This policy covers the Allivista website (allivista.com), the Allivista API, and the Allivista MCP connector / desktop extension. It explains exactly what we collect, why, and — for your stored memory — why we cannot read it.
Allivista provides a structural-knowledge cortex and an end-to-end encrypted memory service that AI assistants reach through the Model Context Protocol (MCP). "We", "us", and "Allivista" refer to the operator of allivista.com.
alv_…) are stored only as a SHA-256 hash.
We never store the plaintext key and cannot recover it — if you lose it, you revoke and reissue.discover / verify). For signed-in users we may
store your query terms and the results so you can review them in your account. You can delete this history at any time.discover and
verify are processed on our servers against a fixed research-literature cortex, and a short natural-language
narration is generated using a third-party large-language-model provider (Anthropic). Only the explicit tool
inputs you send are transmitted — never the rest of your AI assistant's conversation.remember / recall) is end-to-end encrypted.
Text you store is encoded into a per-user dialect and encrypted with AES-256-GCM on your own device, using a key
derived from a passphrase that never leaves your device. Our servers store only ciphertext and opaque token identifiers.
We cannot read your stored memory, and we cannot recover it if you lose your passphrase.We share the minimum necessary with infrastructure providers who process data on our behalf:
| Provider | Purpose | What it sees |
|---|---|---|
| Amazon Web Services | Hosting, authentication (Cognito), database, compute | Account data, ciphertext memory, hashed keys, usage counts |
| Anthropic | Generates the narration for discover / verify | Only the concept terms for that query |
| PayPal | Subscription billing | Processes your payment; we store a subscription id and billing email |
All traffic is encrypted in transit (TLS). API keys are stored hashed. Your memory is end-to-end encrypted with a key that never leaves your device.
You can view and delete your query history and stored memory from your account, revoke API keys at any time, and request export or deletion of your account data by emailing us. Deleting a memory document removes its ciphertext from our store.
Allivista is not directed to children and is not intended for use by anyone under 16.
Allivista is operated from the United States and data is processed on US-based AWS infrastructure.
We will update this page and revise the "Last updated" date when this policy changes materially.
Questions or data requests: privacy@allivista.com.
privacy_policies) and its bundled README.md.