Privacy Policy
Last updated: September 15, 2026
This Privacy Policy explains how ALSES BIOTECH (USA) LLC ("alsesAI", "we", "our", or "us") collects, uses, stores, and protects your information when you use www.alsesai.com and related services (the "Platform"). By using the Platform, you agree to this Policy.
1. Information We Collect
- Account information: username, email address, and your password (stored only as a bcrypt hash — we never store or see your plaintext password).
- Profile information: research field, bio, avatar, social links, researcher verification materials you choose to submit, and — for institutions — name, type, website, email, phone, and description.
- Content you create: posts, comments, likes, saves, literature shares, IP Vault entries (patent showcases and blockchain timestamps), direct messages, and institution content.
- AI interactions: questions you ask the AI assistant and files or images you upload to it. These are processed by our AI provider solely to generate your answer.
- Payment information: when you purchase a membership, payment is processed directly by Stripe, Inc. We never see, store, or handle your full card number. We receive only the transaction status, your membership tier, and billing metadata from Stripe.
- Usage and technical data: IP address, browser type and language, device information, login activity, pages visited, and interaction logs (used for security, abuse prevention, and product improvement).
- Token and Gene records: daily free-token consumption, Gene point balances, and transaction history needed to operate the points system.
2. How We Use Your Information
- To provide, operate, and secure the Platform (authentication, sessions, rate limiting, abuse and prohibited-content detection — including automated multilingual screening of posts, comments, and messages).
- To deliver paid memberships, Gene points, invoices, and refunds via Stripe.
- To personalize content recommendations (e.g., questions matched to a researcher's field).
- To send essential account communications (email verification, password reset, security alerts). We do not send marketing email without consent.
- To comply with legal obligations and enforce our Rules and User Agreement.
3. Third-Party Processors
- Stripe, Inc. — payment processing. Stripe's own privacy policy governs the payment data it collects.
- DeepSeek — large-language-model provider. Your AI questions and uploaded attachments are transmitted to DeepSeek's API to generate responses. Do not upload secrets, patient data, or third-party confidential information to the AI assistant.
- Cloud infrastructure — the Platform is hosted on Tencent Cloud (currently the Hong Kong region).
- Blockchain timestamping — content you submit to the timestamp service is hashed and anchored to a public blockchain. Blockchain records are permanent and publicly visible; the hash and any content you choose to publish there cannot be deleted later.
4. Data Storage and Security
We use bcrypt password hashing, JWT session tokens, HTTPS, upload type/size restrictions, login rate limiting, and automated abuse detection. No system is perfectly secure; please use a unique password and keep it confidential.
5. Data Retention and Deletion
- Account data is kept while your account is active. You may edit or delete your own posts and comments at any time.
- If you delete your account, we delete or anonymize your personal data within a reasonable period, except: (a) records we must keep for legal, tax, or fraud-prevention reasons (e.g., payment records, kept as required by law); (b) content anchored to public blockchains, which is technically immutable; and (c) content you published publicly, which may remain visible in anonymized form unless you delete it first.
- Invoices and transaction records are retained as required by applicable accounting and tax law.
6. Your Rights and Choices
Depending on your jurisdiction (including GDPR/UK GDPR and U.S. state privacy laws such as CCPA/CPRA), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any right, contact us at the address below. We do not sell your personal information and do not share it for cross-context behavioral advertising.
7. Cookies and Local Storage
We use browser local storage for session tokens, language and view preferences, and interface state. We do not use third-party advertising cookies. Analytics, if any, are aggregate and not used to profile individuals for ads.
8. Children's Privacy
The Platform is not directed at children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data. Accounts require users to be at least 18. If you believe a minor has provided us data, contact us and we will delete it.
9. International Transfers
We are a U.S. company and our infrastructure is currently in Hong Kong. By using the Platform you understand that your data will be transferred to and processed in these locations, with safeguards described in this Policy.
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be announced on the Platform with an updated date above. Continued use after the effective date constitutes acceptance.