Legal

Privacy Policy

Last updated: August 13, 2026

This Privacy Policy explains how AALY ("AALY," "we," "us") collects, uses, and protects information across the AALY platform — the dashboard, the REST API, and the Model Context Protocol (MCP) server that let developers and their AI agents design, generate, and operate backends. It applies to the developers and teams who create an AALY account or otherwise use the platform, referred to below as "you."

1. Overview

AALY is an AI-native backend platform. You — or an AI agent acting on your behalf, through tools like Claude Code, Cursor, or our own MCP server — define entities, fields, relationships, and rules; AALY generates and hosts a production backend (API, database, and auth) from that definition, and keeps operating it as your schema evolves.

This policy covers the platform as a whole: the marketing site at aaly.io, the AALY dashboard and API, and the MCP server at mcp.aaly.io. It is written for the developers and customers who build on AALY. It is not a privacy policy for the end users of the applications our customers build on top of AALY — except where noted in Backend Data below, since operating those backends necessarily brings AALY's infrastructure into contact with that data too.

2. Information We Collect

Backend data

AALY's core function is to host and run the backends it generates. That means AALY infrastructure — API gateways, compute, and the databases provisioned per project — directly stores and processes the runtime data flowing through the backends you build, including records created by your own application's end users. We are not a passive pass-through for this data, because we operate the infrastructure it lives on — but we also don't treat it as ours:

  • You control the schema, access rules, and lifecycle of this data through your project configuration; we don't read, export, or repurpose it outside of operating the platform.
  • Our systems and authorized personnel access this data only to operate the service (e.g., executing the API calls your app or agents make), to investigate abuse or security incidents, to provide support you request, or where required by law.
  • We do not sell this data, use it for advertising, or use it to train our own or third-party AI models.
  • Where applicable law treats you as the data controller for your end users' information and AALY as a processor or service provider, our processing of it is governed by the AALY Terms of Service (and a Data Processing Addendum on request) rather than by this policy alone. If you collect personal data from your own end users through an AALY-generated backend, you're responsible for having your own privacy policy and legal basis for that collection.

3. How We Use Information

We do not sell your information. We do not use it for advertising or for marketing unrelated to AALY. We do not use your project schema, configuration, or backend data to train third-party AI models without your explicit consent.

4. Model Context Protocol (MCP) Server

AALY exposes an MCP server at mcp.aaly.io so that AI agents — Claude Code, Claude Desktop, Cursor, and similar tools — can manage AALY projects programmatically on your behalf, using the same account and API-key authentication as the REST API.

The MCP server's scope is deliberately narrow: it handles account identity (confirming who is authenticated), project metadata (names, slugs, identifiers), and entity/field schema definitions — the structural specification of your backend. It does not read, write, or otherwise handle the runtime data stored in the backends your projects generate — the records your application's own end users create. That data is only ever accessed through the REST API your backend exposes, using credentials you control.

Tool calls made through the MCP server are recorded as part of our operational logs (see above) for security and debugging.

5. Data Retention

We retain account and project data for as long as your account is active. If you delete a project, its schema, configuration, and associated backend data are deleted within 30 days, except where we need to retain limited records for legal, security, or fraud-prevention purposes. If you close your AALY account, we delete or anonymize your account information on a similar timeline. Operational logs are retained for a limited period (typically up to 12 months) for security and debugging before being purged or aggregated. You can request deletion at any time — see Contact below.

6. Third-Party Subprocessors

We rely on a limited set of infrastructure and service providers to run AALY:

Each provider is bound by its own data protection terms, and we only share the minimum information needed for it to perform its function.

7. Your Rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict some of our processing. To exercise any of these rights, email security@aaly.io. We'll respond promptly and may need to verify your identity first.

If you're an end user of an application built by an AALY customer on our platform, these requests should generally go to that developer or company first, since they control the collection and use of your data — see Backend Data above.

8. Contact

Questions about this policy, or a privacy or security request? Email security@aaly.io.

This policy may change as AALY evolves. When we make material changes, we'll update the date at the top of this page.

← Back to home