Legal
Privacy Policy
Effective: August 27, 2026 · Last updated: August 27, 2026
The short version. Alphie is a personal assistant that remembers your context so it can act for you. To do that it stores your conversations and the memory built from them, and — only if you connect them — credentials for services you ask it to use. We do not sell your data, we do not show ads, and we do not use your content or your Google data to train AI models. Data received from Google APIs is handled under the Limited Use requirements below.
1. Who we are
Alphie is operated by BIG NEWS LLC, a Delaware limited liability company, 1201 Orange St, Suite 600, Wilmington, DE 19801-1171, United States ("we", "us", "Alphie"). This policy covers the Alphie web application at app.04bot.com, the Alphie desktop client, and this website at 04bot.com.
For questions about this policy or to make a privacy request, email [email protected].
2. Information we collect
| Category | What it includes | Why |
|---|---|---|
| Account | Email address, display name, and either a password (stored only as a bcrypt hash — never in plain text) or, if you sign in with Google, your Google account's email address and unique account identifier. | To create your account, sign you in, and address you correctly. |
| Your content | Messages you send to Alphie and its replies; files you upload; documents, notes, tasks and knowledge bases you create; and the memory Alphie derives from your conversations (facts, preferences, recurring context). | This is the product. Without stored context, Alphie cannot remember you between sessions. |
| Connected-service credentials | API keys, OAuth tokens and application passwords that you choose to store so Alphie can act on your behalf (for example a Google Drive token, or an email account). | To perform the actions you ask for. Stored encrypted at rest — see Security. |
| Technical data | IP address, client and browser version, timestamps, request and error logs, and — in the desktop client — the operating system and device name you give the device. | To operate the service, route requests to the right device, debug failures, and detect abuse. |
| Usage analytics | The Alphie web application loads Google Analytics 4, which sets cookies and records page views, approximate location derived from IP, and device/browser characteristics. This website (04bot.com) does not load analytics. | To understand which parts of the product are used. Analytics never receives the contents of your conversations or your files. |
Signing in also sets one authentication cookie holding a signed session token. It is required for the service to function.
3. Google user data
This section describes specifically how we handle data received through Google APIs. It governs over anything more general elsewhere in this policy.
3.1 What we request, and why
| Scope | What it lets Alphie do | Why we need it |
|---|---|---|
openid, userinfo.email |
See your Google account's email address and unique identifier. | To create or link your Alphie account when you use "Sign in with Google", and to show you which Google account is connected. |
drive.readonly |
Browse your Google Drive folders and files, and read the content of files you open or point Alphie at. | So you can browse Drive inside Alphie's file view, and ask Alphie to read, summarize, search or index documents that already exist in your Drive. Read-only: Alphie cannot create, modify or delete anything in your Drive. |
3.2 How we access it
Access is on demand and initiated by you. Alphie calls the Google Drive API when you browse a folder, open or search a file, or ask it to work with a document. We do not crawl or mirror your Drive in the background. If you later enable a scheduled synchronization for a specific folder into a knowledge base, that folder is listed on a schedule you set, and you can turn it off at any time.
3.3 How we store it
- OAuth tokens are stored encrypted at rest, scoped to your account, on our server. They are never written to logs and are never sent to any third party other than Google itself.
- File listings (names, folder structure, sizes, modification times) are fetched live from Google and held only for the duration of the request, except where you have added a folder to a knowledge base, in which case the listing is stored so the index can be kept current.
- File content is fetched at the moment you request it and is not bulk-copied to our servers. Two things you should understand clearly:
- If you ask Alphie to read or summarize a file, the extracted text becomes part of that conversation, and conversations are stored with your account until you delete them.
- If you add a Drive file or folder to a knowledge base, a copy and/or a search index of that content is stored in your account until you remove it.
3.4 How we share it
To answer a question about a document, its text must be sent to the AI model that generates the answer. That model is operated by a third-party provider acting as our processor. We only transmit Google user data to providers whose API terms prohibit using submitted content to train their models, and we do not send Google user data to any other category of recipient except as required by law or to investigate a security incident.
We do not sell Google user data, we do not use it for advertising or any form of profiling for marketing, and we do not transfer it to data brokers.
3.5 Limited Use
Alphie's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, for data obtained through restricted scopes such as drive.readonly:
- We use it only to provide or improve user-facing features that are prominent in the Alphie interface — browsing your Drive, and reading or indexing the documents you point us at.
