Privacy Policy and Cookie Notice
Last Updated: August 6, 2026
Privacy Policy
Effective as of August 6, 2026.
Alter Labs, Inc. (“Alter,” “we,” “us,” or “our”) provides a hosted credential-authorization platform for AI agents. This Privacy Policy describes how Alter processes personal information that we collect through our digital or online properties or services that link to this Privacy Policy (including our websites, documentation, developer portal, Alter Wallet, the embedded Alter Connect experience, our SDKs and command-line interface, and support and billing features), as well as other activities described below (collectively, the “Service”).
Notice to European users: Please see the “Notice to European users” section below for additional information for individuals located in the European Economic Area or the United Kingdom (which we refer to as “Europe”).
Controller vs. processor — please read. Alter plays two different roles. As a controller, Alter decides how and why to process information about its own account holders and website visitors — for example, developer account details, billing data, and Service usage data; this Policy governs that processing. As a processor, Alter handles certain data on behalf of, and under the instructions of, its business customers — for example, the identifiers of a customer’s End Users and the Connected-Account Credentials and metadata that flow through the Service; for that data the customer is the controller, the customer’s own privacy notice governs its relationship with the End User, and Alter’s obligations are set out in the Data Processing Agreement. If you are an End User of an application built on Alter, please contact that application’s provider about your data.
Index
- Personal information we collect
- Tracking & other technologies
- How we use your personal information
- Retention
- How we share your personal information
- Your choices
- Other sites and services
- Security
- International data transfer
- Children
- Changes to this Privacy Policy
- How to contact us
- U.S. state privacy notices
- Notice to European users
- Cookie Notice
Personal information we collect
Information you provide to us. Personal information you may provide through the Service or otherwise includes:
- Contact data, such as your first and last name, email address, professional title, and company name.
- Account and profile data, such as the username and password you set to establish an account (we store only a salted, one-way hash of your password), and, if you enable two-factor authentication, the associated two-factor secrets and session records.
- Organization and configuration data, such as organization and application names, Authorized User roles, Agent identities and configuration, Provider and identity-provider configuration (including encrypted OAuth application client secrets), policies, approval settings, legal-notice URLs, and other settings selected by account administrators.
- Communications data based on our exchanges with you, including when you contact support or sales.
- Billing and payment data, such as your billing contact and the plan, invoices, and the last four digits and brand of a payment card. Payment details are collected and processed by our payment processor (Stripe); Alter does not store full card numbers.
- Feedback data, such as survey responses, documentation feedback, and feature requests you voluntarily submit.
Information we process to deliver the Service (as processor, on our customers’ instructions).
- Connected-Account Credentials: OAuth access and refresh tokens, API keys, and managed secrets you or your End Users authorize, encrypted at rest in a dedicated secrets vault; our application database stores only metadata and an opaque vault-key reference.
- Connected-Account metadata: the Provider, granted scopes, the account display name or email associated with the Connected Account, Provider subject identifiers, and token expiry/refresh metadata.
- End User identifiers: identifiers our customers’ applications pass to the Service (for example, a subject identifier from the customer’s identity provider), released email/display claims, mapped group memberships, and the last verified identity claims used for policy evaluation.
- Authorization and approval data: Grants, requested and approved scopes, principal and delegation relationships, policy decisions, human-approval decisions, revocation status, and related lifecycle data.
- Provider request metadata: the Provider endpoint, method, status, timing, and policy result associated with a brokered request. Where a customer enables an approved diagnostic payload capture feature, the resulting Customer Data is processed on the customer’s instructions under the Data Processing Agreement and the customer’s configured retention settings.
- Diagnostic payload capture: off by default and enabled per application by the customer. When enabled, Alter retains copies of Provider request and response bodies (each capped at 64 KB, with larger content stored truncated and flagged) and deletes them after 30 days. The contents are determined by what the customer’s agent transmits.
