Antigravity Alliance Inc. — AllyOS & The Kite & Wing Alliance Last Updated: March 29, 2026 Effective Date: March 29, 2026
This Privacy Policy explains how Antigravity Alliance Inc. ("we," "us," "our"), a Delaware C-Corp operating from Cape Town, South Africa, collects, uses, shares, and protects your personal information when you use our platforms, websites, mobile applications, and related services (collectively, the "Services").
We operate two distinct services:
Data Controller: Antigravity Alliance Inc. Registered: Delaware, United States Operating address: Cape Town, South Africa
Privacy Contact: privacy@thekitealliance.com Legal Contact: legal@thekitealliance.com Support Contact: support@thekitealliance.com Data Protection Officer: dpo@thekitealliance.com
We process your personal information for the following purposes across all jurisdictions:
| Purpose | Global Legal Basis |
|---|---|
| Provide and maintain the Services (accounts, bookings, session tracking, school management) | Performance of contract with you |
| Process payments and prevent fraud | Performance of contract / Legitimate interest in security |
| Respond to support requests and customer inquiries | Performance of contract / Legitimate interest in customer service |
| Send transactional emails (booking confirmations, receipts, password resets) | Performance of contract |
| Calculate AllianceScore, XP, and league rankings (Kite & Wing Alliance) | Performance of contract |
| Display wind/weather conditions at spots | Legitimate interest in providing accurate platform data |
| Improve the Services through analytics, A/B testing, and user research | Legitimate interest in platform optimization |
| Ensure platform security, prevent abuse, and detect fraud | Legitimate interest in protecting the Services and users |
| Comply with legal obligations (tax, regulatory, reporting) | Legal obligation |
| Send marketing communications (with your prior consent) | Your explicit consent |
| Enable and moderate community features (forums, reviews, check-ins) | Performance of contract / Legitimate interest in community safety |
| Maintain data backups and disaster recovery | Legitimate interest in business continuity |
| Enforce our Terms of Service and resolve disputes | Legitimate interest in protecting legal rights |
Key Commitments: We will never sell your personal data. We will never use your session or activity data to build advertising profiles. We do not share data with third parties for marketing purposes without your explicit consent.
We share personal information only in the following circumstances:
We use trusted third-party services to operate the Services. All service providers are bound by data processing agreements and are prohibited from using your data for their own purposes:
| Provider | Purpose | Data Shared | Infrastructure Location |
|---|---|---|---|
| Supabase | Database hosting, authentication, backups | All account and platform data (encrypted at rest with AES-256) | US / EU |
| Railway | API server compute hosting | Request/response data in transit (encrypted with TLS 1.2+) | US |
| Stripe | Payment processing | Transaction amounts, billing info, payment method tokens | US / EU |
| Mapbox | Maps and geolocation services | Approximate location, spot coordinates (no personal data) | US / EU |
| Open-Meteo | Weather and wind forecasting | Spot coordinates (no personal data) | Global |
| Vercel | Frontend application hosting, CDN | IP address, browser data, page requests | Global |
| Resend / Postmark | Transactional email delivery | Email address, name, email content | US / EU |
| Plausible Analytics | Privacy-friendly usage analytics | Anonymized page views, referrer, country (no personal data collected) | EU |
We may disclose your information if required by law, subpoena, court order, government request, or to protect the rights, safety, or property of Antigravity Alliance Inc., our users, or the public. We will notify you of such disclosures unless legally prohibited.
If Antigravity Alliance Inc. is acquired, merged, or sells assets, your personal information may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy and before the transfer takes effect.
Our Services operate globally. Your data may be transferred to and processed in multiple countries, including:
For transfers from the European Economic Area, United Kingdom, or Switzerland to countries without an adequacy decision, we rely on:
For transfers from South Africa, we comply with Protection of Personal Information Act (POPIA) Section 72 requirements, ensuring adequate protection through data processing agreements and encryption standards.
