Skip to main content

    Security at Ally

    The practical steps we take to protect your Ally account and the water-care data you trust us with.

    Last updated: July 26, 2026

    How we protect your data

    Encryption in transit and at rest

    Ally uses modern industry-standard encryption for data in transit and at rest through our cloud provider. Specific protocol versions and cipher choices are set and updated by the underlying platform over time.

    Managed cloud infrastructure

    Ally runs on a managed cloud platform with automated backups, DDoS protection at the platform edge, and routine patching by the provider.

    Least-privilege data access

    Access to production data is limited to what is needed to operate the Service. We collect only what the Service needs and do not sell personal information.

    Account-scoped access controls

    Row-level security policies scope reads and writes to the authenticated user. Admin actions run through separate roles with audit logs.

    AI features

    In-app AI processing

    Ally's in-app AI features only send data you provide, such as messages, water tests, and uploaded photos. Requests are transmitted over encrypted connections to upstream AI providers listed on our Subprocessors page.

    We do not promise that upstream AI providers never use inputs to improve their systems, and we do not promise a fixed automatic deletion window for AI logs. What we can commit to is using providers that are appropriate for the feature and being transparent about which ones we use.

    For more detail, see AI Transparency.

    ChatGPT connected app

    OAuth authorization and read-only access

    The ChatGPT connected app uses OAuth. It only becomes active if you sign in to Ally and explicitly approve access on the Ally authorization screen. After approval, ChatGPT can call the currently available Ally tools without asking you to approve again for each request.

    The current v1 tools are read-only and scoped to your Ally account. They can list your aquatic spaces, return a snapshot with health information, return water test history for a period you choose, and return upcoming tasks. They cannot create, edit, or delete Ally records.

    We intentionally keep the connector's footprint small. It does not create a dedicated Ally database store for OAuth access tokens. Passwords, access tokens, refresh tokens, and authorization codes are not intentionally logged. Ally may keep limited operational records such as tool name, request status, and diagnostic errors used to keep the connection working.

    Signing out of Ally alone does not disconnect the ChatGPT connection. To stop future access, disconnect Ally inside ChatGPT's app or connector settings. For more detail, see the Privacy Policy and Privacy Rights page.

    Practices we follow

    Account protection

    • Password hashing with an industry-standard algorithm
    • Session management through the managed auth platform
    • Sign in with Apple support

    Application boundaries

    Server functions and edge functions verify the caller and use least-privilege service roles. Client apps only see data returned by those checks. New tables are protected by row-level security policies scoped to the authenticated user.

    Infrastructure and monitoring

    Ally runs on a managed cloud platform with automated backups and error monitoring. We monitor reliability and investigate incidents but do not currently publish a formal uptime guarantee or service credit program.

    Compliance status

    We aim to align with the intent of privacy laws such as GDPR and CCPA. We do not currently hold SOC 2, ISO 27001, or similar external certifications. Compliance and certification work is ongoing and we will update this page as our posture changes.

    Reporting a security concern

    If you believe you have found a security issue in Ally, email security@allybywaiterapp.com with as much detail as you can share, including reproduction steps and impact. We take reports seriously and will get back to you.

    We do not currently run a paid bug bounty program and do not promise a specific response deadline or reward. What we do commit to is treating good-faith reporters respectfully and working with them on a fix. For coordinated disclosure guidance, see the security research page.

    Have security questions?

    Reach out with any questions about how Ally handles your data.

    For details on how we handle your data, see our Privacy Policy.