Alignbase Privacy Policy
Effective date: July 30, 2026
Last updated: July 30, 2026
Sunpeak AI, Inc., doing business as Alignbase (“Alignbase,” “we,” “us,” or “our”), provides tools for teams to create, manage, version, review, govern, and distribute context for AI agents.
This Privacy Policy explains how we collect, use, disclose, and retain personal information when you use:
- the Alignbase website at alignbase.ai;
- the Alignbase web application;
- our APIs, Model Context Protocol endpoints, installation materials, and related software;
- support, sales, and other business communications; and
- other services that link to this Privacy Policy.
We refer to these collectively as the “Services.”
“Personal information” means information that identifies, relates to, describes, or could reasonably be linked with an individual. It does not include information that has been aggregated or deidentified so that it cannot reasonably be linked to an individual.
The Services are offered for business and professional use. If you use Alignbase through a Workspace managed by your employer, client, or another organization, the Workspace administrators may control your access and the content and activity associated with that Workspace. That organization may have its own privacy notice and may be responsible for responding to some requests about personal information in Workspace content.
For account information, website activity, direct communications, and our own business operations, Alignbase decides why and how personal information is processed. For Customer Content that we process for a customer or Workspace, we generally process that information to provide the Services at the direction of the customer, Workspace administrators, and authorized users. A separate written agreement may describe these roles in more detail.
1. Personal information we collect
We collect the following categories of personal information.
Account and profile information
When you create or use an account, we may collect:
- your name, email address, profile image, and account identifiers;
- your password in a protected, hashed form;
- your email-verification status;
- your company or Workspace name;
- your role, permissions, access settings, and Workspace membership; and
- account settings and notification preferences.
If you sign in with Google, Google provides information allowed by the permissions shown during sign-in, such as your Google account identifier, email address, name, profile image, email-verification status, and hosted domain. We do not receive your Google password.
Customer Content
We collect content that you, another user, a Workspace administrator, a connected agent, or an integration submits to the Services. This may include:
- context, instructions, prompts, configuration, and metadata;
- documents, drafts, versions, comments, review decisions, approvals, and other organizational metadata;
- agent names, ownership, capabilities, setup information, and permissions;
- information about integrations and connected systems; and
- other information included in material submitted to or transmitted through the Services.
Customer Content may contain personal information about you or other people. The person or organization that submits Customer Content is responsible for having the rights and permissions needed to do so. Our Terms of Service prohibit submitting certain sensitive and regulated data unless a signed agreement expressly allows it.
Service activity and audit information
We collect information about actions taken in the Services so we can operate the product, enforce permissions, maintain audit history, and help customers understand what happened. This may include:
- signups, sign-ins, sign-outs, verification, invitations, password resets, and account changes;
- Customer Content viewed, created, changed, proposed, reviewed, published, distributed, or deleted;
- administrator actions, permission changes, and access assignments;
- agent and integration setup, authorization, access, and activity;
- MCP and API requests, the context versions returned, request status, and related provenance;
- support and product interactions; and
- timestamps, user and Workspace identifiers, session identifiers, request identifiers, and audit metadata associated with these events.
Device, network, and technical information
When you access the Services, we and our infrastructure providers may automatically receive:
- IP address and a temporary hashed form of the IP address used for request correlation;
- browser family, device class, operating or client type, and whether the request appears to come from a browser, bot, or API client;
- requested pages or routes, referring or redirect information in a limited form, request time, response status, and performance data;
- approximate country based on network information;
- Cloudflare request identifiers and edge network information;
- cookie, local storage, session, and observability identifiers; and
- error reports, traces, metrics, and diagnostic information.
We do not use precise location from your device. We do not intentionally put email addresses, raw authentication tokens, or raw user-agent strings in ordinary access logs.
Communications and business information
If you contact us, request a demo, schedule a meeting, respond to a survey, or otherwise communicate with us, we may collect:
- your name, business contact details, company, and job information;
- the contents of messages and attachments;
- meeting and scheduling information;
- support history and feedback; and
- order, subscription, invoice, transaction, and contract information if you obtain a paid plan or enter into a commercial agreement with us.
We do not collect full payment-card numbers through the current Services. If we later offer online payment processing, the payment provider will collect payment details under its own privacy notice, and this policy will be updated as needed.
2. Sources of personal information
We collect personal information:
- directly from you;
- from other users, inviters, and Workspace administrators;
- from connected agents, integrations, and systems that an authorized user connects to Alignbase;
- from authentication providers, such as Google, when you choose that sign-in method;
- automatically from your browser, device, network, and use of the Services;
- from service providers that help us operate, secure, monitor, and support the Services; and
- from business partners, public sources, or professional contacts in connection with sales and business operations.
