Aletheiaby Lonia AI

Privacy

Your documents stay on your device.

Aletheia is built so that almost no data ever leaves your browser. This policy explains what is processed locally, what is sent off your device only with your explicit choice, the account data we hold, and the rights you have over it.

Last updated: July 14, 2026

On-device processing

The most important fact about Aletheia's privacy posture is this: the documents and web pages you process are handled in your browser. Uploaded files never leave your device. When you scan a URL, the cors-proxy described below fetches the content on your behalf and immediately hands it back to your browser without storing it. Your content is not sent to a third party, and the only opt-in cloud path is the single image you may choose to send for AI description.

The following all happen on your device, with no network call:

  • Parsing PDFs, DOCX files, and other documents.
  • Running OCR on scanned image-only PDFs.
  • Generating on-device image descriptions with the built-in vision model.
  • Restructuring page content into a properly headed, navigable form.
  • Identifying form fields and adding labels.
  • Writing the resulting accessible version to your local library.

URL scanning

When you scan a web page or document by pasting its URL, Aletheia uses a fetch service called the cors-proxy to retrieve the content on your behalf. The proxy fetches the URL you provided, returns the content to your browser, and then forgets about the request. The proxy does not store the URL, the page content, or any identifying information beyond the technical metadata needed to enforce the protections described below.

The proxy applies the following protections to keep the service safe for everyone:

  • Connections to private or internal network addresses are blocked, so the proxy cannot be used to scan resources that are not on the public internet.
  • Rate limits cap how many scans can run from one device or account in a given period.
  • The platform-wide abuse prevention list described below also applies to scanning.
  • Only HTML pages, PDFs, Word documents, and common image formats are processed; other file types are rejected before download.
  • Responses are capped at five megabytes; larger files must be downloaded by you and uploaded through the file upload path instead.

The proxy does not write request URLs, response bodies, or any scanned content to logs. Operational metrics like total request counts are aggregate only and do not associate URLs with users.

You are responsible for the URLs you choose to scan. Use the scanning feature only on content you have the right to access, including compliance with the terms of service, copyright policies, and robots.txt directives of the site you are scanning.

AI image description data handling

Image description has three modes, and the default everywhere is on-device:

  • On-device, the default. Descriptions are generated by a vision model running in your browser. No image and no page content leaves the device. This is the only AI path on the Free, Student, and Campus tiers.
  • Enhanced AI, opt-in (Personal and Family). You can choose to send a single image to Lonia-provided cloud AI, routed through OpenRouter, for a higher-detail description. It is off until you turn it on. Your request is authenticated with your sign-in session, the image you select and a short instruction are sent to the AI provider in a single request, and the image is discarded as soon as the description is returned. We do not log, retain, or train on images you submit.
  • Bring your own key, Professional. You connect your own Anthropic, OpenAI, or OpenRouter key. Your browser calls the provider you configured directly: an image you choose to describe goes straight from your device to that provider, under your own account and terms, and is discarded once the description is returned. Your key does not pass through Lonia and is never sent to Lonia. It is stored encrypted in your browser using AES-GCM-256 with a non-extractable key, and it is used only to make the request from your browser. On-device fallback applies when no key is set.
  • Institution-managed key, Enterprise. Your organization's administrator enrolls one institutional API key with Lonia's Enterprise Worker once, over TLS. The Worker envelope-encrypts the key with a master-key wrapping mechanism and stores it encrypted at rest; it is never returned to any client. When a seat opts to describe an image with Enhanced AI, the request goes from the seat's browser to Lonia's Enterprise Worker, which decrypts the institutional key in memory only for that request, calls the provider on the institution's behalf, and discards the image once the description is returned. Individual seats never see or handle the key, and every seat's Enhanced AI usage bills to the institution's single provider account. On-device fallback applies when no key is configured.

