-
Does your solution process FERPA-related data?
On the Campus tier, Aletheia processes limited student-associated account data. FERPA data segmentation is built in: per-institution scoping (institution_id), a K-12/higher-ed discriminator, per-institution retention, and two-gate, audit-logged access for any individual student visibility.
Reference: Security Whitepaper
-
Does your solution process GDPR-related or PIPL-related data?
EU institutions may use Aletheia. A Data Processing Agreement with Standard Contractual Clauses is available. Data is stored in the US region (not the EEA); see INTL.
Reference: DPA
-
Does your solution process personal data regulated by state law(s) (e.g., CCPA)?
Aletheia processes personal data subject to US state laws such as the CCPA; the privacy policy covers these rights.
Reference: Privacy Policy
-
Does your solution process user-provided data that may contain regulated information?
User-submitted documents may contain regulated information. Aletheia processes them on-device, includes PII detection to warn users, and does not store documents on Lonia infrastructure.
Reference: Privacy Policy
-
Web Link to Product/Service Privacy Notice
Response: https://aletheia.lonia.ai/privacy
Aletheia privacy policy.
Reference: Privacy Policy
-
Have you had a personal data breach in the past three years that involved reporting to a governmental agency, notice to individuals (including voluntary notice), or notice to another organization or institution?*
Aletheia has had no reportable personal-data breach in the past three years.
-
Use this area to share information about your privacy practices that will assist those who are assessing your company data privacy program.*
Response: Aletheia's privacy program centers on data minimization: documents are processed on-device, only account identity, plan/billing status, and usage counts leave the device, there are no third-party trackers, user data is not sold, and user data is not used to train Aletheia's AI models.
Reference: Privacy Policy
-
Have you had any violations of your internal privacy policies or violations of applicable privacy law in the past 36 months?
Aletheia has had no known violations of its privacy policy or applicable privacy law in the past 36 months.
-
Do you have a dedicated data privacy staff or office?
Privacy is owned by a designated privacy contact (privacy@lonia.ai, with legal@lonia.ai for legal matters) rather than a separate privacy office, and privacy-by-design is built into the architecture.
Reference: Privacy Policy
-
If you have completed a SOC 2 audit, does it include the Privacy Trust Service Principle?
Aletheia has not completed a SOC 2 audit, so the Privacy Trust Services Principle does not apply.
-
Do you conform with a specific industry-standard privacy framework (e.g., NIST Privacy Framework, GDPR, ISO 27701)?
Aletheia applies privacy-by-design and is GDPR-aligned (DPA with SCCs available). It holds no ISO 27701 or equivalent privacy certification.
Reference: DPA
-
Does your employee onboarding and offboarding policy include training of employees on information security and data privacy?
Security and privacy responsibilities are communicated to team members; a formally documented training component within onboarding/offboarding is maturing.
-
Do you have contractual agreements with third parties that require them to maintain standards and to comply with all regulatory requirements?*
Sub-processor contracts (DPAs, with SCCs where relevant) require them to maintain appropriate standards and meet regulatory requirements.
Reference: Sub-processors
-
Do you perform privacy impact assessments of third parties that collect, process, or have access to personal data to ensure they meet industry and regulatory standards and to mitigate harmful, unethical, or discriminatory impacts on data subjects?
Sub-processors are established providers with published security and privacy programs and executed DPAs. A formally documented third-party privacy impact assessment process is maturing.
Reference: Sub-processors
-
Does your change management process include privacy review and approval?
Changes affecting personal data are reviewed against privacy-by-design before release; a formally documented privacy sign-off step is maturing.
-
Do you have policy and procedure, currently implemented, guiding how privacy risks are mitigated until they can be resolved?
Where a privacy risk cannot be resolved immediately, exposure is reduced through the minimal data footprint and on-device processing. A documented interim-mitigation procedure is maturing.
-
Do you collect, process, or store demographic information?*
Aletheia does not collect, process, or store demographic information.
Reference: Privacy Policy
-
Do you capture or create genetic, biometric, or behaviometric information (e.g., facial recognition or fingerprints)?*
Aletheia does not capture or create genetic, biometric, or behaviometric information. There is no facial recognition or fingerprinting. (The on-device model describes images the user chooses to submit; that is user content processed locally, not biometric capture by Aletheia.)
Reference: Privacy Policy
-
Do you combine institutional data (including "de-identified," "anonymized," or otherwise masked data) with personal data from any other sources?*
Aletheia does not combine institutional data with personal data from other sources.
Reference: Privacy Policy
-
Is institutional data coming into or going out of the United States at any point during collection, processing, storage, or archiving?
Institutional account data is stored in the US region and is not routed outside the United States by Aletheia. (On BYOK, the user's own provider call goes wherever the user's chosen provider operates, under the user's own contract.)