3. How we use personal information
We use personal information to:
- provide, operate, maintain, and support the Services;
- create and manage accounts and Workspaces;
- authenticate users, verify email addresses, and secure accounts;
- apply Workspace roles, permissions, access controls, and agent authorizations;
- process and distribute Customer Content as directed by authorized users and Workspace settings;
- connect agents, integrations, and other systems;
- maintain versions, provenance, and audit history;
- send verification, security, invitation, account, service, and support messages;
- send a weekday product digest when enabled in account settings;
- respond to questions, support requests, and feedback;
- understand product use, diagnose errors, monitor performance, and improve the Services;
- detect, investigate, prevent, and respond to fraud, abuse, unauthorized access, security incidents, and violations of our terms;
- enforce agreements and protect the rights, safety, and property of Alignbase, our users, and others;
- manage subscriptions, contracts, invoices, and other business relationships;
- comply with law, legal process, and valid government requests;
- establish, exercise, or defend legal claims; and
- complete a financing, acquisition, reorganization, sale of assets, or similar business transaction.
We may create aggregated or deidentified information from personal information and use it for lawful business purposes, such as measuring service performance and understanding product use. We will not try to reidentify information that we maintain as deidentified.
4. Customer Content and service improvement
We may use Customer Content to provide, secure, maintain, support, develop, and improve the Services; follow authorized user instructions and Workspace settings; prevent or address fraud, abuse, or security incidents; and comply with law, subject to this policy and our agreements.
We may also use service activity, feedback, and aggregated or deidentified information to maintain and improve the Services, subject to this policy and our agreements.
Connected agents and integrations may process information under their own terms and privacy notices. Workspace administrators and authorized users decide which systems to connect and which permissions and information to make available to them.
5. How we disclose personal information
We may disclose personal information as described below.
Workspace users and administrators
Information associated with a Workspace may be available to other authorized Workspace users based on their roles and permissions. Workspace administrators may access and manage account information, Customer Content, activity, agents, integrations, and permissions within the Workspace. They may also restrict, deactivate, or delete access.
Connected agents and integrations
When an authorized user connects an agent, developer tool, or other integration, we disclose information to that system as needed to follow the user’s instructions and the configured permissions. The receiving system may use that information under its own terms and privacy notice.
Service providers
We disclose personal information to vendors and contractors that process it for us to provide services such as:
- cloud hosting, databases, storage, content delivery, and network security;
- authentication and identity verification;
- email delivery and internal business communications;
- monitoring, logging, error reporting, and service analytics;
- customer support and meeting scheduling;
- billing, accounting, legal, and other professional services; and
- security, fraud prevention, and incident response.
Current providers include Amazon Web Services for hosting and email delivery, Cloudflare for network and security services, Google for optional sign-in and web fonts, New Relic for production monitoring, and Calendly when a visitor chooses to open a scheduling link. We also use an internal communications provider to receive limited operating notices, such as a notice containing the account email when a new user signs up. Providers may change as the Services change.
Legal, safety, and enforcement disclosures
We may disclose personal information when we reasonably believe disclosure is needed to:
- comply with law, a subpoena, court order, or other valid legal process;
- respond to lawful requests from public authorities;
- enforce our agreements or investigate violations;
- detect, prevent, or address fraud, abuse, or security issues; or
- protect the rights, safety, and property of Alignbase, our users, or others.
When legally allowed and appropriate, we may notify the affected customer or user before responding to a legal demand.
Business transactions
We may disclose or transfer personal information in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, including during due diligence. A recipient may continue to use the information subject to this policy unless applicable law requires otherwise.
At your direction
We may disclose personal information when you ask us to, direct us to, or give us permission. We may also disclose information as described when it is collected.
6. Cookies and similar technologies
We use cookies, local storage, session storage, and similar technologies for:
- authentication and session management;
- security and fraud prevention;
- remembering interface and navigation preferences;
- maintaining draft and editing state;
- correlating requests for debugging and service reliability; and
- measuring service use and performance.
Our authentication cookie is needed for signed-in use of the web application. It is configured to reduce access by client-side scripts and, in production, to travel only over secure connections. A browser session can remain stored for up to 30 days, but an authenticated session may end sooner after inactivity or for security reasons.
Interface-preference cookies may remain for up to one year unless you clear them. Some editing and navigation preferences may also be stored in your browser’s local or session storage.
Our infrastructure and feature providers may use their own cookies or similar technologies when their code or services are used. For example, Cloudflare may process network and device information to provide security and performance services, Google receives information when its sign-in service or web fonts are used, and Calendly receives information when you open or use its scheduling page. Their processing is governed by their own privacy notices.
We do not currently use cookies for cross-context behavioral advertising. Most browsers let you block or delete cookies and clear local storage. Blocking essential storage may prevent parts of the Services from working.
Do Not Track and Global Privacy Control
Some browsers offer a “Do Not Track” setting. There is no uniform industry standard for responding to Do Not Track signals, so the Services do not currently change behavior in response to them.