We retain your data for as long as your account is active, plus the following periods after account deletion:
| Data Type | Retention After Deletion | Justification |
|---|---|---|
| Account information | Deleted within 30 days | Compliance with user deletion requests |
| Session & activity data | Anonymized within 30 days (aggregate stats retained indefinitely) | Platform analytics and historical records |
| Booking & payment records | 7 years | Tax compliance and financial auditing |
| Support tickets & communications | 2 years | Legal protection and dispute resolution |
| Community content (posts, reviews, journals) | Anonymized (attributed to "Deleted User") | Historical record and community integrity |
| Server logs & access logs | 90 days | Security monitoring and troubleshooting |
| Marketing consent records | 3 years after last interaction | Legal obligation and audit trail |
| Backup & disaster recovery copies | 30 days after deletion | Business continuity and recovery procedures |
| Analytics data (Plausible) | Aggregated and anonymized (retained indefinitely) | No personal data retained |
All users, regardless of jurisdiction, have the following baseline rights:
You can exercise your rights through:
We will respond to all requests within 30 days (or sooner where required by law). We may need to verify your identity before processing your request.
This section outlines jurisdiction-specific rights and obligations. Your rights depend on where you are located. If you fall under multiple jurisdictions, the most protective standard applies.
Data Controller: Antigravity Alliance Inc., registered in Delaware, operating from Cape Town, South Africa
Data Protection Officer: dpo@thekitealliance.com
Legal Bases for Processing: - Contract: Providing the Services, processing bookings, delivering functionality - Consent: Marketing communications, optional analytics, optional third-party integrations - Legitimate Interest: Platform security, fraud prevention, service improvement, analytics, user support - Legal Obligation: Tax compliance, regulatory reporting, law enforcement cooperation - Vital Interest: Emergency situations affecting user safety
Your Rights Under GDPR: - Right of Access: Obtain confirmation of processing and receive a copy of your data - Right to Rectification: Correct inaccurate or incomplete data - Right to Erasure ("Right to be Forgotten"): Request deletion except where legal obligations require retention (e.g., tax records) - Right to Restrict Processing: Ask us to limit processing to storage only in certain circumstances - Right to Data Portability: Receive your data in a structured, portable format and transmit it to another controller - Right to Object: Object to processing based on legitimate interest or for direct marketing; we will stop processing for marketing purposes - Rights Related to Automated Decision-Making: Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects; you may request human review - Right to Lodge a Complaint: File a complaint with your local Data Protection Authority (DPA)
Supervisory Authorities: - EU/EEA residents: Contact your national Data Protection Authority - UK residents: Information Commissioner's Office (ICO) — ico.org.uk - Swiss residents: Federal Data Protection and Information Commissioner (FDPIC)
Legal Basis Transparency: For any specific processing activity, contact dpo@thekitealliance.com for details on the legal basis applied.
Information Officer: Antigravity Alliance Inc., dpo@thekitealliance.com
Processing Conditions Under POPIA: - Lawfulness: We process personal information lawfully and in good faith - Accountability: We maintain records of processing activities and data protection measures - Specific Purpose: We collect information only for legitimate, explicitly disclosed purposes - Further Processing: Secondary uses are limited to compatible purposes; marketing requires consent - Adequate & Relevant: We collect only data necessary for stated purposes - Retention: Data is retained no longer than necessary (see Section 6) - Security: We implement appropriate technical and organizational safeguards - Data Subject Rights: You have rights to request access, correction, and deletion
Your Rights Under POPIA: - Right to be Informed: Know whether we process your data, what data, and for what purpose - Right of Access: Request a copy of your personal information - Right to Correction: Correct inaccurate data - Right to Deletion: Request erasure where lawful (subject to legal retention) - Right of Objection: Object to processing of your personal information in certain circumstances - Right to Lodge a Complaint: File a complaint with the Information Regulator
Complaint Procedure: Contact the Information Regulator of South Africa: - Website: justice.gov.za - Email: inforeg@justice.gov.za - Physical Address: JD Dlamini Building, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
California Data Subject Rights:
Categories of Personal Information Collected: - Identifiers (name, email, IP address, device IDs) - Commercial information (payment history, transactions) - Internet activity (browsing history, interaction data) - Geolocation data (approximate location from IP, precise GPS if enabled) - Sensory information (profile photos, user-submitted videos) - Inferences (skill level, preferences, AllianceScore)
Data Disclosure: We do not sell or share personal information. Your data is disclosed only to service providers as outlined in Section 4.3.