Third-party sources. We may combine personal information we receive from you with personal information within the categories above that we obtain from other sources, such as: the organization that provides or administers your access; our business customers that integrate the Service; End Users who complete a Connect or Wallet flow; Providers and customer-selected identity providers that return authorized account, token, and profile information; and the service providers listed below.
Automatic data collection. We and our service providers may automatically log information about you, your device, and your interaction with the Service, such as:
- Usage and audit data, such as records of API calls and lifecycle events, including the action taken, timestamps, the calling agent/application and actor identifiers, requested vs. granted scopes, delegation context, result (success / failure / denial), and the IP address associated with a request.
- Device and log data, such as browser type and version, device and operating-system information, pages viewed, referrer, approximate location derived from IP address, timestamps, and error and performance data.
- Product and documentation analytics, such as page views, feature interactions, environment, and pseudonymous browser and session identifiers. Public documentation analytics remains pseudonymous; in the developer portal, after a signed-in account holder’s profile loads, the browser analytics record may be linked to that holder’s user ID, email, name, and organization.
- Command-line and server-side telemetry, such as a random local telemetry identifier used by the
altercommand-line interface and operational events sent by our backend and onboarding tools that may identify an organization, application, or session. Command-line telemetry can be disabled withALTER_NO_TELEMETRY=1orDO_NOT_TRACK=1.
For more information concerning our automatic collection of data, please see the Cookie Notice below.
Tracking & other technologies
Cookies and other technologies. Some of our automatic data collection is facilitated by cookies and other technologies. For more information, see our Cookie Notice below. We also store a record of your preferences regarding the use of these technologies.
Diagnostics and session-replay technologies, such as those provided by PostHog and Sentry, employ software code to record error, performance, and interaction data (including DVR-like session replays in the developer portal and Alter Wallet). Inputs and rendered text are masked, automatic element-text capture and network/console capture are disabled, and known token-endpoint breadcrumbs are redacted, to reduce collection of Credentials or Customer Data. We contractually require these providers to maintain appropriate data-protection safeguards and prohibit them from using your data for generalized AI model training.
How we use your personal information
We may use your personal information for the following purposes or as otherwise described at the time of collection:
- Service delivery and operations. To provide the Service (including storing and refreshing Credentials and enforcing Grants and policies), establish and maintain your account, enable security features, communicate with you about the Service (including service-related announcements, updates, security alerts, and support and administrative messages), and provide support and respond to your requests, questions, and feedback.
- Service improvement and analytics. To analyze your use of the Service, understand user activity, diagnose errors, improve performance, and develop new features. For example, we use PostHog for product and documentation analytics.
- Security, fraud prevention, and audit. To authenticate users, protect against fraud, abuse, and security incidents, and create audit logs for security, compliance, and traceability.
- Direct marketing. We may send business customers and contacts direct marketing communications about Alter products and features, and may personalize those messages; you can opt out as described in the “Your choices” section. Where consent is required, we send promotional communications only with that consent.
- Compliance and protection. To comply with applicable laws, lawful requests, and legal process; protect our, your, or others’ rights, privacy, safety, or property (including making and defending legal claims); audit our internal processes; enforce the terms that govern the Service; and prevent, identify, investigate, and deter fraudulent, harmful, unauthorized, or illegal activity.
- Corporate events. To share certain personal information in the context of an actual or prospective corporate event, as described in “How we share your personal information.”
- To create aggregated, de-identified, and/or anonymized data. We may create aggregated, de-identified, or anonymized data from personal information by removing information that makes it identifiable, and we will not attempt to re-identify it except to test whether our de-identification controls are effective or as permitted by law. We may use and share such data for our lawful business purposes, including analyzing and improving the Service.
No advertising, no sale, and no model training. Alter does not use personal information or cookies for interest-based or cross-context behavioral advertising, and does not sell or “share” personal information as those terms are defined under U.S. state privacy laws. Alter does not use Customer Data, Credentials, the contents of Connected Accounts, or the inputs or outputs of a customer’s Customer Application or Agents to train, fine-tune, or otherwise develop any machine-learning or artificial-intelligence model.
