Privacy Policy
Effective Date: January 23, 2025
Table of Contents
1. Introduction
AlignWithMe, Inc. ("AlignWithMe," "Company," "we," "us," or "our") respects your privacy and is committed to protecting it through our compliance with this Privacy Policy.
This Privacy Policy describes the types of information we may collect from you or that you may provide when you access or use the AlignWithMe web application located at alignwithme.com (the "Service") and our practices for collecting, using, maintaining, protecting, and disclosing that information.
This Privacy Policy applies to information we collect through the Service and in email, text, and other electronic messages between you and the Service. It does not apply to information collected by any third party, including through any application or content that may link to or be accessible from the Service.
Please read this Privacy Policy carefully to understand our policies and practices regarding your information. By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with our policies and practices, do not use the Service.
2. Information We Collect
We collect several types of information from and about users of our Service, including:
2.1 Information You Provide to Us
When you register for an account, use our Service, or otherwise interact with us, we may collect:
- Account Information: Name, email address, password, profile photograph, company or organization name, job title, and timezone preferences.
- Assessment Data: Personality assessment results (including MBTI, DISC, Enneagram, and Clifton StrengthsFinder), voice interview recordings and transcripts, questionnaire responses regarding work style and communication preferences, and feedback on generated content.
- Organizational Data: Team membership, organizational structure, reporting relationships, professional goals, milestones, and collaboration notes.
- Payment Information: Billing address and payment card information, which is processed and stored by our third-party payment processor, Stripe, Inc.
2.2 Information Collected Automatically
When you access or use the Service, we automatically collect certain information, including:
- Device Information: Information about your device, including device type, operating system, browser type and version, and unique device identifiers.
- Log Data: Internet Protocol (IP) address, access times, pages viewed, referring URL, and actions taken on the Service.
- Usage Information: Information about how you use the Service, including features accessed, time spent on pages, and interaction patterns.
2.3 Information from Third-Party Services
If you choose to connect third-party services to your account, we may collect information from those services:
- Google Calendar: With your authorization, we access calendar event information, including event titles, dates, times, locations, attendee names and email addresses, meeting links, and event status. We request read-only access and do not modify, create, or delete calendar events.
- Microsoft Outlook: With your authorization, we access the same categories of calendar information as described above through the Microsoft Graph API with read-only permissions.
3. Use of Information
We use information that we collect about you or that you provide to us, including personal information:
- To provide, maintain, and improve the Service, including generating your Personal User Guide and meeting preparation recommendations.
- To personalize your experience and deliver content and features relevant to your interests.
- To process transactions and send related information, including purchase confirmations and invoices.
- To send you technical notices, updates, security alerts, and administrative messages.
- To respond to your comments, questions, and requests and provide customer service.
- To communicate with you about products, services, offers, and events offered by us, where you have opted in to receive such communications.
- To monitor and analyze trends, usage, and activities in connection with our Service.
- To detect, investigate, and prevent fraudulent transactions and other illegal activities and protect the rights and property of AlignWithMe and others.
- To comply with legal obligations and enforce our terms and policies.
4. Google API Services User Data Policy Compliance
AlignWithMe's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Limited Use Disclosure
Notwithstanding anything else in this Privacy Policy, if you provide the Company access to Google data, the Company's use of that data will be subject to these restrictions:
- The Company will only use access to read, write, modify, or control Google Calendar data to provide or improve user-facing features that are prominent in the requesting application's user interface.
- The Company will not transfer Google Calendar data to third parties unless (i) necessary to provide or improve user-facing features that are prominent in the requesting application's user interface, (ii) you provide affirmative consent, (iii) necessary for security purposes, or (iv) necessary to comply with applicable law.
- The Company will not use Google Calendar data for serving advertisements.
- The Company will not allow humans to read Google Calendar data unless (i) you have provided affirmative consent for specific data, (ii) it is necessary for security purposes, (iii) it is necessary to comply with applicable law, or (iv) our use is limited to internal operations and the data have been aggregated and anonymized.
Scope of Access
We request the following OAuth scopes from Google:
https://www.googleapis.com/auth/calendar.readonlyhttps://www.googleapis.com/auth/calendar.events.readonlyhttps://www.googleapis.com/auth/userinfo.email
Revocation of Access
You may revoke our access to your Google Calendar data at any time through the Settings page of the Service or through your Google Account permissions at myaccount.google.com/permissions.
5. Artificial Intelligence Data Processing
AlignWithMe utilizes artificial intelligence and machine learning technologies to provide core features of the Service. This section describes how your data is processed by AI systems.
5.1 Voice Transcription
Voice interviews are transcribed using Deepgram, Inc.'s speech-to-text service. Audio data is streamed in real-time and is not permanently stored by the Company after transcription is complete. We retain only the resulting text transcript.
5.2 Content Generation
Your interview transcripts, questionnaire responses, and personality assessment results are processed by large language model services provided by OpenAI, L.L.C. or Google LLC to generate your Personal User Guide, relationship insights, and meeting preparation suggestions.
5.3 Data Use for Model Training
We maintain API agreements with our AI service providers that prohibit the use of your data to train their machine learning models. Your conversations and generated insights are not used for model improvement by these third parties.
6. Disclosure of Information
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
We may disclose personal information that we collect or you provide as described in this Privacy Policy:
- Within Your Organization: To other members of your organization or team who have been granted access to view your profile, subject to the sharing settings you configure.
