Skip to content

ALYT Developer Platform Privacy Policy

In force from 2026-09-04, approved by Fizzify Inc. Adapted from the GitHub General Privacy Statement (github/site-policy, https://github.com/github/site-policy/blob/main/Policies/privacy-policies/github-general-privacy-statement.md) under CC0 1.0 Universal. Version: [0.1] Effective date: 2026-09-04

This policy explains what personal data Fizzify Inc. (“ALYT”, “we”) collects when you use the ALYT Developer Platform at developers.alyt.com, why, and what rights you have. It covers developer accounts only. Data handled by the ALYT home platform on behalf of households is covered by the ALYT product privacy policy, published with the product.

Fizzify Inc., registered in Wyoming, USA, is the data controller for the Developer Platform. Contact: info@fizzify.co.

We collect only what the Platform needs to work, to be secure, and to be accountable.

  1. Account data: your email address, your name, and, if you register for an organisation, its name.
  2. Developer type, self-declared: individual, brand or integrator.
  3. Submissions: the connector descriptors, code and text you send for review, and your support contact details for a PUBLIC connector.
  4. Messages you send us, for example a request for AI access or a reply to a review.
  1. IP address and user agent of requests to the portal and the API.
  2. Request traces: for every API request, the short public identifier of the API key used, the endpoint, the time, the result code and the latency. Traces never contain the key secret.
  3. Usage counters per key: API calls, messages and, where enabled, AI tokens or seconds. These drive quotas and would drive any future billing.
  4. Audit log: who did what and when on your account. Key issued, key revoked, submission sent, approval granted or refused, sign-in.
  5. Essential cookies that keep you signed in and remember your settings. We set no advertising or analytics cookies.

We do not collect payment details today, because there is no billing. We do not collect demographic data. We do not read household device data through your developer account.

PurposeData usedLawful basis (GDPR)
Operate your account and the sandboxaccount data, key identifierscontract
Enforce quotas and rate limitsusage counters, tracescontract, legitimate interest
Detect abuse and secure the platformIP address, traces, audit loglegitimate interest
Review and publish connectorssubmissions, support contactcontract
Answer your requestsmessages, account datacontract
Meet legal obligations and resolve disputesaudit log, account datalegal obligation
Send service notices such as key revocation or terms changesemail addresscontract, legal obligation

We do not use your personal data to train AI models. We do not send marketing email unless you opt in.

  1. Processors that act on our instructions:
    1. an email delivery provider, to send sign-in codes, review decisions and service notices (our own mail server, run by Fizzify Inc.; no third party handles them);
    2. Cloudflare, Inc., whose Turnstile service protects the signup and sign-in forms from automated abuse. Turnstile receives your IP address and browser signals to decide whether a request is automated.
  2. Households and operators: when a connector you publish as PUBLIC is installed, the connector page shows your developer name, developer type, verified status and support contact.
  3. Authorities: we may disclose data to law enforcement, regulators or courts when the law requires it or to protect the safety of ALYT and its users. We will tell you unless the law forbids it.
  4. A successor: if Fizzify Inc. sells or transfers the Platform, your data may transfer with it under this policy.

We do not sell personal data. We do not share it for cross-context behavioural advertising.

DataRetention
Account datawhile the account is open, then deleted within 90 days
Request traces1 year from the request
Usage countersaggregated monthly; per-request detail follows the trace retention
Audit logindefinitely, because it is the record of who issued, revoked, submitted and approved
Submissionswhile the connector exists; a PUBLIC connector’s history is kept for as long as any installation may depend on it
Support messages2 years

Where the law requires a shorter or longer period, the law wins.

We protect personal data with access controls, encryption in transit, hashed storage of key secrets, and audit logging. No system is perfectly secure. If a breach affects your data, we will tell you without undue delay and within any legally required period.

The Platform is operated from the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the United States. We rely on the European Commission’s standard contractual clauses for such transfers. [Fizzify Inc. is not certified under the EU-U.S. Data Privacy Framework; counsel to confirm the transfer mechanism before publication.]

Depending on where you live, you may have the right to:

  1. know what personal data we hold about you and receive a copy;
  2. correct inaccurate data;
  3. have your data deleted, subject to the retention we must keep by law or for the audit log;
  4. restrict or object to processing based on legitimate interest;
  5. receive your data in a portable, machine-readable format;
  6. withdraw consent where processing is based on consent;
  7. not be discriminated against for exercising these rights.

To exercise a right, email info@fizzify.co from your account address. We may ask you to verify your identity. We respond within 30 days, or within 45 days where California law applies, and will tell you if we need longer.

You may complain to your supervisory authority. In the EEA, contacts are listed by the European Data Protection Board. In the UK, the Information Commissioner’s Office. In California, the California Privacy Protection Agency.

  1. Categories collected in the last 12 months: identifiers (email, name, IP address), professional information (organisation, developer type), and internet activity (request traces, usage counters, audit events).
  2. Sources: you, and your use of the Platform.
  3. Purposes: as described in section 3.
  4. Disclosed for a business purpose to: the processors in section 4.
  5. We do not sell or share personal information as defined by the CCPA, and have not in the last 12 months. We honour Global Privacy Control signals.
  6. Requests may be made twice in a 12-month period free of charge. An authorised agent may act for you with your signed permission.

The Platform is for developers aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe we have, tell us and we will delete it.

We may revise this policy. We will give at least 30 days’ notice of material changes by email or a notice on the Platform. Every version is kept in the platform repository with its effective date.

Fizzify Inc. 300 N Gould St STE N, Sheridan, WY 82801, USA info@fizzify.co

Last updated