> ## Documentation Index
> Fetch the complete documentation index at: https://docs.alesta.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Trust and data scope

> Understand public-domain processing, connected data, user-supplied context, telemetry, retention, and human-control boundaries.

Alesta works with public domain evidence, authorized connected data, and information workspace members choose to provide. Each source has a different permission and interpretation boundary.

This page explains product behavior. It does not replace the applicable [Privacy Policy](https://alesta.ai/privacy-policy), [Terms of Service](https://alesta.ai/terms-of-service), customer agreement, or your organization's legal review.

## Public-domain processing

The first profiling run starts from the company domain and can process:

* public company and product pages;
* visible page metadata and navigation;
* public technical and on-page signals;
* eligible aggregated performance data;
* bounded search and competitor evidence;
* public competitor homepages;
* public social-profile context found on the site.

Public information can still be inaccurate, outdated, incomplete, or contain personal information. Review extracted content before using it.

## Connected data

Private provider data requires an offered integration and authorization from someone with the necessary provider access. Examples include Google Analytics, Search Console, and GitHub repository metadata used for an explicitly confirmed issue action.

Before connecting, review the account identity, requested scopes, selected resource, business purpose, workspace membership, and revocation path.

Alesta's public privacy materials identify service providers used for product operation and analysis, including Clerk for authentication, Stripe for payments, Google measurement services, public-data and crawl providers, and OpenRouter or configured model providers for AI processing. Provider handling remains subject to the current configuration and applicable provider terms.

## What the domain does not authorize

A public domain does not grant access to private analytics, CRM data, revenue, product usage, support conversations, ad accounts, private social analytics, or internal strategy.

Reading a source also does not authorize Alesta to:

* send email;
* publish to a social platform or community;
* change a website, ad account, or analytics property;
* contact a person;
* deploy code;
* make a legal, employment, credit, or other high-impact decision.

External writes exposed by a supported Signal require a separate review and confirmation.

## User-supplied context

Workspace members can provide correction briefs, company facts, competitor domains, document instructions, chat messages, and attachments.

Do not submit unnecessary secrets or sensitive data. Never place passwords, access tokens, private keys, recovery codes, session cookies, payment-card details, or unapproved customer records in a prompt, document, attachment, or support request.

## Marketing-to-app domain handoff

When you submit a domain on alesta.ai before signup, the marketing site stores only the normalized hostname in a first-party cookie for up to 30 minutes. The application consumes it after signup so it can attach the domain without placing it in a public URL.

Production and staging handoffs use separate cookie scopes.

## Telemetry preference

Alesta uses operational and product telemetry to keep the service working and understand aggregate feature use. **Settings > General > Privacy** includes a control for anonymous OpenTelemetry usage sharing.

The public privacy policy describes additional website and product analytics providers. Use the in-product preference and applicable browser or organization controls together.

## AI processing and training statement

Alesta's public privacy materials state that private account data and workspace outputs are not used to train a proprietary Alesta model. Data sent to a configured model provider can include the public site content, measurements, competitor evidence, user instructions, or attachments needed for that request.

Review provider configuration and applicable terms for retention and handling details.

## Retention and deletion

Workspace analyses and documents are retained while the workspace exists under the current public policy. Deleting a workspace is intended to delete its analyses. If the required deletion control is not available in the current interface, contact Alesta through an approved support or privacy channel.

Disconnecting a provider stops active access for the workspace, but generated documents can retain information previously incorporated into their content. Review or delete that content separately when required.

## Data-minimization checklist

* Is the source necessary for a defined decision?
* Is the selected account and workspace correct?
* Can a smaller permission or population answer the question?
* Can aggregated evidence replace person-level data?
* Who will review the result?
* How long will it remain useful?
* How can access be revoked?
* Is there an approved basis for this use?

## References

* [Alesta Privacy Policy](https://alesta.ai/privacy-policy)
* [Alesta Terms of Service](https://alesta.ai/terms-of-service)
* [Integrations and permissions](/account/integrations-and-permissions)
* [Workspaces](/account/workspaces)
