Privacy Policy
Last updated: 22 August 2026
1. Who we are
Zalek Labs Ltd ("we", "us", "our") is a company registered in England and Wales under company number 17414810. Alhora is our product: a desktop publishing application that helps authors format books for print and digital distribution. Our website is alhora.app.
Zalek Labs Ltd is the data controller for the personal data described in this policy. We are based in the United Kingdom, and we process personal data in line with the UK GDPR and the Data Protection Act 2018.
If you have any questions about this policy, please contact us at [email protected].
2. The short version
We collect the minimum needed to run your account and your plan: an email address, a payment identifier from Stripe, and a record of which devices you have activated. Your manuscripts stay on your computer unless you deliberately send something to us. Most of the measurement on this website is our own and is a count of how often things happen, with nothing in it that identifies anybody. There is one exception, and we would rather lead with it than bury it: we advertise Alhora on ChatGPT, and to do that we run OpenAI's advertising pixel on this site and tell OpenAI when someone who clicked one of our ads installs the app or subscribes. Section 3 sets out exactly what that involves and section 9 tells you how to stop it. We use no other third-party analytics, we do no behavioural profiling, we do not sell your data, and we never will.
3. What data we collect
Account information
When you create an account we collect your email address and a hashed version of your password. If you sign in with Google, we receive your name, email address, and profile picture URL from Google. If you sign in with Apple, we receive a stable identifier and an email address, which may be one of Apple's private relay addresses. We do not receive or store your Google or Apple password.
We store the provider's permanent identifier for your account so that signing in again matches you to the same Alhora account.
Billing information
Payments are processed by Stripe. We do not see or store your card number, and card details never reach our servers. Stripe provides us with a customer identifier, subscription and payment identifiers, your plan and its status, period dates, and invoice history so we can manage your entitlement and show you your receipts. See Stripe's Privacy Policy for how they handle your payment data.
Device information
When you activate the desktop app, we store a device identifier, a device name (which may include a name you have given your computer), the platform (macOS, Windows or Linux), a hashed hardware fingerprint, and the dates of activation and last use. This is used solely to enforce the per-account device limit and to let you manage your devices.
AI usage records
If you use the optional AI features, we keep a record of each attempt: which kind of check it was, whether it succeeded, how long it took, and the number of tokens processed. These are counts and timings tied to your account — we use them to apply fair-use limits, to bill credits correctly, and to spot faults. We do not store the text you checked. We also keep a credit ledger, which records amounts and reasons only.
One narrow exception: a longer background "deep read" needs somewhere to hold your text between the moment you start it and the moment you collect the result. That text sits on our servers only while the job is running and is erased as soon as it finishes. The result itself is kept for you to retrieve, and is deleted when you delete your account.
Hosted ARC files
If you use hosted ARC links, we store the EPUB file you upload, its original filename, the recipient's name, an optional recipient email address, the link's expiry, and a download count. The recipient's email address, if you provide one, is never included in any response from our systems — not in the public download route, and not in your own listing.
Support correspondence
If you email us, we keep your message and our reply so we can help you and pick up the thread later. If you send a file to help diagnose a problem, we use it only for that, and delete it afterwards.
Technical logs
Our servers and the network in front of them produce standard logs — IP address, timestamp, request path, response status, user agent. We use these to keep the service running and secure. Application logs deliberately record counts, timings and status codes only, never the contents of a request.
Your manuscripts
Alhora is a local-first application. Your manuscript files, projects and exports are stored on your own computer. We do not upload, read, index or back up the content of your books. The only content that reaches us is what you deliberately send: an AI check, an ARC upload, or a support attachment — each described above, and each described in section 9 of our Terms.
Feature requests
If you post to the feature requests board, or vote on someone else's request, we store what you wrote and the fact that your account voted.
The board is public. Request titles, request text, vote counts and our replies are readable by anyone on the internet, with no account, and can be indexed by search engines. Treat anything you post there as published.
What is shown beside a request is a public handle you choose the first time you post — not your name and never your email address. Pick something you are happy to see in public and in search results. Your email is never displayed on the board or included in anything the board sends to a browser.
Some of it stays private: who voted for what is never shown, only the total, and if you report a request the person who wrote it is not told who reported it.
You do not have to use the board at all. Nothing about your account, your subscription or the app depends on it.
Measurement on this website
We count how often certain things happen on the marketing pages — how many people opened a guide, clicked a download button, or used one of the free calculators. We do this so we can tell which pages are useful, and it works like this:
- The only thing stored is a number: one running total for each event, on each page, on each day. For example, “download clicked, on the KDP guide, on 8 August: 42”.
