Draft version: 2026-07-22
Proposed publication date: with the approved Privacy Policy
Status: counsel approval copy; not yet effective
Alderson agents perform multi-step work across models, files, tools, and connected applications. A useful agent is more than a chat response. It must understand a request, assemble context, choose tools, recover from failures, produce an output, and recognize whether the result passed an available check.
We want to learn from those real workflows so Alderson agents become more reliable and capable. For eligible Free accounts, that can include using selected prompts, model-visible context, outputs, agent execution traces, tool work, corrections, validation, and outcomes to evaluate and train shared Alderson agents and models. Enterprise works differently: the organization controls its detailed data and destination, and Alderson does not use that data for shared training by default.
The Privacy Policy governs how Alderson handles personal information. The Terms of Service govern use of the Service and the permission granted for Free account data. If this page conflicts with either document, the Privacy Policy or Terms control.
Four kinds of information
Alderson separates service data into four categories.
Personal information
Personal information is information about, linked to, or reasonably linkable to a person. An email address is an obvious example. An account, installation, project, conversation, or episode identifier can also be personal information if it can reasonably be connected to someone.
Calling information telemetry, metadata, encrypted, pseudonymous, tokenized, or hashed does not automatically make it anonymous. Alderson treats linkable Actions and operational records as personal information and applies the Privacy Policy to them.
Customer Content
Customer Content is the substance of the work: prompts, instructions, files, images, source material, model-visible context, connected-application content, model inputs and outputs, agent execution or reasoning traces, exact tool inputs and results, edits, corrections, feedback, validation, and outcomes.
Alderson processes Customer Content to perform requested actions. This is separate from selecting an Action for a governed training dataset, although both can occur while the Free account training control is on.
Minimum Operational Data
Minimum Operational Data is technical information needed to run and protect the product. It can identify a software version, feature, reviewed component, timing range, completion status, retry count, static error class, entitlement, or validation status without retaining the substance of the underlying work.
This minimum profile is required for signed-in Free access. It supports authentication, metering, compatibility, reliability, security, deletion, and support. Content-bearing Free Actions are a distinct data layer used for shared agent development as described below.
Free Actions and Training Editions
An Alderson Action is a structured record of something meaningful in a product journey or agent episode. An Action can have ordered steps, causal links, state changes, content references, and a result. Together, Actions can show not only that an agent failed, but where it failed, what eligible context it used, what it tried, and whether a later correction worked.
A Training Edition is a selected, governed collection of Actions and content references prepared for evaluation or model development. An edition has a manifest recording its sources, policy version, purpose, selection criteria, and status. Free Actions are not automatically placed into every training run merely because they were collected.
The Free Service has two data layers
The Free Service has an operational layer and a content-bearing training layer. The operational layer is required for ordinary Free use. The training layer is active only while Improve Alderson for everyone is on.
The required operational layer may include:
- opaque account, installation, session, run, and action identifiers;
- Alderson app, agent, schema, feature, component, tool, model, and provider identifiers and versions;
- coarse operating-system and device-capability information;
- timing ranges, token or usage counts, queue time, retries, and rate status;
- completed, cancelled, failed, recovered, and validation status;
- reviewed static error, security, compatibility, and capability codes; and
- plan, destination, retention, and policy identifiers used to enforce the correct data mode.
The operational layer is designed to be content-free.
While Improve Alderson for everyone is on, the training layer may record eligible product journeys and agent episodes, including:
- prompts, instructions, model inputs, model-visible context, and outputs made available to Alderson;
- the ordered steps, branches, retries, and state transitions of an agent;
- agent-generated plans, reasoning summaries, execution traces, and other intermediate work available to the Service;
- tool names, calls, arguments, results, and errors;
- portions of files or connected-application content actually read, created, or changed by an agent or model;
- edits, corrections, user feedback, human labels, validation results, and observed outcomes; and
- model, token, timing, runtime-health, and coarse device details needed to reproduce or compare the episode.
These records may contain personal or confidential information even after direct account identifiers are separated from an edition. Do not use Free for information you are not authorized to contribute for these purposes.
What Alderson deliberately excludes
Actions are designed not to intentionally capture:
- passwords, passkeys, recovery codes, private keys, or keychain values;
- API keys, access or refresh tokens, authentication cookies, or authorization headers;
- secret environment variables or credential stores;
- raw IP addresses in the ordinary Actions store;
- unopened host files or a scan of unrelated directories;
- unrestricted keystroke, clipboard, pointer, audio, video, or screen recording; or
- a model provider's private hidden chain-of-thought when that information is not returned to Alderson.
The distinction around reasoning matters. Alderson may record the observable steps and intermediate work of its own agent system, along with reasoning summaries or reasoning content that a model provider actually returns and that the Service is permitted to process. Alderson does not claim access to a provider's undisclosed internal chain-of-thought.
Credential removal, field validation, content segmentation, and filtering are risk controls, not guarantees. A prompt, file, output, or tool result can still contain a person's name, a client's confidential material, a secret placed in an unexpected field, or content the user lacked authority to contribute. That is why Free training is inappropriate for regulated records, privileged material, or confidential employer and client work.
