A
Ally
← back home

Privacy

Last updated: 2026-05-06

The short version

Ally exists to work for you, not against you. We collect the minimum data we need to do that — your email, your conversations with Mira, and the style preferences she picks up — and we never sell it, license it, or use it to train models for anyone else. You can export everything we have on you, or delete your account, at any time from Settings.

What we collect

  • Email address. Required to sign in via magic link.
  • Conversations. Everything you type or speak to Mira, and her replies. Voice is transcribed to text and the audio itself is not stored.
  • Profile preferences. Sizes, brands you wear, colors you like, returns, and any facts Mira learns from your conversations to help her recommend better.
  • Usage logs. IP, browser type, and request timestamps via our hosting provider. Standard for any web service.

Where it lives

All data is stored in our Supabase project hosted in Frankfurt (EU). Data is encrypted at rest. Network traffic between your device and our servers is encrypted with TLS.

Who else sees it

To deliver the service, parts of your data flow through these processors:

  • Anthropic— Mira's replies are generated by Claude. Your messages are sent to Anthropic's API and processed by their model. Anthropic's commercial terms prohibit using API content for model training.
  • Supabase — Database, authentication, storage.
  • Vercel — Web hosting and request routing. Generates standard server logs.
  • Resend — Email delivery (sign-in links, waitlist confirmations).
  • ElevenLabs— When voice mode is in active use, Mira's text replies are sent to ElevenLabs to synthesize audio. They do not retain the text after synthesis.

We do not sell your data, share it for advertising, or hand it to retailers. Brand promise: Ally is loyal to you.

Your rights

  • See it. Visit Settings → Export my data to download a JSON file with everything we have on you.
  • Delete it. Settings → Delete my account permanently removes your account, profile, and all conversations. Cannot be undone.
  • Correct it.Tell Mira: “I'm actually a 31 waist” — she updates your profile.
  • Sign out everywhere. Settings → Sign out from all devices invalidates every active session.

EU users have additional rights under GDPR, including the right to object to processing and the right to lodge a complaint with a supervisory authority.

Cookies

We use one set of cookies, all strictly necessary:

  • Auth cookies set by Supabase to keep you signed in across page loads. HTTP-only, secure, SameSite=Lax.
  • Preference cookies like ally-he-gender for Hebrew gender and ally:last-email in localStorage for one-tap re-sign-in.

We do not use advertising or analytics cookies. Vercel may set its own cookies for security and challenge mitigation; those are session-scoped and don't track you across sites.

Children

Ally is built for users 18 and older. We do not knowingly collect data from anyone under 18. If you are a parent and believe your child has signed up, contact us and we'll delete the account.

Changes to this policy

If we change anything material in this policy, we'll email registered users at least 14 days before the change takes effect. For minor edits (typos, clarifications), we update the “last updated” date above.

Contact

Questions, concerns, or requests: hello.useally@gmail.com

Ally is operated by Samuel Eskenasy. This page describes data handling in plain language; the underlying obligations are governed by applicable privacy law including GDPR for EU users.