- There is no identifier in it at all. No account, no session, no visitor id, no IP address — not even a hashed one — no device, no browser, no location, no referrer, no timestamp beyond the date.
- Because there is nothing to link the counts to, they cannot be traced to you, and there is no way for us to reconstruct what any individual person did.
- It sets no cookie and stores nothing on your device.
- It is entirely our own, running on our own servers. No third party is involved and nothing is shared with anyone.
The counting described above is not personal data and stores nothing on your device.
If you arrived from one of our ads
We advertise Alhora on other platforms. When you click one of those ads, the link you follow carries the platform’s own numbers for the campaign and the ad — they are in the address bar when you land, and they identify the ad, not you. If, and only if, you arrive that way:
- We add one to a counter for that ad, so we can see what our money bought.
- We set one first-party cookie containing a random code we generated for that ad, and nothing else. There is no identifier for you in it — two people who click the same ad get an identical cookie — and it is
HttpOnly, so no script on the page and no third party can read it. It lasts 30 days and is then gone. - If you go on to create an account within those 30 days, we record which ad brought it, and any purchase that account then makes is counted against that ad. That is a link between your account and an ad, and we would rather say so plainly than describe it as anonymous, because once you have an account it is not.
- For most platforms, nothing goes back to them. Meta, Google and the rest are told nothing by us about what you did after you clicked. That counting happens on our servers and stays there.
Deleting that cookie costs you nothing: the only effect is that we cannot tell which ad you came from. Nothing about your account, your subscription or the app depends on it.
OpenAI's advertising pixel
We advertise Alhora inside ChatGPT. OpenAI, like every ad platform, will only run those ads properly if it is told which of them led to something — so this is the one place where a third party is involved in measurement on this site, and where information about what you did goes back to somebody else. Here is all of it.
- A script from OpenAI runs on every page of this website. It is loaded from
bzrcdn.openai.com. It is not on the pages of the desktop app, which contains no analytics of any kind. - It stores things on your device. OpenAI's script sets a first-party
__opprefcookie holding an identifier for the ad you clicked. Separately, we save a small record in your browser's local storage containing the campaign and ad numbers from the address bar, and the date you arrived. Both last 30 days and are then gone. Earlier versions of this policy said our measurement stored nothing on your device; that is no longer true of this part, and this paragraph replaces it. - We tell OpenAI when an ad worked. If you arrived from one of our ads and go on to sign in to the app, or to buy a subscription, our server sends OpenAI an event saying so. For a purchase, that event includes the list price and the plan you bought.
- We do not send OpenAI anything that identifies you. Not your email address — not even a hashed one — not your name, not your IP address and not your browser's user agent. OpenAI's own format has fields for all of those and we leave every one of them empty. The only thing we send that is specific to you at all is OpenAI's own click identifier, which came from them, describes the ad rather than the person, and is what lets them match the sale to the advert.
- We have switched off OpenAI's "automatic advanced matching". That is a setting which, left on, lets their script read what you type into forms on this site — an email address on the sign-up page, for instance — hash it, and send it to them to match you to an advert. It is on by default for new advertisers. We turned it off, because the previous bullet would otherwise not be true.
- OpenAI is an independent controller of what it receives, and will use it for measuring and improving its advertising. Their handling of it is governed by their own privacy policy, not this one.
If you would rather none of this happened, section 9 explains how to switch it off, and there is no consequence for doing so: nothing about your account, your subscription or the app depends on any of it.
What we do not collect
- No third-party analytics beyond the one named above. There is no Google Analytics, no product analytics SDK and no session recording anywhere. The single third-party script on this website is OpenAI's advertising pixel, described in full earlier in this section; there is no other advertising or tracking pixel, and there is none at all in the desktop app.
- No per-visitor measurement of ordinary browsing. We cannot tell you how many people visited a page, only how many times something happened on it — and we have chosen it that way, because the first requires identifying people and the second does not. The one exception is the ad-campaign attribution described above, which is limited to accounts that arrived from an ad we paid for.
- No analytics of any kind inside the desktop app. Everything in the section above applies to this website only.
- No behavioural profiling, and no automated decision-making with legal or similarly significant effects.
- No special category data. Please do not send us any.
4. How we use your data, and our lawful basis
Under UK GDPR we must have a lawful basis for each purpose. Ours are:
- Creating and running your account — email address, password hash, sign-in identifiers. Basis: performance of a contract.
- Authenticating you across the desktop app and website. Basis: performance of a contract.
- Taking payment and managing your plan — Stripe identifiers, plan status, invoices. Basis: performance of a contract.