Account data we collect

Aletheia uses Google or Microsoft sign-in for every tier, including Free. We hold the minimum needed to run your account:

  • Email address from your OAuth provider, for sign-in and product communication.
  • Plan tier and renewal status.
  • Usage logs needed to apply your plan, such as monthly page counts and Enhanced AI counts where applicable.
  • For the Student tier, verification that your email uses a .edu domain. We do not record which institution.

We do not send marketing email without your explicit consent. The email address above is used only for account communication, such as billing, security notices, and account changes, together with any newsletter you choose to opt into. You can unsubscribe from optional communication at any time.

Billing data

Payments are processed by Stripe. Stripe handles your card details; Aletheia does not receive or store full card numbers. We receive the limited billing status Stripe exposes, such as whether a subscription is active, and a payment card fingerprint used for the abuse prevention described below.

How your data is shared

We do not sell your data and do not share it with advertisers. Data is shared only with the service providers needed to operate Aletheia:

  • Stripe for payment processing and subscription billing.
  • Supabase for authentication and account data storage.
  • OpenRouter only when you opt in to Enhanced AI, to route the single image you chose for a description.

International data transfers

Some of the services that run Aletheia are hosted in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, the account data we hold and, where you have turned it on, the single image you send for an Enhanced AI description may be processed in the United States. Where that happens, the transfer is made under an appropriate safeguard, including the European Commission Standard Contractual Clauses where they apply.

We document these transfers in full so a reviewer can see exactly which path is covered and how the risk is handled:

  • The Data Protection Impact Assessment describes each processing path (on-device, Enhanced AI, and bring-your-own-key), the risks to your rights, and the measures that mitigate them.
  • The scoped Standard Contractual Clauses cover the Lonia-mediated Enhanced AI image path for the Personal and Family tiers, which routes to a United States hosted provider.
  • The Transfer Impact Assessment evaluates that transfer against United States surveillance law and sets out the supplementary measures applied.

Our on-device processing, which is the default everywhere, involves no cross-border transfer at all, because it happens entirely in your browser. Institutional deployments are covered by the transfer terms in the Data Processing Agreement. Our primary account data store is hosted in the United States; a migration to an EU region is under consideration but has not been scheduled.

Data retention

Account data is retained while your account is active and for a limited period afterward as needed for legal, tax, and accounting obligations. Usage logs are retained only as long as needed to enforce plan limits and support the service. Documents are not retained by us at all, because they live in your local library on your device.

Abuse Prevention Data

To prevent abuse of our services, Lonia AI maintains a platform-wide restricted-actors list containing hashed identifiers. These identifiers are SHA-256 hashes of normalized email addresses, payment card fingerprints provided by Stripe, and optionally other identifiers used to detect repeated abuse patterns.

Restrictions apply to all Lonia AI services, including Aletheia. A restriction added in connection with one service may prevent account creation or payment on any other Lonia AI service.

This data is retained under legitimate business interest for as long as the restriction remains active. Hashed identifiers cannot be reversed to recover original values.

Restricted actors may submit a one-time appeal by writing to privacy@lonia.ai. If the restriction is lifted, you will receive confirmation at the email address you provide in your appeal, and you will be able to sign up or sign in as normal.

No analytics, no tracking, no telemetry

The marketing site and the Aletheia product do not run third-party analytics, advertising trackers, session replay tools, or telemetry packages.

Your rights under GDPR and CCPA

Because most processing is local, the data we hold about you is small. Where we do hold account data, you have the rights you would expect under the GDPR and the CCPA:

  • The right to know what data we hold about you.
  • The right to correct inaccurate account data.
  • The right to deletion. We delete the account-level data we hold; there is nothing to delete on the document side because we never had your documents.
  • The right to portability. You can export your local library at any time from the product.
  • The right to object to processing.

To exercise any of these rights, email privacy@lonia.ai. Note that records retained for abuse prevention may be kept under legitimate business interest as permitted by law, including GDPR Article 17(3)(b).

