Last updated 8 August 2026
allora is operated by Artila Studios LLC ("we", "us"). This policy explains what the allora mobile app and this website collect, why, who else processes it, and what you can do about it. It is written to be read, not to be survived.
The short version: we make money from subscriptions, not advertising. There is no advertising business here, so there is nothing that would benefit from profiling you, and we have not built anything that does.
Your email address, a username, a display name, and a password. Passwords are stored only as salted hashes by our authentication provider — we cannot see them and cannot recover them.
Posts, photos, videos, captions, comments, stories, highlights, direct messages, likes, and anything you put in your profile such as a bio, link, avatar or cover photo. This is the content of the service; we store it so we can show it to the people you've chosen to show it to.
Who you follow, who follows you, follow requests, and accounts you have blocked.
If you report a post, comment or account, we keep a record of the report, who filed it and who it concerns, so it can be reviewed. Reports filed about you are not disclosed to you — releasing them would identify the person who filed them.
Which tier you're on, when it renews or expires, and the transaction identifier issued by the App Store or Google Play. We never receive or store your card details. Payment is handled entirely by Apple or Google.
If you choose to verify your identity, the check is performed by Stripe on a page hosted by Stripe, in your own browser. allora receives only a session reference and the outcome. We do not receive, process or store your legal name, date of birth, nationality, document number or any photograph of you or your documents. Stripe's handling of that data is governed by Stripe's privacy policy.
For users in the UK, EU and other jurisdictions with similar law, our lawful bases are: performance of a contract (we cannot run an account or show your posts to your followers without this data); legitimate interests (keeping the service secure, preventing abuse, and handling reports); consent (push notifications and optional identity verification, both of which you can decline or withdraw); and legal obligation where we are required to retain or produce something.
We use a small number of service providers, each doing one job. They process data on our instructions and are not permitted to use it for their own purposes.
Some of these providers operate internationally, so your data may be processed outside your country, including in the United States. Where required, transfers rely on Standard Contractual Clauses or an equivalent safeguard.
Other people see your posts, stories and profile according to the settings you choose. If your account is private, only followers you have approved can see them. Blocking works in both directions. Direct messages are visible to the people in the conversation.
We do not read your direct messages except where we are compelled to by law, or where content is reported to us and reviewing it is necessary to act on the report.
They are not end-to-end encrypted. Messages are encrypted in transit and at rest, but we hold the keys, which means they are technically accessible to us. We would rather say so plainly than imply a protection we don't provide.
Depending on where you live, you may have the right to access your data, correct it, delete it, take it elsewhere, object to or restrict certain processing, and withdraw consent. Two of these are built into the app so you never have to ask us:
Both remain available even if your subscription has lapsed — your rights don't expire with your billing. For anything else, email [email protected].
If you're in the UK or EU and think we've handled your data badly, you can complain to your local data protection authority. We'd appreciate the chance to fix it first.
We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding twelve months. You have the right to know, delete, correct and to non-discrimination for exercising those rights; the export and deletion tools above are how you exercise the first two.
allora is not intended for anyone under 13, and we do not knowingly collect information from them. Where local law sets a higher age for consent to data processing — 16 in parts of the EU — that age applies instead. If you believe a child has created an account, email us and we will remove it.
Data is encrypted in transit and at rest. Access to the production database is restricted, and the app enforces per-row access rules at the database level rather than trusting the client to ask nicely. No system is perfectly secure, and we won't claim otherwise.
If we change this policy we'll update the date at the top, and we'll tell you in the app before anything material takes effect. We will not quietly start selling your data and note it in a diff.
Artila Studios LLC
New Jersey, United States
[email protected]
Artila Studios LLC is the data controller for the personal data described in this policy.