Alcove Docs

Safety

Secrets, private trip data, and what Alcove will not do silently.

Secrets stay out of git

Never commit passwords, passport numbers, confirmation codes, card data, or API keys into a trip repository. Use a vault or connector for booking secrets. PR templates in the starter remind you before merge.

Private by default

Trip repos you connect remain under your GitHub visibility settings. Alcove does not publish private trip content to the marketing site or make private repos public.

Subject memory is account-scoped. Lessons are not applied to a trip until a human accepts a change that lands as a PR.

No silent mutation of main

Alcove review and watch propose. Only the traveler merges. Alcove does not auto-merge.

Provenance honesty

Claims about people or outcomes should carry a provenance label when recorded in memory or research: verified, connector-derived, repo-derived, user-reported, inferred, or unknown. Do not invent observed behavior from itinerary state alone.

Abuse and fair use

Automated review is rate-limited. Fair-use limits protect the service from bot loops; they are not a substitute for your own operational security.

On this page