, contactable at saul@sitesbysaul.com.

<!-- No postal address here, by the owner's decision on 2026-09-14. The entity is named and a working contact address is given, which is what a data subject needs in order to reach us. Revisit if a jurisdiction we operate in demands a postal address specifically. -->


The short version


What we collect

You give us

WhatWhyHow long
Email addressTo identify your account and let you sign inUntil you delete your account
PasswordTo sign you in. Stored as an Argon2id hash — we cannot read it or recover it, only check itUntil you delete your account
Your messages and Alapon's repliesTo show you your conversation history and to answer your next question in contextUntil you delete the conversation or the account
Saved memoriesOnly what you explicitly add. Off by defaultUntil you delete them
Uploaded documentsSo Alapon can answer questions about them and cite them30 days, then deleted automatically
Language and script preferenceSo replies come back in the script you write inUntil you delete your account

Created as you use it

WhatWhyHow long
Usage records (token counts, timestamps, which model)To enforce your plan's daily limit and to control cost. Contains no message content12 months, then deleted [OWNER: confirm — long enough for a billing dispute, short enough to be defensible]
Subscription status and a Google Play purchase tokenTo know which plan you are onWhile the subscription exists, plus 24 months for billing and tax records [OWNER: confirm against your accountant]
Security events (sign-ins, failed sign-ins, session reuse)To detect someone attacking your accountSee "what survives deletion"
Safety recordsOnly when a message is blocked or specially handled. Ordinary messages are never recorded hereSee "what survives deletion"
Crash reportsIf the app stops unexpectedly, so the fault can be fixed. The error and your phone model only — never your messages and nothing that identifies youKept; see "if the app crashes"

If the app crashes

When the app stops unexpectedly it writes down what went wrong and sends it the next time you open it. We send it to our own server. We do not use Crashlytics, Sentry, or any other crash service, so no third company receives anything.

What is in a crash report: the name of the programming error, the list of functions the app was running when it failed, the app version, your Android version, and your phone model — for example "Samsung SM-A155F".

What is not in it, by design: your messages, your documents, your email address, your account, your location, your phone number, any advertising or device identifier, and your IP address. The error's own description is deleted on your phone before the report is sent, because that description sometimes quotes the text that caused the problem — and that text could be something you wrote. Our database has no column for any of it.

You can turn crash reports off in Settings. They are on when you install the app, and switching them off takes effect at once — after that nothing is even written down on your phone.

What we never collect


What survives account deletion, and why

When you delete your account we immediately remove your conversations, your messages, your memories, and your uploaded documents; we sign out every device; and we scramble your email address so it is not kept in readable form and so you can sign up again with it.

Two records remain, attached to an account number that no longer identifies anyone:

1. Security logs — sign-ins, failed sign-ins, and session-token reuse. If these could be erased by deleting an account, someone who broke into your account could erase the evidence of having done so. That would make you less safe, not more private.

2. Safety records — only for messages that were actually blocked or specially handled, never ordinary conversation. Each holds a short excerpt (at most 300 characters) so that a person reviewing an appeal has enough to judge it fairly.

Neither holds your conversations. We consider this the honest trade: a small, named exception in exchange for logs that cannot be tampered with. If you object to it, please do not create an account.


Where your data goes

Alapon uses an AI model to generate replies.

Today, no outside AI company receives your messages. The model runs on servers we operate ourselves. Your message goes to our server, the model answers there, and the reply comes back. No third-party AI provider — not OpenAI, not Google, not Anthropic, not anyone else — is sent your conversations.

Your messages do leave Bangladesh, to our server. That server is in Singapore, chosen because it is close enough to Dhaka to be fast. It is operated by us and the data on it is ours and yours, not a vendor's.

Apart from Google Play (for subscriptions), we do not share, sell, rent, or trade your data with anyone. There are no advertisers and no data brokers involved in this product.

The provider we will use, named in advance

We are not using them yet. Nothing has been sent to them. We are naming them now rather than on the day we switch over, so you can decide how you feel about it before it affects you.

We read those terms on 15 September 2026, on Together's own documentation and terms pages — not from a summary of them.

Before the first message is sent to them, this page will be updated to say so in the present tense, with the date. If you are reading this sentence, it has not happened yet. We will not switch that on quietly.


Training

We do not use your private conversations to train or tune AI models.

There is a setting for contributing conversations to improvement. It is off. It cannot be on by default, and turning it on has to be a deliberate act by you, with a plain explanation of what it means at the moment you do it.


Your rights

From inside the app, at any time:

You do not need to email us or wait for us to act. If you would rather write to a person, saul@sitesbysaul.com.

If you have uninstalled the app or cannot sign in, the deletion page explains how to ask us instead: how to delete your account.

Under PDPA 2026 you may have further rights, including correction and complaint to a regulator. [COUNSEL TO COMPLETE — the specific rights and the regulator's name and contact.]


Security

We do not claim to be unbreakable. If you find a security problem, please write to saul@sitesbysaul.com — we would much rather hear from you than not.


Children

Alapon is not intended for children under 18. [OWNER/COUNSEL: 18 is the conservative choice and the one to default to. Going lower pulls the app into Play's Families policy and adds parental-consent duties under PDPA 2026 — more obligation, for an audience that is not the paying market.] We do not knowingly collect data from them. If you believe a child has created an account, contact saul@sitesbysaul.com and we will delete it.


Important: Alapon is not a professional

Alapon is an AI assistant. It can be confidently wrong. It is not a doctor, a lawyer, an accountant, or a counsellor, and nothing it says is professional advice.

If you are in danger or thinking about harming yourself, please contact local emergency services or a crisis line. Alapon will try to point you to one, but it is software and it is not a substitute for a person.

Alapon is an independent product. It is not made by, affiliated with, or endorsed by OpenAI, Google, Anthropic, or any other AI company, whichever model happens to be generating a reply.


Changes

If we change this policy we will update the date at the top and tell you in the app before the change takes effect. We will not quietly widen what we collect.

Contact

LeadRescue LLC · saul@sitesbysaul.com