Reference: Sub-processors
-
Do you capture device information (e.g., IP address, MAC address)?
Network-level IP is processed transiently at the Cloudflare edge for routing and abuse prevention. Aletheia does not capture MAC addresses or build device fingerprints, and uses no third-party trackers.
Reference: Cookies
-
Does any part of this service/project involve a web/app tracking component (e.g., use of web-tracking pixels, cookies)?
Aletheia uses no third-party analytics, tracking pixels, session replay, or advertising cookies.
Reference: Cookies
-
Does your staff (or a third party) have access to institutional data (e.g., financial, PHI, or other sensitive information) through any means?
Staff do not access institutional user documents (processed on-device). Access to limited account data is least-privilege and audit-logged.
Reference: Security Whitepaper
-
Will you handle personal data in a manner compliant with all relevant laws, regulations, and applicable institution policies?
Aletheia commits to handling personal data in compliance with applicable laws, regulations, and institutional policies.
Reference: Privacy Policy
-
Do you have a documented privacy management process?
Privacy commitments are documented in the privacy policy and the DPA, and privacy-by-design governs the architecture.
Reference: Privacy Policy
-
Are privacy principles designed into the product lifecycle (i.e., privacy-by-design)?
Privacy-by-design is core: on-device processing, data minimization, and no third-party trackers.
Reference: Privacy Policy
-
Will you comply with applicable breach notification laws?
Aletheia commits to applicable breach-notification laws (DPA, 72 hours).
Reference: DPA
-
Will you comply with the institution's policies regarding user privacy and data protection?
Aletheia complies with the institution's user-privacy and data-protection policies.
Reference: Privacy Policy
-
Is your company subject to the laws and regulations of the institution's geographic region?
Aletheia is subject to the applicable laws and regulations of the institution's region for the services it provides.
Reference: DPA
-
Do you have a privacy awareness/training program?*
A formal, tracked privacy-awareness program is being established; privacy-by-design principles are applied today.
-
Is privacy awareness training mandatory for all employees?
Mandatory, tracked privacy training is being formalized as the team grows.
-
Is AI privacy and ethics awareness/training required for all employees who work with AI?
Dedicated AI privacy-and-ethics training for AI staff is being formalized; the applied AI principles (no training on user data, human-in-the-loop) already reflect these values.
-
Do you have any decision-making processes that are completely automated (i.e., there is no human involvement)?
Aletheia makes no fully automated decisions about individuals. AI output is always presented to the user for review.
Reference: Security Whitepaper
-
Do you have a documented process for managing automated processing, including validations, monitoring, and data subject requests?
AI is assistive, not decisional, so automated-decision governance is limited in scope; the privacy policy and DPA cover data-subject requests. Documentation is maturing alongside the AI transparency statement.
Reference: DPA
-
Do you have a documented policy for sharing information with law enforcement?
Aletheia holds minimal data and discloses only under valid legal process. A formally documented law-enforcement request policy is maturing.
Reference: Privacy Policy
-
Do you share any institutional data with law enforcement without a valid warrant or subpoena?*
Aletheia does not share institutional data with law enforcement without a valid warrant or subpoena.
Reference: Privacy Policy
-
Does your incident response team include a privacy analyst/officer?
The designated privacy contact participates in incident handling. A separately staffed privacy-analyst role is planned as the team grows.
-
Will data be collected from or processed in or stored in the European Economic Area (EEA)?
Data is collected, processed, and stored in a single US region, not the EEA.
Reference: Sub-processors
-
Do you have a data protection officer (DPO)?
Privacy is owned by a designated privacy contact (privacy@lonia.ai). A formally appointed GDPR Article 37 Data Protection Officer is not currently mandated at Aletheia's scale; one will be appointed if the criteria are triggered.
Reference: Privacy Policy
-
Will you sign appropriate GDPR Standard Contractual Clauses (SCCs) with the institution?
Aletheia will sign GDPR Standard Contractual Clauses; they are incorporated in the DPA (Annex D).
Reference: DPA
-
Will data be collected from or processed in or stored in China?
Data is not collected, processed, or stored in China.
Reference: Sub-processors
-
Do you comply with PIPL security, privacy, and data localization requirements?
Aletheia does not target China or store data there, so PIPL localization requirements do not apply. This would be reassessed if a China deployment were contemplated.
-
Have you performed a Data Privacy Impact Assessment for the solution/project?
Privacy-by-design and a minimal data footprint reduce privacy risk; the DPA documents processing details. A formally documented Data Privacy Impact Assessment is maturing and available to institutions on request.
Reference: DPA
-
Do you provide an end-user privacy notice about privacy policies and procedures that identify the purpose(s) for which personal information is collected, used, retained, and disclosed?
Aletheia provides an end-user privacy notice describing why personal information is collected, used, retained, and disclosed.