Cookies

The marketing site uses no tracking cookies. The product uses only first-party browser storage strictly necessary for it to function, such as your local library and your preferences. It does not use cookies for cross-site tracking. The full posture, including a runtime audit of the marketing site and how strictly necessary cookies are treated under the ePrivacy Directive, is set out in the Cookies and tracking statement.

Children

Aletheia is not directed at children under 13, and we do not knowingly collect personal information from children under 13. The Student tier is intended for verified higher-education students.

Institutional Deployment

The sections above describe how Aletheia handles data for individual-tier users, where you are the person whose account it is. This section describes the additional data handling that applies when Aletheia is deployed by an institution under a Campus or Enterprise license. If you use Aletheia through a seat assigned by your school, employer, or another organization, both this section and the sections above apply to you.

Who controls your data in an institutional deployment

In an institutional deployment, the institution is the Controller of the personal data processed for its seats, and Lonia AI is the Processor acting on the institution's documented instructions. The institution decides why and how the data is processed; Lonia processes it only to provide Aletheia. The terms of that relationship are set out in a Data Processing Agreement between the institution and Lonia. You can read the template at the Data Processing Agreement page.

Data flow in an institutional deployment

An institutional deployment involves three kinds of data flow beyond the individual-tier flows above:

  • Administrator invitations. An institution designates administrators, who are identified by name, email address, and administrator role. Administrators manage seats and licensing, not the content that individual users process.
  • Student and employee usage. Each assigned user signs in with Google or Microsoft OAuth and processes their own documents on their own device, exactly as an individual-tier user does. The documents themselves stay on the user's device and are not stored by Lonia.
  • Aggregate metrics. The administrator dashboard shows aggregate usage, such as seat counts and total processing activity, for licensing and reporting. It does not show the content individual users process.

FERPA data segmentation

For education deployments, Aletheia is built with FERPA data segmentation. Student-scoped data carries an institution identifier so that an administrator's reach is bounded to their own institution, and the deployment is classified as K-12 or higher education. There is no central store of student document content for an administrator to browse; documents remain on each student's device. This architecture is described further in the Security Whitepaper.

Healthcare Enterprise and PII detection

For healthcare-sector Enterprise deployments, Aletheia includes architectural detection of personally identifiable information as part of how it handles content on the device. This is a detection feature built into the product. It is not a HIPAA compliance certification, and Lonia does not claim HIPAA compliance certification for Aletheia. The feature helps a healthcare organization handle content carefully; it does not, by itself, make a deployment HIPAA compliant.

Data retention in an institutional deployment

Data retention is configurable per institution, with a default of 365 days. A scheduled job deletes student-scoped data once the institution's retention window has passed. The institution sets the retention period that fits its own obligations.

What an institutional administrator can and cannot see

By default, an institutional administrator sees aggregate information only: seat counts and total usage, not any individual user's documents or the detail of what an individual processed. Individual, student-scoped visibility is available only through a separate FERPA-privileged path that is not granted by default. That path is protected by two gates, a server-side check in the database and a matching client-side condition, and every use of it is written to an append-only audit log that cannot be edited or deleted. In other words, an administrator cannot quietly look at an individual student's activity; the privileged path is restricted and every use is recorded.

Sub-processors and further documents for institutions

The third parties that process data on Lonia's behalf are listed in the standalone Sub-processor List, a versioned page with an update-on-change and advance-notification policy, and are also summarised in the Sub-processors section of the Security Whitepaper. Institutions can also review the Data Processing Agreement template and the Security Whitepaper as part of a procurement review.

Institutional contact

Institutional privacy and data protection questions, and requests to execute a Data Processing Agreement, can be sent to legal@lonia.ai.

Changes to this policy

If we update this policy, we will update the "last updated" date above. Material changes will be communicated to anyone with an active account.

Contact and governing law

Questions, requests, or concerns about privacy can be sent to privacy@lonia.ai.

This policy is governed by the laws of the State of New Jersey, without regard to conflict of laws principles.