Skip to main content

    Trust Center

    The policies and practices that guide how we operate Ally.

    Last updated: July 26, 2026

    Policies and documentation

    Security highlights

    Encryption

    Industry-standard encryption in transit and at rest through our cloud platform.

    Least-privilege access

    Row-level security policies scope reads and writes to the authenticated user.

    Authentication

    Managed auth with Sign in with Apple and email sign-in.

    AI transparency

    Subprocessors and behavior documented rather than promised in absolutes.

    Compliance status

    GDPR

    Aim to align

    We aim to align with the intent of the EU General Data Protection Regulation. We do not currently hold a third-party GDPR certification.

    CCPA

    Aim to align

    We aim to align with California Consumer Privacy Act rights around access and deletion.

    We do not currently hold SOC 2, ISO 27001, or equivalent third-party certifications. We update this page as our posture changes.

    Data protection at a glance

    Your rights

    • Access your personal data
    • Export your data in a standard format
    • Request correction of inaccurate data
    • Delete your account and Ally-controlled data
    • Disconnect the ChatGPT app from ChatGPT settings

    Our commitments

    • Do not sell your personal data
    • Collect only what the Service needs
    • Be transparent about subprocessors and connected apps
    • Notify you of material privacy changes

    Questions about trust and security?

    Contact us with any questions about our security practices or data handling.