Privacy Policy
Effective date: July 4, 2026
Last updated: July 4, 2026
1. Introduction
Alyria, LLC(“Alyria,” “we,” “us,” or “our”) operates the marketing website at alyria.ai(the “Site”). This Privacy Policy explains what information we collect through the Site, how we use and share it, how long we keep it, and the choices and rights you have.
This policy covers the public marketing site only. Your organization’s use of the Alyria platform — Beacon, Observatory, Lyra, Constellation, Spectra, Umbra, and the Agent Exposure Report engagement — is governed by a separate Master Services Agreement (MSA) and Data Processing Addendum (DPA) between you and Alyria, LLC, not by this policy. How the product itself custodies your fleet data is summarized in Section 6 and governed in full by those agreements. See also our Terms of Service.
By using the Site, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Site.
2. Information We Collect
The Site is an informational website with a contact form. We collect far less than a product application would, and we are specific about what we collect and why.
Information you provide
When you submit the contactor “book a demo” form, we collect the fields you choose to give us: your name, email address, company, approximate team or fleet size, your area of interest (for example, the Agent Exposure Report or a demo), and your message. We use this to respond to your inquiry, evaluate fit, and follow up with you about Alyria.
Information collected automatically
To keep the Site secure and to understand aggregate usage, we and our analytics provider process limited technical data: your IP address, browser user-agent, language, referring page, pages viewed, and coarse device characteristics (for example screen size, timezone, platform, and hardware concurrency). When you submit a form, a snapshot of this technical context is stored alongside your submission to help us detect spam and abuse.
Cookies and local storage
We set essential cookies and local storage needed for the Site to function and for privacy-conscious analytics attribution. We do not use third-party advertising or cross-site tracking cookies. See Section 4 for analytics detail. You can block or clear cookies in your browser at any time; the Site remains usable without them.
What we do not collect
This marketing site is not where your organization enters its agents, secrets, or fleet data — those never touch it. We do not build advertising profiles, we do not run third-party ad trackers, and we do not sell personal data. Please do not send secrets, credentials, or confidential material through the contact form; anything you send us there is readable by us so that we can reply.
3. How We Use Your Information
We use the information we collect to:
- Respond to you. We use your contact details and message to answer your inquiry, provide the information or demo you requested, and follow up about the Agent Exposure Report or a pilot.
- Operate and secure the Site. We use technical data to deliver the Site, keep it available, and detect and prevent spam, abuse, and fraudulent submissions.
- Understand and improve the Site. We use aggregate, website-visit analytics to understand how the Site is used and where to improve it.
- Communicate with you. Where you have asked us to, or where we have a legitimate interest consistent with applicable law, we may send you information about Alyria. You can opt out of non-essential messages at any time.
4. Analytics & Session Recording
We use PostHog to monitor website visits and understand how visitors move through the Site. PostHog is a SOC 2 Type II certified analytics platform, and the data it collects for us is stored in the United States.
- Website-visit analytics. We record pageviews, page leaves, referral sources, and a small set of interactions (such as clicks and contact-form submissions) to understand demand and usage in aggregate.
- Session recording (session replay).We record how visitors navigate the Site — mouse movement, clicks, scrolling, and page structure — so we can see where the experience is confusing. All text inputs are masked in these recordings, and passwords are never captured; we see that a field was filled, not its contents.
- Identification. You are anonymous until you submit the contact form. If you provide your email there, we associate your analytics activity with that email and your company so we can understand your journey and follow up. We never tie a recording to you from replay alone.
- First-party proxied. Analytics requests are routed through a first-party reverse proxy on our own domain, so no third-party analytics host is contacted directly from your browser.
Analytics data is used to improve the Site and understand demand. It is not used to make decisions that produce legal or similarly significant effects about you. You can limit this collection by enabling “Do Not Track” in your browser, blocking cookies, or asking us to delete your data (see Section 9). PostHog’s privacy policy is available at posthog.com/privacy.
