Alloy

Privacy Policy

Last updated: 2026-08-22

About this policy

This policy covers how Memriq, Inc. ("Memriq", "we") collects and uses information in Alloy.

What we collect

  • Account data — the email address you sign in with, and your sign-in method.
  • Study signals — for example, how long you spent on a section of a written passage, and how long you spent on a segment of an audio episode.
  • Your answers and your confidence ratings on practice questions, drills and exams.
  • Operational logs — the ordinary records a web application keeps in order to run and to be debugged.

Alloy keeps a learner model of you, one per course: a per-concept estimate of your mastery, how well-calibrated your confidence is, and how quickly a given concept fades for you.

If you send a bug report through the in-app reporter, it carries the page you were on, your browser details, and — if you use the picker — a screenshot of what you clicked and a short replay of roughly the last thirty seconds in the app.

How we use it

We use it to run the platform, to decide what to teach you next, and to show you your own progress. Alloy also reads these models in aggregate to produce platform-level numbers on an internal operator dashboard.

Large language model completions are processed by OpenAI and/or Anthropic; we transmit only the context and prompts each feature requires.

What an employer can see

No employer sees you at all unless you have turned employer visibility on in your account. An absence of that consent is treated as a refusal.

Study behaviour is blocked from employer-facing pages by a check in the code, not by a promise. If one of those fields ever appeared, the request fails outright rather than quietly stripping the field.

Code you ask us to scan

To scan a private repository, Alloy never asks you for a password or a token; if a URL you paste contains a token, we refuse the URL rather than store it. The short-lived access it uses lives about an hour, is scoped to the repositories that were ticked, is never stored and never reused. A token used to open a pull request is held for that single request, and is never written to our database, a log line or an error message.

Where it lives

Alloy runs on infrastructure operated by Memriq in the United States, primarily Railway (compute), Neo4j Aura (graph data), MongoDB Atlas (document and event data), and Resend (transactional email). Sign-in is brokered by Google.

Cookies

Alloy uses first-party session cookies issued by NextAuth to keep you signed in.

Your data and your choices

There is no self-serve way to delete your Alloy account or your data in the product today, and there is no button that downloads everything Alloy holds about you. The portfolio export is a way to share your work; it is not a data-deletion mechanism.

To have your account and data deleted, email [email protected] from the address on your account. We will acknowledge within 5 business days and complete the deletion within 30 days. We will tell you what we are keeping and why — that is billing records only, and only for as long as tax law requires.

Deletion is permanent. Your progress, your exam history, any certificates you have earned and any unused credits go with the account and cannot be restored.

To ask about the data Alloy holds about you, write to [email protected].

Changes

We may update this policy. The date at the top of this page is the date of the current version.

Contact

Questions about this policy go to [email protected].