- We do not use it to develop, improve or train generalized or non-personalized AI or machine-learning models. It is never added to any training corpus, ours or anyone else's.
- We do not use it for serving advertisements, and we do not sell it.
- We do not allow humans to read it, except: (a) with your explicit consent for a specific problem you have reported to us; (b) where necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized.
3.6 Revoking access and deleting Google data
You can disconnect Google Drive at any time in Alphie under Settings → Google Drive → Disconnect, or from Files → Google Drive. Disconnecting asks Google to revoke the token and deletes the stored token from our vault immediately. You can also revoke access independently at myaccount.google.com/permissions.
Revoking access stops future access, but does not by itself erase content that has already been copied into a conversation or a knowledge base at your request. To have that erased as well, delete the conversation or knowledge base, or email us and we will do it for you.
4. How we use information
- To operate the assistant: answer you, remember your context, and carry out the actions and automations you ask for.
- To connect to the third-party services you explicitly connect, on your instruction.
- To keep the service secure and available — rate limiting, abuse investigation, backups, debugging.
- To respond to your support requests.
- To comply with law and enforce our Terms of Service.
We do not sell personal information, show advertising, use your content for advertising or marketing profiling, or use your content or your Google user data to train AI models — ours or third parties'.
5. Who we share with
| Recipient | What they receive |
|---|---|
| AI model providers (currently one or more of OpenAI, Anthropic, DeepSeek, Groq, MiniMax and Google, depending on the model configured for your account, and where applicable the API gateway that routes to them) | The prompt for each request: your message, the relevant context and memory Alphie assembles for it, and any document text you asked Alphie to work with. They process it to generate the response. See §3.4 for the additional restriction that applies to Google user data. |
| Infrastructure providers — Akamai/Linode (servers, Singapore) and Cloudflare (DNS, TLS termination, CDN and abuse protection) | Data in transit and at rest on the servers we rent. They do not use it for their own purposes. |
| Google Analytics | Web application usage events as described in §2. Never conversation or file content. |
| Services you connect | Whatever the action you requested requires — for example, the recipient and body of an email you asked Alphie to send. Governed by that service's own privacy policy. |
| Legal and safety | Information required to comply with a valid legal process, or to protect the rights, property or safety of our users or the public. |
If BIG NEWS LLC is involved in a merger, acquisition or sale of assets, we will notify you before your information becomes subject to a different privacy policy.
6. Where your data lives, and how it is protected
- Location. Our production servers are located in Singapore. If you are outside Singapore, using Alphie involves an international transfer of your data.
- In transit. All traffic between you and Alphie is encrypted with TLS.
- At rest. Credentials you store (API keys, OAuth tokens, passwords for connected services) are encrypted with a key derived from your account, not stored alongside them in plain text. Account passwords are stored only as bcrypt hashes and cannot be recovered by us.
- Local-first where it matters. When you use the Alphie desktop client, credentials that are only usable on your machine — SSH keys, local device passwords, local network credentials — stay on your device and are not uploaded to our servers. Only credentials that are inherently cloud-usable (such as a Google Drive token) are held server-side so they work across your devices.
- Access. Access to production systems is limited to personnel who need it to operate the service.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any regulator as required by applicable law.
7. Retention and deletion
- Conversations, memory, files and knowledge bases are kept until you delete them or until your account is deleted.
- Connected-service credentials are kept until you disconnect that service.
- Technical logs are kept for a limited operational period and then rotated out.
- Backups. We keep encrypted database backups for up to 7 daily and 4 weekly copies. Deleted content may persist in a backup until that backup expires.
- Account deletion. Email [email protected] from your account address. We will delete your account and its content from live systems within 30 days, and it will age out of backups as described above.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Alphie's interface lets you view and delete your conversations, memory entries and connected services directly. For anything else — including a full export or account deletion — email [email protected], and we will respond within 30 days.
If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority. If you are a California resident, we do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.
9. Children
Alphie is not directed to children. You must be at least 13 years old to use it, and at least 16 if you are in the European Economic Area or the United Kingdom. We do not knowingly collect personal information from children below those ages; if we learn that we have, we will delete it.
10. Changes to this policy
We may update this policy as the product changes. The "last updated" date at the top always reflects the current version. If a change materially reduces your rights or materially expands how we use your data, we will notify you in the application before it takes effect.
11. Contact
BIG NEWS LLC
1201 Orange St, Suite 600
Wilmington, DE 19801-1171, United States
[email protected]