We honor legally recognized opt-out preference signals, such as Global Privacy Control, when applicable. Because we do not currently sell personal information or share it for cross-context behavioral advertising, such a signal does not otherwise change how the Services operate.
Other parties may collect information about online activity over time and across different websites when their services are loaded on our website, as described above. We do not allow those parties to use Customer Content for their own advertising.
7. Sale, targeted advertising, and profiling
We do not sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising, and we do not process personal information for targeted advertising as those terms are defined by applicable US state privacy laws.
We do not use personal information to profile individuals in furtherance of decisions that produce legal or similarly significant effects concerning employment, credit, housing, insurance, health care, education, criminal justice, or access to basic necessities.
We have not sold or shared personal information for cross-context behavioral advertising in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 18.
8. Data retention
We retain personal information for as long as reasonably needed for the purposes described in this policy. The retention period depends on the type of information, the Workspace’s instructions and settings, the length of the business relationship, security and audit needs, and legal requirements.
In general:
- account and profile information remains while an account is active and for a reasonable period afterward;
- Customer Content and its version history remains while the applicable Workspace uses the Services, until an authorized user deletes it, or as provided in a written agreement;
- deactivation disables access but may not delete the user record because Workspace audit history needs to identify prior actors;
- authorized administrators may permanently delete users, and Workspace deletion may be requested, subject to permissions, contractual limits, backups, and legal retention;
- session authorization ends when the session expires or is revoked, while related records may remain for a limited period for security and operating needs;
- security, request, audit, MCP, agent, and diagnostic records remain for as long as reasonably needed to secure the Services, investigate issues, maintain product history, meet customer audit needs, and enforce agreements;
- support, contract, invoice, and business records remain for the relationship and afterward as needed for tax, accounting, dispute, and legal purposes; and
- backup copies may remain for a limited period after deletion until they are overwritten through ordinary backup cycles.
We may retain information longer when needed to comply with law, preserve evidence, resolve a dispute, collect fees, enforce an agreement, or protect the Services and our users. We may retain aggregated or deidentified information that cannot reasonably be linked to an individual.
9. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal information. These measures include access controls, secure authentication practices, encrypted network connections, protected credential storage, tenant-scoped data access, logging, monitoring, backups, and incident-response practices appropriate to the nature of the Services.
No system is fully secure. You are responsible for protecting your credentials, using available Workspace controls, reviewing agent and integration permissions, and choosing what information to submit. Contact us promptly at [email protected] if you believe an account or credential has been compromised.
10. Your choices and controls
Depending on your account and role, you may:
- update your name, email address, password, and notification settings;
- turn the weekday product digest on or off;
- sign out of your current browser session;
- manage connected agents, permissions, access controls, and integrations;
- deactivate your account; and
- ask a Workspace administrator to correct or delete information controlled by the Workspace.
You may opt out of non-transactional marketing email by using the unsubscribe link in the message or contacting us. We may still send service, security, legal, billing, and account messages.
Account deactivation stops access but does not necessarily delete the account record, Customer Content, or audit history. To request deletion or exercise a privacy right, use the process below.
11. US state privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- confirm whether we process your personal information;
- access or obtain a copy of personal information;
- correct inaccurate personal information;
- delete personal information;
- obtain personal information in a portable format;
- opt out of the sale of personal information, targeted advertising, or certain profiling;
- limit certain uses or disclosures of sensitive personal information;
- appeal a decision we make about a privacy request; and
- receive equal service and not be discriminated against for exercising a privacy right.
Alignbase does not currently sell personal information, use it for targeted advertising, or perform the profiling described in Section 7.
To submit a request, use account settings where the requested control is available or email [email protected] with the subject “Privacy Request.” Tell us the right you want to exercise and the email address associated with your account. If your request concerns Customer Content controlled by a Workspace, we may direct the request to the Workspace administrator or the customer responsible for that content.
We may ask for information reasonably needed to verify your identity, authority, and relationship to the information. We will use verification information only to process the request. We may deny or limit a request when permitted by law, such as when we cannot verify the request, need information for security or legal purposes, or process it on behalf of a customer.
You may use an authorized agent where applicable law allows it. We may require proof that the agent has permission to act for you and may ask you to verify your identity directly.
If we deny a request, you may appeal by emailing [email protected] with the subject “Privacy Appeal” and explaining why you believe the decision should be changed. We will respond within the period required by applicable law.
