00Overview
This Privacy Policy explains how [OWNER-LEGAL: company legal name and registered address] (“Aetherfy”, “we”, “us”) collects, uses, and protects information when you use the Aetherfy platform, websites, APIs, SDKs, and CLI (the “Service”). It applies to account holders and visitors, and covers our roles as both a controller (for account and billing data) and a processor (for the data you store in the Service).
01Information we collect
- Account data — your name, email, and authentication identifiers, provided through Supabase Auth when you sign in with Google, GitHub, or email/password.
- Billing data — plan, subscription status, and usage records. Payments are processed by Stripe; we receive billing metadata and the last digits/brand of a card, but we do not store full card numbers.
- Customer Data — the vectors, embeddings, payloads, collections, agent code, and configuration you upload or generate. We process this on your behalf as a processor.
- Usage and diagnostic data — API request metadata, metering counters, logs, and error traces used to operate, secure, and bill the Service.
02How we use information
- to provide, maintain, and secure the Service;
- to authenticate you and manage your account;
- to meter usage and bill your plan;
- to send transactional email (see below) about your account, billing, and security;
- to monitor, debug, and improve reliability and performance, and to detect abuse.
We do not sell your personal data, and we do not use Customer Data to train models.
03Where your data is stored
Account, billing, and metadata are stored in PostgreSQL on Amazon RDS in the us-east-1 region. The Customer Data you place in the vector database is stored in the regions you choose and replicated across our regional vector replicas — us (iad), eu (fra), and ap (sin) — according to your plan and per-resource region settings. Selecting additional regions means your Customer Data is copied to those regions to serve low-latency reads.
If you are located in the EU/EEA and select non-EU regions, your data may be transferred outside the EEA. Where required, such transfers rely on an appropriate safeguard such as [OWNER-LEGAL: transfer mechanism, e.g. Standard Contractual Clauses].
04Transactional email
We send transactional email (billing notices, security and account messages) through Resend. Messages are sent from billing@mail.aetherfy.com and replies are routed to support@aetherfy.com. These messages are service-related; we do not require you to opt in to receive them while you hold an account.
05Cookies
We use cookies and similar local storage strictly to keep you authenticated and maintain your session. We do not use advertising cookies. Any product-analytics events are used to understand aggregate engagement, not to build cross-site advertising profiles.
06Third-party processors
We share data with a small set of sub-processors that help us run the Service, each bound to protect it:
- Supabase — authentication and identity;
- Stripe — payment processing and billing;
- Amazon Web Services — hosting, PostgreSQL/RDS, and regional compute and vector replicas;
- Resend — transactional email delivery.
07Data retention and deletion
We retain account and billing data for as long as your account is active and as required for legal, tax, and accounting purposes. You can delete your account from the account settings; the account-purge flow removes your Customer Data and associated resources across regions. Backups and logs are rotated on a limited schedule and then expire. Records we are legally required to keep (for example, invoices) are retained for the period the law requires.
08Security
We protect the Service with encryption in transit, tenant isolation for agent compute, hashed storage of API keys, scoped access controls, and security headers. No system is perfectly secure, but we work to protect your data commensurate with its sensitivity and to notify affected users of incidents as required by law.
09Your rights (including GDPR)
Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. If you are in the EU/EEA or UK, you have these rights under the GDPR, and you may lodge a complaint with your local supervisory authority. Our legal bases for processing include performance of our contract with you, our legitimate interests in operating and securing the Service, and compliance with legal obligations. To exercise a right, contact us at the address below.
10Children
The Service is not directed to children, and we do not knowingly collect personal data from anyone under the age required to consent in their jurisdiction. If you believe a child has provided us data, contact us and we will delete it.
11Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you.
12Contact
For privacy questions or to exercise your rights, contact [OWNER-LEGAL: data-protection / privacy contact email], or our support team at support@aetherfy.com.