Privacy Policy
Version 2026-08-10-v3
This Privacy Center explains what Alera collects, how educational AI uses your data, and how you can export or delete it. Alera is educational software—not a medical device and not a substitute for clinical care.
In-product controls live in Settings → Privacy Center. Signed-in users can open Settings to export or delete data.
What data we collect
We collect only what you provide or generate while using Alera, plus technical data needed to operate and secure the service.
- Account: email, name, authentication metadata (via Supabase Auth)
- Health-related inputs you upload or enter: labs, wearable readings, journal notes, family history, medications/conditions you add
- Product usage: settings, plan/subscription status metadata, in-app preferences
- Technical logs: security and reliability logs (IP/user-agent may appear in hosting logs)
- Payments: Stripe processes card payments; Alera does not store full card numbers
Why we collect it
We use this data to provide Alera’s educational features, secure your account, and improve reliability—not to sell your health information.
- Authenticate you and protect your account
- Generate educational trajectories, Living Forecast estimates, and related insights from data you supply
- Support labs confirmation, journal, search, and other product tools you use
- Process subscriptions and receipts through Stripe
- Respond to support, security, and legal obligations
Where it is stored
Application data is stored in our production Postgres database (hosted with our database/auth provider). The web app runs on our hosting provider. Wearable OAuth tokens are encrypted at rest with a server-only key before storage.
Hosting, database, and auth processors may store backups according to their retention schedules. After you delete your Alera account, we remove application records we control; provider backups expire on their schedules.
What AI uses it
Alera’s trajectory / Living Forecast engine (our educational inference service) uses biomarkers, wearable summaries, and profile context you provide to produce educational estimates with uncertainty and disclaimers.
Optional “Ask Alera” chat may send relevant conversational context to an LLM provider when configured. Chat is not used to invent clinical diagnoses or fake citations. If the LLM is unavailable, Alera falls back to rule-based educational answers.
- Inference model outputs are educational estimates—not medical facts
- When inference is down, Alera shows “Unable to load” instead of inventing scores
- Model version identifiers are included with inference responses when available
Connected services
Depending on configuration, Alera may connect to:
- Supabase — authentication and database hosting
- Vercel — application hosting
- Stripe — subscription payments
- OpenAI — optional chat and text-to-speech (only if enabled for the deployment)
- Inference host — educational trajectory engine
- Wearable platforms — only if you connect or upload (Oura, Fitbit, Whoop, Garmin, Google Health Connect, Apple Health export, or manual entry)
Delete my data
You can permanently delete your Alera account and application data from Settings → Privacy Center → Delete account. You will be asked to confirm. Deletion removes Alera-controlled records; identity-provider backups follow that provider’s retention.
Export my data
You can download a machine-readable JSON export of your Alera account data from Settings → Privacy Center → Export data. The export is an educational data package—not an official medical record.
AI transparency
Alera’s trajectory engine produces organ-system educational stability estimates, regime labels (for example Baseline / Keep watch / Lower stability), drivers, and uncertainty. Outputs include disclaimers and are intended for discussion with a qualified clinician.
Limitations: estimates may be incomplete or wrong; sparse data lowers confidence; the service is not validated as a medical device. Model identifiers (for example trajectory-graph educational versions) help with reproducibility when investigating a result.
Human involvement: you confirm lab imports before save; you decide whether to act on educational outputs; clinical decisions remain with you and your clinician.
Retention
We retain account and health-related data while your account is active. After account deletion, Alera application records we control are removed promptly, including best-effort removal of uploaded lab files from storage. Security logs and processor backups may persist for a limited period (typically up to 90 days unless a longer period is required for security or legal reasons).
Age eligibility
Alera’s consumer product is intended for adults 18 years of age or older. Email signup and social sign-in both require an 18+ affirmation plus Terms and Privacy acceptance.
Correction
You can update your name and account settings in Settings. Email changes go through a verification link. To correct health-related entries, edit or re-upload data in the relevant tools (for example Labs or Journal), or delete incorrect uploads where the product allows. For assistance, email privacy@aleralabs.io.
Contact
Privacy questions and requests: use the email on your account Settings page or the operator contact for this deployment. Related: Terms and Conditions.