Privacy Policy

Last updated: August 27, 2026

1. Introduction

AllSource ("we", "our", or "us") operates the AllSource platform, including AllSource Core, Query Service, MCP servers, and web dashboard (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name, email address, and authentication credentials. If you sign up via OAuth (Google, GitHub), we receive your profile information from those providers.

2.2 Usage Data

We collect metrics about your use of the Service, including event ingestion counts, query volumes, API call frequency, and storage usage. This data is used for billing, capacity planning, and service improvement.

2.3 Event Data

You store event data in the AllSource event store. We do not access, analyze, or share the contents of your event data except as necessary to provide the Service (e.g., executing your queries). Your event data remains yours.

2.4 Technical Data

We automatically collect IP addresses, browser type, operating system, referring URLs, and device information when you interact with our web dashboard.

2.5 Attribution Answers You Choose to Give Us

During onboarding we ask an optional question — "how did you find us?" — and, if you say an AI assistant sent you, we offer an optional free-text box asking what you asked it. Both are entirely optional and skipping them has no effect on your account. If you answer, we store your answer (including the free text, verbatim, up to 500 characters), the option you selected, your tenant ID, your plan at the time, and the timestamp. We never store your email address against these answers. The same two optional fields are available on our self-service /api/v1/onboard/start endpoint for programmatic signups.

Unlike the event data described in 2.3, these answers are our own operational data and are read by our team: we use them to work out which questions people ask AI assistants before finding us, and what to write next. They are not used for advertising, are not sold, and are not shared with third parties. Ask us and we will delete yours — see the Contact section below.

2.6 Design Partner Applications

If you apply to the design partner program, we collect your name, work email, a short description of what you are building and its current memory problem, campaign attribution parameters, consent version, and submission time. We use this information only to assess fit, contact you about the program, support an accepted integration, and evaluate which campaign sources produce qualified applications.

Application details are stored in a private administrative event stream. We do not put applicant contact details or answers in public analytics properties, campaign URLs, GitHub issues, or public event streams. Rejected and waitlisted applications receive a retention deadline 90 days after the decision. Accepted applications receive a retention deadline 90 days after the 60-day program. You can request earlier removal using the contact address below.

3. How We Use Your Information

  • Provide, operate, and maintain the Service
  • Process billing and enforce usage quotas
  • Send transactional emails (account verification, billing receipts, security alerts)
  • Monitor service health and prevent abuse
  • Improve the Service based on aggregate usage patterns
  • Respond to support requests
  • Comply with legal obligations

4. Data Storage and Security

Your event data is stored in the AllSource Core engine with write-ahead logging (WAL) and Parquet columnar storage. All data is encrypted in transit (TLS 1.2+). We implement industry-standard security practices including multi-tenancy isolation, role-based access control (RBAC), and comprehensive audit logging.

5. Data Retention

Event data retention depends on your plan tier (7 days for Developer, 90 days for Team, unlimited for Enterprise). Account information is retained while your account is active and for a reasonable period afterward for legal and operational purposes. You may request deletion of your account and associated data at any time.

6. Data Sharing

We do not sell your personal information. We may share data with:

  • Service providers who assist in operating the Service (payment processing, email delivery, infrastructure hosting)
  • Legal authorities when required by law, court order, or governmental regulation
  • Business transfers in connection with a merger, acquisition, or sale of assets

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to or restrict processing of your data
  • Withdraw consent at any time

To exercise these rights, contact us at sales@wolventech.com.

8. Cookies

We use essential cookies for authentication and session management. Google Analytics 4 receives cookieless measurement pings with analytics and advertising storage denied by default. We remove URL query strings and referrer query strings, disable Google Signals and advertising personalisation, and do not set advertising cookies. Enhanced measurement covers aggregate interactions such as scrolls, outbound links, forms, videos, and downloads; automatic browser-history page views and site-search capture are disabled.

9. Children's Privacy

The Service is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us for removal.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy, contact us at sales@wolventech.com.