- Keeping accounting and tax records of what you paid. Basis: legal obligation.
- Enforcing the device limit and issuing export entitlements. Basis: performance of a contract.
- Running AI checks you request, and the credit accounting behind them. Basis: performance of a contract.
- Applying fair-use limits and daily caps to AI features. Basis: legitimate interests — keeping the service available and affordable for everyone.
- Hosting ARC files you upload and serving them to the recipients you choose. Basis: performance of a contract.
- Sending transactional email — password resets, receipts, service notices you need to receive. Basis: performance of a contract.
- Answering support requests. Basis: performance of a contract, or legitimate interests where you are not yet a customer.
- Publishing what you post to the feature requests board, under the handle you chose, and counting your votes. Basis: consent — you choose whether to post at all, and you give it by posting. You can withdraw it by asking us to remove a request.
- Moderating that board — reviewing reports, hiding abusive or spam content, and deciding what to build next from what authors asked for. Basis: legitimate interests — keeping a public board usable and safe, and building the software our customers want.
- Security, fraud prevention and diagnosing faults — logs, rate limiting. Basis: legitimate interests — protecting the service and its users.
- Product and marketing email you opt in to. Basis: consent, which you can withdraw at any time.
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and we have kept the processing to the minimum that achieves the purpose. You can object to any of it — see section 8.
We will never sell your personal data, and we will never use it for advertising or share it with data brokers.
5. Who we share data with
We share data only with the service providers below, only to the extent needed to operate Alhora, and only under contracts that require them to protect it. None of them may use your data for their own purposes.
- Stripe — payment processing, subscription management and invoices. Receives your email address and payment details you enter with them.
- Render — cloud hosting for our servers and database. Holds the account, billing-reference, device, AI usage and ARC data described above.
- Cloudflare — network and security layer in front of alhora.app. Processes connection data such as IP addresses in transit.
- Anthropic — the AI provider behind Alhora's optional AI checks. Receives the passage of text you submit for a check, and nothing else — no name, no email, no account identifier. Your text is not used to train models.
- Google — only if you choose to sign in with Google.
- Apple — only if you choose to sign in with Apple.
- Google Fonts — this website loads its typefaces from Google's font service, which means your browser's IP address is visible to Google when a page loads. No fonts are loaded from third parties inside the desktop app.
- Resend — delivers our email: transactional messages such as password resets and purchase confirmations, and, only if you have asked for them, release notes. Receives your email address and the contents of that message.
- OpenAI — advertising measurement, and only while our ads are running. Receives the events described earlier in this section. It is the one entry on this list that is not simply a supplier acting on our instructions: OpenAI is an independent controller of what it receives, and uses it for its own advertising measurement under its own privacy policy.
We may also disclose data where the law requires it — for example in response to a valid court order — or to establish or defend legal claims. If Alhora or Zalek Labs Ltd is ever sold or reorganised, your data may transfer to the new owner, who would be bound by this policy or a materially equivalent one; we would tell you first.
6. Where your data is processed
Our servers are hosted by Render in the United States, and Stripe, Resend, Anthropic, Cloudflare, OpenAI, Google and Apple also process data outside the UK.
Where personal data leaves the UK, we rely on an approved transfer mechanism — UK adequacy regulations where they apply, and otherwise the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with the supplementary safeguards those require. You can ask us for details of the mechanism used for any specific transfer.
7. How long we keep data
- Account data — for as long as your account exists. Deleting your account removes it from our systems immediately.
- Billing records — retained by us and by Stripe for up to 7 years after your last transaction, to meet UK tax and accounting obligations. These survive account deletion because the law requires it.
- Device activations — until you deactivate the device or delete your account.
- AI usage records and credit ledger — for the life of the account, then deleted with it.
- AI deep-read text — erased the moment the job finishes, whether it succeeded or failed. The result is deleted with your account.
- Hosted ARC files — the link stops working at expiry (you choose, up to 30 days) or when you revoke it. Files are removed when you delete the link or your account, and may also be lost earlier on a server redeploy.
- Sign-in handover tokens — the temporary tokens used to pass a desktop sign-in from your browser to the app expire after 5 minutes and are deleted on pickup.
- Feature requests you posted — kept after you delete your account, but no longer connected to you: the request stays on the board shown as from a deleted account, and your handle is released for someone else to use. They are kept because other authors' votes and our public replies are attached to them, and deleting the request would take those with it.
- Your votes and any reports you sent — deleted with your account. Removing your votes lowers the totals on the requests you voted for.
