Altabric
Privacy policy
Last updated: 15 July 2026
This policy explains what personal data we collect, why we collect it, who we share it with, and what your rights are. It covers three things: the altabric.com website, the altabric platform (the product you sign in to and use), and any third-party accounts you choose to connect to the platform, such as LinkedIn. We try to keep it short and honest.
Who we are
Altabric is based in London, United Kingdom. For any question about this policy, or to exercise any of your rights, write to contact@altabric.com.
The two roles we play
Data-protection law distinguishes between a controller (who decides why and how personal data is used) and a processor (who handles it on someone else's instruction). Altabric plays both roles, and it matters which one applies:
- We are the controller for the personal data described in this policy: website-visitor data, the account details of the people who use the platform, the details of anyone who contacts us, billing data, and the identity and access tokens of any third-party account you connect. This policy governs all of that.
- We are a processor for the content our customers put into the platform — the documents, data and prompts an organisation uploads to have the platform work on them. We handle that content only on the customer's instruction. The terms for it are set out in a separate data processing agreement with the customer organisation (available on request), not in this policy.
What we collect, and why
When you visit the website. Our website host (Cloudflare) processes your IP address and basic browser information to serve pages and compile anonymous, aggregate traffic statistics. The marketing website sets no cookies and does not track you across other sites.
When you contact us. If you fill in a contact form or email us, we collect your name, work email, organisation, role, and your message, and use them only to respond. The lawful basis is our legitimate interest in answering people who get in touch.
When you use the platform. To give you an account we collect your name, email and organisation, and we keep operational logs (sign-in events, actions taken, and technical records needed to run and secure the service). The platform sets a strictly-necessary cookie to keep you signed in. The lawful basis is performance of our contract with you, and our legitimate interest in keeping the service secure and working. Any personal data contained in the content you upload is handled under the processor role described above.
When you connect a third-party account (e.g. LinkedIn). See the dedicated section below.
When you pay. Payments are handled by Stripe. We receive confirmation of payment and billing details; we do not see or store your full card number, which Stripe holds. The lawful basis is performance of our contract with you.
How your content is processed by AI
The platform works by sending content to large-language-model providers to be read, summarised, classified or drafted. Depending on the configuration in force, those providers are Anthropic, OpenAI, Google, xAI and DeepSeek — reached either directly or through the OpenRouter aggregator. They act as our sub-processors for that content.
Two commitments matter here, and they are the point of the design:
- We do not use your content to train any AI model, and we send it to these providers under their API terms, which likewise do not use API content to train their models.
- Content is sent only to fulfil the task you have asked the platform to perform, and each customer's data is isolated from every other customer's.
Connecting LinkedIn (and other channels)
If you connect a LinkedIn account so that altabric can publish content on your behalf, you authorise us through LinkedIn's own sign-in and consent screen. From LinkedIn we receive:
- your basic profile identity — your name and a LinkedIn account identifier (via "Sign in with LinkedIn"); and
- an access token that lets us post as you.
We use these only to identify the account you have connected and to publish the specific content you create and instruct us to publish, as posts on your own LinkedIn feed. Specifically:
- We request only the permissions needed to identify you and to post (openid, profile, w_member_social). We do not read your messages, connections, or activity.
- We store only your access token and this basic identity — not your wider LinkedIn profile, and not your LinkedIn content. The token is stored encrypted and used solely to publish content you have directed. We never post anything without your instruction.
- We do not sell or share this data, and we do not use it for advertising or ad-targeting.
- You can disconnect at any time inside altabric, and you can revoke our access from your LinkedIn settings. We delete the stored data immediately when you disconnect, when you ask us to, if you close your LinkedIn account, or if we stop operating the integration. Tokens also expire (currently after 60 days) and are removed on expiry unless you reconnect.
The same principles apply to any other publishing channel you connect in future.
Who we work with
We use the following service providers (processors and sub-processors) to run the website and the platform. Each link goes to that provider's own privacy policy:
Cloudflare, Inc. — hosts the marketing website, processes contact-form submissions, routes incoming email, and provides anonymous traffic analytics. Privacy policy · DPA.
Railway Corp. — hosts the altabric platform and its databases. Privacy policy.
Stripe, Inc. — processes payments and billing. Privacy policy.
AI model providers — content submitted to the platform may be processed, under API terms that do not train on it, by Anthropic, OpenAI, Google, xAI and DeepSeek, directly or via the OpenRouter aggregator.
LinkedIn Corporation — where you connect a LinkedIn account, receives the content you instruct us to publish, on your behalf. Privacy policy.
Google LLC — operates Gmail, where contact messages are received and stored. Privacy policy.
We do not share your personal data with anyone else, we do not sell it, and we do not use it for advertising. We may disclose data where the law requires it, or to a successor if the business is transferred, in which case this policy would continue to apply.
International transfers
Several of the providers above are headquartered in the United States. Transfers of personal data to them are made under the UK Extension to the EU–US Data Privacy Framework and/or Standard Contractual Clauses, which provide a recognised legal basis for international transfers under UK GDPR.
How long we keep it
- Website analytics — up to six months, in anonymous form.
- Contact messages — kept until you ask us to delete them.
- Account and operational data — for as long as your account is active, and then deleted or anonymised within a reasonable period after closure, except where we must keep records longer (for example, billing records for tax purposes).
- Connected-account tokens — deleted when you disconnect the account or when the token expires.
To ask us to delete your data, write to contact@altabric.com.
How we protect it
We encrypt data in transit, and we encrypt sensitive items — including any connected-account tokens — at rest. Access to production systems is restricted and logged, and each customer organisation's data is isolated from every other's within the platform. No system is perfectly secure, but these are the measures we take.
Your rights
Under UK GDPR, you have the right to ask us:
- What personal data we hold about you
- To correct it if it is wrong
- To delete it
- To restrict or object to how we use it
- To receive a copy of it in a portable format
- To withdraw any consent you have given (for example, by disconnecting a channel)
Send any such request to contact@altabric.com. If you think we have mishandled your data, you can also complain to the UK Information Commissioner's Office at ico.org.uk.
Changes to this policy
If we change this policy, the "last updated" date at the top will change, and any material change will be flagged on the site.