Privacy Policy

Effective 5 August 2026 · Last updated 5 August 2026

Please read this first. Aleph Developments is a one-person independent studio, and this document was drafted in-house rather than by a qualified lawyer. It is an honest and specific description of how the software actually works — every technical claim in it was checked against the source code — but it has not been reviewed by counsel in Myanmar or anywhere else. If you are relying on it for a business decision, or if you are subject to the GDPR, the CCPA or a similar regime, treat it as a starting point and get it reviewed.

1. Who we are

Aleph Developments is an independent software studio operated by Macrae Myint in Yangon, Myanmar. For the purposes of this policy, Aleph Developments is the data controller for the small amount of personal information described below, and can be reached at this email address.

2. What this policy covers

It covers this website (alephdevelopments.online), the Aleph Creative Studios hub at studios.alephdevelopments.online, and all six applications in the suite: Aleph Vector, Aleph Photo, Aleph Lumen, Aleph Motion, Aleph Pages and Aleph Draft. Any future Aleph Developments product answers to this same policy unless its own page says otherwise.

3. The short version

We do not upload your files. We do not set cookies. We do not run analytics of any kind. The only personal data we hold is the email address you give us if you create an account, and — once billing begins — whatever Stripe needs to take a payment. We do not sell, rent or share anything, and we do not use your work to train anything.

4. Your files never reach us

This is the most important thing on the page, and it is architectural rather than a promise about restraint. Every Aleph tool does its editing inside your browser. When you open an image, a PDF, a video or a project file, the page reads it from your disk into your own device's memory and works on it there, using your processor. When you export, the browser writes a new file to your downloads folder. At no point is the document transmitted to us.

The practical consequences are worth stating plainly, because they cut both ways. We cannot see your work, so we cannot leak it, be compelled to hand it over, or index it. We also cannot recover it. There is no copy on our side to restore from, so exporting and backing up your own files is genuinely your responsibility — see the Terms of Service, which says the same thing in the place where it is binding.

5. What we actually collect

Account information

If you create an account, we collect your email address. Sign-in works by emailing you a six-digit one-time code, which you type back into the page. There is no password, so there is no password for us to store or for anyone to steal. We use your address to send those codes, to tie your subscription to you once billing begins, and to contact you about the service if we have to. We do not send marketing email.

Payment information

If a paid plan is ever introduced, payments will be handled entirely by Stripe. Card numbers are entered on Stripe's own hosted page and never touch our servers or our code; we receive a customer reference and a subscription status. Right now this path is dormant — the checkout endpoint refuses requests, so no payment can be taken and no cardholder data is processed at all.

Server logs

Our host, Vercel, keeps ordinary operational logs of requests to our sites and serverless functions. These typically include an IP address, a timestamp, the path requested and a browser user-agent string. We do not build profiles from them, and we look at them only when something is broken or being abused. They are retained according to Vercel's own schedule rather than ours.

6. What we never collect

  • No analytics. There is no Google Analytics, no Plausible, no PostHog, no Vercel Analytics, no tag manager, no heatmap and no session recorder in any Aleph property. This is checkable: view the source of any page.
  • No cookies. Not for sessions, not for preferences, not for anything. That is why you have never seen a consent banner from us. Details on the Cookies & Local Storage page.
  • No advertising or third-party trackers. We sell no ad space and embed no ad network.
  • No document contents, ever — not the files you open, not thumbnails of them, not their filenames, not their metadata.
  • No training data. We do not use your work to train machine learning models, and we could not: we do not have it.
  • No data brokers. We buy no data about you and sell none.

7. Storage on your device

The tools do keep a handful of small values in your browser's own storage — your theme, your language, your sign-in token, your saved presets. That data stays on your device and is not personal information we hold. Every key is listed, with its purpose and lifetime, on the Cookies & Local Storage page, and clearing your browser's site data for our domains removes all of it.

8. Who else is involved

Four third parties are involved in running the service. That is the complete list, and each one is here because it does a specific job we cannot do ourselves.

ProviderWhat it doesWhat it can see
Vercel
United States
Hosting for every site and the serverless functions behind sign-in. Request logs, including your IP address. Never your documents.
Stripe
United States
Payment processing and subscription state. Currently dormant — no paid plan is offered. Your payment details and billing email, once you subscribe.
Resend
United States
Delivers the sign-in code emails. Your email address and the contents of those code emails.
Google Fonts
United States
Serves the typefaces used inside the Aleph Creative Studios apps. Your IP address and browser, disclosed to Google when a font is fetched.

A note on Google Fonts, since most sites omit it. Loading a webfont from Google's servers reveals your IP address to Google, which is a real third-party disclosure even though no cookie is involved. The Aleph Creative Studios apps currently load their typefaces this way; the site you are reading right now deliberately does not, and loads no third-party resource whatsoever. Self-hosting the fonts across the apps is on the list.

9. Where data goes

We are based in Myanmar and all four of the providers above are based in the United States, so the limited data described here is processed outside Myanmar. If you are in the European Economic Area, the United Kingdom or a jurisdiction with similar transfer rules, please be aware of that before creating an account. We rely on the providers' own transfer mechanisms and have not independently negotiated standard contractual clauses with them.

10. How long we keep things

  • Your email address: for as long as your account exists, and until you ask us to delete it.
  • Sign-in codes: minutes. They are single-use and short-lived by design.
  • Billing records: held by Stripe for as long as their own retention and any applicable tax or accounting obligation requires.
  • Server logs: per Vercel's retention schedule, which is short and not under our control.
  • Your documents: not applicable — we never receive them.

11. Your rights and how to use them

Whatever regime applies to you, we will honour these on request: to know what we hold about you, to get a copy of it, to have it corrected, to have it deleted, to object to how we use it, and to withdraw consent. In practice the answer is short, because the file is short — an email address and a subscription status.

Email us from the address on the account, with "Privacy request" in the subject line and a sentence saying what you want. We aim to reply within seven days and to complete the request within thirty. There is no charge, and asking us to delete your account is not conditional on telling us why.

12. Children

The Aleph tools are general-purpose creative software and are not directed at children. We do not knowingly collect an email address from anyone under 13, or under 16 where local law sets the line there. If you believe a child has created an account, write to us and we will remove it.

13. Security

How we protect what little we hold, what our architecture rules out, and how to report a vulnerability are all on the security page. In short: everything is served over HTTPS, secrets live in server-side environment variables and never in the browser bundle, and there is no password database or document store to breach in the first place.

14. Changes to this policy

If we change this policy we will update the "last updated" date at the top, and for any change that materially affects you — a new subprocessor, a new category of data, a new purpose — we will say so on this site before it takes effect, and email account holders if it is significant. We will not quietly start collecting something and backdate the paperwork.

15. Contact

Privacy questions, requests and complaints: email us, Aleph Developments, Yangon, Myanmar. If you write to us and are not satisfied with the answer, you may also have a right to complain to a supervisory authority in your own country.

16. Language

These documents are written in English. If they are ever translated, the English version is the one that governs. The tools themselves are localised into seven languages; the legal documents deliberately are not, because a mistranslated clause is worse than a clause you have to read in a second language.