A Alphie
How It Works Features Demo Download Blog
|

Legal

Privacy Policy

Effective: August 27, 2026 · Last updated: August 27, 2026

The short version. Alphie is a personal assistant that remembers your context so it can act for you. To do that it stores your conversations and the memory built from them, and — only if you connect them — credentials for services you ask it to use. We do not sell your data, we do not show ads, and we do not use your content or your Google data to train AI models. Data received from Google APIs is handled under the Limited Use requirements below.

1. Who we are

Alphie is operated by BIG NEWS LLC, a Delaware limited liability company, 1201 Orange St, Suite 600, Wilmington, DE 19801-1171, United States ("we", "us", "Alphie"). This policy covers the Alphie web application at app.04bot.com, the Alphie desktop client, and this website at 04bot.com.

For questions about this policy or to make a privacy request, email [email protected].

2. Information we collect

CategoryWhat it includesWhy
Account Email address, display name, and either a password (stored only as a bcrypt hash — never in plain text) or, if you sign in with Google, your Google account's email address and unique account identifier. To create your account, sign you in, and address you correctly.
Your content Messages you send to Alphie and its replies; files you upload; documents, notes, tasks and knowledge bases you create; and the memory Alphie derives from your conversations (facts, preferences, recurring context). This is the product. Without stored context, Alphie cannot remember you between sessions.
Connected-service credentials API keys, OAuth tokens and application passwords that you choose to store so Alphie can act on your behalf (for example a Google Drive token, or an email account). To perform the actions you ask for. Stored encrypted at rest — see Security.
Technical data IP address, client and browser version, timestamps, request and error logs, and — in the desktop client — the operating system and device name you give the device. To operate the service, route requests to the right device, debug failures, and detect abuse.
Usage analytics The Alphie web application loads Google Analytics 4, which sets cookies and records page views, approximate location derived from IP, and device/browser characteristics. This website (04bot.com) does not load analytics. To understand which parts of the product are used. Analytics never receives the contents of your conversations or your files.

Signing in also sets one authentication cookie holding a signed session token. It is required for the service to function.

3. Google user data

This section describes specifically how we handle data received through Google APIs. It governs over anything more general elsewhere in this policy.

3.1 What we request, and why

ScopeWhat it lets Alphie doWhy we need it
openid, userinfo.email See your Google account's email address and unique identifier. To create or link your Alphie account when you use "Sign in with Google", and to show you which Google account is connected.
drive.readonly Browse your Google Drive folders and files, and read the content of files you open or point Alphie at. So you can browse Drive inside Alphie's file view, and ask Alphie to read, summarize, search or index documents that already exist in your Drive. Read-only: Alphie cannot create, modify or delete anything in your Drive.

3.2 How we access it

Access is on demand and initiated by you. Alphie calls the Google Drive API when you browse a folder, open or search a file, or ask it to work with a document. We do not crawl or mirror your Drive in the background. If you later enable a scheduled synchronization for a specific folder into a knowledge base, that folder is listed on a schedule you set, and you can turn it off at any time.

3.3 How we store it

  • OAuth tokens are stored encrypted at rest, scoped to your account, on our server. They are never written to logs and are never sent to any third party other than Google itself.
  • File listings (names, folder structure, sizes, modification times) are fetched live from Google and held only for the duration of the request, except where you have added a folder to a knowledge base, in which case the listing is stored so the index can be kept current.
  • File content is fetched at the moment you request it and is not bulk-copied to our servers. Two things you should understand clearly:
    • If you ask Alphie to read or summarize a file, the extracted text becomes part of that conversation, and conversations are stored with your account until you delete them.
    • If you add a Drive file or folder to a knowledge base, a copy and/or a search index of that content is stored in your account until you remove it.

3.4 How we share it

To answer a question about a document, its text must be sent to the AI model that generates the answer. That model is operated by a third-party provider acting as our processor. We only transmit Google user data to providers whose API terms prohibit using submitted content to train their models, and we do not send Google user data to any other category of recipient except as required by law or to investigate a security incident.

