The Record
What we keep. What we don't.
This page tells you, in full and before you decide, what data the system collects, what it does not, where each piece lives, who can see it, and how to remove it.
The three things that matter most
Aletheia does not retain generated letters or reports on its infrastructure. They are processed temporarily to create the result and return it to your browser, where the current tab holds them for you.
We do not run analytics on the content of your letters, reports, or assessment. There are no trackers, behavioural analytics, or session recordings. Limited technical monitoring helps us repair faults and check important operations without sending what you wrote; its exact limits are below.
Your assessment answers are encrypted with a key only you hold. Your account is set up with a passphrase that becomes the encryption key. What sits on our side is unreadable without it — including by us.
The rest of this page elaborates all three.
What is collected
| What | Readable to Aletheia while stored? | When deleted |
|---|---|---|
| Account & sign-in — your email address (used to send your sign-in link) and a yes/no record that you accepted the terms | Yes — this is the one group we need to read to operate your account | When you ask for account deletion |
| Your assessment — everything you record while answering, plus limited progress facts used in your private reports: when an item was first answered or skipped, how many times its score or attribution later changed, and whether its first resolution was an answer or a skip | No — encrypted with your passphrase | "Reset questions" wipes it; deleted with account |
| Your customisation — the personal touches (how you sign the letter, how you address the people in it) and the list of questions you excluded | No — encrypted with your passphrase. One exception: the simple style choices (writing style, structure, length, recipient) are readable by us — they are picks from a menu, like "longer letter", not content | "Reset customisations" wipes it; deleted with account |
| Wellbeing check-ins — for the SRS-8 safety check, only the resulting risk level is stored; its individual answers and free text are not. For the PWA-9 wellbeing check, answers and scores are stored when trend saving is on, so the app can show change over time | No — encrypted with your passphrase. We can see only the timestamps, so the app knows when a re-check is due | Deleted with account; or turn off trend saving from your /account page — that removes PWA-9 answers and scores and older SRS-8 history, keeping only the minimum dates and latest safety result needed for re-check timing |
| Generation history — which model generated a letter or report, when, how many questions went in, and limited usage facts such as token counts and duration. Kept to enforce generation limits and operate the service; no prompt, letter, or report content | Yes — the record above, nothing more | Preserved on both resets, so the generation limit cannot be bypassed by resetting; deleted with account |
| Feedback — optional post-letter feedback you choose to send | Yes — it is meant for us to read so we can improve the product | Deleted with account |
| Technical monitoring — approved error, warning, status, timing, app-version, browser/device/display, and code-location fields for important technical operations | Yes — these records deliberately contain no account identity, request content, assessment, screening, prompt, note, feedback, letter, or report content | Automatically removed by the monitoring provider after its history window, currently no longer than 90 days |
That is the information Aletheia retains. Other personal material either stays in your browser or is processed temporarily when you ask for a letter or report.
What is not retained or tracked
- Generated letters and reports. Aletheia does not retain them on its infrastructure. The current browser tab holds them so you can read and download them.
- Your individual safety-screening (SRS-8) answers. Only the resulting risk level is kept (encrypted, in your wellbeing history); the answers themselves, including anything you type, are never stored.
- No session recording or behavioural monitoring. No screen recordings, advertising trackers, or outside analytics run on the assessment or letter pages. The limited encrypted assessment-progress facts listed above are used only for your private reports; technical monitoring contains no user content.
- No advertising or marketing data. Nothing about you is collected for, shared with, or sold to advertisers.
- No password. Sign-in is by one-click email link, so there is no password for us to store or leak.
How generated material is handled
Aletheia's API, the routing service, and the selected model process the information needed to create a letter or report. This happens temporarily, over encrypted connections, only when you ask for generation. Aletheia does not save the prompt, letter, or report in its database.
Your current browser tab holds the generated material while you read it. A refresh or return within that tab can restore it. It normally disappears when the tab or browser session ends, although a browser may restore tab storage after a restart.
What this means in practice:
- If you want to keep a letter or report, download and save the document somewhere safe — or copy the text into a file of your own.
- If the current-tab copy is gone when you return, you will need to generate the material again.
- Aletheia cannot retrieve a past letter or report from its infrastructure because it does not retain one.
Why your assessment answers stay encrypted
The why is simple here too: the assessment holds the most personal material in the product — what you confirmed about your childhood, who you attributed it to, the notes in your own words — and material like that must stay private, whatever happens on our side. So we treat it the way a password manager treats what you store in it: we hold it, but we cannot read it.