Automated decision-making. Alter does not use your personal information to make decisions producing legal or similarly significant effects about you through solely automated means without human involvement. The Service executes the Grants and policies our customers configure; any automated action on a Connected Account is taken on the customer’s instruction, and the customer is responsible for the design and oversight of its own Agents.
Further uses. In some cases we may use personal information for further purposes, in which case we will ask for your consent if the further use is not compatible with the initial purpose for which the information was collected.
Retention
We generally retain personal information to fulfill the purposes for which we collected it, including satisfying legal, accounting, or reporting requirements, establishing or defending legal claims, or preventing fraud. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it and whether we can achieve those purposes through other means, and applicable legal requirements. In particular: account and billing data are retained for the life of your account and as required afterward for tax, accounting, and legal purposes; Credentials and Grants are retained until you or your End User revokes them or the associated resource is deleted, after which Credentials are deleted from the vault without a recovery window (subject to a short asynchronous wind-down); audit logs are retained per the customer’s plan while the customer is active, after which customer-submitted identity fields are deleted or irreversibly de-identified within the contractual deletion period unless a legal hold or law requires retention; authentication and security records are retained for the period reasonably necessary to detect abuse, investigate incidents, enforce our terms, and comply with law; and analytics and diagnostic data are retained for the period configured in the relevant service. Data in backups is isolated from ordinary use and deleted on the backup rotation schedule. When we no longer require personal information, we delete, anonymize, or isolate it from further processing.
How we share your personal information
We may share your personal information with the following parties or as otherwise described in this Privacy Policy or at the time of collection:
- Affiliates. Our corporate parent, subsidiaries, and affiliates.
- Service providers (sub-processors). Third parties that provide services on our behalf or help us operate the Service or our business (such as hosting, the secrets vault, transactional email, payment processing, error monitoring, product analytics, and edge security and bot protection), under contracts requiring appropriate safeguards. Our current sub-processors are listed on our Subprocessor page.
- Payment processors. Any payment-card information you use to make a purchase is collected and processed directly by our payment processor, Stripe, which may use your payment data in accordance with its privacy policy.
- Authentication providers. Google and GitHub, when enabled and selected for operator social sign-in, and a customer-selected identity provider for Wallet, each under its own privacy notice.
- Providers you connect. When you or your End Users authorize a Connected Account, we exchange the information necessary to obtain and refresh Credentials and make the calls you direct; each Provider’s own privacy policy governs its handling.
- Your organization and its administrators. If an account is provided or managed by an organization, its authorized administrators can manage access and may receive account, usage, security, and audit information associated with that organization.
- Professional advisors. Lawyers, auditors, bankers, and insurers, in the course of the services they render to us.
- Authorities and others. Law enforcement, government authorities, and private parties, where we believe in good faith it is necessary or appropriate for the compliance and protection purposes described above.
- Business transferees. Parties to an actual or prospective corporate transaction (for example, an investment in, financing of, or sale, transfer, or merger of all or part of our business or assets, or an insolvency or similar proceeding), subject to this Policy.
We do not sell personal information, do not “share” it for cross-context behavioral advertising, and do not use Credentials, Connected-Account contents, captured request bodies, or Customer Data to create advertising profiles.
Your choices
- Access or update your information. You may review and update certain account information by logging into your account.
- Opt out of marketing communications. You may opt out of marketing-related emails using the unsubscribe instructions in the email or by contacting us; you may continue to receive service-related and other non-marketing messages.
- Cookies and other technologies. For information about cookies and how to control them, see our Cookie Notice below.
- Command-line telemetry. You can disable command-line telemetry with
ALTER_NO_TELEMETRY=1orDO_NOT_TRACK=1. - Do Not Track and opt-out preference signals. Because we do not sell or “share” personal information, we do not currently offer a sale/share opt-out, and the Service does not currently respond to “Do Not Track” or Global Privacy Control signals. Before introducing any processing for which applicable law requires recognition of an opt-out preference signal, we will implement and disclose the corresponding signal handling.
