Privacy Policy
Last updated · August 28, 2026
This Privacy Policy describes how ModulexAI, LLC ("Alesta", "we", "us", or "our") collects, uses, discloses, and protects personal data when you use the Alesta websites, applications, and APIs (the "Service"), and the rights and controls you have over that data.
The short version: you give Alesta a website domain. The launch profile gathers available public information about that domain and candidate competitors, produces analyses and documents from it, and shows them in your workspace. You may also connect Google Analytics or Google Search Console so the Service can read your own measurements; that is optional, and Section 7 sets out exactly what is read and how long it is kept.
1. Who we are
The Service is operated by ModulexAI, LLC, a Delaware limited liability company ("the Company"). For the purposes of the EU and UK General Data Protection Regulation (GDPR), the Company is the Data Controller for the personal data described in this policy. You can reach us at contact@alesta.ai for any privacy matter.
The Service consists of the marketing site at alesta.ai, the application at app.alesta.ai, and the APIs behind them.
2. Information we collect
We collect the minimum the Service needs to work, in six categories:
- Account data. When you sign up, our authentication provider (Clerk) collects your name, email address, and sign-in identifiers, and passes us the profile the Service needs to operate your account. If you sign in through a third-party identity provider (such as Google or Apple), we receive the profile data that provider shares under your settings.
- Workspace input. The website domain you supply. This is the only input the Service requires, and the analysis it produces derives from it.
- Connected account data. If you connect Google Analytics or Google Search Console, we read the measurements described in "Google user data and Limited Use" using the access you grant. Connecting is optional; the Service works without it.
- Billing data. Paid plans are billed through Stripe. Stripe collects and stores your payment details; we receive and retain only what we need to run your subscription (plan, billing status, invoice records), never your full card number.
- Usage data. Standard technical telemetry: pages visited, features used, browser and device type, IP-derived coarse location, and error logs. We use PostHog and Vercel Analytics for this. It exists to keep the Service working and to understand which features matter.
- Communications. If you write to contact@alesta.ai, we keep the correspondence so we can answer you and improve support.
3. Analysis data and public sources
The core of the Service is an automated analysis of the domain you supply. That analysis gathers publicly available data:
- the publicly served pages of the site itself (a bounded read: the homepage plus a limited crawl of public pages);
- performance measurements of the site (Google PageSpeed Insights and the Chrome UX Report);
- bounded search, on-page, and technical evidence about the domain from specialist data providers;
- candidate competitor domains and their public homepages, gathered the same way.
Public web pages sometimes contain personal data (an author byline, a team page, a support email address). Where such data enters an analysis, we process it only to produce that workspace’s analysis, we do not enrich it against other sources, and we do not build profiles of individuals from it. If you believe an analysis contains personal data about you that you want removed, contact us at contact@alesta.ai.
Connected data. The analysis described in this section uses public sources only and requires no connected account. Separately, you may choose to connect Google Analytics or Google Search Console so the Service can read your own measurements; that connection is optional and user-initiated, the access requested is shown before you grant it, and Section 7 describes exactly what is read, stored, and for how long.
4. How we use information
- to provide the Service: run analyses, render your workspace, generate documents;
- to operate your account and subscription, including credit metering and billing;
- to secure the Service: abuse prevention, rate limiting, debugging, incident response;
- to communicate with you about the Service (transactional email, support replies);
- to improve the Service, using aggregated or de-identified usage data;
- to comply with legal obligations.
Where the GDPR applies, we rely on performance of a contract (running the Service you signed up for), legitimate interests (security, product improvement), consent where we ask for it, and legal obligation for the uses above.
5. AI processing
Alesta’s analyses and documents are produced in part by large language models routed through OpenRouter and configured model providers. The material sent for a request may include public site content, measurements, and competitor evidence needed to produce that workspace output.
No training. We do not use your private account data or workspace outputs to train a proprietary Alesta model. Third-party model handling and retention are governed by the provider configuration and applicable provider terms.
6. Sharing and subprocessors
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share data only with the service providers that run the Service, each bound to process it for us:
- Clerk (authentication and session management).
- Stripe (payments and billing).
- Microsoft Azure (cloud infrastructure the application runs on).
- Vercel (marketing-site hosting and web analytics).
- PostHog (product analytics).
- Google (PageSpeed Insights and Chrome UX Report measurements of the analyzed domain).
- DataForSEO (bounded search, on-page, technical, and competitor evidence about the analyzed domain).
- Firecrawl (bounded crawling of the analyzed site’s public pages and of competitor homepages).
- OpenRouter and configured model providers (AI processing used to produce analyses and documents).
Google appears here in one role, and elsewhere in another. In the list above, Google is a provider we send a measurement request to about the domain being analyzed. That is different from a Google account you connect. There, Google is a source you authorize us to read from: your Analytics and Search Console measurements are read from Google, not sent to it, and they are not shared with any of the providers above. Section 7 covers connected Google accounts on their own.