- To Service Providers: To contractors, service providers, and other third parties we use to support our business, who are bound by contractual obligations to keep personal information confidential and use it only for the purposes for which we disclose it to them.
- For Legal Purposes: To comply with any court order, law, or legal process, including responding to any government or regulatory request; to enforce our Terms of Service and other agreements; or if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of AlignWithMe, our users, or others.
- Business Transfers: To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of AlignWithMe's assets. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.
- With Your Consent: For any other purpose disclosed by us when you provide the information or with your consent.
7. Third-Party Service Providers
We engage the following categories of third-party service providers to operate and improve the Service:
| Provider | Purpose | Data Processed |
|---|---|---|
| PropelAuth, Inc. | Authentication services | Account credentials, profile information |
| Stripe, Inc. | Payment processing | Payment card information, billing address |
| Google LLC | Calendar integration, AI processing | Calendar events, assessment responses |
| Microsoft Corporation | Calendar integration | Calendar events, attendee information |
| OpenAI, L.L.C. | AI-powered content generation | Transcripts, questionnaire responses |
| Deepgram, Inc. | Speech-to-text transcription | Voice audio streams |
| LiveKit, Inc. | Real-time voice communication | Audio streams during interviews |
| Twilio Inc. (SendGrid) | Email delivery | Email address, message content |
| PostHog, Inc. | Product analytics | Usage data, device information |
| Functional Software, Inc. (Sentry) | Error monitoring | Error logs, diagnostic information |
9. Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected and to comply with our legal obligations.
| Data Category | Retention Period |
|---|---|
| Account information | Duration of account plus 30 days following deletion |
| Personal User Guide content | Duration of account |
| Interview transcripts | Duration of account |
| Voice recordings | Not retained; transcribed in real-time only |
| Calendar data | Cached temporarily (5 minutes); not permanently stored |
| Payment and billing records | 7 years (as required by law) |
| Server logs | 90 days |
Account Deletion
Upon deletion of your account, we will delete or anonymize your personal information within 30 days, except where retention is required to comply with legal obligations, resolve disputes, or enforce our agreements. To request account deletion, contact us at privacy@alignwithme.com.
10. Data Security
We have implemented appropriate technical and organizational measures designed to protect the security of personal information we process. These measures include:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS) 1.3 or higher.
- Encryption at Rest: Sensitive data, including OAuth tokens, is encrypted using AES-256-GCM encryption before storage.
- Network Security: Our database infrastructure operates on a private network that is not accessible from the public internet.
- Access Controls: Access to production systems is restricted to authorized personnel and is logged and audited.
- Authentication: We employ secure authentication mechanisms through PropelAuth with support for single sign-on (SSO) using SAML and OIDC protocols.
However, no method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at security@alignwithme.com.
11. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal information:
- Right of Access: You may request a copy of the personal information we hold about you.
- Right of Rectification: You may request that we correct inaccurate or incomplete personal information.
- Right of Erasure: You may request that we delete your personal information, subject to certain exceptions.
- Right of Portability: You may request that we provide your personal information in a structured, commonly used, machine-readable format.
- Right to Restrict Processing: You may request that we limit our processing of your personal information in certain circumstances.
- Right to Object: You may object to our processing of your personal information in certain circumstances.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time.
To exercise any of these rights, please contact us at privacy@alignwithme.com. We will respond to your request within 30 days, or 45 days for complex requests, as permitted by applicable law.
12. California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA).
Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information:
- Identifiers: Name, email address, IP address, account credentials.
- Commercial Information: Records of services purchased, subscription history, payment records.
- Internet or Electronic Network Activity: Browsing history within the Service, interaction with features, referring URLs.
- Professional or Employment-Related Information: Job title, company name, organizational role, professional relationships.
- Inferences: Personality insights, communication preferences, and work style characteristics derived from assessment data.
- Sensitive Personal Information: Account login credentials (processed solely for authentication purposes).
Sale or Sharing of Personal Information
AlignWithMe does not sell personal information as defined under the CCPA. AlignWithMe does not share personal information for cross-context behavioral advertising purposes. Accordingly, we do not offer an opt-out mechanism for the sale or sharing of personal information because we do not engage in such activities.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights, including by denying you goods or services, charging you different prices, providing a different level of quality, or suggesting that you will receive different treatment.
13. International Data Transfers
AlignWithMe is headquartered in the United States. If you access the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers maintain facilities.
When we transfer personal information outside of the European Economic Area, United Kingdom, or Switzerland, we implement appropriate safeguards, including standard contractual clauses approved by relevant supervisory authorities, to ensure that your personal information receives an adequate level of protection. By using the Service, you consent to the transfer of your information to the United States and other jurisdictions as described in this Privacy Policy.
14. Children's Privacy
The Service is intended for use by business professionals and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and you believe that your child has provided us with personal information without your consent, please contact us at privacy@alignwithme.com. If we learn that we have collected personal information from a child under 16, we will take steps to delete such information promptly.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. When we make material changes to this Privacy Policy, we will:
- Update the "Effective Date" at the top of this Privacy Policy;
- Provide notice to you via email or through the Service at least 30 days prior to the changes taking effect; and
- Provide a summary of the material changes.
Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the revised Privacy Policy. We encourage you to review this Privacy Policy periodically.
16. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
AlignWithMe, Inc.
Privacy Inquiries: privacy@alignwithme.com
Security Concerns: security@alignwithme.com
Response Time: We will respond to inquiries within 30 days.