Privacy Policy
This policy describes what Ravenwood Capital Management, LLC collects when you use AlphaLode, and how it is used. Short version: we collect what is needed to run the Service, we use cookieless analytics, and we do not sell personal information.
What we collect
- Account data: your email address and a bcrypt hash of your password (we never store the password itself). If you sign in with Google or GitHub, we receive your email address from them. We also store your full name and chosen community alias. Your full name and sign-in email are not shown in the member feed or chat directory.
- Billing data: payments are processed by Stripe. Stripe collects your billing address to calculate applicable sales tax. AlphaLode stores your Stripe customer and subscription identifiers; full card numbers never reach our servers.
- Application programming interface (API) keys: stored as Secure Hash Algorithm 256-bit (SHA-256) hashes; the key itself is shown to you once and cannot be recovered by us.
- Password reset: reset links are single-use and expire in 60 minutes. Only a SHA-256 hash of each link's token is stored in the portal database, together with the account identifier, creation and expiry times, use time, and requesting Internet Protocol (IP) address.
- Server logs: standard web-server access logs (IP address, request path, timestamp) kept for security and debugging.
- Account activity logs: for signed-in members we record, per account, the API and terminal requests you make, including request paths and query parameters (for example search terms and filters), with timestamps. We keep these for security, abuse prevention, support and product improvement.
- Usage analytics: we run a self-hosted, cookieless analytics instance (GoatCounter at stats.alphalode.com). It records the page viewed, referrer, browser and screen class, and country. It sets no cookies and does not store your IP address; a short-lived salted hash is used only to distinguish unique visits within a day. No data is shared with any third-party analytics or advertising company.
Cookies
We use only strictly necessary cookies: s (your signed
session, 14 days, HttpOnly/Secure) and os (a transient
anti-forgery value used only during Google/GitHub sign-in). We use no
advertising or cross-site tracking cookies. Display preferences such as theme
and tab order stay in your browser's local storage.
Saved research
Watchlists, saved screens, layout, and alert rules are stored on AlphaLode's servers per account and are deleted with the account. Account deletion requests their removal from the terminal server; if that server is unavailable, cleanup may be delayed.
Text messages
If you add a mobile number and opt in to service update texts, we store the number with your account together with a record of your consent (timestamp and IP address), kept to honor and document your preference. Messages are service updates only. You can opt out at any time by replying STOP or by unchecking the option on your account page. Texts are delivered by Twilio, acting as our processor, which handles your number solely to deliver them.
Research alert email
Membership accounts can choose and confirm an email address for saved research rule alerts. We store the destination, confirmation time, and delivery status. Alert emails state the company and rule type and link back to the terminal. You can turn them off from your account page. Deleting your account removes the destination and local delivery records.
Community feed
Signed-in accounts can read member posts. Accounts with Basic or Membership access can post, reply, like, and follow. We store these actions with your account. Other signed-in accounts can see your alias and posts. Reports are available to moderators. Deleting your account removes your posts and actions from the service, but copies saved by other people may remain.
Member chat
Members can send direct messages to other members inside the terminal. The member directory and chat threads show community aliases, not full names.
- Encryption: Messages are end-to-end encrypted in your browser using keys generated on your device. AlphaLode's server stores only encrypted message bytes and routing metadata: sender, recipient, and timestamp. AlphaLode cannot read message contents.
- Your key: Your private key never leaves your device. If you clear browser storage or switch devices without exporting your key, no one, including AlphaLode, can decrypt messages you previously received.
- Deletion: You can permanently delete any message you sent or an entire conversation. This removes the encrypted bytes from the server for both participants and cannot be reversed.
- Routing metadata: Information about who messaged whom and when is kept while the messages exist. The operator can see this metadata for abuse handling. Message contents are not readable, but the fact and timing of a conversation are.
- What this protects against, and what it does not: Encryption happens in your browser, so the stored messages are unreadable to the server and to anyone who obtains them from it. Because the messaging code is delivered to your browser by AlphaLode, this protection assumes AlphaLode serves honest code; it is not a defense against a compromised operator who alters that code. There is no message-history forward secrecy yet: if your private key is ever stolen, past messages you received could be decrypted. Chat is intended for personal and community use, not for records-retained regulated communications.
Member mail
Each member receives a neutral account email address at mail.alphalode.com. You can use it to send and receive ordinary email with any outside address. Previous addresses continue receiving mail, but are not shown in the member directory.
- Storage: Ordinary email is not end-to-end encrypted. AlphaLode's server stores addresses, subject, and body text for sent and received messages so you can read them in the terminal. Messages remain until you delete them or the inbox storage limit removes older received messages.
- Deletion: Deleting a message permanently removes it from AlphaLode's server. Copies held by the outside party's mail provider are beyond AlphaLode's control.
- Delivery: Outbound mail is delivered through Twilio SendGrid, a third-party email delivery provider that processes the message in transit. Attachments are not supported.
- Use: Sending limits apply to prevent abuse. Using the address for unsolicited bulk mail is grounds for account termination under the terms of service.
How we use it
To provide and secure the Service, process subscriptions, prevent abuse, and understand aggregate usage. Legal bases: performance of a contract and legitimate interest.
Sharing
Service providers only: Stripe (payments and sales tax calculation), Twilio (text-message delivery, if you opt in), Twilio SendGrid (email delivery), and our cloud infrastructure provider (hosting). We do not sell or rent personal information, and we do not share it with advertisers or data brokers.
Retention and backups
Account data is kept while your account is active. You can delete your account yourself from the account page. Deletion is immediate and permanent, cancels any subscription at once, and does not refund unused paid time. Billing audit records are retained with your name, email address, and phone number removed. Encrypted-in-transit daily backups of account data are retained for up to 30 days, after which they roll off automatically.
Your rights
Use "Download your data" on your account page to download your portal records yourself. The download includes profile and subscription information, key prefixes, trial requests, alert and text consent records, community activity, sent and received member mail, chat routing metadata, usage events, and account events. It excludes passwords, token hashes, full API keys, and encrypted chat contents.
You can correct your name, phone number, and community alias on the account page, or delete your account there. Send any other request using "Other privacy requests" on that page or by mail to Ravenwood Capital Management, LLC, 4002 E Sumac Dr., Spokane, WA 99223. We will respond within 30 days.
Children
The Service is not directed to anyone under 18.
Changes; contact
Material changes will be posted here with a new effective date. Contact: Ravenwood Capital Management, LLC, via your account page or by mail to 4002 E Sumac Dr., Spokane, WA 99223.