How to Exercise Rights: - In-app: Account Settings → Privacy - Email: privacy@thekitealliance.com - Toll-Free Phone: Available upon request
We will verify your identity before processing requests. Requests will be fulfilled within 45 days.
Data Protection Officer (DPO) Equivalent: dpo@thekitealliance.com
Legal Bases Under LGPD: - Contract: Providing the Services and fulfilling booking obligations - Consent: Marketing communications and optional services - Legitimate Interest: Platform security, fraud prevention, service improvement - Legal Obligation: Tax compliance, regulatory reporting - Public Interest: When processing furthers public interest - Vital Interest: Emergency situations affecting safety
Your Rights Under LGPD: - Right to Confirmation & Access: Confirm whether we process your data and access it - Right to Correction: Request correction of incomplete or inaccurate data - Right to Deletion: Request erasure of personal data ("right to be forgotten") where applicable - Right to Anonymization: Request anonymization of data no longer necessary for processing purposes - Right to Data Portability: Receive your data in a portable format - Right to Withdrawal of Consent: Withdraw consent for optional processing at any time - Right to Lodge a Complaint: File a complaint with ANPD
ANPD (Autoridade Nacional de Proteção de Dados): - Website: anpd.gov.br - Complaint Portal: Available on ANPD website
Privacy Officer: dpo@thekitealliance.com
Australian Privacy Principles: We comply with the Australian Privacy Principles covering collection, use and disclosure, data quality and accuracy, data security, openness, access and correction, unique identifiers, anonymity, and transborder data flows.
Your Rights Under Australian Privacy Act: - Right to Know: Know what personal information we hold and how it's used - Right of Access: Request access to your personal information (may be restricted in limited circumstances) - Right to Correct: Request correction of incomplete, inaccurate, or out-of-date information - Right to Complain: Lodge a complaint about our handling of your personal data
Office of the Australian Information Commissioner (OAIC): - Website: oaic.gov.au - Complaint Email: enquiries@oaic.gov.au - Phone: 1300 363 992
Data Controller: Antigravity Alliance Inc.
Personal Information Protection Commission (PPC) Compliance: We comply with APPI requirements for collection, use, provision, security, and retention of personal information.
Your Rights Under APPI: - Right of Access: Request disclosure of personal information we hold - Right to Correct: Request correction of inaccurate personal information - Right to Use Suspension: Request suspension of use of personal information - Right to Delete: Request deletion of personal information in certain circumstances - Right to Lodge a Complaint: File a complaint with the Personal Information Protection Commission
Cross-Border Transfer Rules: Transfers outside Japan comply with APPI Article 23, ensuring adequate protection through: - DPAs with overseas recipients - Standard contractual clauses approved by competent authorities - Explicit user consent where required
Personal Information Protection Commission (PPC): - Website: cas.go.jp/jp/seisaku/hourei/bunsyo/personal.html
Data Controller: Antigravity Alliance Inc.
PDPA Compliance: We comply with PDPA requirements for collection, use, processing, and protection of personal data.
Consent Requirements: - We obtain explicit consent before collecting, using, or processing personal data (except in specified exceptions) - Consent must be informed, voluntary, and freely given - You may withdraw consent at any time through Account Settings
Your Rights Under PDPA: - Right to Know: Know what personal data we process - Right of Access: Request access to your personal data - Right to Correct: Request correction of inaccurate data - Right to Delete: Request deletion of unnecessary data - Right to Data Portability: Receive your data in portable format - Right to Object: Object to processing in certain circumstances - Right to Lodge a Complaint: File a complaint with the Personal Data Protection Committee
Personal Data Protection Committee: - Website: pdpc.go.th
Data Protection Officer: dpo@thekitealliance.com
PDPA Compliance: We collect and process personal data in accordance with Singapore's PDPA, including requirements for consent, accuracy, protection, retention, transfer, and notification.