We do not sell Google user data, we do not use it for advertising or any form of profiling for marketing, and we do not transfer it to data brokers.

3.5 Limited Use

Alphie's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, for data obtained through restricted scopes such as drive.readonly:

  • We use it only to provide or improve user-facing features that are prominent in the Alphie interface — browsing your Drive, and reading or indexing the documents you point us at.
  • We do not use it to develop, improve or train generalized or non-personalized AI or machine-learning models. It is never added to any training corpus, ours or anyone else's.
  • We do not use it for serving advertisements, and we do not sell it.
  • We do not allow humans to read it, except: (a) with your explicit consent for a specific problem you have reported to us; (b) where necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized.

3.6 Revoking access and deleting Google data

You can disconnect Google Drive at any time in Alphie under Settings → Google Drive → Disconnect, or from Files → Google Drive. Disconnecting asks Google to revoke the token and deletes the stored token from our vault immediately. You can also revoke access independently at myaccount.google.com/permissions.

Revoking access stops future access, but does not by itself erase content that has already been copied into a conversation or a knowledge base at your request. To have that erased as well, delete the conversation or knowledge base, or email us and we will do it for you.

4. How we use information

  • To operate the assistant: answer you, remember your context, and carry out the actions and automations you ask for.
  • To connect to the third-party services you explicitly connect, on your instruction.
  • To keep the service secure and available — rate limiting, abuse investigation, backups, debugging.
  • To respond to your support requests.
  • To comply with law and enforce our Terms of Service.

We do not sell personal information, show advertising, use your content for advertising or marketing profiling, or use your content or your Google user data to train AI models — ours or third parties'.

5. Who we share with

RecipientWhat they receive
AI model providers (currently one or more of OpenAI, Anthropic, DeepSeek, Groq, MiniMax and Google, depending on the model configured for your account, and where applicable the API gateway that routes to them) The prompt for each request: your message, the relevant context and memory Alphie assembles for it, and any document text you asked Alphie to work with. They process it to generate the response. See §3.4 for the additional restriction that applies to Google user data.
Infrastructure providers — Akamai/Linode (servers, Singapore) and Cloudflare (DNS, TLS termination, CDN and abuse protection) Data in transit and at rest on the servers we rent. They do not use it for their own purposes.
Google Analytics Web application usage events as described in §2. Never conversation or file content.
Services you connect Whatever the action you requested requires — for example, the recipient and body of an email you asked Alphie to send. Governed by that service's own privacy policy.
Legal and safety Information required to comply with a valid legal process, or to protect the rights, property or safety of our users or the public.

If BIG NEWS LLC is involved in a merger, acquisition or sale of assets, we will notify you before your information becomes subject to a different privacy policy.

6. Where your data lives, and how it is protected

  • Location. Our production servers are located in Singapore. If you are outside Singapore, using Alphie involves an international transfer of your data.
  • In transit. All traffic between you and Alphie is encrypted with TLS.
  • At rest. Credentials you store (API keys, OAuth tokens, passwords for connected services) are encrypted with a key derived from your account, not stored alongside them in plain text. Account passwords are stored only as bcrypt hashes and cannot be recovered by us.
  • Local-first where it matters. When you use the Alphie desktop client, credentials that are only usable on your machine — SSH keys, local device passwords, local network credentials — stay on your device and are not uploaded to our servers. Only credentials that are inherently cloud-usable (such as a Google Drive token) are held server-side so they work across your devices.
  • Access. Access to production systems is limited to personnel who need it to operate the service.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any regulator as required by applicable law.

7. Retention and deletion

  • Conversations, memory, files and knowledge bases are kept until you delete them or until your account is deleted.
  • Connected-service credentials are kept until you disconnect that service.
  • Technical logs are kept for a limited operational period and then rotated out.
  • Backups. We keep encrypted database backups for up to 7 daily and 4 weekly copies. Deleted content may persist in a backup until that backup expires.
  • Account deletion. Email [email protected] from your account address. We will delete your account and its content from live systems within 30 days, and it will age out of backups as described above.

8. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Alphie's interface lets you view and delete your conversations, memory entries and connected services directly. For anything else — including a full export or account deletion — email [email protected], and we will respond within 30 days.

If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority. If you are a California resident, we do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.

9. Children

Alphie is not directed to children. You must be at least 13 years old to use it, and at least 16 if you are in the European Economic Area or the United Kingdom. We do not knowingly collect personal information from children below those ages; if we learn that we have, we will delete it.

10. Changes to this policy

We may update this policy as the product changes. The "last updated" date at the top always reflects the current version. If a change materially reduces your rights or materially expands how we use your data, we will notify you in the application before it takes effect.

11. Contact

BIG NEWS LLC
1201 Orange St, Suite 600
Wilmington, DE 19801-1171, United States
[email protected]

法律条款

隐私政策

生效日期:2026 年 8 月 27 日 · 最近更新:2026 年 8 月 27 日

简版。 Alphie 是一个会记住你的上下文、并据此替你办事的个人助理。为此它会保存你的对话和由对话沉淀出的记忆;只有在你主动连接某项服务时,才会保存该服务的凭证。我们不出售你的数据,不投放广告,也不会用你的内容或你的 Google 数据训练 AI 模型。通过 Google API 取得的数据,按下文「有限使用」要求处理。

1. 我们是谁

Alphie 由美国特拉华州有限责任公司 BIG NEWS LLC 运营,地址:1201 Orange St, Suite 600, Wilmington, DE 19801-1171, United States(下称「我们」)。本政策适用于 app.04bot.com 网页应用、Alphie 桌面客户端,以及 04bot.com 官网。

如对本政策有疑问或需行使权利,请发邮件至 [email protected]。

2. 我们收集哪些信息

类别具体内容目的
账号信息 邮箱地址、显示名,以及密码(仅以 bcrypt 哈希形式存储,绝不明文保存);若你使用 Google 登录,则为你 Google 账号的邮箱地址与唯一标识。 创建账号、登录、正确称呼你。
你的内容 你发给 Alphie 的消息及其回复;你上传的文件;你创建的文档、笔记、任务与知识库;以及 Alphie 从对话中沉淀出的记忆(事实、偏好、反复出现的上下文)。 这就是产品本身。没有留存的上下文,Alphie 无法跨会话记住你。
已连接服务的凭证 你主动选择保存、以便 Alphie 代你操作的 API Key、OAuth token、应用专用密码(例如 Google Drive token 或邮箱账号)。 执行你要求的操作。静态加密存储,详见安全。
技术数据 IP 地址、客户端与浏览器版本、时间戳、请求与错误日志;在桌面客户端上还包括操作系统和你为该设备起的名字。 维持服务运行、把请求路由到正确设备、排查故障、发现滥用。
使用分析 Alphie 网页应用加载了 Google Analytics 4,它会写入 Cookie 并记录页面访问、由 IP 推断的大致位置、设备与浏览器特征。本官网(04bot.com)不加载任何分析工具。 了解产品哪些部分被真正使用。分析工具不会收到你的对话内容或文件内容。

登录还会写入一个身份验证 Cookie,内含签名的会话令牌。这是服务运行所必需的。

3. Google 用户数据

本节专门说明我们如何处理通过 Google API 取得的数据。就该类数据而言,本节效力高于本政策其他更笼统的表述。

3.1 我们申请了哪些权限,为什么

权限范围它允许 Alphie 做什么为什么需要
openid、userinfo.email 读取你 Google 账号的邮箱地址与唯一标识。 用于「使用 Google 登录」时创建或关联 Alphie 账号,并向你显示当前连接的是哪个 Google 账号。
drive.readonly 浏览你 Google 云端硬盘的文件夹与文件,并读取你打开或指定的文件内容。 让你能在 Alphie 的文件视图里浏览云端硬盘,并让 Alphie 阅读、总结、检索或索引你云端硬盘里已有的文档。只读:Alphie 无法在你的云端硬盘中创建、修改或删除任何内容。

