Your data works for you, then leaves.
Alleo is built on a simple rule: we don't store your personal data — we borrow it. What flows from your connected apps is used for the task in front of it and discarded when the task ends. Nothing you give Alleo is ever used to train AI models.
The life of your data
When you ask Alleo to do something, here is the complete journey your information takes.
Alleo reads only what the task needs from your connected apps, over OAuth, at the moment it needs it.
The work happens inside an isolated sandbox created for this one run. No other user, task, or system can see in.
The sandbox and everything in it — your emails, events, and documents — is destroyed when the task completes.
Only what you'd expect an assistant to keep: the deliverables you asked for, your conversations with Alleo, and a small derived memory — patterns, preferences, and facts like “prefers morning meetings” — never the raw emails, events, or files they were learned from. You can view and delete every memory at any time.
Data privacy
Do you use customer data to train AI models?
No. Never. We do not train models on your data, and no third party does either. All AI inference runs on Microsoft Azure under agreements that prohibit retention and training on customer data.
Do you store my emails, calendar, or documents?
No. Data from your connected apps is transient: Alleo fetches what a task needs, works with it inside that task's isolated run, and discards it when the run ends. We don't sync your inbox into our databases, and we don't build a copy of your accounts on our side.
What persists is deliberately small: the files and reports Alleo produces for you, your conversation history with Alleo, and derived memory — the patterns, habits, and small facts Alleo learns so it gets better at working with you. Derived memory describes you; it does not contain your source data.
Which AI providers do you use?
One cloud. All inference — every model Alleo uses — runs inside Microsoft Azure in the United States. Your data is never sent to OpenAI, Anthropic, Google, or any other AI vendor's infrastructure, because we don't use their infrastructure.
Infrastructure & security
What do you actually store, and where?
- Conversations — your chats with Alleo, encrypted, kept to give the assistant context.
- Derived memory — preferences, patterns, and small facts. Viewable and deletable in settings at any time.
- Files and deliverables — what you upload and what Alleo produces for you, in Azure Blob Storage, accessible only through short-lived signed links.
- Account and usage data — settings, and restricted operational logs used for debugging and support.
Everything above lives on Microsoft Azure in the United States, encrypted in transit with TLS 1.2+ and at rest with AES-256.
How does Alleo access my apps?
Exclusively through OAuth 2.0, the same authorization standard your apps use with each other. Alleo requests the minimum scopes a connection needs, never sees or stores your passwords, and can never reach an account you haven't explicitly connected. You can disconnect any app instantly — from Alleo settings or from the provider's own security page — and sync stops immediately.
What security measures are in place?
- Encryption: TLS 1.2+ in transit, AES-256 at rest
- Isolated execution: every agent run in its own ephemeral sandbox
- Data isolation: strict per-user scoping on every query
- Secret isolation: credentials and tokens are never placed where an AI model can read them
- Infrastructure: Microsoft Azure physical, network, and platform security
Agent security
What happens when Alleo works on a task?
Every run executes inside a dedicated, isolated cloud sandbox created for that run and destroyed when it ends. Your data is never processed on shared, long-lived machines; one user's run can never see another's; and the sandbox's entire filesystem ceases to exist at completion. Only the deliverables you asked for survive it.
How do you protect against prompt injection?
- Content boundaries: untrusted content — emails, web pages, documents — is structurally separated from the instructions the AI follows.
- Secret isolation: connection tokens, credentials, and signed links never enter model context. The model cannot leak what it never sees.
- Clean surfaces: what Alleo shows you never includes internal identifiers, raw payloads, or system internals.
Security practices
How do you handle security incidents?
- Notification: affected customers notified without undue delay, as required by law and contract
- Containment: immediate isolation of affected systems
- Forensics: full analysis to determine scope and root cause
- Remediation: fixes and preventive measures, verified before close
- Cooperation: full cooperation with relevant authorities
How do I report a vulnerability?
Email dillon@alleo.ai with a clear description, reproduction steps, and potential impact. Please test only against accounts you own, avoid denial-of-service and social-engineering techniques, and give us a reasonable window to remediate before public disclosure. We review every good-faith report, and we will not pursue legal action against researchers who act in good faith under these rules.
Your data control
- Access or export: request a copy of the personal data associated with your account
- Delete: delete your account and everything in it, at any time
- Revoke: disconnect any app instantly; sync stops the moment you do
- Manage memory: view and delete anything Alleo has learned about you, item by item
To exercise any data right, contact dillon@alleo.ai. We respond to every request within 30 days.
Deletion timeline
| When | What happens |
|---|---|
| Immediate | Account access revoked, app connections disconnected, all activity stopped |
| Within 24 hours | Hard delete from production systems — conversations, memory, files |
| Within 7 days | Backups destroyed |
Records we are legally required to keep, such as billing history, may be retained longer.
Subprocessors
Alleo uses the following service providers, each bound by data processing agreements and contractually obligated to maintain appropriate security measures.
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting, storage, and all AI inference | United States |
| Auth0 (Okta) | Authentication | United States |
| Composio | App connection management (OAuth) | United States |
| E2B | Isolated agent sandboxes | United States |
| Zep | Memory infrastructure | United States |
| Tavily | Web search | United States |
| Stripe | Payment processing | United States |
| Twilio | SMS delivery | United States |
Have security questions?
We're happy to walk through our practices, data handling, or enterprise requirements in detail.