AlwaysNoticed

Draft — pending legal review. This document has not been reviewed by a lawyer and is not yet binding on anyone.

Privacy Policy

Draft of 8 September 2026. Placeholders in [BRACKETS] are unresolved.

This policy explains what AlwaysNoticed, operated by [COMPANY LEGAL NAME], stores when you use the service, where it is stored, how long we keep it, and who else touches it. It covers the dashboard at alwaysnoticed.com, the browser extension, and the sessions we run against connected LinkedIn accounts.

1. What we store

Your account with us
Email address, name, the workspace you belong to, your role in it, and the authentication records that let you sign in. Passwords for our dashboard are handled by our authentication provider and are never visible to us in readable form.
The LinkedIn session credential
When you connect a LinkedIn account, we store the session credential that the browser extension hands over. It is encrypted with envelope encryption and written to a private volume that only the automation can read. It is never written to our database, never included in logs, and never shown in the dashboard. We do not ask for, receive, or store your LinkedIn password.
Account configuration
Target profile lists, topics, tone and banned-phrase rules, daily limits, schedule, and the network configuration of the dedicated IP assigned to that account.
The activity log
Every action taken during a session: the comment text published, the post it was published on, likes, follows, dismissals, the persona chosen for that night, session start and end, and — where a session failed — the reason. This is the record we show you, and the record we would rely on if you ever had to explain what happened on an account.
Analytics captured from your LinkedIn account
Followers, profile views, impressions, engagements and audience demographics, taken from the analytics export that LinkedIn makes available inside the account you connected. We do not scrape anyone else's profile data to produce these numbers; they are your account's own figures, retrieved as the account holder.
Post content encountered during a session
To decide what to comment on and to avoid commenting twice, we store an identifier and a short summary of posts the session saw, along with the text of comments we published. We do not build or sell a database of LinkedIn profiles.
Operational and cost records
Per-account, per-day records of language-model usage, compute and network cost, error counts, and connection health.
Support requests
Messages you send us in the dashboard, and any file you attach, stored in a private bucket scoped to your account.
Billing
Handled by our payment processor. We store your plan, subscription status, invoice history and the processor's customer identifier. We do not store your card number.

We do not sell personal data, we do not share it for advertising, and we do not use your content to train models of our own. There is no advertising or third-party analytics tracker on this website.

2. Where it is stored

The database — your account, configuration, activity log, captured analytics, cost and support records — is a Supabase Postgres project hosted in [REGION]. Row-level security separates every tenant and every account inside a tenant.

Session credentials and the per-account browser profiles live on private Modal volumes in [REGION], separate from the database. Sessions run in Modal containers in [REGION], and each account's LinkedIn traffic leaves through a dedicated IP address provided by our egress provider, located in [REGION] and used by that one account only.

Support attachments are stored in a private Supabase storage bucket in [REGION], reachable only through a signed link scoped to the account they belong to.

3. Why we may process it

To operate the service you asked for and to bill you for it (contract); to keep accounts working, investigate failures, prevent abuse and protect our own business (legitimate interests); and to meet legal and accounting obligations (legal obligation). Where consent is the basis — for example, marketing email — you may withdraw it at any time.

4. How long we keep it

Session credential
Kept while the account is connected. Deleted when you disconnect the account, when the subscription ends, or on request — whichever happens first.
Activity log and captured analytics
Kept for the life of the subscription and for [12] months afterwards, so that you can still explain or export past activity, then deleted.
Browser profile for an account
Deleted with the account.
Support requests and attachments
[24] months from the last message on the request.
Billing records
Kept as long as tax and accounting law in [JURISDICTION] requires, typically [7] years.
Operational logs
[90] days.

5. Who else touches it

We use these sub-processors. Each one is contracted to process data only on our instructions.

Supabase
Database, authentication and file storage, in [REGION].
Modal
Compute for the nightly sessions, and the private volumes holding session credentials and browser profiles, in [REGION].
OpenAI
Generating comment text. Post context and your style rules are sent; your session credential never is.
OpenRouter
Routing to additional language models for generation and research, with the same boundary.
[EGRESS PROVIDER]
The dedicated IP address assigned to each connected account, in [REGION].
[PAYMENT PROCESSOR]
Subscription billing and card handling. They hold your payment details; we do not.
[EMAIL PROVIDER]
Transactional email — sign-in links, failure notices, invoices.

We will update this list before adding a sub-processor that handles customer data. LinkedIn Corporation is not a sub-processor: it is the platform your account already lives on, and your relationship with it is your own.

6. International transfers

Where data moves between [REGION] and a country with different data-protection law, we rely on the transfer mechanism recorded in our agreement with that sub-processor, such as standard contractual clauses. [CONFIRM MECHANISM PER PROVIDER.]

7. Your rights

Depending on where you live, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to processing, or send it elsewhere in a portable form. Write to hello@alwaysnoticed.com and we will respond within thirty (30) days.

Deletion on request: ask us to delete an account and we delete the encrypted session credential and the account's browser profile immediately, and the configuration, activity log and captured analytics within thirty (30) days. Billing records and anything else we are legally required to keep are retained for the periods above and nothing more. If you are an agency, a client whose account you connected may write to us directly and we will act on their request for their own account, telling you that we have.

If you think we have handled your data badly, tell us first. You may also complain to the supervisory authority in [JURISDICTION].

8. Security

Session credentials are encrypted at rest with envelope encryption on a private volume. Every table in the database enforces row-level security, and the boundary between tenants and between people inside one tenant is covered by automated policy tests that run against the real schema. Each account has its own browser identity and its own dedicated IP, so no account shares infrastructure state with another. Access to production by our own staff is limited to what is needed to operate the service, and credentials are never logged, including on failure paths.

No system is beyond compromise. If a breach affects your data, we will tell you and the relevant authority within the time the law requires.

9. Children

The service is for business use by adults. We do not knowingly collect data from anyone under 18.

10. Changes and contact

We will post changes here and, if they are material, notify you by email at least thirty (30) days before they take effect.

Data controller: [COMPANY LEGAL NAME], [REGISTERED ADDRESS]. Contact: hello@alwaysnoticed.com. [APPOINT A DPO / EU-UK REPRESENTATIVE IF REQUIRED.]