ALERO AI DATA, MODEL TRAINING, AND SERVICE IMPROVEMENT

POLICY

Effective Date: August 1, 2026

Last Updated: August 1, 2026 This AI Data, Model Training, and Service Improvement Policy ("Policy") explains how AleroCore Technologies uses information to provide, evaluate, secure, and improve Alero, Alero Core, Alero AI, the Alero Reasoning Bar, and related artificial intelligence features and services.

In this Policy, "Alero," "we," "us," and "our" refer to AleroCore Technologies. "Services" refers to Alero websites, applications, APIs, Reasoning Bars, voice features, connected services, customer installations, and related technology.

This Policy supplements Alero’s Privacy Policy and Terms of Service and should be read together with those documents.

1. Purpose and Scope

This Policy applies to information processed through Alero-owned Services and Alero-powered features installed on customer websites or connected to customer systems.

It distinguishes between information used to provide and secure the Services and information that may be used for evaluation, testing, or model improvement.

Alero does not use customer or end-user content to train general-purpose Alero models by default unless the applicable customer or user affirmatively authorizes that use or a separate written agreement expressly permits it.

2. Information Covered by This Policy

Depending on how the Services are used, information covered by this Policy may include:

  • Prompts, questions, instructions, and inputs;
  • Generated responses and other outputs;
  • Feedback, ratings, corrections, and evaluation signals;
  • Conversation history and limited contextual information;
  • Uploaded documents, files, or customer-provided knowledge sources;
  • Technical information, telemetry, usage records, and performance data;
  • API requests, responses, logs, and error information;
  • Voice transcripts, summaries, and related interaction data where voice features are enabled;
  • Security, fraud-prevention, abuse-detection, and diagnostic information; and
  • Aggregated, de-identified, or derived information.

3. Use of Information to Provide the Services

Alero may process information as necessary to generate responses, maintain conversation continuity, route requests, operate customer configurations, perform authorized actions, provide technical support, and deliver other requested functionality.

This processing may involve third-party artificial intelligence, hosting, infrastructure, communications, analytics, security, or other authorized service providers.

Processing required to provide the Services is separate from using information to train a general-purpose model.

4. Security, Fraud Prevention, and Abuse Detection

Alero may use information to maintain security, detect abuse, investigate fraud, enforce usage limits, prevent unauthorized access, diagnose technical problems, and protect Alero, its customers, service providers, and users.

Alero may continue this processing even when a customer or user has limited or declined model-training use because it is necessary for system integrity, legal compliance, and core service operation.

5. Evaluation and Quality Improvement

Alero may use limited information to evaluate service quality, reliability, safety, relevance, instruction-following, routing performance, and error patterns.

Evaluation activities may include:

  • Automated testing and benchmarking;
  • Measuring response quality and consistency;
  • Reviewing error patterns and failure cases;
  • Testing safety and abuse-prevention controls;
  • Improving model routing and provider selection;
  • Assessing latency, reliability, and system performance;
  • Developing de-identified or aggregated evaluation datasets; and
  • Authorized human review of selected interactions where reasonably necessary.

Where reasonably feasible, Alero seeks to use de-identified, aggregated, sampled, redacted, or otherwise minimized information for evaluation activities.

6. General Model Training

Alero does not use identifiable customer or end-user content to train, fine-tune, or develop general-purpose shared Alero models by default.

Alero may use customer or end-user content for general model training only when:

  • The customer or user affirmatively opts in;
  • A written customer agreement expressly authorizes the use;
  • The information has been sufficiently de-identified or aggregated so that it cannot reasonably be linked to an individual

or customer; or

  • Another lawful basis and required notice or consent apply.

Opting in to general model training is not a condition of purchasing or using the standard paid Services unless a service- specific disclosure clearly states otherwise.

7. Customer-Specific Improvement

A customer may authorize Alero to use information from that customer’s account or implementation to improve customer- specific configurations, knowledge retrieval, routing rules, prompts, workflows, or related functionality.

