Privacy Policy
ALLYK Privacy Policy
Last updated: September 27, 2026
ALLYK is operated by MAYAYAI. This policy explains how we handle information submitted through the ALLYK website, account setup, workspace, connector, marketplace, and support flows. It is written for transparency and does not replace a customer contract or a data processing agreement where one is required.
Roles and Scope
MAYAYAI generally acts as the controller for website, account, trial, billing-contact, security, and product-administration information. When a business customer asks ALLYK to process its workspace content or a connected service on that customer's instructions, the customer normally decides the purpose and means of that processing and MAYAYAI may act as a processor or service provider/contractor. The applicable role depends on the contract, feature, and data flow.
Information We Collect
Depending on the feature, ALLYK may process account and contact information such as name, work email, normalized phone number, company, role, region, sign-in method, workspace membership, plan, and billing status. It may also process customer workspace content such as chats, projects, attachments, feedback, connector configuration metadata, action approvals, action outcomes, device metadata, and operational audit events.
Camera capture is optional. A live camera preview is processed locally in the browser only after an affirmative choice. ALLYK does not passively record the preview or upload preview frames. A still becomes workspace content only after you explicitly capture it and press Send; normal attachment, model-provider, retention, and privacy-request controls then apply.
Usage And Billing
To display plan allowances and operate the service, ALLYK records minimized usage metadata for completed logical product outcomes: workspace, time, client surface, outcome type, interaction units, and, for a BYOK request, the selected provider, model, and provider-reported numeric token totals. ALLYK does not place prompts, model responses, files, credentials, raw connector payloads, page loads, or failed attempts in this usage ledger. BYOK token totals are informational only; the selected model provider charges for BYOK usage directly.
ALLYK uses this metadata to show usage, apply the selected plan's allowance, prevent abuse, support security and billing inquiries, and maintain an audit trail. It does not sell this information or use it for cross-context behavioral advertising. Current plans do not automatically charge an overage; a future change to that policy will be disclosed before it takes effect.
Restricted Information
Do not submit passwords, API keys, payment-card numbers, government identifiers, medical records, bank-account secrets, regulated records, or confidential third-party data unless you have a separately reviewed agreement and a feature explicitly approved for that category. Do not paste provider service-role keys, gateway secrets, or production credentials into a chat.
Information Use
We use information to create and secure accounts, prevent repeated trial abuse, provide workspace access, maintain project context, prepare approval-gated automation, respond to support and privacy requests, process subscription entitlements, protect the service, and maintain auditability. ALLYK is not designed to make a legal or similarly significant decision about a person without a responsible human determination.
Approvals And Services
ALLYK may read connected-service context, draft a proposed action, and record a human decision. Write actions require the configured connector policy and approval boundary. A connected provider receives only the data and scope authorized for that connection and action. Users can revoke a supported connection; ALLYK records the revocation as an operational event.
Linked Clients
When you choose to link an installed ALLYK client, we record a human label, client type, version, platform, link time, last-use time, and the notice version shown at linking. ALLYK shows the raw linking key once and stores only a cryptographic hash. Linking a client does not install software, scan a device, share workspace content, grant connector access, or allow native edits.
Cross-install availability is optional and off by default. When enabled, only the linked client's label, client type, and last-use time can be shown to your other linked ALLYK clients in the same workspace. It never shares a raw key, device identifier, file, chat, local path, location, or workspace content. You can turn availability off, rename the label, or revoke the client in Devices at any time; revocation immediately ends that client's access.
Diagnostics Plugins
When you connect ALLYK Diagnostics from a supported AI application, that host can send the context or scores you select, read active task titles and saved Diagnostics reviews, and save a review when you request it and grant write access. The host receives those inputs and results and may retain them under its own policies. This connection does not provide your full chat history, model keys or ALLYK's private calculation code.
Access is bound to your ALLYK account and workspace, expires after one hour, and can be revoked in Plugin connections. Revocation stops future access; it cannot erase copies already received by the host. We store hashed connection credentials, scope and expiry information, request-limit counters and minimized connection/review events. Preview content is not saved by this feature. Reviews you choose to save become task content under the same workspace rights and retention controls. Connecting does not authorize model training or execution of recommendations.
BYOK LLM Use
ALLYK offers deterministic assessment and bring-your-own-key model workflows. A customer-selected model provider receives the context submitted for an authorized provider-backed request. The provider's own terms, region, retention, and model-data controls apply. A one-request key is request-scoped. Where saved models are enabled, a key you deliberately save is encrypted server-side and can be managed or revoked in LLM settings. Keys must not be stored in chat history, browser SQLite, settings events or product audit logs. Use dedicated model-key controls rather than ordinary chat messages.
Optional Product Improvement
Helping improve ALLYK is optional and off by default. A user may enable a narrowly scoped preference in ALLYK Privacy settings for de-identified product feedback and minimized operational signals to be considered in a human-reviewed product-improvement process. That preference does not permit use of raw chats, file or attachment contents, credentials, BYOK API keys, connector payloads, health or other regulated data, public case studies, research evidence, or model training. A user can withdraw the preference at any time; withdrawal applies to future improvement processing.
Learning And Research
Workspace content, feedback, and operational events do not become research evidence, training data, or a public case study automatically. Research use requires separate consent, anonymization, classification, claim-ledger mapping, evidence-strength review, and human approval. The optional product-improvement preference above is not research consent. Withdrawing research consent can be requested from the Privacy section inside ALLYK.
Sharing And Providers
We do not sell personal information or share it for cross-context behavioral advertising. We use selected service providers for infrastructure, database/authentication, payment processing, email, connected productivity services, and security operations. Provider use is limited to the configured service and subject to the applicable contract and provider terms. We do not disclose payment-card details because payment providers process those details in their own checkout environment.
Retention And Deletion
ALLYK uses archive-first handling for workspace records that may be needed for security, billing, audit, synchronization, or dispute handling. Archived records are excluded from active product analysis. Account deletion revokes access and archives active workspace records; it does not automatically override legally required, security, billing, or contractual retention. A requested deletion is evaluated through the authenticated privacy-request workflow before any irreversible action is taken.
Offline Browser Storage
When offline context is available, ALLYK may keep a browser-origin-scoped SQLite copy of the current workspace's messages, attachment bytes, and synchronization queue on the device. Use Settings to clear that local copy, or clear ALLYK site data in the browser. Clearing the local copy does not erase the cloud workspace and does not replace an authenticated privacy request.
Your Privacy Choices
An authenticated user can open ALLYK Privacy to turn the optional product-improvement preference on or off, download the account summary currently loaded in the app, or submit an access, export, correction, deletion, processing-restriction, research-consent withdrawal, or opt-out request. We verify the requester and record the review outcome. You may also email mail@mayayai.com. Where a request concerns a customer workspace, we may need to involve the customer's workspace administrator or act under the customer's instructions.
Security
ALLYK uses scoped authentication, workspace checks, private storage paths, approval policies, audit records, and secret-redaction boundaries. No system is risk-free. Before a feature is represented as generally available for sensitive or regulated data, it must pass the product's privacy, security, vendor, and release-control gates. Read the Security & Trust page for the current assurance boundary.
International Processing
ALLYK and configured providers may process information in countries other than the user's location. Before enabling a provider or processing flow for a customer that requires international-transfer safeguards, MAYAYAI and the customer must review the applicable contract, location, and transfer mechanism.
Changes and Contact
We may update this policy as ALLYK changes. Material updates will carry a revised date. For privacy, security, or rights questions, contact mail@mayayai.com.