Security at Ally
The practical steps we take to protect your Ally account and the water-care data you trust us with.
Last updated: July 26, 2026
How we protect your data
Encryption in transit and at rest
Ally uses modern industry-standard encryption for data in transit and at rest through our cloud provider. Specific protocol versions and cipher choices are set and updated by the underlying platform over time.
Managed cloud infrastructure
Ally runs on a managed cloud platform with automated backups, DDoS protection at the platform edge, and routine patching by the provider.
Least-privilege data access
Access to production data is limited to what is needed to operate the Service. We collect only what the Service needs and do not sell personal information.
Account-scoped access controls
Row-level security policies scope reads and writes to the authenticated user. Admin actions run through separate roles with audit logs.
AI features
In-app AI processing
Ally's in-app AI features only send data you provide, such as messages, water tests, and uploaded photos. Requests are transmitted over encrypted connections to upstream AI providers listed on our Subprocessors page.
We do not promise that upstream AI providers never use inputs to improve their systems, and we do not promise a fixed automatic deletion window for AI logs. What we can commit to is using providers that are appropriate for the feature and being transparent about which ones we use.
For more detail, see AI Transparency.
ChatGPT connected app
OAuth authorization and read-only access
The ChatGPT connected app uses OAuth. It only becomes active if you sign in to Ally and explicitly approve access on the Ally authorization screen. After approval, ChatGPT can call the currently available Ally tools without asking you to approve again for each request.
The current v1 tools are read-only and scoped to your Ally account. They can list your aquatic spaces, return a snapshot with health information, return water test history for a period you choose, and return upcoming tasks. They cannot create, edit, or delete Ally records.
We intentionally keep the connector's footprint small. It does not create a dedicated Ally database store for OAuth access tokens. Passwords, access tokens, refresh tokens, and authorization codes are not intentionally logged. Ally may keep limited operational records such as tool name, request status, and diagnostic errors used to keep the connection working.
Signing out of Ally alone does not disconnect the ChatGPT connection. To stop future access, disconnect Ally inside ChatGPT's app or connector settings. For more detail, see the Privacy Policy and Privacy Rights page.
Practices we follow
Account protection
- Password hashing with an industry-standard algorithm
- Session management through the managed auth platform
- Sign in with Apple support
Application boundaries
Server functions and edge functions verify the caller and use least-privilege service roles. Client apps only see data returned by those checks. New tables are protected by row-level security policies scoped to the authenticated user.
Infrastructure and monitoring
Ally runs on a managed cloud platform with automated backups and error monitoring. We monitor reliability and investigate incidents but do not currently publish a formal uptime guarantee or service credit program.
Compliance status
We aim to align with the intent of privacy laws such as GDPR and CCPA. We do not currently hold SOC 2, ISO 27001, or similar external certifications. Compliance and certification work is ongoing and we will update this page as our posture changes.
Reporting a security concern
If you believe you have found a security issue in Ally, email security@allybywaiterapp.com with as much detail as you can share, including reproduction steps and impact. We take reports seriously and will get back to you.
We do not currently run a paid bug bounty program and do not promise a specific response deadline or reward. What we do commit to is treating good-faith reporters respectfully and working with them on a fix. For coordinated disclosure guidance, see the security research page.
Have security questions?
Reach out with any questions about how Ally handles your data.
For details on how we handle your data, see our Privacy Policy.