3.2 我们如何访问

访问是按需发生、由你发起的。只有当你浏览文件夹、打开或搜索文件、或要求 Alphie 处理某个文档时,Alphie 才会调用 Google Drive API。我们不会在后台爬取或镜像你的云端硬盘。如果你之后为某个文件夹开启了到知识库的定期同步,则该文件夹会按你设定的周期被列举,你可随时关闭。

3.3 我们如何存储

  • OAuth token 加密存储于我们的服务器,按账号隔离;绝不写入日志,除 Google 本身外不发送给任何第三方。
  • 文件清单(名称、目录结构、大小、修改时间)实时从 Google 获取,仅在请求期间持有;除非你已把某个文件夹加入知识库——此时清单会被保存,以便索引保持最新。
  • 文件内容在你请求的那一刻才获取,不会被批量复制到我们的服务器。有两点请你明确知悉:
    • 你要求 Alphie 阅读或总结某个文件时,抽取出的文本会成为该对话的一部分,而对话会随你的账号保存,直到你删除它。
    • 你把云端硬盘的文件或文件夹加入知识库时,该内容的副本和/或检索索引会保存在你的账号下,直到你移除它。

3.4 我们如何共享

要回答关于某份文档的问题,其文本必须被发送给生成答案的 AI 模型。该模型由第三方供应商运营,作为我们的受托处理方。我们只会把 Google 用户数据传输给其 API 条款明确禁止将提交内容用于模型训练的供应商;除法律要求或调查安全事件外,不会传输给任何其他类别的接收方。

我们不出售 Google 用户数据,不将其用于广告或任何营销画像,也不会转让给数据经纪商。

3.5 有限使用(Limited Use)

Alphie 对从 Google API 收到的信息的使用与向其他应用的传输,将遵守 Google API 服务用户数据政策,包括其中的「有限使用」要求。

具体而言,对于通过 drive.readonly 等受限范围获得的数据:

  • 我们仅将其用于提供或改进在 Alphie 界面中显著可见的面向用户的功能——浏览你的云端硬盘,以及阅读、索引你指定的文档。
  • 我们不会用它开发、改进或训练通用的、非个性化的 AI 或机器学习模型。它绝不会进入任何训练语料,无论是我们的还是他人的。
  • 我们不会将其用于投放广告,也不会出售。
  • 我们不允许人工读取,除非:(a) 经你就所报告的具体问题明确同意;(b) 出于安全目的确有必要,例如调查滥用;(c) 为遵守适用法律;或 (d) 数据已经过聚合与匿名化处理。

3.6 撤销授权与删除 Google 数据

你可以随时在 Alphie 中断开 Google 云端硬盘:设置 → Google Drive → 断开连接,或在 文件 → Google Drive 处操作。断开时我们会请求 Google 撤销该 token,并立即从我们的凭证库中删除它。你也可以在 myaccount.google.com/permissions 独立撤销授权。

撤销授权会终止后续访问,但本身不会抹除应你要求已复制进对话或知识库的内容。若你也要删除这部分,请删除相应对话或知识库,或发邮件给我们代为处理。

4. 我们如何使用这些信息

  • 运行助理本身:回答你、记住你的上下文、执行你要求的操作与自动化。
  • 按你的指令连接你明确授权的第三方服务。
  • 保障服务的安全与可用:限流、滥用调查、备份、故障排查。
  • 响应你的支持请求。
  • 遵守法律,并执行我们的服务条款。

