Privacy Policy
How Alphas Next LLC collects, uses, stores, shares, and protects information in connection with the Focalect web application.
Focalect is currently in beta and under active development. It may contain bugs, errors, interruptions, and inaccurate data, may change or become unavailable at any time, and we cannot guarantee the security, integrity, or availability of any data during beta. If you have any concern about the privacy or security of your data, please do not sign up, connect any accounts, or use the Service. By using Focalect during beta, you accept these risks.
This Privacy Policy explains how Alphas Next LLC, an Illinois limited liability company (“Focalect,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information in connection with the Focalect web application (the “Service”).
What Focalect does, in plain terms: Focalect is a business analytics dashboard for growing companies. An organization owner connects the organization’s own business accounts (Stripe, Facebook, Instagram, TikTok, and YouTube) so that we can read metrics and records from those accounts and present them back to that organization as dashboards. Our core function is read-only analytics. We do not run ads or use your data for advertising, we do not sell or rent your data, and we do not use it to train machine-learning models. We access only the data needed to build your dashboards, and we do not post or publish content on your behalf.
By using the Service, you agree to this Policy.
01Our Role: Controller and Processor
Focalect handles data in two legal roles:
- As a controller, for the account and usage data of the people who sign up for and use the Service (Sections 2.A and 2.B).
- As a processor, for the business data we access on behalf of an organization through its connected accounts (Section 2.C). We process that data solely to provide the Service, on the organization’s instructions. Some connected data — most notably Stripe customer records — includes personal data about the organization’s own customers. For that data the organization is the controller; those individuals do not have accounts with us and should direct any requests to the organization that collected their data. We do not contact, profile, or market to them.
Organizations processing personal data through the Service may require a separate Data Processing Agreement (DPA); contact us to put one in place.
02Information We Collect
We request only the data and access needed to provide the Service.
A. Account information (you provide)
- User: name, email address, and a password (stored only as a bcrypt hash, never in plain text). We also store your organization membership and role and your saved dashboard layout preferences.
- Organization: organization name and invite code.
- Authentication: you log in with email and password. We do not use “Sign in with Google/Facebook/etc.” — the connections in Section 2.C exist only to pull business data, not to log you in.
B. Usage and device data (collected automatically)
- Device and browser information, IP address and approximate location, and interaction data. See Section 9 on cookies.
C. Connected business data (you authorize)
When an organization owner connects an account, we access data through that platform’s official API, store it tagged to that organization, and use it only to build that organization’s dashboards. We store OAuth access/refresh tokens for these connections encrypted at rest (see Section 10).
- Stripe (via Stripe Apps). Stripe Apps grants read access as its only authorization option for all its data, although Stripe Apps enforces a necessary read-write for payments that is NEVER used by us; in practice Focalect performs read operations only and never creates, modifies, refunds, or moves money. We read and store financial records including charges, payment intents, balance transactions, subscriptions and subscription items, invoices, refunds, checkout sessions, products, prices, and customer records.
Important — third-party personal data
The Stripe customer sync includes personal data about your organization’s own customers: name, email, phone, billing and shipping address, account balance, tax-exempt status, locale, and any metadata you have stored. We hold this data solely to display it back to your organization, as a processor acting on your instructions.
- Facebook (Pages). We access your Page’s identity (ID and name) and daily Page-level metrics such as follows and media views. Aggregate Page metrics as well as permalink, caption — the actual post text — plus postedAt, likes, comments, shares, and watch-time.
- Instagram (Business). We access your professional account profile (user ID, username, account type), daily account insights (reach, views, profile views, follower changes), recent media (captions, media type, thumbnail, permalink, timestamp), per-post insights (likes, comments, shares, saves, reach, views), and follower count. Post captions are stored as written and may incidentally include a person’s name if you mention one; we do not use captions for any purpose other than displaying your analytics.
- TikTok. We access your profile (open ID, avatar, display name, profile web and deep links, bio, and verified status), your account statistics (follower, following, likes, and video counts), and your public videos (descriptions, cover images, share URLs, timestamps, and like/comment/share/view counts), used to build your dashboards. Read-only; we do not post or upload on your behalf.
- YouTube (YouTube Data & Analytics API). We access your channel identity (channel ID and name), subscriber count, and daily channel analytics (views, likes, comments, shares, subscribers gained/lost, estimated watch minutes, average view duration). Channel-level aggregates only — no individual viewer personal data.
We never ask for, collect, or store your login credentials for any connected platform. Access is granted through each platform’s authorization (OAuth) flow and can be revoked by you at any time (Section 8).
03Third-Party Platforms and Their Terms
Your use of connected platforms through Focalect is also governed by each platform’s own terms and privacy policies.
