Only activated data sources
Alcilla does not access available data indiscriminately. Which systems are connected and which content is processed depends on your configuration.
Alcilla is designed for enterprises that want to leverage AI-assisted workflows without giving up control over their data and infrastructure. That's why there is no prescribed operating model. You decide what content is processed locally, what shared data is provided centrally in your environment, and which selected functions run via Alcilla.Station. The specific data processing always depends on the functions you activate and the services you connect.
At the local single-user workstation, Alcilla runs on the user's computer. Personal content such as notes, chat histories, local knowledge bases, and Recorder recordings can be processed and stored there.
Alcilla.Hub provides shared enterprise knowledge and common content centrally and authorization-dependent for multiple users. Alcilla.Nexus connects your own AI servers through a unified mediation and load-balancing layer.
Alcilla.Station provides selected AI and supplementary services on our infrastructure in Germany. You determine which services to use; other functions can remain local independently.
Alcilla does not access available data indiscriminately. Which systems are connected and which content is processed depends on your configuration.
Customer data is not used for AI model training. Work content is also not sent to Alaska.Labs for analysis, advertising, or product improvement purposes.
You determine the operating model, data sources, AI models, and permissions. For external services and recordings, the respective legal and organizational requirements must also be observed.
Alcilla processes different data depending on the selected product and activated features. As a general rule everything is processed locally except for Alcilla.Station. This can include emails and attachments, calendar data (appointments and contacts), notes and chat histories, documents and searchable content generated from them, local or central knowledge bases, Recorder contents, audio recordings, transcripts and meeting minutes, as well as detected tasks, decisions and appointments. The knowledge store is fed by these various functions, and all functions can access it in return. Connected systems include for example email servers (IMAP/SMTP), calendars and contacts (CalDAV/CardDAV), file and document servers, research services, custom model endpoints, or Alcilla.Station. Content may also be processed for summaries, extractions, and other AI-assisted operations.
The storage location depends on the selected operating model and your configuration. In the local operating model, personal work content is processed and stored on the respective workstation. This includes among other things emails, notes, chat histories, local knowledge bases, and Recorder contents. With Alcilla.Hub, all data also remains stored locally on the respective workstation — with two exceptions: shared Kanban boards and the shared live editor reside on the central Hub instance in your controlled infrastructure. Similarly, shared knowledge indices released by the Hub are located on the Hub itself, not locally on the workstations. With Alcilla.Nexus, the actual AI processing also remains on your own AI servers, while the remaining data is treated as in local operation.
During purely local operation with local models, no external model calls are generated. External connections arise only through functions that you configure yourself — for example to email servers via IMAP/SMTP, calendars and contacts via CalDAV/CardDAV, file and document servers, research services, custom model endpoints, or Alcilla.Station. Whether data remains within your own infrastructure or leaves your company depends on the respective target system. Only the content that the configured service requires for the requested function is transmitted.
Alcilla.Station processes only the content necessary for each activated service. For a transcription, these are for example the relevant audio data; for document conversion or indexing, the selected documents are transferred. On the Station side, no human ever sees the content, there is no content logging whatsoever, and no data is passed on to third-party AI providers. The processing is described as purpose-bound. You determine which Station services are active — other features like email, Kanban and notes remain local independently.
No. Customer data is not used for training AI models. This applies to local models, customer-owned AI servers, and services provided via Alcilla.Station. With Alcilla.Station, processing is purpose-bound for the respective request, without content logging and without passing on to third-party AI providers. For external model endpoints that you configure yourself, the data protection and terms of use of the respective provider additionally apply.
Alcilla does not transmit product telemetry. Emails, chat histories and other work content are not sent to Alaska.Labs for analytics, advertising, or product improvement purposes. For Alcilla.Station, processed content is not logged. For all other operating models — local, Alcilla.Nexus and Alcilla.Hub — logging and monitoring are entirely the customer's responsibility within their own infrastructure; Alcilla does not automatically transmit anything externally there either. Technical metadata from licensing, update checks, error reports, or support incidents should be documented separately depending on the specific version in use.
No central account is required for the local standalone mode. In central operation with Alcilla.Hub, login is via an OIDC-compatible identity provider already present at your organization, such as Keycloak. Groups and roles from the OIDC token form the source of authority for shared areas. Shared knowledge bases and Kanban boards can be linked to existing group structures. Searching follows a default-deny principle: if there is no matching access rights hit, the respective area is not displayed.
Yes. Alcilla only integrates mailboxes, calendars, files and other systems when these functions are configured and selected for the respective purpose. Data sources that are not connected or not selected do not enter processing. Additionally, the search scope in the RAG chat can be limited to specific folders, sources or shared knowledge areas; document search can also be deliberately disabled for general questions. This allows sensitive folders, mailboxes or data sources to be completely excluded depending on configuration.
Alcilla.Hub supports end-to-end TLS encryption. This can be implemented natively or via a reverse proxy. Secrets (credentials) are stored encrypted. Whether and how application data, local databases, central knowledge stores and backup copies are additionally encrypted at rest depends on the respective installation and infrastructure — for example disk or database encryption — and should be reviewed and defined separately for the specific operating model.
Locally stored data remains under your control and is managed within the respective Alcilla environment. This includes personal knowledge bases, chat histories, transcripts and other local work content. Original content, converted content, transcripts, chat histories, local knowledge bases and search indices can be removed from the respective Alcilla environment or from connected stores when sources are no longer in use (delete or rebuild indices). For central content and managed services, deletion options, retention periods, backup copies and recovery rules follow the specific installation or agreed service. Specific deadlines for Station processing, handling of backups, retention of central Hub data, as well as export and complete tenant deletion are established before deployment.
The Alcilla Recorder can process audio recordings locally and create transcripts and structured minutes from them. Transcripts can be imported into the local knowledge index and become searchable via RAG chat. Central processing occurs only when a corresponding service has been configured; during a transcription via Alcilla.Station, the required audio data is transferred to Alcilla.Station. Speakers in the minutes can be named or anonymized. All participants must be informed before recording begins and consent to the recording. The person or organization initiating the recording is responsible for lawful use and compliance with legal, labor law and internal requirements.
You decide on the specific operating model, connected data sources, AI models used and authorized persons. This includes in particular to connect only necessary systems and services, regularly review access rights, define appropriate storage and deletion rules, secure local systems and endpoints, and examine the legal basis for processing. For recorder recordings, consent of all participants must be obtained. Self-configured external providers must additionally be evaluated for data protection compliance.
External connections arise exclusively for services that you set up and configure yourself. Whether data is processed solely within your own infrastructure or leaves your company depends on the respective target system. Alcilla.Nexus is the operating model running Alcilla on your own enterprise infrastructure, while Alcilla.Station is our operated public service.
Which architecture is suitable depends on your data, existing infrastructure, and organizational requirements. Alcilla can start completely local and later be actively expanded with central or managed components.