Przejdź do treści głównej

Privacy and data

Alvo Privacy Policy.

This page explains what personal data Alvo processes, why and on what legal basis, how long we keep it, who we share it with, and how you can exercise your rights.

Updated 25 September 2026
Short version

Alvo is currently free. We do not sell personal data, show ads, or profile users.

Short version

  • Alvo is currently free. We do not sell personal data, show ads, or profile users.
  • Forecasts and briefs are computed by Alvo's deterministic core; your data is not sent to external AI models.
  • We use only strictly necessary and preference cookies, so there is no consent banner.
  • Send requests about your data, including account deletion, to privacy@alvo.energy; we reply within 30 days.
01

Who is responsible

The data controller is ФОП ЯКИМЕНКО ВАЛЕНТИН МИКОЛАЙОВИЧ (ФОП), a sole proprietor registered in Ukraine, which operates Alvo; the full registered details and address are published at /en/imprint. Privacy requests can be sent to privacy@alvo.energy.

02

Data we process

Only what the Service needs to work:

  • Account data: email, name, organization, and two-factor settings — through our authentication provider, WorkOS. Alvo does not store passwords.
  • Workspace data: strategy parameters, BESS assumptions, saved profiles, decision-ledger entries, and audit events.
  • Usage: feature-usage counters linked to your account.
  • Product usage statistics: when you view a forecast, run a BESS plan, download an export, or open an AI brief, we store only the type of that action and how many such actions happened that week. The workspace identifier is used only to estimate how many different workspaces were active that week (HyperLogLog) and is never stored; no user identifier, page, exact time, IP address, or user agent is recorded in these statistics.
  • Email recipients: email, name, language, and opt-in status for the daily decision-package emails.
  • API keys: the key's name and prefix, who created it and when, when it was last used, and when it was revoked. The key itself is stored only as a hash.
  • Demo requests and inquiries: the name, email, company, and message you send through the form or by email.
  • Technical data: IP address and request headers — for security and rate limiting, and in server logs.
  • Anonymous visit counters: only the event type, page, and time — and, for one event, a coarse loading-time band; no cookie, no identifier, and no IP address in the event itself.
03

Why, and on what legal basis

Each purpose has its own legal basis under Article 6 GDPR and Article 11 of the Ukrainian Law on Personal Data Protection:

  • Your account, providing the Service, and service emails — performance of a contract (the Terms of Service).
  • Security, abuse prevention, rate limiting, and the audit log — our legitimate interest in a secure, stable Service.
  • Anonymous visit counters — our legitimate interest in knowing which pages are useful; the counters contain no personal data.
  • Product usage statistics — our legitimate interest in knowing which features are actually used.
  • Replying to a demo request or inquiry — the consent you give in the form, which you can withdraw at any time by email.
  • Complying with the law, for example a request from a competent authority — legal obligation.
  • Alvo's forecasts are built from market data; we do not use your account or workspace data to train models.
04

How long we keep data

No longer than needed:

  • Account and workspace data, including email recipients and API-key metadata — while the account exists, plus 30 days after it is closed.
  • Audit and security logs — 12 months.
  • Demo requests and inquiries — 12 months after the last contact.
  • Server request logs — 30 days.
  • The weekly HyperLogLog sketch we use to estimate how many workspaces were active — deleted at most 35 days after that week's last event from a signed-in user. It holds no workspace identifier, but it is derived from them: whoever holds it can test whether a known identifier was active that week, so until it is deleted it is pseudonymous data, not anonymous. Only the weekly action counts and the resulting estimate outlive it, and neither holds any identifier.
  • Database backups are made daily and kept for up to 14 days — on the server and in an off-server copy held in Ukraine — so deleted data normally leaves the backups within 14 days of deletion.
  • Where the law requires longer retention, we keep only the minimum needed, and only for as long as the law requires.
05

Who we share data with

We do not sell personal data or share it with advertisers. Data is processed only by our sub-processors — hosting, authentication, email, and CDN — under data-processing agreements; the current list is published at /en/sub-processors. We disclose data to public authorities only when the law requires it.

06

International transfers

The primary data processing and storage environment is European Union (DigitalOcean — Frankfurt (fra1)). Database backups are also held in Ukraine — at the controller's place of registration. WorkOS and Resend are located in the United States — these transfers are governed by EU Standard Contractual Clauses; Cloudflare processes traffic on its global network. Details are in the DPA and the sub-processor registry.

07

What stays in your browser

Language, theme, density, strategy parameters, and BESS settings are stored in browser localStorage; for signed-in accounts, the current strategy and saved profiles can also sync to your account. CSV imports are read in the browser; the original file is not stored on the server.

08

Your rights

You can ask to access, correct, delete, restrict, or port your data, object to processing, or withdraw consent. Write to privacy@alvo.energy from the address linked to your account so we can confirm the request comes from you. We reply within 30 days.

09

Deleting your account

There is no self-serve account deletion in the interface yet. Write to privacy@alvo.energy from your account address — we will delete the account and its related data within 30 days and confirm by email, except data we must keep by law.

10

Where to complain

If you believe we are infringing your rights, you can complain to the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua) or to the data-protection supervisory authority in the EU country where you live or work. We would appreciate the chance to resolve it with you first.

11

Security

Alvo uses server-side input validation, API security headers, rate limiting, no-store API responses, and data minimization. Integration secrets, keys, and production credentials are not stored in the browser.

12

Changes to this policy

The date at the top of this page shows the latest version. We notify registered users of material changes by email.

Cookies

Alvo uses only strictly necessary and preference cookies. There are no advertising or analytics cookies, so we do not ask for consent — we only show a short notice.

NamePurposeLifetimeType
alvo_sessionYour signed-in session8 hoursStrictly necessary
alvo_userSigned session profile (name, email, organization) for the interface8 hoursStrictly necessary
alvo_oauth_stateProtects OAuth sign-in against request forgery10 minutesStrictly necessary
alvo_auth_returnThe page to return to after sign-in10 minutesStrictly necessary
alvo_pending_authAn unfinished sign-in step (email verification or a two-factor check)Up to 15 minutesStrictly necessary
alvo_mfa_factor, alvo_mfa_enroll_factorA two-factor verification or enrolment step10 minutesStrictly necessary
alvo_localeThe language you chose1 yearPreference
alvo-ws-themeLight or dark theme1 yearPreference
alvo_market_zoneThe market zone selected in the workspace1 yearPreference

Cloudflare, which serves the site, may set its own strictly necessary security cookies (for example __cf_bm) to filter automated traffic. The anonymous visit counters work without cookies.

Questions about your data?

Write to privacy@alvo.energy — we reply within 30 days. For general product questions, see the help center.