12. California privacy disclosures
California law may require additional disclosures for California residents. The categories below describe personal information we have collected and disclosed for business purposes during the preceding 12 months. The examples do not mean that we collect every listed item about every person.
| Category | Examples we collect | Sources | Business purposes | Categories of recipients | Retention criteria |
|---|---|---|---|---|---|
| Identifiers | Name, business email, account ID, user ID, Workspace ID, Google account ID, IP address, session and request identifiers | You, Workspace users and administrators, Google sign-in, browsers, devices, and service providers | Provide accounts and the Services, authentication, security, support, communications, and business operations | Workspace users and administrators, connected systems at your direction, infrastructure, authentication, email, monitoring, communications, support, and professional-service providers | For the account or customer relationship and a reasonable period afterward; session and request identifiers may have shorter operational periods |
| Customer records and business contact information | Profile information, company, job information, account settings, contract, invoice, and support records | You, your organization, Workspace users, business contacts, and service providers | Provide and support the Services, manage customer relationships, contracts, billing, and compliance | Workspace administrators, billing, accounting, support, communications, and professional-service providers | For the account or customer relationship and afterward as needed for support, accounting, tax, legal, and dispute purposes |
| Commercial information | Plan, subscription, order, transaction, contract, and renewal information | You, your organization, and service providers | Provide paid Services, administer contracts, invoicing, accounting, and business planning | Billing, accounting, cloud, support, and professional-service providers | For the commercial relationship and afterward as needed for accounting, tax, legal, collection, and dispute purposes |
| Internet or other electronic network activity | Routes and pages requested, interactions, device and browser class, approximate country, request and response data, session activity, agent, API, MCP, and integration activity | Browsers, devices, networks, connected systems, and service providers | Operate, secure, monitor, troubleshoot, audit, and improve the Services | Workspace administrators where applicable, connected systems at your direction, cloud, network, security, and monitoring providers | For periods reasonably needed for operations, security, diagnostics, audit history, enforcement, and legal compliance |
| Professional or employment-related information | Company, role, hosted domain, Workspace role and permissions, professional contact details | You, Workspace users and administrators, Google sign-in, and business contacts | Manage accounts, permissions, Workspaces, support, sales, and customer relationships | Workspace users and administrators, authentication, communications, support, and professional-service providers | For the account, Workspace, or business relationship and a reasonable period afterward |
| User-generated content and communications | Customer Content, documents, drafts, versions, prompts, instructions, organizational metadata, support messages, feedback, and meeting information | You, Workspace users and administrators, connected agents and integrations | Provide, support, secure, and improve the Services; follow user directions; maintain versions and audit history | Workspace users and administrators, connected systems at your direction, cloud, email, support, scheduling, monitoring, and professional-service providers | While the Workspace uses the Services, until authorized deletion, or as set by a written agreement; communications remain as needed for support and business records |
| Sensitive personal information | Account login credentials and the contents of Customer Content or communications when they contain sensitive information | You, Workspace users, connected systems, and authentication providers | Authenticate users, secure accounts, provide and support the Services, and follow authorized user directions | Service providers and Workspace recipients only as needed for these purposes or at your direction | Credentials remain while active or until replaced; content and communications follow the periods for the records in which they appear |
We may also derive limited operational information, such as browser family, device class, or whether a request appears to be from a person, bot, or API client. We do not use it to infer sensitive traits or make decisions with legal or similarly significant effects.
We do not intentionally collect biometric information, precise geolocation, government identification numbers, health information, or payment-card or bank account numbers through the current Services. Our Terms prohibit users from submitting specified sensitive and regulated data unless a signed agreement allows it.
As described in Section 7, we have not sold personal information or shared it for cross-context behavioral advertising during the preceding 12 months. We use sensitive personal information only as reasonably needed to provide, secure, and support the Services, and not to infer characteristics about individuals.
California residents may exercise the rights described in Section 11. We will not discriminate against you for exercising a privacy right.
California’s “Shine the Light” law permits certain residents to ask about personal information disclosed to third parties for their own direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing.
13. Children
The Services are not directed to children and are available only to users who are at least 18 years old. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and delete it when appropriate.
14. Processing in the United States
Alignbase is based in the United States, and the Services are intended for US business and professional users. We and our service providers process and store information in the United States and may process it in other countries where our providers operate. Privacy laws in those places may differ from the laws where you live.
If an organization needs specific international data-transfer or processing terms, it must enter into a separate written agreement with Alignbase before using the Services for information subject to those requirements.
15. Third-party services and links
The Services may link to or connect with websites, agents, integrations, and services that Alignbase does not control. This Privacy Policy does not cover their privacy practices. Review the privacy notice of a third party before giving it personal information or connecting it to Alignbase.
16. Changes to this policy
We may update this Privacy Policy as the Services and our practices change. We will post the updated policy and change the “Last updated” date above. If a change materially reduces privacy protections or applicable law requires additional notice, we will provide notice through the Services, by email, or through another reasonable method before the change takes effect.
17. Contact us
For privacy questions, requests, or complaints, contact:
Sunpeak AI, Inc.
Doing business as Alignbase
Texas, USA
- Effective date
- July 30, 2026
- Last updated
- July 30, 2026