我们不会出售个人信息、投放广告、将你的内容用于广告或营销画像,也不会用你的内容或 Google 用户数据训练 AI 模型——无论是我们的还是第三方的。

5. 我们与谁共享

接收方接收到什么
AI 模型供应商(目前为 OpenAI、Anthropic、DeepSeek、Groq、MiniMax、Google 中的一家或多家,取决于你账号所配置的模型;如适用,还包括中转这些请求的 API 网关) 每次请求的 prompt:你的消息、Alphie 为其组装的相关上下文与记忆,以及你要求 Alphie 处理的文档文本。它们据此生成回复。针对 Google 用户数据的额外限制见 §3.4。
基础设施供应商——Akamai/Linode(服务器,新加坡)与 Cloudflare(DNS、TLS 终结、CDN 与防滥用) 在我们租用的服务器上传输与存储的数据。它们不会将其用于自身目的。
Google Analytics §2 所述的网页应用使用事件。绝不包含对话或文件内容。
你连接的服务 完成你所请求的操作所必需的内容——例如你要求 Alphie 发送的那封邮件的收件人与正文。受该服务自身的隐私政策约束。
法律与安全 为遵守有效法律程序,或为保护用户或公众的权利、财产与安全所必需的信息。

若 BIG NEWS LLC 发生合并、收购或资产出售,我们会在你的信息适用另一份隐私政策之前通知你。

6. 数据存放在哪里,如何保护

  • 存放地点。我们的生产服务器位于新加坡。若你身处新加坡境外,使用 Alphie 即涉及数据的跨境传输。
  • 传输中。你与 Alphie 之间的全部流量均经 TLS 加密。
  • 静态存储。你保存的凭证(API Key、OAuth token、所连服务的密码)以派生自你账号的密钥加密存储,不以明文与之并存。账号密码仅以 bcrypt 哈希保存,我们无法还原。
  • 该留在本地的就留在本地。使用 Alphie 桌面客户端时,那些只在你本机才可用的凭证——SSH 密钥、本地设备密码、本地网络凭证——会留在你的设备上,不会上传到我们的服务器。只有本身就依赖云端才能使用的凭证(例如 Google Drive token)才保存在服务端,以便跨设备可用。
  • 访问控制。生产系统的访问权限仅限于运行服务所必需的人员。

没有系统是绝对安全的。如果我们发现涉及你个人数据的安全事件,将按适用法律要求通知你及监管机构。

7. 留存与删除

  • 对话、记忆、文件与知识库会一直保留,直到你删除它们或你的账号被删除。
  • 已连接服务的凭证保留至你断开该服务为止。
  • 技术日志仅保留有限的运维周期,随后滚动清除。
  • 备份。我们保留加密的数据库备份,最多 7 份每日备份与 4 份每周备份。已删除的内容可能在备份中留存至该备份过期。
  • 账号删除。请用你的账号邮箱发信至 [email protected]。我们将在 30 天内从线上系统删除你的账号及其内容,备份中的副本按上述周期自然过期。

8. 你的权利

依你所在地区,你可能享有访问、更正、导出、删除个人信息,反对或限制特定处理,以及撤回同意的权利。Alphie 界面本身即可查看并删除你的对话、记忆条目与已连接服务。其他事项——包括完整导出或删除账号——请发邮件至 [email protected],我们将在 30 天内回复。

若你位于欧洲经济区或英国,你还有权向当地监管机构投诉。若你是加州居民:按 CCPA/CPRA 的定义,我们不出售也不共享你的个人信息,且不会因你行使权利而对你区别对待。

9. 未成年人

Alphie 并非面向儿童。你须年满 13 周岁方可使用;若你位于欧洲经济区或英国,须年满 16 周岁。我们不会在知情的情况下收集低于该年龄者的个人信息;一旦发现,将予以删除。

10. 本政策的变更

我们可能随产品演进更新本政策。页首的「最近更新」日期始终对应当前版本。若某项变更实质性削减你的权利或实质性扩大我们对你数据的使用,我们会在其生效前于应用内通知你。

11. 联系我们

BIG NEWS LLC
1201 Orange St, Suite 600
Wilmington, DE 19801-1171, United States
[email protected]

本页中文版仅为方便阅读而提供。如中英文表述存在歧义,以英文版为准。

A Alphie

Your Personal AI Runtime

Product

How It Works Features Demo Download Blog

Contact

Email Us Get Started

Legal

Privacy Policy Terms of Service

© 2026 Alphie. Your AI, your way.