6. The Product’s Data-Custody Stance
Alyria’s trust claim, “under your keys,” is a statement about the product architecture, governed by the MSA and DPA rather than by this Site policy. We summarize it here so the boundary is clear:
- Default custody. In the Agent Exposure Report pilot and the Platform tier, fleet data and the audit chain are encrypted under an envelope key we hold and delete on account termination or on your request, which renders the stored data permanently unreadable — a crypto-shred. Nothing for you to configure.
- Enterprise custody. Enterprise customers can bring their own KMS key (BYOK) or hold a key they never share with us (HYOK). Revoke the key and you can verify in your own cloud audit logs that our access ended.
- Roadmap. Client-held keys, where we never hold the key at all, are future work that will ship only behind an externally audited protocol. Until then we describe them as a roadmap item, not a present property.
- This Site is different. The marketing site is an ordinary public website. A message you send us through the contact form is readable by us, because that is how we reply. Do not send secrets or credentials through it.
7. Data Retention
We keep information only as long as needed for the purposes described in this policy or as required by law, then delete or anonymize it. You can ask us to delete your data sooner at any time (see Section 9).
| Data category | Retention period |
|---|---|
| Contact & demo submissions | Up to 24 months after our last correspondence, then deleted or anonymized; sooner on request |
| Technical snapshot attached to a submission (IP, user-agent, device hints) | Same as the submission it accompanies |
| Website-visit analytics (PostHog events) | Rolling basis, up to 12 months |
| Session recordings (PostHog) | Rolling basis, typically up to 30 days per our configuration; deletable on request |
| Server & delivery logs (hosting) | Up to 30 days |
| Cookies & local storage | Per item lifetime; clearable anytime in your browser |
| Marketing / CRM record (if you opt in) | Until you unsubscribe or ask us to delete it |
8. Data Security
We protect information collected through the Site with appropriate technical and organizational measures:
- Encryption in transit. All traffic to and from the Site is served over TLS.
- Private submission storage. Contact submissions are written to private, access-controlled storage that is not publicly listable.
- Restricted access. Access to submissions is limited to authorized personnel; our internal submissions view is IP-allowlisted and token-gated.
- Least data.The Site collects only what it needs, and does not touch your organization’s agents, secrets, or fleet data.
- Coordinated disclosure. To report a vulnerability, see our security.txt or email security@alyria.ai.
9. Your Rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Access. Request a copy of the personal data we hold about you.
- Correction. Ask us to correct inaccurate or incomplete data.
- Deletion. Ask us to delete your data, subject to any legal retention obligations.
- Portability. Receive your data in a structured, commonly used, machine-readable format.
- Object or restrict. Object to or restrict certain processing, and withdraw consent where we rely on it.
- Opt out of messages. Unsubscribe from non-essential communications at any time.
California residents
Under the California Consumer Privacy Act (CCPA) as amended by the CPRA, you have the right to know what personal information we collect and how we use and disclose it, to request deletion, to opt out of the “sale” or “sharing” of personal information, and to limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising, so that right is satisfied by default. We will not discriminate against you for exercising any of these rights.
EU, EEA, and UK residents
Under the GDPR and UK GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local data protection authority. We process personal data on the legal bases of your consent, our legitimate interests in operating and improving the Site and responding to your inquiries, and, where applicable, taking steps at your request before entering into a contract.
To exercise any of these rights, email hello@alyria.ai. We will respond within the timeframe required by applicable law.
10. International Data Transfers
Alyria, LLCis based in the United States, and information collected through the Site is processed and stored in the United States. If you access the Site from outside the United States, your information may be transferred to and processed there, where data protection laws may differ from those in your jurisdiction. For transfers of personal data from the EU or EEA we rely on the European Commission’s Standard Contractual Clauses (SCCs); for transfers from the UK we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs, as applicable.
11. Children’s Privacy
The Site is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact hello@alyria.ai and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will revise the “last updated” date above and post the revised policy on this page. Your continued use of the Site after a change takes effect constitutes acceptance of the updated policy.
13. Contact
Questions, concerns, or requests about this policy or your data? Contact us:
Alyria, LLC
Privacy & general inquiries: hello@alyria.ai
Security inquiries: security@alyria.ai
© 2026 Alyria, LLC. All rights reserved.
Terms of Service →