Consent Model: - We obtain consent before collecting and processing personal data - Consent is explicit for sensitive personal data - You may withdraw consent at any time (though this may affect Services functionality)
Your Rights Under Singapore PDPA: - Right of Access: Request access to your personal data - Right to Correct: Request correction of inaccurate data - Right to Withdraw Consent: Withdraw consent for non-essential processing - Right to Lodge a Complaint: File a complaint with the Personal Data Protection Commission
Personal Data Protection Commission (PDPC): - Website: pdpc.gov.sg - Email: enquiries@pdpc.gov.sg
We implement comprehensive technical and organizational measures to protect your data:
Technical Security: - Encryption in transit using TLS 1.2+ (all data moving between your device and our servers) - Encryption at rest using AES-256 (all data stored in Supabase) - Row-level security (RLS) policies in our database ensuring multi-tenant data isolation - Secure password hashing using bcrypt with salt - Two-factor authentication (2FA) available for all accounts - API authentication using secure tokens with expiration and rotation
Organizational Security: - Regular security audits by qualified third parties - Dependency vulnerability scanning and automated patching - Role-based access controls (RBAC) for internal team members (principle of least privilege) - Data access logging and monitoring - Incident response procedures and breach notification protocols - Data processing agreements with all service providers - Regular staff training on data protection and information security
Limitations: No system is 100% secure. We cannot guarantee absolute security despite our best efforts. If we become aware of a data breach that affects your personal data, we will:
The Services are not directed at children under the age of 16. We do not knowingly collect personal information from children under 16 without verified parental or guardian consent.
For Users 13–16: - We require parental or guardian consent before account creation - Parents/guardians can request access to, correction of, or deletion of their child's data - We limit data collection and processing to what is necessary to provide the Services - We do not use children's data for marketing or behavioral profiling
Schools & Instructors: Schools and instructors using AllyOS are responsible for obtaining appropriate parental/guardian consent for minors enrolled in their programs.
If You Believe We Have Collected Data from a Child Without Consent: Contact us immediately at privacy@thekitealliance.com and we will delete the data as soon as reasonably possible.
The Services may contain links to third-party websites, services, applications, or integrations (e.g., WOO, Surfr, Open-Meteo, weather services, social media). We are not responsible for the privacy practices of these third parties.
We encourage you to review their privacy policies before sharing your personal data with them. Your interactions with third-party services are governed by their respective policies, not this Privacy Policy.
Third-Party Integrations: When you voluntarily connect third-party services to your account (e.g., WOO sensors, Surfr data), we will share the minimum necessary data and make clear what data is transferred.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law.
When We Make Changes: - We will post the updated policy on our website with a new "Last Updated" date - For material changes, we will notify you via email or in-app notification at least 30 days before the changes take effect - Continued use of the Services after the effective date of updates constitutes your acceptance of the updated policy - If you do not agree with updated terms, you may delete your account
If you have questions about this Privacy Policy, wish to exercise your rights, or have privacy concerns:
General Privacy Inquiries: Email: privacy@thekitealliance.com Subject line: "Privacy Inquiry — [Your Name]"
Legal Matters: Email: legal@thekitealliance.com
Data Subject Rights Requests: Email: privacy@thekitealliance.com Subject line: "Data Subject Request — [Your Name]"
Technical Support & Reported Breaches: Email: support@thekitealliance.com Subject line: "Security Issue — [Description]"
Data Protection Officer (DPO): Email: dpo@thekitealliance.com
Company Information: Antigravity Alliance Inc. Registered: Delaware, United States Operating: Cape Town, South Africa
Response Time: We aim to respond to all inquiries and requests within 30 days. For time-sensitive matters, we may respond sooner.
This Privacy Policy was drafted with consideration for international privacy laws and best practices. It is not a substitute for professional legal advice tailored to your specific circumstances. Antigravity Alliance Inc. recommends consulting with qualified legal counsel regarding data privacy compliance in your jurisdiction.
Version History: - v1.0 — March 29, 2026 — Initial global policy covering AllyOS and The Kite & Wing Alliance with regional supplements
Hey! Got questions about Ally OS? I'm here to help.