Home
Privacy Policy

Privacy Policy

Last updated: September 22, 2026

1. Introduction

This Privacy Policy explains how Entalpa Corp. (“we”, “us”, “our”), a corporation incorporated in the State of Delaware, United States (File No. 10580292), collects, uses, and protects your personal data when you use the Entalpa platform (“Service”).

Our mailing address is: 228 Park Ave S, PMB 85451, New York, NY 10003, United States.

As a US-based company serving users globally, we comply with applicable privacy laws including the EU General Data Protection Regulation (GDPR) for users in the European Economic Area, and the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 for users in the United Kingdom.

Data protection contact: contact@entalpa.com

2. Data We Collect

2.1 Account Data

When you register, we collect your email address and, optionally, your name. Passwords are managed by our authentication provider and are not stored directly by the Service.

2.2 Project and Content Data

We store the projects, requirements, user stories, and stakeholder information you create or import, along with collaboration settings and edit history.

2.3 Usage Data

We collect data about your use of AI features, including credit consumption and usage history.

2.4 Technical Data

We may collect standard technical information such as browser type, device information, and error monitoring data (including IP address) to maintain service reliability.

2.5 Payment and Transaction Data

Credit purchases use Stripe-hosted Managed Payments Checkout. Stripe and Link collect the contact, billing, location, device, fraud-prevention, and payment information needed to complete the transaction. Entalpa's hosted integration does not receive or store your full card number, bank-account credentials, or payment authentication codes.

Entalpa receives and retains the transaction evidence needed to grant credits, reconcile payments and refunds, prevent abuse, and provide product support. This can include your Entalpa account identifier, purchase and product references, quantity, amount, currency, provider transaction identifiers, payment status, and refund status. Stripe sends receipts, invoices, and refund notifications from Link; transaction support is available through Link, while Stripe handles payment disputes.

2.6 Cookies, Analytics and Advertising Measurement

We use strictly necessary cookies to operate the Service (for example, to keep you signed in). These do not require consent.

With your consent, we also use Google Analytics (provided by Google LLC) to understand how visitors use our site and application. Google Analytics sets cookies that collect information such as pages visited, session duration, approximate location (derived from IP, which we configure to be anonymised), device type, and referring source. We do not load Google Analytics until you accept via our cookie banner, and you can reject or withdraw consent at any time by clearing your browser storage for this site.

We advertise Entalpa on third-party platforms. With your separate consent, we use conversion measurement provided by those advertising platforms at three points: when you generate a draft with the free demo on our site, when you follow the prompt to create an account in order to keep that draft, and when an account is first created. Its purpose is narrow: to tell us which of our advertisements led to someone trying Entalpa or signing up, so we can judge which campaigns are worth running. Each measurement is tied to the thing it counts — the draft you generated, or the new account — rather than to a page you visit, which is what allows each step to be counted once rather than on every visit. The two demo measurements involve no account and no name or email address; the draft reference is discarded with the draft itself. Our cookie banner asks for analytics and advertising separately, and refusing advertising does not affect anything else on the site — the conversion is then measured without storing anything on your device.

We do not use these cookies to build advertising profiles about you, and we do not run remarketing or interest-based advertising.

The legal basis for both analytics and advertising cookies is your consent (Article 6(1)(a) GDPR and the Privacy and Electronic Communications Regulations). You can change or withdraw either choice at any time by clearing your browser storage for this site, which brings the banner back.

2.7 Demo Submissions Without an Account

Our public pages let you generate a sample project from a product idea without registering. When you do, we store the text you submitted and the project generated from it, and we set a cookie in your browser so that only you can later claim that draft. The idea you type is sent to the AI provider listed in section 4 in order to generate the sample.

We do not store your IP address with the submission. Your IP is counted in a short-lived, self-expiring counter used only to limit how many samples one visitor can generate per day; it is not linked to the submission or retained beyond 24 hours.

An unclaimed draft, including the text you submitted, is deleted automatically 7 days after it is created. If you register and claim the draft, it becomes part of your project data and is covered by section 7.

2.8 What We Do Not Collect

Entalpa does not use cross-site tracking, advertising profiles, remarketing or interest-based advertising. We do not perform device fingerprinting or collect precise geolocation. Stripe and Link handle payment-country, billing-location, device, and fraud signals as described in 2.5; outside that transaction context, our analytics provider may derive only an approximate location from IP with your consent. Our only advertising use of cookies is the conversion measurement described in 2.6, and only with your consent.

3. How We Use Your Data

We use your data to provide and operate the Service, including AI-powered features. We also use it for billing, error monitoring, responding to support requests, and improving service security and reliability.

For EU and UK users, our legal bases are performance of contract (Article 6(1)(b) GDPR) and legitimate interest (Article 6(1)(f) GDPR) as applicable to each purpose.