The plain version of how this works:
- When you sign up, your account is set up with a passphrase (either one generated for you, or one you set yourself). That passphrase becomes the key to your assessment.
- The key never leaves your browser. We never see it, never store it, cannot recover it.
- The answers you write are encrypted with that key before they reach us. What sits on our side is unreadable without the key — including by us.
- When you sign back in later, you re-enter the passphrase. The key comes back into your browser, and your assessment becomes readable to you again.
One honest boundary.
When you ask for a letter or report, your browser unlocks the information needed for that request and sends it to Aletheia over an encrypted connection. Aletheia's API prepares the request, and the routing service and selected model process it temporarily to create the result. Aletheia does not retain the prompt, letter, or report on its infrastructure. The routing request is restricted to model providers marked as not collecting user data; the routing service and model provider otherwise handle the request under their applicable data terms.
A backup, in case you forget the passphrase.
At sign-up, you also see a 24-word backup code, shown once. It can unlock your data if you forget your passphrase. We do not have a copy. If you lose both the passphrase and the backup code, what is on our side stays unreadable — to you and to us. There is no recovery button we can offer. The encryption puts the power over this material in your hands alone, and that power comes with a matching responsibility: keeping the passphrase and the backup code safe is on you.
Authentication: passwordless
Sign-in is by email link. You enter your email, we send a one-click sign-in link, you click. There is no password to create, no password to remember, no password for us to leak.
Sign-in links expire shortly after issue and become single-use after click.
Technical monitoring
We use Sentry to detect errors and measure the reliability and speed of important technical operations, such as saving your work or generating a letter. Sentry receives limited technical details about the affected part of the service, the error or status code, the app version, timing, and browser, device, and display information. It does not receive the personal content you enter in Aletheia. These records are stored in Germany for up to 90 days. We use them only to operate, secure, and repair the service, based on our legitimate interests.
Each record is rebuilt from a short allowed list before it leaves the app. Error messages are replaced with fixed technical summaries. A record cannot contain your email or account ID, stored IP address, URL or query, request or response body, cookies or headers, assessment or screening material, prompts, letters, reports, notes, feedback, credentials, database values, or other text you supplied.
The browser connection exposes its network address while delivering a record, as any internet connection does, but Sentry is configured not to store it. Sentry acts as our service provider for this limited technical purpose.
Right to export
You can take your data with you.
- Your assessment responses and everything you entered around them — answers, notes, customisations — can be downloaded in open file formats that common software can read. Because this material is encrypted with your passphrase, you need to be signed in and unlocked; the unlocking happens in your browser before the export is built.
- Your generated letter or report is yours to download. Aletheia does not retain a server-side copy after generation, so there is no stored letter or report to include in a later account export.
Right to delete
Deleting is a right, not a request: you do not have to ask us, justify anything, or wait for anyone. The data is yours, so you can remove as much or as little of it as you want, on your own, from your /account page. Three delete actions exist:
Reset your questions. Removes everything you entered while answering the assessment.
Reset your customisations. Removes all the letter set-up choices you made.
Delete your account. Removes everything — profile, answers, preferences, generation history, feedback, the email itself, and your sign-in record. There is nothing left in the live service to associate with you. We offer this because you should be able to walk away completely, without asking permission.
In every case the data disappears from the app immediately and is permanently erased from our systems within 30 days. We keep backups solely for disaster recovery — so the service can be restored after a technical failure or accident — never to retain data you have deleted; your deleted data is cleared from them as each backup is dropped in the normal recovery cycle, within that same 30-day window. Throughout, your encrypted answers stay unreadable to us, because the key never leaves your device.
The action is server-side and, from your side, irreversible. We log every reset action — what was reset, when, and a one-way fingerprint of where the request came from (never your raw IP address) — so we can investigate any data-loss report you bring us.
Anonymous-by-design intent
We do not link your assessment data to any external identity beyond the email used for sign-in. We do not enrich your data from third-party sources. We do not buy data about you.
Even within our own operations, we cannot read your assessment content — it is encrypted with your passphrase (see Why your assessment answers stay encrypted above). What we can see on our side is your email, your sign-in history, and the fact that your account took the assessment — never what is in the answers themselves.
The minimum viable identifying information is your email. We are exploring fully anonymous access options for future versions, but they are not promised.
