Privacy notice

What data Alessandria handles

Alessandria handles three things: who you are (the email address you sign in with), what you upload (a lecture recording and the study material made from it) and your preferences. There are no visit analytics, no profiling cookies, and your material is never used to train any model.

Updated on

Who is responsible for this data

Alessandria is not a company with a legal department: it is the work of one person, a student. The data controller — the person who decides what is collected and answers for it — is named below, together with the address to write to. A person reads that address, not a form.

Which also means something convenient: any question about this data is settled by sending one email, with no procedure in between.

What data is handled

Four groups, and there are no others.

  1. Who you are

    The email address you sign in with, and the way you proved it was you. Alessandria does not hold that part: the sign-in service does (see below). What reaches Alessandria is a code — a meaningless string that stands for your account. That code is what holds your courses together, and it contains neither your name nor your email.

  2. What you upload, and what comes out of it

    The lecture recording, or the text file. Then everything derived from it: the transcript, the full write-up, the notes, the glossary, the concept map, the timeline, the quizzes and the flashcards. Alongside it stay the names you type — the course, the lecture, the exam date and any notes you add — plus a copy of the text of your documents that powers the search box, so a word can be found without reopening everything.

  3. Your preferences

    The processing options and, if you choose to use it, the Notion connection with its key. These follow the account, because they have to be the same on your laptop and on your phone. Theme, language and text size do not: they stay in the browser you are using and never leave it.

  4. A technical record of how much work each step took

    For every processing step, one line stays: the date, which step it was, for which course and lecture, how much work it took and whether it succeeded. It exists for one reason — knowing what it costs to run the service. It does not contain the content of the lecture.

On top of that, what any website gets: the network address a request comes from. It is used to stop the service being abused, and to keep count when someone asks for too much at once.

One thing worth saying plainly, because it is your responsibility and not ours: if you type a lecturer’s name into Alessandria, or record a lecture, that data is about other people. At many universities, recording a lecture is something you have to ask permission for first — and asking is on you.

What is not collected, and it is not a detail

  • There are no visit analytics. No counters, no analysis tools, neither on this site nor inside the app. We do not know how many times you opened a page, because nothing measures it.
  • There are no profiling or advertising cookies. There is no advertising at all, so there is nothing to profile. The cookie details have their own page.
  • There are no social buttons phoning home. No third-party content on these pages can recognise you.
  • The typeface is served from here, not from an outside provider: opening a page, your browser makes no request to any other site.

This is also why this page is far shorter than the ones you are used to. Most of a normal privacy notice describes measurement tools. There are none here.

Why it is handled

  • To do what you asked: without the recording there is nothing to transcribe, and without an archive you would not find anything again. That is performing the service you chose to use.
  • To keep the service standing and defend it: network addresses and request limits stop it being abused, and the record of work done is how its cost is known. That is the legitimate interest of whoever runs it.
  • For the Notion connection, if you switch it on: that only happens because you asked, and it can be switched off whenever you like.

Who else handles it, and where it sits

Every other page on this site says what Alessandria does and not how it is built inside. Here it is different, and it has to be: who your data is handled with is part of what you are entitled to know.

  • Clerk holds sign-in: your email, and the password or method you use to get in. No credential ever reaches Alessandria — only the confirmation that it is you, and your account code.
  • Cloudflare holds everything else: the pages you are reading, the file storage, the course archive, and the processing that turns a lecture into study material.
  • Notion, and only if you switch it on: it receives the notes you choose to publish, and nothing else.
  • sending.dev delivers the only two emails Alessandria ever sends: the message you write in the contact form — with the name and address you typed there — and the welcome note when you sign up. Nothing else passes through it: not the lecture, not the notes, not the archive.
  • Wikipedia, for the timeline only: to check a date, a search is run against the encyclopedia the way you would run it yourself. What leaves is the thing being looked up — an event, a name — and nothing about you: not your account, not the rest of the lecture.

Where it physically sits: on Cloudflare’s network, which spans the world. It is not configured to pin data to one region, so it may be processed outside the European Union, under the contractual safeguards that provider applies. We would rather write that down than let it be inferred.

Your material trains nothing

The lecture you upload, the transcript and the notes made from it are never used to improve, train or correct any model. They are not read out of curiosity, not sold, not handed to anyone, and never added to any set of examples.

There is one exception, and it has a precise shape: if you write in because something is broken and you send us a piece of your material so we can see the problem, we look at that piece — because you asked us to — and use it for nothing else.

How long it stays, and how it is deleted

  1. The recording you upload: minutes

    The audio file exists only to be transcribed, and it is deleted as soon as the transcript is ready. If something breaks halfway — you close the tab, the network drops — that copy can be left behind: an automatic check runs twice a day and finds them. If you want certainty that nothing is left of a recording, write to the address below and it is deleted by hand.

  2. The study material: as long as you want it

    Notes, glossary, maps, quizzes and flashcards stay in your archive with no expiry, because you need them until the exam and after it. From inside the app you can delete a single document, a whole lecture, a whole course with everything in it, and the chat history. When you delete, the file is removed from storage, not merely hidden from a list.

  3. The technical record: it stays

    The lines saying how much work each step took remain after you delete the material, because they are the accounting of the service. They hold the date, the step and the name of the course and lecture — not their content.

  4. Closing the account

    There is no button that does it on its own today, and we would rather say so than have you hunt for one. It is closed by writing to the address below: the archive is deleted and access removed. If you want to do the bulk of it yourself first, deleting your courses from the app already deletes all the material.

Your rights

You can ask what data there is, have it corrected, have it deleted, have its use restricted, receive a copy of it, and object to a use of it. They all work the same way: by writing to the address below.

An honest note about receiving a copy: there is no download button inside Alessandria, and that is a deliberate product choice stated elsewhere too. It is not a way of withholding your data: ask for a copy and you get one.

If you believe this data is being handled badly, you can go to the supervisory authority in your country. In Italy that is the Garante per la protezione dei dati personali.

How it is protected

  • Every account lives in its own space: the archive is filed under your account code, and one request cannot read another account’s.
  • Everything travels over encrypted connections, and access is verified on every single request: knowing a file’s address is not enough to read it.
  • No service credential is written into the pages your browser downloads. Keys live on the server only.

Nobody can promise nothing will ever go wrong, and anyone who promises that is overselling. If something did happen to your data, what can be promised is that it would be written down, rather than waiting for someone to notice.

Who it is meant for

Alessandria is built for university students and is not meant for children. If you are under fourteen, the account needs to be opened by whoever looks after you.

If this text changes

The date at the top is the date of the last revision, and it is the real one: it moves when the text changes, not every time the site is published. If something that matters changes — new data, a new provider, payments — it will be written here before that thing starts working, not after.

How to ask

For anything about this data — a copy, a correction, a deletion, or just a question — write to:

alessandriaforstudents@gmail.com

Data controller: Alessandro Mancano