Scope
This policy describes the Alpavo web application and its public documentation. It applies to persona information you enter, local version history, import and export files, optional wallet connection, proof receipt history, and routine hosting telemetry.
Do not enter information you do not have permission to use. Alpavo is not designed for secrets, medical records, financial account data, government identifiers, or other highly sensitive personal information.
Local data
Persona fields, appearance recipes, selected character, snapshot history, and proof receipt history are stored in your browser using local storage. This data is not synchronized to an Alpavo account in the MVP.
Anyone with access to your browser profile or an exported file may be able to read that content. Clearing site data, using private browsing, changing devices, or browser cleanup may remove it. Export important work yourself.
Wallet data
When you choose Connect Wallet, Alpavo requests only the public address you select and the active chain ID. The page listens for account and network changes so it can show the current state.
Connection alone does not request a signature, approval, payment, or transfer. Public addresses and on-chain activity are inherently public.
Optional proof transactions
The persona-proof control remains separate from wallet connection. Before a configured request, Alpavo displays the business ID, digest, network, contract, wallet, purpose, zero transfer value, and a final acknowledgement.
If you approve a proof transaction in your wallet, your wallet provider and the relevant network process public transaction information under their own terms. Alpavo locally stores the returned hash and receipt fields for history and recovery. Alpavo does not collect seed phrases or private keys. Never share them with this site.
Imports and exports
Import reads the JSON file you deliberately select in your browser. The file is parsed locally and added only when its Alpavo digest checks pass. Export creates a file on your device at your request.
Exported personas may contain personal or copyrighted material you entered. You decide where to store or share them. Alpavo cannot control a file after it leaves the browser.
Hosting and analytics
The hosting provider may process IP address, device and browser information, requested path, timing, and security signals needed to serve and protect the site. Privacy-conscious product analytics may record aggregate page usage and performance.
Alpavo does not intentionally send persona field contents or local snapshot contents to analytics. A future feature that requires server processing will receive a separate data-flow review and updated notice before launch.
Retention and control
Local data remains until you delete a character, clear browser storage, or the browser removes it. Deleting a character removes its local snapshots from the current browser. Exported copies must be deleted separately wherever you saved them.
Because the MVP has no persona account database, there is no central persona record for Alpavo to retrieve or erase. Hosting security logs may be retained for the provider’s limited operational period.
Security and changes
Alpavo uses browser isolation, content escaping, digest verification, and explicit transaction review to reduce common risks. No system is perfectly secure. Keep your browser updated, inspect the domain, and review every wallet prompt.
This policy may change when product data flows change. Material changes will be dated on this page. Continued use after an update means the revised policy applies prospectively.
Questions
For privacy questions, use the project support channel associated with the deployment that linked you to this policy. Include the page URL and a description of the issue, but do not send private keys, seed phrases, or sensitive persona content.