Security posture
What we actively do:
- Protected in transit. Every connection between your browser, our systems, and our AI provider is encrypted while traveling, so eavesdroppers on the internet cannot read it.
- Protected at rest, with an extra layer for your most personal material. Everything stored is encrypted by default. On top of that, your assessment answers and the personal terms on your profile are encrypted with a key only you hold (your passphrase). The encryption protecting this material is the same industry standard trusted by password managers and banks — chosen to meet today's requirements with room to spare, strong enough by current understanding to withstand even the attack scenarios expected from future quantum computers. Even with full access to our database, we cannot read it.
- Accounts are isolated by design. The separation between accounts is enforced inside the database itself, not just in the app — by design, no account can see or touch another account's records, and even a bug in the app could not cross that line.
- Every letter is quality-checked on your device. When your letter finishes arriving, your browser checks it for technical faults — internal system labels leaking into the text, malformed or cut-off output — and alerts you with the option to regenerate.
What we cannot promise:
- Zero-day protection. No system can promise that. We patch dependencies and follow upstream security advisories.
- Hardened against state-level adversaries. No consumer product can honestly promise that, and we will not pretend to. If your threat model includes nation-state attackers, you need specialist tooling beyond any web product.
What we don't do
The single thing we refuse, stated generally: we do not watch you. We do not measure, profile, or experiment on what you do or what you write inside the product — not to study you, not to optimise you, not to sell you anything. None of the behavioural machinery below has been built. We do not use your answers, letters, or reports for analytics, advertising, profiling, or product experiments, and we do not build a tracking profile. The app processes the needed material only when you ask it to generate a letter or report. The limited encrypted assessment timing and change facts named above exist only to produce your private questionnaire-quality report. Technical monitoring records describe code health, not what you did or wrote.
One clarification so the picture is exact: the product does analyse your answers when you ask it to — that is what the letter and the optional reports are. That temporary processing runs at your request, for you, from material that stays encrypted at rest; it is never done for our own purposes, and Aletheia does not retain the generated material.
The list below names specific things you might assume we'd have, because most products do. We don't.
- No trackers on assessment, customisation, or generation pages.
- No behavioural analytics on the content of your letter or your assessment responses.
- No third-party tracking scripts on assessment-flow pages.
- No data sold, rented, or shared for advertising or profiling.
- No advertising integrations. There is no advertising business in this product.
- No nag emails. We do not email you to "come back and finish your assessment." Reminders you actually want will only ever exist as an explicit opt-in.
- No A/B testing on you. The experience of signed-in users is not silently swapped mid-flow.
On the public pages you are reading now, there is also nothing today — no analytics, no trackers. If we ever add measurement here — to see whether these pages do their job, or to improve how we present the product — it will be aggregate-only and profile-free: counts, not identities.
Hosting and jurisdiction
- Application: Serverless functions run in Frankfurt, Germany; static assets are distributed through a global content delivery network.
- Database and authentication: Hosted in the EU.
- Technical monitoring: The limited technical records described above are stored by Sentry in Germany. Sentry and its approved service providers may perform support or other processing outside Germany under contractual transfer safeguards.
- Letter and report generation: Aletheia's Frankfurt-hosted API prepares the generation request and sends it through a routing service to a single large language model. The routing request is restricted to model providers marked as not collecting user data. The routing service and model provider process the request under their applicable data terms. The result returns through Aletheia's API, and Aletheia does not retain the prompt, letter, or report on its infrastructure.
The honest limit
Privacy guarantees are guarantees about the system as designed. They depend on:
- Our hosting and database providers living up to their security commitments (we check their public security posture; their infrastructure is theirs to run, not ours).
- Your own device and account security (an attacker with access to your email inbox can sign in as you). Your email is also your only door into the account: lose access to that inbox and no sign-in link can reach you, which locks you out in a different way than a lost passphrase.
- You keeping your passphrase and backup code safe. Because we do not have a copy of either, losing both means permanently losing access to the encrypted content of your account — your answers, your notes, your personal terms. The account itself still opens by email, but that material stays locked. The trade-off for "we cannot read your data" is that we also cannot recover it for you.
- The third-party software we build on. Like every web product, ours is assembled from established software components — we pin exact versions, watch for reported vulnerabilities, and update on a schedule.
We can promise the architecture. We cannot promise the world around it.
200 questions — years of clarity.