- Declining to provide information. We need certain information to provide the Service; if you do not provide information we identify as required, we may not be able to provide the corresponding features.
- Delete your content or close your account. You can delete certain content through your account. To close your account, please contact us.
Other sites and services
The Service links to and integrates with third-party Providers and websites we do not control. This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. Connect pages do not load web fonts from third-party font services; where a customer configures a branded font, Alter retrieves it server-side and serves it from Alter’s own origin, so the browser does not disclose an IP address, user agent, or referrer to the font provider. Provider catalog and Connect surfaces may request a Provider logo from Simple Icons CDN, jsDelivr, or Brandfetch, which receives ordinary browser metadata for that request.
Security
We employ technical, organizational, and physical safeguards designed to protect the personal information we collect, including encryption of End User OAuth tokens and managed secrets at rest in a dedicated secrets vault (separate from the application database, which stores metadata and an opaque vault-key reference) and separate encryption of OAuth application client secrets under keys held outside the database; encryption in transit (TLS); passwords stored only as salted one-way hashes, with two-factor authentication available, bot protection on sign-in and sign-up, and breached-password screening; a zero-trust authorization model in which every access decision traces to an explicit ownership record; audit logging with tamper-evidence; and network protections, including controls against server-side request forgery on outbound connections. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information; you are responsible for securing your own account and systems.
International data transfer
We are headquartered in the United States and may use service providers that operate in other countries, so your personal information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country. Users in Europe should read the important information provided in the “Notice to European users” section below about transfers of personal information outside of Europe.
Children
The Service is intended for businesses and users 18 years of age and older, and is not directed to children. We do not knowingly collect personal information from children. If you are a parent or guardian and believe we have collected personal information from a child in a manner prohibited by law, please contact us and we will comply with applicable legal requirements to delete the information.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes, we will notify you by updating the date of this Privacy Policy and posting it on the Service or by other appropriate means. Any modifications are effective upon posting the updated version (or as otherwise indicated at the time of posting).
How to contact us
- Email: privacy@alterauth.com
- Security: security@alterauth.com
- Mail: Alter Labs, Inc., 169 Madison Ave, STE 15836, New York, NY 10016
U.S. state privacy notices
California residents (Shine the Light). California’s “Shine the Light” law permits California residents to request information about a business’s disclosures of personal information to third parties for those third parties’ own direct-marketing purposes. Alter does not disclose personal information to third parties for their own direct marketing.
Nevada residents. You may opt out of the sale of certain personal information for monetary consideration. Alter does not sell personal information; if you are a Nevada resident with a question, email privacy@alterauth.com.
Contact us. Questions about our privacy practices may be sent to the contacts in “How to contact us” above.
Notice to European users
Where this applies. This section applies to individuals in the UK and the EEA (“Europe”). References to “personal information” include “personal data” as defined in the GDPR.
Controller. Alter Labs, Inc. is the controller of the personal information covered by this Policy that Alter processes as a controller (for purposes of the EU GDPR and UK GDPR, as applicable, the “GDPR”). For the End User and Connected-Account data Alter processes on behalf of its business customers, the customer is the controller and Alter is a processor under the Data Processing Agreement.
Our legal bases for processing. In respect of each purpose for which we use your personal information, the GDPR requires a “legal basis.” Our legal bases are:
- Contractual necessity — to create and administer the requested account, authenticate the user, provide the Service, process billing, and respond to service requests.
- Legitimate interests — to secure the Service, prevent fraud and abuse, maintain audit and diagnostic records, understand and improve the Service, communicate with business customers, and establish or defend legal claims, where those interests are not overridden by your rights.
- Compliance with law — to meet tax, accounting, sanctions, regulatory, and lawful-request obligations.