How Free Actions improve Alderson
Selected Free Actions may be used for several related purposes.
Evaluation and scoring
Alderson can compare versions of an agent against real failure and success patterns, test whether a known correction still works, measure whether a workflow reaches a verified outcome, and build benchmarks that reflect the actual product rather than an artificial demo.
Supervised fine-tuning
Reviewed examples can teach an agent or model to choose a better next step, use a tool correctly, follow a required schema, recover from a known failure, or produce an output that satisfies a validator.
Preference and reinforcement learning
Corrections, comparisons, validation, and outcomes can help Alderson learn which of several actions is more useful, reliable, safe, or efficient. This may include preference optimization, reinforcement learning, reward or scoring models, and policies that control routing or tool use.
Reliability, safety, and product design
Actions can reveal compatibility problems, fragile steps, unsafe behaviours, confusing approval flows, and missing safeguards. Some improvements change code, interfaces, documentation, or tests rather than model parameters.
Human review
A limited number of authorized Alderson personnel and contracted service providers may review selected Actions to filter, label, evaluate, investigate, or prepare a Training Edition. Access should be need-to-know, subject to confidentiality and use restrictions, and logged where the system supports it.
Your Free account control
New personal Free accounts start with Improve Alderson for everyone on. You can change this setting at any time in the Data Controls section of your account.
You can turn the control off without closing the Free account. After you turn it off, Alderson will not collect new content-bearing runs for shared training. Limited content-free operational data continues so Alderson can provide, secure, and troubleshoot the Service. The change applies going forward. It does not automatically remove Actions collected while the setting was on or information already used to train a model. Previously collected Actions remain subject to the retention, deletion, rights, and remediation rules below. You may also request account deletion. Account deletion:
- stops new content-bearing Actions from the deleted account;
- revokes active Training Editions associated with the account from future training runs; and
- begins the source-data deletion process described below.
Enterprise is the customer-controlled option for organization data. If law in a user's location requires express consent or a different choice mechanism, Alderson will not activate the affected collection or use there until that mechanism or another lawful product rule is in place.
Retention, deletion, and trained models
Encrypted raw Free Actions and separately encrypted content objects are intended to expire within 365 days. Shorter retention may be used when the information is no longer needed.
A selected Training Edition may be frozen beyond the source period so that a training or evaluation run is reproducible. It remains governed by its manifest until deleted or revoked and is reviewed at least annually. Derived de-identified statistics, evaluations, and trained model parameters may remain for the useful life of the relevant product or model.
The intended account-deletion process destroys the account's server-side content-encryption key, schedules physical deletion of raw objects, revokes associated active Training Editions, and prevents those editions from entering future training runs. It does not silently delete local projects or copies already sent to a model provider or connected application.
Machine learning is not a conventional database lookup. Deleting source data or revoking an edition may not reverse statistical changes already incorporated into a model that completed training. Where applicable law requires more, Alderson will assess correction, output suppression, dataset exclusion, retraining, fine-tuning, or another technically reasonable model-remediation measure.
Enterprise works differently
Enterprise data exists for the Enterprise customer, not as a supply of shared Alderson training data.
An Enterprise customer's signed agreement and configuration determine:
- what detailed activity or Customer Content is recorded;
- whether recording occurs at all;
- the customer-controlled tenant, storage account, or other destination;
- which administrators and customer personnel can access it;
- whether the customer uses it for audit, evaluation, fine-tuning, retrieval, or its own model-development work;
- retention, deletion, region, and residency requirements; and
- the limited circumstances in which Alderson may provide support.
By default, detailed Enterprise data is not sent to Alderson's Free Actions store and is not used to train shared Alderson agents or models. Alderson may process it transiently to perform a requested action or route it to the customer's configured destination. Alderson-hosted retention happens only if the Order Form or data processing addendum expressly requires it.
An Enterprise customer may use its own data to evaluate or fine-tune its own models, subject to its authority, provider terms, workplace notices, and other legal obligations. Alderson does not obtain a shared-training right merely by helping route or structure that data. An Enterprise contribution to shared Alderson training requires a separate express written agreement.
Dataset transparency and governance
Before an Action enters a governed training program, Alderson checks the applicable policy version, Terms version, account setting, source, deletion status, and edition status. Each Training Edition records its purpose, selection criteria, safeguards, access rules, and retention period.
Where law requires training-data transparency disclosures, Alderson will publish them before making a covered system available.
Alderson enforces the Free or Enterprise data mode before accepting an Action. The enforcement includes the account setting, destination, credential-removal boundary, retention rules, deletion status, and edition-revocation status.
Your rights and questions
You may request access, correction, export, or deletion and exercise other applicable privacy rights through https://alderson.ai/account/privacy or privacy@alderson.ai. A request involving information in a training dataset or model may require additional verification and may have technical limitations, which Alderson will explain rather than treating as a reason to ignore the request.
Questions about this explanation or Alderson's data practices may be sent to privacy@alderson.ai. Security reports should be sent to security@alderson.ai.
If Alderson materially changes the categories, purposes, recipients, retention, or model-development use described here, it will update the applicable notices and obtain any new choice, agreement, or consent required before the new practice begins.