Privacy Policy

Last updated October 8, 2026

Who is responsible

Alexandria Library, Inc., a Delaware corporation at 131 Continental Dr, Suite 305, Newark, DE 19713, USA, is responsible for the personal data described here, the controller in the words of European data protection law. Write to us at benmowinckel@gmail.com.

What Alexandria is

Alexandria provides instructions that your own model uses to build your own personal data system, including a detailed private record of your thinking. The strongest available private home may be user-owned Git files, documents in your own Google Drive, or your model provider’s personalisation. If none is writable, your model leaves an explicit handoff in the chat instead of claiming it saved anything. An optional hosted connector lets independent systems use the Library, Marketplace, membership, and publishing features.

Your private record stays private

Your private record stays with the storage or model provider you chose. Private Git and Drive files remain in accounts you control; native memories remain with your model provider. Alexandria has no endpoint that accepts this private material and cannot read or retrieve it. Backups and cross-app connections are optional and use only accounts you approve.

This promise covers the private record. Information you deliberately publish, feedback you submit, and the connector records described below do reach services we operate.

What the hosted connector stores

Account and billing records. Your account number and name here (and your GitHub ID and login, if you joined with GitHub), email address, billing status, and Stripe customer or subscription identifiers. Account records are encrypted at rest. We also keep a keyed hash of the address you sign in with, which can tell us the address is yours again but cannot be turned back into it. While you sign in, the code is kept only as a keyed hash, and it is deleted within the hour.

Authentication records. A SHA-256 hash of your Alexandria API key; the raw key stays on your machine. Short-lived browser session and onboarding tokens are also stored when those flows are used.

Onboarding email. If you provide your email when you start Alexandria, we store it with the invite code you used (encrypted) and its hash, so we can send the matching setup message and a few gentle reminders with the same message until your code is used (the same day, two days later, a week later, two weeks later, then monthly for six months). Every message has an unsubscribe link. Your private files and captures are never part of this email record.

Waitlist. If you join the waitlist, we keep your email address and when you joined, send one confirmation, and email you once when there is room for you. Every message has an unsubscribe link.

Invite counts. For each invite code we keep when it was first used to read the source and how many of the people it brought have joined. Between signing in and joining, your account record can also hold a hash of the invite code your browser used, removed once the join is counted. Both are kept per code, with no IP address, device, or record of which files anyone read.

Invite link opens. When someone opens a member’s invite link, we keep a keyed hash of the network the visit came from for 70 days, so three different people can make that member’s next month free. The network address itself is never stored.

What you give back. For each billing month we keep counts of what you gave back to the network, such as invite opens, people who joined through you, modules you shared and how many people ran them, pieces of yours others opened, and how often your model used the connector, together with what the bill charged. These are numbers only, never what anyone read or said, and they decide whether a month is free.

Service activity. A two-day log of which Alexandria endpoints your account used and when; module IDs you explicitly approve reporting, with any notes you explicitly attach; Library publishing, access, purchase, account-connection events, and feedback you explicitly submit.

Chat app connections. If you connect a chat app, we keep its registration (its name and the addresses it returns to), your approval of it, and SHA-256 hashes of its sign-in credentials, which expire after an hour and after thirty days and are deleted once expired. Removing the connection or your account ends them at once. If you make a key for an app that asks for one instead, we keep the key’s SHA-256 hash, the app name you typed, and when you made it, with no expiry, until you remove the key or your account, which erases them. A change it prepares to your page is held encrypted for fifteen minutes, or until you confirm it, and then erased. We never receive your conversation, only the requests the app makes, such as the handle of a person it looks up.

Messages. If you turn on messages, your computer’s public key, who may write to you, and anyone you block. A message to you is locked on the sender’s computer so that only yours can open it, and we hold it only until your computer collects it. If you keep your post box on your own website, we hold no messages for you at all, only that website address, a fingerprint of each message’s locked text, and short-lived passes your website checks with us. For each message we also keep who wrote to whom and when, and whether it was collected or answered.

Content you publish. Files, works, profile details, and other material you deliberately send to the Library, together with their titles, access settings, prices, and file metadata.

The Mirror’s files/library/market/ folder. Anything you approve into this folder is read only by Alexandria’s matching and by you, never by a person you share with, and every read appears in your access log. Today two things can read it. One is the market’s decision model, described next. The other is a matching route that only Alexandria’s operator can open, with a secret of its own, built for a wider matcher later; nothing in Alexandria uses it today, and it stays open only while that secret is set. When Alexandria reviews a round by hand, it reads the round’s questions, never anyone’s folder. A market where companies and people pay for answers is on, and every rule starts off. For a buyer Alexandria switched on, the market reads this folder only if you chose, in your own browser, to be asked or answered for, through a decision model in our own Cloudflare account that does not keep what it reads. Your own rules decide who may ask, how you answer, and how much of you your answers carry. By default a buyer receives only totals and open answers that at least 100 people stand behind, never who answered; it sees your answers together, or your name, only if a rule of yours allows it. A folder you make inside it for one buyer, or for every buyer of one kind (labs, funds, companies or people), answers that buyer instead of the whole folder. Where your folder does not say whether a round is for you, the round’s letter asks you that along with its questions, and a letter like that comes at most once a week; an email tells you a letter has come, naming only the kind of asker, and a letter tells you what the round paid you when it closes. Your Library page shows anyone reading it that you are open to being asked only if a rule of yours says so, and a buyer who adds you to a round from it learns nothing more about you than anyone reading your page. A writing model from Anthropic reads this folder only if a rule of yours allows it and that option is switched on, which today it is not. You are paid on your own bill for every answer a buyer receives.