For credit purchases, we use transaction evidence to grant the purchased credits, maintain the billing ledger, reconcile refunds, answer product-support requests, and comply with accounting, security, fraud-prevention, and legal obligations.

4. Third-Party Services and Payment Providers

We use trusted third-party service providers to operate the Service, including cloud infrastructure providers, AI inference providers, an authentication service, a bot-protection provider, error monitoring tools, an email delivery provider, and — subject to your consent — an analytics provider and the advertising platforms we run campaigns on, for the conversion measurement described in 2.6. Providers that process data on our instructions are bound by data processing agreements or equivalent safeguards. We will tell you which providers these are on request.

Your project content is sent to a third-party AI inference provider (such as Anthropic, OpenAI, Google, Cerebras, or AWS Bedrock) to generate and analyse requirements. This data is processed solely to return results to you and is not retained by the provider. We do not use your content to train AI models, and our agreements with AI providers prohibit them from using your data for model training.

We do not sell your data. We do not share your data for advertising purposes.

Stripe acts as merchant of record for credit purchases through Managed Payments, while Checkout and customer communications identify the purchase as sold through Link. For the transaction, tax, fraud, dispute, receipt, and payment-support functions they control, Stripe and Link operate under their own terms and privacy notices rather than solely on Entalpa's instructions. See the Stripe Privacy Policy and Link Privacy Policy.

5. Connected Clients and Integrations

Entalpa can be connected to an external AI client or coding agent — for example through the Model Context Protocol (MCP). This section describes what that authorisation means, because it is different in kind from the processors listed in section 4.

A connected client acts with your account's permissions. Once you authorise it, it can read and modify the same projects, requirements, stories and stakeholders that your account can already reach, as described in 2.2. It gains no access you do not already have, and none to other users' data.

Authorisation uses OAuth. You approve it in your browser, and the client receives a token rather than a password. We do not issue an API key for this, and the client never receives your Entalpa credentials.

The client is chosen and run by you, and it is not one of our processors. Content it reads from your projects is typically sent onward to whichever model provider that client uses — which may be a different company from the AI providers named in section 4, and may be a model running on your own machine. We neither select nor control that provider, and the safeguards described in section 4 do not extend to it. Reviewing the privacy terms of any client you connect is worth doing before you authorise it.

The Entalpa MCP server is remote — it runs on our infrastructure at api.entalpa.com/mcp. No Entalpa software is installed on, or runs on, your own computer.

You can revoke access at any time from your account settings, or by removing the connection in the client itself. Revoking takes effect immediately for new requests. If you would like confirmation of which clients are currently authorised on your account, contact us using the details in section 13.

6. International Data Transfers

Entalpa Corp. is based in the United States. Your data may be stored and processed in the US and other countries where our service providers operate.

If you are located in the EU or UK, we ensure appropriate safeguards are in place for international transfers, including EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) where applicable.

Stripe and Link may process Managed Payments data in the countries described in their own privacy notices and apply their own transfer safeguards to that processing.

7. Data Retention

We retain your account and project data for as long as your account is active, or for 12 months following your last activity. Billing and usage records are retained for 7 years as required by law. Error monitoring logs are retained for 90 days. Upon account deletion, we delete or anonymise your personal data within 30 days, except where retention is required by law.

Stripe and Link control retention and deletion of the Managed Payments and Link data they hold. A request to delete transaction data from Stripe or Link is separate from a request to delete your Entalpa account. Entalpa can still retain limited billing evidence where accounting, fraud-prevention, dispute, or other legal obligations require it.

Samples generated without an account (section 2.7) are deleted 7 days after they are created unless you register and claim them. The per-visitor rate-limit counters described there expire on their own within 24 hours.

8. Data Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit, hashed authentication credentials, access controls, and infrastructure hosted in secure data centres.

9. Your Rights

EU and UK users have the right to access, correct, delete, restrict, or port their personal data, to object to processing based on legitimate interest, and to withdraw consent where applicable. We support data export in ReqIF and CSV formats.

All users may contact us at any time to access, correct, or delete their personal data.

To exercise your rights, contact us at contact@entalpa.com. We will respond within one month.

To exercise rights over data held in your Link account or Managed Payments transaction records, use Link or Stripe's privacy channels. We will assist with the Entalpa records we control, but we cannot promise to delete records independently controlled or legally retained by Stripe or Link.

10. Children's Data

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will delete it promptly.

11. Complaints

EU users may lodge a complaint with their local data protection supervisory authority. A list of EU authorities is available at edpb.europa.eu.

UK users may contact the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

We encourage you to contact us first so we can try to resolve your concern.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via the Service. The “Last updated” date at the top indicates the most recent revision.

13. Contact

For any questions about this Privacy Policy or your personal data:

Entalpa Corp.
228 Park Ave S, PMB 85451
New York, NY 10003, United States
Email: contact@entalpa.com