Google / YouTube
Focalect uses YouTube API Services. By connecting your Google account you agree to the YouTube Terms of Service. Google’s handling of your data is described in the Google Privacy Policy.
Focalect’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the user-facing analytics features of the Service; we do not transfer or sell it, use it for advertising, or use it to train generalized AI/ML models.
You can review or revoke Focalect’s access to your Google data at any time on the Google security settings page.
Meta (Facebook & Instagram)
Data accessed through Meta’s platforms is subject to Meta’s Privacy Policy and Platform Terms. We access this data only to build your analytics and do not share it except as described in this Policy.
TikTok
Data accessed through TikTok’s APIs is subject to TikTok’s Privacy Policy. We use this data only to build your analytics.
Stripe
Stripe’s handling of data is described in the Stripe Privacy Policy. We access connected Stripe account data to generate analytics and perform read operations only.
04How We Use Your Information
We use the information we collect only to:
- Provide, operate, and maintain the Service and generate the dashboards you request
- Create and manage your account, organization, and connected integrations
- Understand usage and improve the Service
- Communicate with you about your account, support, and updates
- Detect, prevent, and address security incidents, fraud, and abuse
- Comply with legal obligations
We do not sell or rent your data, do not use connected business data for advertising, and do not use it to train machine-learning models. Connected data is used only to provide the Service to the organization that connected it.
05Legal Bases for Processing (EEA/UK)
Where GDPR/UK GDPR applies we rely on: performance of a contract, legitimate interests (operating, securing, and improving the Service), consent (non-essential cookies and any marketing), and legal obligation. For data we process as a processor, the organization establishes the legal basis.
06How We Share Information
We do not sell personal information. We share it only:
- With sub-processors who host and run the Service:
- Railway — hosting and storage of account data, connection records, and synced metrics.
- For legal and safety reasons — where required by law or to protect rights, property, or safety.
- In a business transfer — as part of a merger, acquisition, or sale of assets.
We do not share connected business data with any party except the sub-processors above, and we require them to protect it and use it only to provide the Service.
07Data Retention
We retain data only as long as your account and the relevant connection are active. When a connection is disconnected, or your account is deleted, or the data is no longer needed to provide the Service, we delete or anonymize it within 30 days, except where retention is required by law. We do not store connected business data indefinitely.
08How to Delete Your Data
You can delete your data at any time:
- Disconnect an integration in the Service. This removes the synced metrics and records for that integration from our analytics store.
- Delete your account to remove all data we hold about you and your connections (subject to legal retention requirements).
- Email us at info@focalect.com with the subject “Data Deletion Request”; we will delete your data and confirm within 30 days.
- Revoke access directly on the platform — the Google security settings page, your Meta Settings → Apps and Websites, your TikTok Settings → Security & permissions → Manage app permissions, or your Stripe dashboard.
This section is the data-deletion process referenced by our platform integrations, including the Data Deletion Instructions URL provided in the relevant developer dashboards.
09Cookies and Tracking
We use a session cookie to keep you signed in and may use similar technologies to remember preferences and understand usage. You can control cookies through your browser.
10Data Security
Because the Service handles sensitive financial and personal data, we maintain technical and organizational safeguards, including:
- Encryption of OAuth tokens at rest — all connected-account access and refresh tokens are encrypted with AES-256-GCM before being stored.
- Passwords stored only as bcrypt hashes, never in plain text.
- Per-organization data isolation — synced data is partitioned by organization identifier.
- Encryption in transit and access controls limiting who and what can reach connected data.
No system is perfectly secure, but we work to protect your information and will notify you and, where required, the relevant platforms and authorities of any breach affecting your data.
11International Data Transfers
Your data may be stored and processed in the United States. Where data is transferred across borders we rely on appropriate safeguards such as Standard Contractual Clauses.
12Your Rights
Depending on your location you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing, and to withdraw consent. California residents (CCPA/CPRA): you may request to know, delete, and correct your information and to opt out of sale or sharing — we do not sell personal information.
To exercise these rights, contact us (Section 14). If the data relates to an organization’s own customers (for example, Stripe customer records), that organization is the controller — direct the request to them, and we will assist as their processor.
13Children’s Privacy
The Service is a business tool for adults and is not directed to children under 18, and we do not knowingly collect their personal data. Our use of YouTube API Services is not directed to children, consistent with the YouTube API Services Terms and applicable law (including COPPA). If you believe a child has provided personal data, contact us and we will delete it.
14Contact Us
Questions or requests about this Policy or your data:
15Changes to This Policy
We may update this Policy and will post the revised version here with a new “Last updated” date, notifying you where appropriate.