Customer-specific improvement does not necessarily mean that the information will be used to train a general-purpose model available to other customers.

The scope of any customer-specific improvement may be described in account settings, an order form, a written customer agreement, or another service-specific disclosure.

8. Third-Party AI Providers

Alero may send inputs and related information to authorized third-party AI providers to generate responses, perform inference, support safety features, maintain reliability, or provide other requested functionality.

Alero’s intent is that third-party AI providers do not use Alero customer data to train or improve their own independent general-purpose models unless Alero has expressly enabled and documented that use and provided any required notice or choice.

Third-party providers may retain or process limited information for security, abuse prevention, legal compliance, or service reliability according to applicable agreements and provider terms.

9. Human Review

Authorized personnel or contractors may review selected interactions where reasonably necessary for technical support, security, fraud prevention, quality evaluation, incident investigation, policy enforcement, or an expressly authorized improvement activity.

Access is limited to personnel with a legitimate business need and is subject to confidentiality, access-control, and security requirements.

Alero does not represent that every interaction is reviewed by a human.

10. Data Minimization and Sensitive Information

Alero seeks to limit the personal information used for evaluation and improvement activities.

Measures may include filtering, redaction, sampling, de-identification, aggregation, access restrictions, and suppression rules.

Users and customers should not submit passwords, authentication codes, private keys, complete financial account credentials, protected health information, confidential legal communications, biometric or genetic information, Social Security numbers, or other highly sensitive information unless an approved Alero feature specifically requests it.

11. Training and Improvement Settings

Where supported by the applicable Service, Alero may offer organization-level or account-level settings that allow customers to choose how eligible content is used.

Available settings may include:

  • Private: Content is used only to provide, secure, support, and maintain the Services and to satisfy legal or operational

requirements. It is not used for general shared-model training.

  • Evaluation: Eligible content may be sampled, redacted, de-identified, or aggregated for quality evaluation, routing

improvement, safety testing, error analysis, and performance optimization. It is not used to train a general shared model unless separately authorized.

  • Training Contributor: Eligible content may be used to train or fine-tune shared Alero models after affirmative

authorization by the customer or user with authority to provide that permission.

Alero may determine which settings are available for a particular plan, account, service surface, or implementation. The selected setting may be documented through account controls, an order form, a customer agreement, or another written or electronic record.

Changing a setting generally applies prospectively after the change is processed. It does not require removal of information from prior evaluations, derived artifacts, or trained models where removal is not technically feasible or would be disproportionate, subject to applicable law.

Security, fraud prevention, abuse detection, debugging, legal compliance, recordkeeping, and core service operation may continue under every setting.

12. Customer and User Choices

Where available, customers and users may manage eligible model-improvement or training preferences through account settings, administrative controls, a written customer agreement, or by contacting Alero.

Requests may be submitted to info@alerocore.com.

A training limitation or opt-out generally applies prospectively to covered future information after the request is verified and processed.

Alero may continue processing information as necessary to provide the Services, maintain security, prevent abuse or fraud, comply with law, preserve records, resolve disputes, or maintain core system functionality.

13. Training Authorization and Withdrawal

When a customer or user affirmatively authorizes eligible content for shared-model training, Alero may record the authorization date, authorizing account, applicable organization, policy version, selected training setting, and related administrative information.

An authorized customer administrator may withdraw the organization’s training authorization through available account controls or by contacting info@alerocore.com.

Withdrawal applies prospectively after the request is verified and processed. It prevents newly covered content from being used for shared-model training but may not remove information from completed training runs, model weights, evaluation datasets, embeddings, safety classifiers, backups, or other derived artifacts where removal is not technically feasible or legally required.

Alero may retain records of the authorization and withdrawal as reasonably necessary to document compliance, resolve disputes, protect security, and satisfy legal obligations.

14. Authority to Contribute Training Content

A customer or user who authorizes content for shared-model training represents and warrants that they have the rights, permissions, licenses, and lawful authority necessary to provide the content and authorize its use for the disclosed training and improvement purposes.

