Privacy Policy

Last updated July 14, 2026

Introduction

This Privacy Policy explains how LuxxAI LLC ("Company," "we," "us," "our") collects, uses, shares, and protects information when you use Adelphos, including the website at theoldgal.com, the Adelphos iOS application, and any related products and services (collectively, the "Services").

By using the Services, you agree to the practices described in this Policy. If you do not agree, please discontinue use of the Services. This Policy is incorporated into our Terms and Conditions.

The Services are intended for users who are at least 18 years of age. The Services are hosted in the United States. If you access the Services from another region, you consent to your data being transferred to and processed in the United States.

You can contact us about this Policy at contactus@theoldgal.com or by mail at 4508 19th Ave NE, Seattle, WA 98102, United States.

Table of Contents

  1. Information We Collect
  2. Content You Create
  3. How We Use Your Information
  4. How We Share Your Information
  5. Service Providers
  6. Cookies and Local Storage
  7. Your Privacy Controls
  8. Data Retention
  9. Account Deletion
  10. Invitations
  11. Children
  12. International Users
  13. Security
  14. Changes to This Policy
  15. Contact Us

1. Information We Collect

Account information. When you register, we collect your email address and password. Passwords are stored as hashes by our authentication provider; we do not store or have access to your plaintext password. You may also sign in through Google or LinkedIn; if you do, we receive only the identity information necessary to authenticate you and do not import additional profile fields from those services.

Profile information. You may add or edit the following in your profile: first and last name, headline, bio, location, avatar image, banner image, LinkedIn URL, graduation year, pledge class, skills, industries, what you are open to (e.g. jobs, mentorship), and whether you are willing to mentor. Most fields are optional.

Detailed profile records. You may add records for your education, work experience, and fraternity positions. Each record may include institution or company name, degree or title, field or department, start and end years, and a description.

Resume. You may upload a resume PDF. Resumes are stored in a private storage bucket and served only through short-lived signed URLs, subject to your visibility setting (see "Your Privacy Controls" below).

Fraternity verification information. To confirm your eligibility as a verified member or alumnus of Alpha Sigma Phi Fraternity, we may collect your chapter, initiation year, referral information, or other documentation you provide during onboarding or claim.

Push-notification device identifier. If you install the Adelphos mobile app and grant push-notification permission, we store the device token issued by Apple or Google alongside your profile identifier so we can deliver notifications to your device. You can revoke permission at any time in your device settings.

2. Content You Create

The Services let you create and share content. We store the content you create, including:

  • Posts, comments, and replies in groups, including any images you attach.
  • Likes and reactions.
  • Direct messages and group-chat messages, including any file or image attachments and any link previews generated for those messages.
  • Event RSVPs, event details you create, mentorship postings, and job postings.
  • Brother connections and connection requests, including any introductory message you send with a request.
  • Per-channel nicknames you choose for group chats.
  • Your "last opened" timestamps for groups and channels, so we can indicate what is new since your last visit.

Other users may see the content you post to the extent your posting context (a specific group, chat, or DM) makes it visible to them. We do not sell your content.

3. How We Use Your Information

We use the information described above to:

  • Operate the Services and let you sign in, browse, post, message, and connect with other verified members.
  • Verify your fraternity affiliation before granting access.
  • Deliver in-app notifications and, if you opt in, push notifications and transactional emails.
  • Enable messaging, groups, community chats, and events.
  • Process donations you choose to make through the website.
  • Respond to your support requests and moderate content that violates our Terms.
  • Diagnose errors and monitor performance so we can keep the Services working.

4. How We Share Your Information

We do not sell your personal information. We share it only with the service providers described in Section 5 that we need in order to run the Services, and only to the extent required for each provider to perform its function. We may also disclose information if we are required to do so by law, to enforce our Terms, or to protect the rights, property, or safety of our users or the public.

