AlphaOne AI

Privacy Policy

Last Updated: August 20, 2026

AlphaOne AI has multiple execution surfaces. Privacy behavior differs between the web/mobile workspace, Local GGUF execution, and the Windows-local HyperRouter gateway. This policy describes those boundaries without treating cloud AI traffic as fully local.

1. BYOK Credentials & Local Storage

Provider API keys are user-supplied credentials. Storage depends on the product surface. Web/mobile interfaces may use device-local application or browser storage. The Windows HyperRouter gateway persists provider credentials and other settings in %APPDATA%\AlphaOneAI\Config\user_settings.json. The current HyperRouter persistence path stores this as ordinary local JSON and does not apply application-layer encryption at rest. Protect access to your Windows account and user profile accordingly.

2. Local AI vs. Cloud AI Processing

  • Local GGUF: when a compatible local model is selected and no cloud fallback is used, inference can run on the user's computer without sending the prompt to a cloud model provider.
  • Cloud providers: requests routed to Google, OpenAI, Anthropic, DeepSeek, Qwen, Kimi AI, Agnes AI, Groq, or other configured upstream services necessarily transmit request data to that provider. Their own privacy policies, retention rules, and account terms apply.

3. HyperRouter Local Network Boundary

HyperRouter binds to localhost by default through ListenLocalhost and normally listens on 127.0.0.1:11436. It is intended for local single-user operation. The current application also enables a permissive CORS policy, so the loopback-only listener and security of the local Windows session remain important boundaries.

4. Conversation State & Operational Telemetry

HyperRouter does not operate as a hosted cloud conversation database. It does, however, maintain local runtime and continuity state required for routing and agentic interoperability. Some state is in memory and some diagnostic/configuration state is persisted under the user's AppData profile.

Operational request telemetry can be stored locally in request_logs.json, including provider/model identity, token counts, latency, status, quota classification, and diagnostic error details. Users can clear HyperRouter request logs from its local dashboard.

5. Website Analytics, Cookies & Advertising

The public AlphaOne AI website may use standard analytics, cookies, advertising technologies, and third-party assets to measure traffic, operate site features, or support the service. These services may process browser/device information according to their own policies. Website analytics and advertising are separate from HyperRouter's local AI-routing process, but users should review the applicable third-party privacy and cookie controls when using the public website.

6. Your Responsibilities & Controls

  • Protect your provider API keys and Windows/browser account access.
  • Use provider credentials only in accordance with the provider's terms.
  • Clear local logs/settings when transferring or disposing of a device.
  • Use Local GGUF mode when you specifically require an offline inference path.

7. Policy Changes & Contact

This policy may be updated as the product architecture changes. The current revision date is shown above. Questions about this policy can be sent to support@alphaone-ai.com.