Last updated: March 2026

Privacy Policy

Information We Collect

Alvyn is a native macOS application. The app itself collects no telemetry, sends no analytics, and does not phone home. Your server credentials (passwords, SSH keys, API keys, and OAuth tokens) are stored in an encrypted vault file on your device at ~/Library/Application Support/Alvyn/vault.enc, encrypted with AES-256 (ChaChaPoly via CryptoKit). The master encryption key for this vault is stored in the macOS Keychain and never leaves your device.

This website collects the minimum data needed to operate the community and support features:

  • Account information provided by your OAuth provider (GitHub, Google, or Apple) — name and email address only
  • Community posts and answers you create voluntarily
  • Support messages you submit via the contact form
  • Standard server logs (IP address, browser type, pages visited) retained for 30 days

How We Use Your Information

We use collected information exclusively to:

  • Authenticate you and associate your community contributions with your account
  • Respond to support requests you submit
  • Maintain the security and availability of this website

We do not sell, rent, or share your personal data with third parties for marketing purposes.

Data Storage & Security

Website data is stored in a PostgreSQL database hosted in the EU. Account OAuth tokens are never stored — only your name and email address received from the provider at sign-in.

All data in transit is encrypted via TLS. We follow industry-standard practices for access control and data protection.

Third-Party Services

This website uses the following third-party services for authentication:

  • GitHub OAuth — optional sign-in provider
  • Google OAuth — optional sign-in provider
  • Apple Sign In — optional sign-in provider

Each provider's own privacy policy governs how they handle your data during the authentication flow. We receive only your public profile name and email address.

The Alvyn app connects directly to third-party storage services when you configure a connection. OAuth authentication for cloud providers uses a loopback flow — your browser opens the provider's login page and the callback is received locally on your device (127.0.0.1). No Alvyn server is involved at any point. All credentials are stored only in your encrypted local vault. Connections are governed by the respective service's privacy policy:

  • Google Drive — OAuth 2.0 with full Drive access scope (auth/drive); tokens stored locally in your encrypted vault
  • Dropbox — OAuth 2.0; tokens stored locally in your encrypted vault
  • Microsoft OneDrive — OAuth 2.0; tokens stored locally in your encrypted vault
  • Box — OAuth 2.0; tokens stored locally in your encrypted vault
  • Backblaze B2 — API key credentials stored locally in your encrypted vault
  • Amazon S3 / compatible — API key credentials stored locally in your encrypted vault

Alvyn never transmits these credentials to our servers. All authentication and data transfer happens directly between your device and the respective service.

Your Rights

You may request deletion of your account and all associated data at any time by contacting us via the support form. We will process all requests within 30 days.

If you are located in the EU/EEA, you have the right to access, correct, delete, or restrict processing of your personal data under the GDPR.

Contact

For privacy-related questions or data deletion requests, use the support form. We will respond within 5 business days.