5. Service Providers

We rely on the following third-party service providers. Each processes only the information described:

  • Supabase — hosts our database, authentication, file storage, and realtime messaging infrastructure. Effectively all account, profile, and content data is stored with Supabase.
  • Stripe — processes donations made through the website. When you donate, Stripe receives your name, email address, chapter (if applicable), and the donation amount. Payment card details are entered directly into Stripe's Checkout and are never sent to or stored by us. Donations are not available in the Adelphos iOS app.
  • Resend — sends transactional email only. This includes email verification, password resets, membership approval or rejection notices, and chapter-request confirmations. Resend receives the recipient email address, first name, chapter name where relevant, and the specific link the email is delivering. We do not send marketing email through Resend.
  • Apple Push Notification service (APNs) and, on Android, Firebase Cloud Messaging (FCM) — deliver push notifications to your device. They receive the device token that identifies your device and the notification payload.
  • Vercel — hosts the website and provides Vercel Analytics and Speed Insights. Vercel receives aggregated pageview and performance data. We do not configure Vercel Analytics to identify individual users.
  • Sentry — captures error reports and performance traces so we can fix bugs. We have explicitly disabled Sentry's default collection of personally identifying information and its session-replay feature; Sentry receives error details and a sample of route timings, not your form entries or activity.
  • Google and LinkedIn — provide optional single sign-on. If you sign in through Google or LinkedIn, they receive standard OAuth authentication information; we receive only the identity information required to complete sign-in.

6. Cookies and Local Storage

We use cookies and browser storage to keep you signed in and to remember short-lived context as you move through the Services:

  • Authentication cookies maintain your Supabase session. Signing out clears them.
  • A short-lived access cookie caches your role information (whether you are a chapter admin or HQ staff) for a few minutes so the app does not re-check on every request.
  • A signup-context cookie carries your chapter and member-type selection from the sign-up form through the email verification callback into onboarding. It is cleared after onboarding.
  • Local storage in your browser holds a draft of your onboarding progress and a small amount of UI state (for example, when you last opened certain groups). This data stays in your browser and is not sent to our servers.

We do not use advertising cookies or third-party cross-site tracking cookies.

7. Your Privacy Controls

You control the visibility of several fields on your profile from Settings → Privacy inside the Services. For each of the fields below, you can choose hidden, brothers only (only members you are connected to), or members (any verified member of the Adelphos network):

  • Contact information (email, phone if provided)
  • Location
  • LinkedIn URL

Your resume defaults to hidden and is only visible to others if you change that setting. Push notifications and email notifications can be turned off in your device settings and in your notification preferences respectively.

8. Data Retention

We retain the information described above for as long as your account is active. When you or a moderator remove a post or comment, it is marked as deleted in our systems but the underlying row may be retained for a period so we can restore it if it was removed in error and so historical activity metrics remain consistent. Direct messages and group-chat messages are retained until you or your account is deleted. Invitation tokens expire seven days after they are created.

If you delete your account, we remove your data as described in Section 9.

9. Account Deletion

You can permanently delete your account at any time from Settings → Delete Account. You will be asked to type the word DELETE to confirm. This action cannot be undone.

When you delete your account, we remove your authentication record, your profile, your education, work, and fraternity-position entries, your device tokens, your memberships in groups and chapters, your posts, comments, likes, and reactions, the messages you have sent, your event RSVPs, your brother connections, and the files you have uploaded (avatars, banners, group post images, and resumes). Historical references to your account in administrative audit records — for example, a membership record that notes who approved a fellow brother years ago — are set to null rather than deleted so that the historical record remains coherent.

If you have made a donation through Stripe, the donation record itself is preserved for our financial records; the copy of your name and email in that record is retained for tax and audit purposes but is not visible to other users.

10. Invitations

The Services do not send invitation emails on your behalf. Chapter administrators generate an invitation link and share it manually (for example, by email, text message, or another channel of their choosing). When someone visits an invitation page, we mask their email so that the invited person is not exposed to unrelated viewers of the link.

11. Children

The Services are intended for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete that information promptly.

12. International Users

The Services are hosted in the United States. Our database provider and hosting provider operate in the United States by default. If you access the Services from outside the United States, you understand and consent to the transfer of your information to, and processing in, the United States, which may have different data-protection standards than your home country.

13. Security

We use industry-standard practices to protect your information. Data is transmitted over encrypted (TLS) connections. Our database enforces row-level security so that users can only read and write the rows they are permitted to. Private files are served through short-lived signed URLs rather than public links. Passwords are stored as hashes and are not accessible to us.

No system is perfectly secure. If we become aware of a security incident affecting your information, we will notify you as required by applicable law.

14. Changes to This Policy

We may modify this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. Modified terms become effective when posted, and if the change is material we will provide additional notice. Your continued use of the Services after any change constitutes acceptance of the modified Policy.

15. Contact Us

Questions about this Privacy Policy or requests about your information can be sent to:

LuxxAI LLC
4508 19th Ave NE
Seattle, WA 98102
United States
Email: contactus@theoldgal.com