Customers and users may not knowingly authorize content for training that:

  • Violates another person’s intellectual-property, privacy, publicity, confidentiality, or contractual rights;
  • Contains trade secrets or confidential information they are not authorized to disclose;
  • Was obtained unlawfully;
  • Is subject to restrictions that prohibit model training or derivative use; or
  • Includes sensitive personal information without any notice, consent, or lawful basis required for that use.

Alero may exclude, remove, restrict, or decline to use content when it reasonably believes that the required rights or authorization are missing.

15. Anonymous Users

Anonymous or unauthenticated users may not always have access to account-level training controls.

Where technically supported, Alero may apply preferences using a browser, device, session, cookie, or other identifier.

Clearing cookies, changing devices or browsers, using private browsing, or otherwise changing technical identifiers may prevent a previously applied anonymous preference from being recognized.

16. Deletion and Restriction Requests

Individuals and customers may submit deletion or restriction requests as described in the Alero Privacy Policy.

Where applicable, Alero will take reasonable steps to delete, de-identify, restrict, or exclude covered information from active source systems and future eligible improvement workflows.

Deletion from backups, logs, evaluation datasets, embeddings, safety classifiers, model weights, or other derived artifacts may not be immediate or technically feasible.

Where removal from an already trained or derived artifact is not feasible or would be disproportionate, Alero may focus on preventing future use, deleting or de-identifying source records, and applying other reasonable safeguards.

17. Retention

Information used under this Policy is retained according to the Alero Privacy Policy, applicable customer agreements, legal obligations, security requirements, and operational needs.

Raw prompts, responses, logs, evaluations, and derived artifacts may have different retention periods.

Derived artifacts may be retained longer than raw interaction records where reasonably necessary for safety, evaluation, system integrity, or lawful business purposes.

18. Enterprise and Contractual Controls

Enterprise or other eligible customers may request additional contractual or technical controls, including restrictions on general model training, retention settings, data-processing terms, or other customer-specific protections.

Any such controls must be documented in an authorized written agreement, order form, or account configuration.

Where a specific written agreement conflicts with this Policy, the more specific written agreement controls for the applicable customer.

19. Customer Responsibilities

Customers that embed, configure, or operate Alero are responsible for:

  • Providing legally required privacy and AI disclosures;
  • Obtaining any required permission or consent from end users;
  • Ensuring that customer-provided content is accurate, lawful, and authorized;
  • Avoiding submission of unnecessary sensitive information;
  • Managing account and integration permissions;
  • Honoring customer-specific commitments made to their own users; and
  • Complying with privacy, consumer-protection, communications, recording, and industry-specific laws.

20. Reasoning Bar and API Disclosures

Alero may provide short, point-of-use disclosures for the Reasoning Bar, APIs, voice features, or other service surfaces.

Those disclosures supplement this Policy and may explain what information is processed, whether limited context is used, and what choices are available.

Customers are responsible for displaying or implementing required end-user notices associated with their installation.

21. No Sale or Cross-Context Behavioral Advertising

Alero does not treat model evaluation or improvement activities described in this Policy as a sale of personal information or sharing for cross-context behavioral advertising.

Alero does not sell personal information or share it for cross-context behavioral advertising as those terms are defined under applicable California privacy law.

22. Changes to This Policy

Alero may update this Policy as its technology, Services, data practices, and legal obligations evolve.

The “Last Updated” date identifies the most recent version.

Alero will not materially expand the use of previously collected identifiable customer or end-user information for general model training without providing any notice, choice, or consent required by applicable law.

Material changes will apply prospectively unless applicable law permits or requires otherwise.

23. Contact Information

Questions, training-preference requests, privacy requests, and concerns regarding this Policy may be directed to:

AleroCore Technologies Email: info@alerocore.com Mailing Address: 5757 West Century Blvd, Suite 120 Los Angeles, California 90045 Website: aleroai.ai