Reference: Privacy Policy
-
Do you describe the choices available to the individual and obtain implicit or explicit consent with respect to the collection, use, and disclosure of personal information?
The privacy policy describes user choices and the consent basis for collection, use, and disclosure.
Reference: Privacy Policy
-
Do you collect personal information only for the purpose(s) identified in the agreement with an institution or, if there is none, the purpose(s) identified in the privacy notice?
Personal information is collected only for the purposes identified in the agreement or the privacy notice.
Reference: Privacy Policy
-
Do you have a documented list of personal data your service maintains?
Data categories are enumerated in the privacy policy, the Sub-processor list, and DPA Annex A.
Reference: Privacy Policy
-
Do you retain personal information for only as long as necessary to fulfill the stated purpose(s) or as required by law or regulation and thereafter appropriately dispose of such information?
Personal information is retained only as long as necessary; per-institution retention defaults to 365 days with scheduled deletion.
Reference: Security Whitepaper
-
Do you provide individuals with access to their personal information for review and update (i.e., data subject rights)?
Individuals can access and update their personal information; data-subject rights are supported through the DPA and privacy policy.
Reference: DPA
-
Do you disclose personal information to third parties only for the purpose(s) identified in the privacy notice or with the implicit or explicit consent of the individual?
Personal information is disclosed to third parties only for the purposes in the privacy notice or with consent.
Reference: Privacy Policy
-
Do you protect personal information against unauthorized access (both physical and logical)?
Personal information is protected against unauthorized access through OAuth-only identity, RLS on every table, and encryption at rest and in transit.
Reference: Security Whitepaper
-
Do you maintain accurate, complete, and relevant personal information for the purposes identified in the privacy notice?
Account identity is refreshed from the institution's identity provider, keeping it accurate and current.
-
Do you have procedures to address privacy-related noncompliance complaints and disputes?
Privacy complaints and disputes can be raised with privacy@lonia.ai and are handled through a documented response path.
Reference: Privacy Policy
-
Do you "anonymize," "de-identify," or otherwise mask personal data?
Institutional reporting is aggregate-only by default; individual student visibility requires the two-gate, audit-logged FERPA-privileged path.
Reference: Security Whitepaper
-
Do you or your subprocessors use or disclose "anonymized," "de-identified," or otherwise masked data for any purpose other than those identified in the agreement with an institution (e.g., sharing with ad networks or data brokers, marketing, creation of profiles, analytics unrelated to services provided to institution)?
Aletheia does not use or disclose de-identified or masked data for advertising, data brokerage, marketing, profiling, or unrelated analytics. User data is not sold.
Reference: Privacy Policy
-
Do you certify stop-processing requests, including any data that is processed by a third party on your behalf?
Stop-processing requests are honored, including for data processed by sub-processors on Aletheia's behalf.
Reference: DPA
-
Do you have a process to review code for ethical considerations?
Code review considers accessibility and privacy impact as part of the development process; a separately documented ethics-review checklist is maturing.
-
Does your service use AI for the processing of institutional data?
Aletheia does not apply AI to institutional account data. AI processes the user's own document content that the user submits, on-device or via the user's BYOK provider; it does not process institutional records, rosters, or admin data.
Reference: Security Whitepaper
-
Is any institutional data retained in AI processing?*
No institutional data is retained in AI processing. On-device inference is transient and local; BYOK calls are governed by the user's provider contract and are not retained by Lonia.
Reference: Security Whitepaper
-
Do you have agreements in place with third parties or subprocessors regarding the protection of customer data and use of AI?*
Data-flow sub-processors are covered by DPAs. On Professional BYOK, the AI provider is reached under the user's own contract and is not a Lonia sub-processor. On Enterprise BYOK, the institution-selected provider is invoked by Lonia's Enterprise Worker and is engaged as a Lonia sub-processor for that path; see /legal/subprocessors.
Reference: Sub-processors
-
Will institutional data be processed through a third party or subprocessor that also uses AI?
Institutional data is not processed through a sub-processor that applies AI to it.
Reference: Sub-processors
-
Is AI processing limited to fully licensed commercial enterprise AI services?
Cloud AI is limited to licensed commercial providers reached via the user's BYOK key; the base tier uses a licensed on-device model.
Reference: Security Whitepaper
-
Will institutional data be used or processed by any shared AI services?
Institutional data is not used or processed by shared AI services.
Reference: Security Whitepaper
-
Do you have safeguards in place to protect institutional data and data privacy from unintended AI queries or processing?
On-device processing by default, PII detection, and user control over what is sent protect institutional data from unintended AI processing.
Reference: Privacy Policy
-
Do you provide choice to the user to opt out of AI use?
Users can opt out of cloud AI: the base tier runs on-device without any cloud AI, and BYOK cloud AI is inactive unless the user connects a key.
Reference: Security Whitepaper