Privacy · Last updated 31 July 2026

We designed the product so there would be very little to write here.

Most privacy policies describe what a company does with the data it collects. This one mostly describes data we never receive in the first place, because the app runs on your device and does not have an account system behind it.

The short version

There is no account with usYour identity is a keypair generated on your device. We never see it, cannot reset it, and hold no email or password for it.
Your learning stays localWhat you study, how you score and how often you retry is stored on your device. There is no server-side copy for us to analyse or sell.
Integrity data never leavesSentinel’s camera, keystroke and pointer signals are processed on your hardware. Only a score and its reasoning attach to a credential.
Sync is sealedDevices sync end-to-end encrypted. Relays pass along bytes they cannot read, and we operate them without keys.
You choose what to revealSharing a credential with an employer is an explicit act, one credential at a time. Nothing is discoverable without your consent.
No advertising, everWe do not sell data, run ads, or share anything with data brokers. The platform is funded by employers and institutions.

What we actually receive

There are only a few points where information reaches us at all. Each is listed below with why it exists and how long we keep it.

Waiting-list emailKept until you ask us to delete it

If you join the waiting list we store the address you gave us, the platforms you picked and the role you chose, so we can email you when it is your turn. We do not use it for anything else, and there is no newsletter.

Messages you send usKept while the conversation is live

Enquiries from the employer and institution pages, and any email you send us, are read by a person and kept as ordinary correspondence.

Encrypted sync trafficTransient — not stored as content

Our relays forward encrypted blocks between your own devices. We hold no key to them and keep no readable copy. Operational logs record volume and timing, not content.

Crash reportsOpt-in, off by default

If you choose to send a crash report, it contains the technical state of the failure and your platform version. It is never sent automatically, and it carries no identity or learning data.

This websiteNo third-party trackers

The site sets no advertising cookies and embeds nothing from another origin — the fonts are served from this domain for that reason. Your dark or light mode preference is stored in your own browser and never sent anywhere.

What this means in practice

We cannot recover your identity

This is the honest cost of the design. If you lose every device holding your key and have no backup, we have no way to restore it, because we never had it. The app will nag you to make a backup, and you should.

A credential you shared stays shared

Once you reveal a credential to an employer, they hold a copy that verifies on its own. You can stop sharing going forward; you cannot un-give what was given.

Institutions you join set their own terms

If you enrol in a classroom run by a school or employer, what you submit there is visible to them under their policy, not ours. The app tells you when you are entering such a space.

Deleting is local, and real

Removing the app removes your data, because that is where it lived. To remove a waiting-list address or an enquiry from our side, email us and we will delete it.

Your rights, and how to use them

For the small amount of information we do hold — essentially an email address and any correspondence — you can ask us for a copy of it, ask us to correct it, or ask us to delete it. One email is enough; we do not require a form or an account, and there is no charge.

We will tell you here when this page changes materially, and the date at the top always reflects the current version. Because everything is open source, you can also read the code that implements all of the above rather than taking our word for it.

Contact

pratyush@ifftu.dev

Alexandria Pvt. Ltd., an IFFTU product.

Read the code

github.com/ifftu-dev/alexandria

Core under the MIT Licence.

How the design works

Technology ›

Identity, sync and integrity, in detail.

Alpha · waiting list

Join the waiting list

We are letting people in a group at a time while the alpha settles. Tell us who you are and what you'd run it on, and we'll email you when it's your turn.

This joins the waiting list, not the alpha — we email you when it’s your turn.