This page explains what personal data Alvo processes, why and on what legal basis, how long we keep it, who we share it with, and how you can exercise your rights.
Updated 25 September 2026
Short version
Alvo is currently free. We do not sell personal data, show ads, or profile users.
Short version
Alvo is currently free. We do not sell personal data, show ads, or profile users.
Forecasts and briefs are computed by Alvo's deterministic core; your data is not sent to external AI models.
We use only strictly necessary and preference cookies, so there is no consent banner.
Send requests about your data, including account deletion, to privacy@alvo.energy; we reply within 30 days.
01
Who is responsible
The data controller is ФОП ЯКИМЕНКО ВАЛЕНТИН МИКОЛАЙОВИЧ (ФОП), a sole proprietor registered in Ukraine, which operates Alvo; the full registered details and address are published at /en/imprint. Privacy requests can be sent to privacy@alvo.energy.
02
Data we process
Only what the Service needs to work:
Account data: email, name, organization, and two-factor settings — through our authentication provider, WorkOS. Alvo does not store passwords.
Usage: feature-usage counters linked to your account.
Product usage statistics: when you view a forecast, run a BESS plan, download an export, or open an AI brief, we store only the type of that action and how many such actions happened that week. The workspace identifier is used only to estimate how many different workspaces were active that week (HyperLogLog) and is never stored; no user identifier, page, exact time, IP address, or user agent is recorded in these statistics.
Email recipients: email, name, language, and opt-in status for the daily decision-package emails.
API keys: the key's name and prefix, who created it and when, when it was last used, and when it was revoked. The key itself is stored only as a hash.
Demo requests and inquiries: the name, email, company, and message you send through the form or by email.
Technical data: IP address and request headers — for security and rate limiting, and in server logs.
Anonymous visit counters: only the event type, page, and time — and, for one event, a coarse loading-time band; no cookie, no identifier, and no IP address in the event itself.
03
Why, and on what legal basis
Each purpose has its own legal basis under Article 6 GDPR and Article 11 of the Ukrainian Law on Personal Data Protection:
Your account, providing the Service, and service emails — performance of a contract (the Terms of Service).
Security, abuse prevention, rate limiting, and the audit log — our legitimate interest in a secure, stable Service.
Anonymous visit counters — our legitimate interest in knowing which pages are useful; the counters contain no personal data.
Product usage statistics — our legitimate interest in knowing which features are actually used.
Replying to a demo request or inquiry — the consent you give in the form, which you can withdraw at any time by email.
Complying with the law, for example a request from a competent authority — legal obligation.
Alvo's forecasts are built from market data; we do not use your account or workspace data to train models.
04
How long we keep data
No longer than needed:
Account and workspace data, including email recipients and API-key metadata — while the account exists, plus 30 days after it is closed.
Audit and security logs — 12 months.
Demo requests and inquiries — 12 months after the last contact.
Server request logs — 30 days.
The weekly HyperLogLog sketch we use to estimate how many workspaces were active — deleted at most 35 days after that week's last event from a signed-in user. It holds no workspace identifier, but it is derived from them: whoever holds it can test whether a known identifier was active that week, so until it is deleted it is pseudonymous data, not anonymous. Only the weekly action counts and the resulting estimate outlive it, and neither holds any identifier.
Database backups are made daily and kept for up to 14 days — on the server and in an off-server copy held in Ukraine — so deleted data normally leaves the backups within 14 days of deletion.
Where the law requires longer retention, we keep only the minimum needed, and only for as long as the law requires.
05
Who we share data with
We do not sell personal data or share it with advertisers. Data is processed only by our sub-processors — hosting, authentication, email, and CDN — under data-processing agreements; the current list is published at /en/sub-processors. We disclose data to public authorities only when the law requires it.
06
International transfers
The primary data processing and storage environment is European Union (DigitalOcean — Frankfurt (fra1)). Database backups are also held in Ukraine — at the controller's place of registration. WorkOS and Resend are located in the United States — these transfers are governed by EU Standard Contractual Clauses; Cloudflare processes traffic on its global network. Details are in the DPA and the sub-processor registry.
07
What stays in your browser
Language, theme, density, strategy parameters, and BESS settings are stored in browser localStorage; for signed-in accounts, the current strategy and saved profiles can also sync to your account. CSV imports are read in the browser; the original file is not stored on the server.
08
Your rights
You can ask to access, correct, delete, restrict, or port your data, object to processing, or withdraw consent. Write to privacy@alvo.energy from the address linked to your account so we can confirm the request comes from you. We reply within 30 days.
09
Deleting your account
There is no self-serve account deletion in the interface yet. Write to privacy@alvo.energy from your account address — we will delete the account and its related data within 30 days and confirm by email, except data we must keep by law.
10
Where to complain
If you believe we are infringing your rights, you can complain to the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua) or to the data-protection supervisory authority in the EU country where you live or work. We would appreciate the chance to resolve it with you first.
11
Security
Alvo uses server-side input validation, API security headers, rate limiting, no-store API responses, and data minimization. Integration secrets, keys, and production credentials are not stored in the browser.
12
Changes to this policy
The date at the top of this page shows the latest version. We notify registered users of material changes by email.
Cookies
Alvo uses only strictly necessary and preference cookies. There are no advertising or analytics cookies, so we do not ask for consent — we only show a short notice.
Name
Purpose
Lifetime
Type
alvo_session
Your signed-in session
8 hours
Strictly necessary
alvo_user
Signed session profile (name, email, organization) for the interface
8 hours
Strictly necessary
alvo_oauth_state
Protects OAuth sign-in against request forgery
10 minutes
Strictly necessary
alvo_auth_return
The page to return to after sign-in
10 minutes
Strictly necessary
alvo_pending_auth
An unfinished sign-in step (email verification or a two-factor check)
Up to 15 minutes
Strictly necessary
alvo_mfa_factor, alvo_mfa_enroll_factor
A two-factor verification or enrolment step
10 minutes
Strictly necessary
alvo_locale
The language you chose
1 year
Preference
alvo-ws-theme
Light or dark theme
1 year
Preference
alvo_market_zone
The market zone selected in the workspace
1 year
Preference
Cloudflare, which serves the site, may set its own strictly necessary security cookies (for example __cf_bm) to filter automated traffic. The anonymous visit counters work without cookies.
Questions about your data?
Write to privacy@alvo.energy — we reply within 30 days. For general product questions, see the help center.