Buying a piece. Buying gives you a code that opens it, which we email you. If you buy without an account, Stripe takes your email and card, and we keep only a keyed digest of the address, so that signing in with it later puts the piece on your account. The seller sees that a piece was bought, never by whom.

Questions to a mirror. When you ask someone’s mirror a question, its owner can see in their access log that you asked (your name here when you are signed in, otherwise only that a visitor asked, and with which of their codes when you used one), when, and which of their layers the answer could draw on. Neither they nor we keep the words of your question or the answer.

Why we use it

Each use has its own legal basis under European data protection law.

Your account, membership, sign-in, and the Library you asked for, including counting the invite opens that make a month free, chat app connections, and messages. We use this data to perform our contract with you.

Billing records that tax and accounting law requires us to keep. This is a legal obligation.

Security, abuse prevention, and the nightly copy of the server. This is our legitimate interest in keeping the service safe and recoverable.

Setup, reminder, and waitlist emails you asked for at /start. We send them because you asked, and any unsubscribe link stops them.

Occasional product notes, sent only to members, who can stop them with any unsubscribe link. This is our legitimate interest in telling customers about the service they use.

Aggregate page analytics with no cookies. This is our legitimate interest in knowing how the site is used.

Services that run it, and where your data goes

Alexandria Library, Inc. is a US company, and so are the services below, so your data goes to the United States. Each transfer from Europe is covered by the EU–US Data Privacy Framework, with its UK extension, or by the provider’s standard contractual clauses.

Cloudflare runs the website and the hosted connector, stores the records above, and counts page views as described below. The market’s decision model would run there too, only for a buyer switched on.

Resend sends our emails, sign-in codes included, and receives the address and the message.

Stripe processes payments and receives the information needed to do so, under Stripe’s privacy policy. Alexandria does not receive or store complete card numbers.

GitHub, if you joined with GitHub, told us your GitHub ID and login.

If you connect a chat app, its provider receives what the connector returns to it, under that provider’s own privacy policy.

Every night a copy of everything our server holds (the database, the stored records, and the published files, in the same form as on the server, so what is encrypted there stays encrypted) is kept on the maintainer’s own computer, never in git or a cloud drive, so the service can be rebuilt if Cloudflare loses it. The last seven nights are kept and older ones are deleted.

Website analytics

We use Cloudflare Web Analytics for aggregate page views, referrers, country, browser, operating system, device type, and page load times. Cloudflare says it uses no cookies or local storage, and does not fingerprint visitors or track them across sites. We do not use advertising trackers or cross-site fingerprinting. Read Cloudflare’s description of Web Analytics.

Cookies and storage

The site sets only the cookies it needs to work, and none when a page loads. Signing in sets alex_signin, which holds your sign-in for 30 minutes while you enter the code, and then alex_library_session, which keeps you signed in for 30 days or until you sign out. Signing in to someone’s mirror from their own website sets alex_mirror_connect for the sign-in and alex_mirror_visitor for a visit of at most eight hours. Only our server can read them.

Your browser’s own storage keeps your theme choice, the invite code you used and the member whose invite link brought you, your place in the /start steps with the email you gave there, the codes someone gave you to their pages or that buying their pieces gave you, your conversations with a mirror, and your marketplace picks. Until you close the tab it also keeps small notes, such as which step of signing in you are on. All of this stays on your device, and clearing this site’s data removes it.

There are no advertising or tracking cookies, so there is no cookie banner.

Retention

Account records stay until you delete your account, and billing records as long as tax and accounting law requires. Endpoint event logs expire after two days, and the log of who opened your Library files or asked your mirror after 30 days. An email you gave at /start or for the waitlist stays until you delete your account or ask us to remove it; once you unsubscribe, it is kept only so we never email it again. A message is deleted when your computer collects it, or after 30 days if it never does, and its record and fingerprint after 30 days. A post box pass works for five minutes and is deleted within a day. Module-call, Library activity, transaction, and submitted-feedback records do not currently expire automatically. Published content stays until you unpublish it or delete your account; unpublishing cannot recall copies someone already downloaded or shared. We may retain records when required for security, fraud prevention, payments, disputes, or law.

Children

Alexandria is not meant for anyone under 18. When we learn that an account belongs to someone younger, we delete it and its data.

Your choices and rights

Your private record is already portable, as ordinary files you can read, edit, move, or delete. Deleting ~/alexandria/ removes your local system but does not delete an optional hosted account.

Depending on where you live, you may have rights to know or access personal data, correct it, delete it, receive a portable copy, restrict or object to processing, and appeal a decision. We do not sell personal information or share it for cross-context behavioural advertising.

You can download what we keep about you and delete your account from your account page. To exercise any other right, or ask us to remove submitted feedback, email benmowinckel@gmail.com. We may need to verify your identity. We answer every request within one month.

You can also complain to a data protection authority, in Norway Datatilsynet, or the one where you live or work.

You can sign out of the website from your account page, which your name at the foot of the library opens. That ends the browser session on this device. It does not delete your account or the key on your computer.

Contact

Alexandria Library, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA — benmowinckel@gmail.com

Terms of Service