We may also disclose information if required by law, to protect the rights, property, or safety of the Company, our users, or the public, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to the transferred data until amended).
7. Google user data and Limited Use
You may connect two Google services to Alesta: Google Analytics and Google Search Console. Connecting is optional and always started by you, the Service works without it, and you can disconnect at any time.
What we request. Two scopes, both read-only: Google Analytics (analytics.readonly) and Google Search Console (webmasters.readonly). We request no write access and no restricted scopes. We do not request access to Gmail, Drive, Docs, Calendar, Contacts, or any other Google service.
What we read
- Google Analytics. Your account and property names, so you can choose which property to analyze; and the measurements themselves: sessions, active users, new users, engagement rate, bounce rate, average session duration, and key-event counts, broken down by date, channel, source, page path, and host.
- Google Search Console. The list of sites you have verified; and clicks, impressions, click-through rate, and average position, broken down by query, country, and page.
No user-level or personal data. We do not read user-level or personal data from either service. Google Analytics and Search Console return these measurements already aggregated, and Alesta asks for nothing at the level of an individual visitor.
What we store, and for how long
- Access tokens. Encrypted at rest. When you disconnect an account, the token is deleted rather than kept for a grace period.
- The measurements themselves. Kept for up to three months, then dropped.
Nothing else is stored. The panel that shows these measurements is composed when you open it and sent to your browser; no saved panel and no document is derived from Google data. For 30 minutes after a reading, opening the page again is served from the reading we already have instead of querying Google a second time, so looking twice does not spend your own property’s API quota twice. That is how a reading is served, not how long it is kept: the reading itself falls under the three-month limit above.
How to disconnect. Remove the connection in the application’s settings, or revoke Alesta’s access from your Google Account at myaccount.google.com/permissions. Either route ends our access and deletes the stored token.
Limited Use
Alesta’s use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
In particular, we do not:
- use or transfer Google data to develop, train, or improve generalized or non-personalized artificial intelligence or machine learning models;
- use Google data for advertising, marketing, or retargeting;
- sell Google data to anyone;
- share Google data with any other workspace;
- or send Google data to an AI model provider.
The last of those is worth stating plainly, because it is easy to assume otherwise about a product that writes analyses with AI. Measurements read from a connected Google account are fetched when you open the panel that shows them, stored, and displayed back to you. They are not sent to the model providers described in Section 5, so the analyses those models write are produced without them. The only parties that handle this data are the infrastructure providers named in Section 6 that operate the Service on our behalf.
9. Data retention
- Account data is kept while your account exists and deleted within 30 days of account deletion, except where the law requires longer.
- Workspace analyses and documents are kept while the workspace exists; deleting a workspace deletes its analyses.
- An access token for a connected Google account is deleted when you disconnect the account, not retained for a grace period.
- Measurements read from a connected Google account are kept for three months and then dropped.
- Competitor page snapshots used as analysis evidence are reused for at most 7 days before being fetched fresh.
- Billing records are retained as long as tax and accounting law requires.
- Support correspondence is kept as long as needed to handle the matter and improve support.
You can request deletion at any time from in-app settings or by writing to contact@alesta.ai; we comply promptly.
10. Security
We protect data with encryption in transit, access controls, isolation between workspaces, and established providers for the highest-risk surfaces (authentication with Clerk, payments with Stripe, so credentials and card numbers never touch our servers). No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you as the law requires. If you believe you have found a security vulnerability in the Service, write to contact@alesta.ai with "Security" in the subject line and we will respond within three business days.
11. International transfers
We are a US company and process data in the United States and in the regions our providers operate. Where data of EEA, UK, or Swiss residents is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses with our providers.
12. Your rights
EEA, UK, and Switzerland. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing relies on it. You may also lodge a complaint with your supervisory authority.
US state privacy laws. Residents of California and of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana) have rights to know, access, correct, delete, and obtain a copy of their personal data, and to opt out of sales, targeted advertising, and profiling. We do not sell personal data and do not share it for cross-context behavioral advertising, so there is nothing to opt out of; the remaining rights are honored on request.
To exercise any right, email contact@alesta.ai. We will verify the request against your account and respond within the time the applicable law sets. We do not discriminate against you for exercising a privacy right.
13. Children
The Service is a business tool, is not directed to children, and may not be used by anyone under 16. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
14. Changes to this policy
We will update this policy as the Service evolves. Material changes are announced on the site or by email before they take effect, and the dates above always reflect the current version.
15. Contact
For any question, request, or complaint about privacy: contact@alesta.ai.
ModulexAI, LLC 8 The Green, Suite B Dover, Delaware 19901 United States