- Consent — where required, for optional cookies, direct marketing, or another specific purpose; you may withdraw consent at any time without affecting prior processing.
Where Alter acts as a processor, the relevant customer (controller) is responsible for the legal basis, and our processing is governed by the Data Processing Agreement.
Retention. See “Retention” above.
No sensitive personal data. We ask that you not provide special-category personal data (such as data revealing racial or ethnic origin, political opinions, religion, health, biometric or genetic data, or trade-union membership) through the Service except as permitted by the Agreement and applicable law.
No automated decision-making. As part of the Service, Alter does not engage in automated decision-making or profiling that produces legal or similarly significant effects on you.
Your rights. Subject to applicable law, you may request access to, and correction, deletion, or a portable copy of, your personal information; restrict or object to certain processing (including processing based on legitimate interests and processing for direct marketing); and withdraw consent. To exercise these rights, email privacy@alterauth.com. If we reject a request, we will explain why, subject to legal restrictions. You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office; in the EEA, the authority listed at the European Data Protection Board’s website.
Data processing outside Europe. We are a U.S.-based company and many of our service providers are also based in the U.S., which is not the subject of an EU “adequacy decision.” Where we transfer personal data out of Europe to a country without an adequacy decision, we use appropriate safeguards — for example, the European Commission’s Standard Contractual Clauses and the UK Addendum — or, in limited cases, rely on a permitted derogation such as your explicit consent. Contact privacy@alterauth.com for a copy of the applicable safeguards, subject to redaction of confidential information.
Cookie Notice
This Cookie Notice explains how Alter uses cookies and similar technologies on our websites, documentation, developer portal, Alter Wallet, the embedded Alter Connect experience, and other browser-based parts of the Service (collectively, the “Sites”). Read it with the Privacy Policy above; capitalized terms not defined here have the meanings given there.
What are cookies?
Cookies are small text files placed on your browser or device when you visit a website. They can be set by the service being visited (“first-party cookies”) or by another provider whose technology is used on that service (“third-party cookies”). We also use local and session storage, software development kits and scripts, replay technology (in a privacy-protected form), and server-side identifiers that associate a browser session or product event with an account, organization, application, or device. Some technologies last only until the browser or tab is closed (“session”); others remain for a stated period or until deleted (“persistent”).
What types of technologies do we use?
- Strictly necessary / essential. Required to authenticate users, maintain sessions, prevent cross-site request forgery, preserve a safe redirect during sign-in, apply security controls, and complete an authorization flow. The browser-based Service may not function correctly if these are blocked.
- Analytics and performance. Where enabled, help us understand use of the developer portal and public documentation, diagnose errors, and improve performance; may collect a browser or device identifier, account or organization identifier, page path, referrer, timestamps, browser and device information, IP address, and interaction events, and may include PostHog session replay and Sentry error monitoring and replay, with inputs and rendered text masked.
- Advertising. Alter does not use advertising or cross-context behavioral-targeting cookies, and does not use cookies to sell or “share” personal information for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws.
Current first-party cookies and storage
Names may include a secure prefix or dynamically generated suffix. Durations are maximums and may end earlier when you sign out, the flow completes, or the item is cleared.