- Support correspondence — up to 2 years after the matter is closed.
- Technical logs — kept for a short rolling period by our hosting and network providers, then deleted automatically. They are never used to build a profile of you.
You can delete your account yourself at any time from Account → Profile. It is immediate and cannot be undone. Cancel any Stripe subscription first, from the billing page — deleting your Alhora account does not by itself stop a recurring payment.
Two things deliberately outlive the account, and we would rather say so plainly than have you find out: billing records, because tax law requires it, and anything you posted to the public feature requests board, which stays but is detached from you as described above. If you want a request of yours taken down as well, email us and we will remove it.
8. Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data ("right to be forgotten"). We may need to keep billing records for the statutory period.
- Restriction — ask us to pause processing while a dispute about accuracy or legitimate interests is resolved.
- Portability — request your data in a structured, commonly used, machine-readable format.
- Object — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where processing is based on consent. Withdrawing it does not affect processing already carried out.
To exercise any of these rights, email [email protected]. We will respond within one month, and will tell you if we need longer because the request is complex. There is no charge. We may ask you to confirm the email address on the account before we act, so that we do not hand your data to someone else.
If you are unhappy with how we have handled your data, you can complain to the UK's supervisory authority, the Information Commissioner's Office — ico.org.uk/make-a-complaint or 0303 123 1113. We would rather you told us first so we can put it right.
9. Cookies and local storage
The Alhora website uses strictly necessary storage:
- A session cookie and a CSRF token cookie, set by our web framework to keep forms and sign-in secure.
- Browser localStorage, which holds your sign-in tokens so you stay signed in between visits.
And one more, only if you arrive through a referral link:
-
A referral cookie, set only when you follow a link of the form
alhora.app/r/…that another author has shared. It contains that author's referral code and nothing else — no identifier for you — and it exists so that if you go on to create an account we know who to credit. It lasts 30 days and is then gone. It is a first-party cookie: it is never sent anywhere but to us, and no third party can read it. Deleting it costs you nothing; the only effect is that the author who recommended us is not credited.
And one more, only if you arrive by clicking one of our ads:
- A campaign cookie, set only when you follow one of our ads from another platform. It contains a random code we generated for that ad and nothing else — no identifier for you, so two people who click the same ad get an identical cookie — and it exists so that if you go on to create an account we can tell which ad paid for itself. It lasts 30 days and is then gone. It is a first-party cookie: it is never sent anywhere but to us, no third party can read it, and no script on the page can either. Section 3 describes in full what we do and do not do with it. Deleting it costs you nothing.
And two more, set for advertising measurement:
-
OpenAI's
__opprefcookie, set by OpenAI's advertising script, which runs on every page of this site. It holds an identifier for the ad you clicked. It lasts 30 days. -
An attribution record in localStorage, under the key
alhora_oai_attribution. It holds the campaign and ad numbers from the address bar and the date you arrived — no identifier for you — and it is what lets us tell OpenAI which ad led to a sale weeks after the click. It expires after 30 days.
These last two are not strictly necessary, and you can refuse them without losing anything. Blocking third-party scripts, using your browser's tracking protection, or clearing site data for alhora.app all stop them; so does any content blocker. Nothing about your account, your subscription, your licence or the desktop app depends on either of them, and we will never gate anything behind accepting them. Section 3 sets out exactly what is sent to OpenAI and what is deliberately not.
Apart from OpenAI's, we use no third-party cookies, no analytics cookies and no cross-site advertising cookies, and no other advertising platform sets or reads anything on this site. The aggregate counting described in section 3 sets no cookie at all; the referral and campaign cookies above are our own, are readable only by us, and hold no identifier for you. Clearing your browser storage signs you out and loses nothing else.
10. Security
We protect your data with:
- HTTPS on all connections, with HSTS enforced.
- Passwords hashed with industry-standard algorithms (never stored in plain text).
- Short-lived JWT access tokens, with rotating refresh tokens.
- Webhook signature verification for all Stripe events.
- Rate limiting on authentication, password reset and AI endpoints.
- Application logging that records counts, timings and status codes only — never the contents of your requests.
No system is 100% secure. If a breach affects your rights and freedoms, we will report it to the ICO within 72 hours and tell you without undue delay where the risk to you is high. If you become aware of a security vulnerability, please report it to [email protected] and give us a reasonable chance to fix it before disclosing it publicly.
11. Children
Alhora is not directed at children under 16, and accounts are for over-16s. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the website. The "last updated" date at the top of this page indicates when the policy was last revised.
13. Contact
For any questions or requests regarding this privacy policy:
- Email: [email protected]