alter_dev_portal.session_token(and secure-prefixed forms) — Developer portal — Strictly necessary — authenticates the developer and maintains the portal session — up to 7 days, refreshed during active use.alter_dev_portal.two_factor(and secure-prefixed forms) — Developer portal — Strictly necessary — short-lived two-factor-challenge state — up to 10 minutes.wallet_session— Alter Wallet — Strictly necessary — maintains the Wallet sign-in session — until the issued session expires (default 1 hour, 15-minute minimum).oauth_state_<app-id>— Alter Wallet — Strictly necessary — verifies the sign-in response and prevents cross-site request forgery — up to 5 minutes.oauth_next_<app-id>— Alter Wallet — Strictly necessary — preserves a validated same-origin destination during sign-in — up to 5 minutes or until the callback completes.alter_connect_session— Alter Connect — Strictly necessary — maintains a short-lived Connect authorization session — up to 10 minutes.ph_<project-key>_posthogand its local-storage entry — Developer portal and documentation, when analytics is enabled — Analytics and performance — maintains a PostHog visitor and session identifier (pseudonymous on public documentation; may be linked to the signed-in account holder in the developer portal) — up to 365 days under the current SDK default.alter-org-auto-selected,alter-org-retry-count(session storage) — Developer portal — Strictly necessary — prevent repeated organization-selection work and limit retry loops in the current tab — until the tab is closed or sign-out.alter_oauth_state,alter_bind_attempted(session storage) — Alter Connect SDK on a customer’s application origin — Strictly necessary — preserve state across a provider authorization redirect and prevent repeated session-binding — until the tab is closed or the flow clears them.alter_cookie_consent— website, documentation, developer portal, and Wallet — Strictly necessary — records the analytics/performance categories accepted or rejected, the consent-policy version, and when the choice was made, stored on the device only and not transmitted to Alter’s servers — up to 180 days or until changed or cleared.
Developer-portal, Wallet, and Connect session cookies are configured HttpOnly, SameSite=Lax, and Secure in production. The Connect SDK stores alter_oauth_state on the customer’s own application origin, and the customer remains responsible for describing its own use of the SDK and related browser storage in its notices.
Other technologies
- Browser web storage. We may use local and session storage for purposes similar to cookies; your browser may provide functionality to clear it.
- Web beacons. We may use pixel tags in HTML-formatted emails to understand engagement (for example, whether an email was opened); most browsers and devices allow you to prevent images from loading.
- Software development kits (SDKs). The Alter Connect SDK stores limited state on the customer’s application origin, as described above.
- Session-replay technologies. As described above, PostHog and Sentry replay in the developer portal and Alter Wallet records interactions in a masked, privacy-protected form to help us diagnose usability and reliability issues; Connect pages do not enable replay or performance tracing without a consent mechanism.
Third-party technologies
- PostHog, Inc. — product and documentation analytics, including masked session replay in the developer portal; server-side events do not place browser cookies.
- Functional Software, Inc. d/b/a Sentry — minimized error/security monitoring (strictly necessary), with optional, consent-gated performance tracing and sampled replay in the developer portal and Wallet; text and inputs masked; not used for advertising.
- Cloudflare, Inc. — edge security, DDoS and bot protection, and Turnstile challenges on authentication forms; may set conditional edge-security cookies (for example,
_cf_bm,cf_clearance). - Stripe, Inc. — hosted checkout and billing-portal pages reached from the developer portal; Stripe controls the cookies on its own domain.
- Simple Icons CDN, jsDelivr, or Brandfetch — Provider logos where an icon is not self-hosted; the browser may disclose ordinary request metadata; not used for Alter advertising.
- A customer-selected identity or OAuth provider — sign-in and Connected-Account authorization redirects; the provider controls cookies on its own domain.
Your choices
Strictly necessary technologies are used because they are required to provide a feature you request or to protect the Service, and cannot be disabled through an Alter preference without disabling the associated feature. Alter provides browser controls to accept, reject, customize, and later withdraw optional analytics and performance choices; the selected categories, the Cookie Notice version, and the time of the choice are stored in a first-party cookie on your device (not transmitted to Alter’s servers), and withdrawal takes effect from the moment the preference is changed. You can also use your browser settings to view, block, or delete cookies and site data; blocking all cookies will prevent sign-in, Wallet, Connect, and other authenticated features from working. Because Alter does not use advertising cookies or sell or “share” personal information, there is currently no sale/share or advertising opt-out, and the Service does not currently read the Global Privacy Control or “Do Not Track” signal.
Changes; questions
We may update this Cookie Notice to reflect changes to the Service, vendors, technologies, or law, and will post the updated version with a revised “Last Updated” date. Questions may be sent to privacy@alterauth.com.