Legal

Privacy Policy

This policy describes what Aethora Labs Inc. does with personal information when you use aethora.ai. It is written to match how the site actually behaves rather than to cover every practice we might one day adopt, so it is specific about what we collect, name every company that receives it, and is equally specific about what we do not do.

Effective 28 August 2026

Who we are

Aethora Labs Inc. operates aethora.ai and the services reachable from it, including the business data readiness review, the referral partner programme, and The Aethora Signal publication. In data protection terms we are the controller of the personal information described here.

For anything in this policy, including requests to access or delete your information, write to privacy@aethora.ai or call (307) 317-9755.

What we collect

We collect personal information in one way only: you type it into a form and submit it. There is no tracking pixel building a profile of you in the background, and we do not buy contact data or enrich what you give us from third party sources.

Contact form

Your name, work email, company, company size, primary use case and budget range are required. A free text description of what you want to automate is optional. This is stored so a person can reply to you.

Data readiness review

Your first name, last name, work email and company are required. Job title, company website, phone number, and the name and title of a signatory are optional. The rest of the form is information about your business and your datasets rather than about you personally: systems in use, data types, volumes, coverage, rights position, headcount, revenue band and similar.

This form asks for descriptive metadata only. Do not paste actual records, protected health information, personal data about other people, credentials or API keys into it. If you do, we may delete the submission rather than store it.

Referral partner application

Your name, work email, company and a description of your audience are required. Your website is optional. If your application is approved and you activate an account, we also hold your chosen password in hashed form, and we record deals attributed to your referral code together with the business contact name and email on each deal.

Accounts

Staff and approved partners have sign in accounts holding an email address, a display name and a hashed password. Accounts cannot be created from the public site. We create them by invitation only.

Cookies, analytics and browser storage

We do not use advertising cookies, and there is no third party ad or marketing tag on this site. The only cookies we set are the ones that keep you signed in, and they are only ever set after you sign in.

Cookies set by aethora.ai
CookiePurposeLifetime
better-auth.session_tokenKeeps you signed in to a staff or partner account. Set only on sign in. Marked HttpOnly, Secure and SameSite=Lax, so it cannot be read by scripts and is not sent on cross-site requests.7 days
better-auth.dont_rememberRecords that a session should not be persisted beyond the browser session.Until the browser closes

In production these carry the __Secure- name prefix, which instructs the browser to refuse them over plain HTTP.

Analytics

We use Vercel Analytics to count page views and see which pages are read. It is a privacy preserving, aggregate product: it sets no cookies, assigns no persistent identifier, and does not follow you across other websites. We cannot use it to identify you.

Browser storage

The data readiness review is long, so as you fill it in your answers are saved in your own browser under the key aethora-data-intake-v3 in sessionStorage. This means a refresh does not cost you your progress. It stays on your device, is never transmitted to us until you press submit, is erased when you submit, and is erased by closing the tab.

One third party request

The readiness review shows logos for the business tools you can select, and those images load from a third party icon host. Loading an image discloses your IP address to that host, as any embedded image would. No other information is shared with it.

Why we use it, and on what basis

Purposes and legal bases
PurposeLegal basis
Replying to an enquiry you sent usSteps taken at your request before entering a contract, and our legitimate interest in responding to people who contact us.
Carrying out a data readiness review you asked forSteps taken at your request before entering a contract.
Assessing a referral partner application, and running the partner programme if you are approvedPerformance of our agreement with you, and our legitimate interest in vetting partners before issuing a referral code.
Operating accounts, keeping you signed in, and keeping an audit trail of partner approvalsPerformance of our agreement with you, and our legitimate interest in the security of the service.
Understanding aggregate site usageOur legitimate interest in knowing which pages are useful, balanced against your privacy by using an analytics product that does not identify you.
Meeting legal, tax and accounting obligationsCompliance with a legal obligation.

Who else sees it

We do not sell personal information, and we do not share it for advertising. We do not disclose it to anyone except the service providers below, each of which processes it on our instructions under a contract.

Service providers
ProviderWhat it doesWhat it receives
VercelHosting, content delivery and analyticsRequests to the site, including IP address, as any web host receives. Aggregate analytics events.
MongoDB AtlasThe database everything is stored inAll form submissions and account records described in this policy.
Google (Sheets API)A working copy of readiness review submissions so our team can review themThe contents of data readiness review submissions, including the name, email, phone and signatory details in them.

We may also disclose information if the law requires it, to establish or defend legal claims, or to protect the rights and safety of people using the service. If our business is acquired, information may transfer as part of that transaction, and this policy continues to apply to it until it is replaced by one that is no less protective.

AI, and what it never touches

We publish The Aethora Signal, an automated briefing written by a large language model with no human in the editing loop. It is worth being exact about what that system reads, because the honest answer is narrower than people usually assume.

  • It reads public sources only: Hacker News, dev.to and arXiv.
  • It has no access to the database holding your enquiry, your readiness review or your partner application. Those code paths do not connect.
  • We do not use anything you submit to train, fine tune or prompt any AI model, ours or a third party's.

The readiness score shown while you fill in the review is not AI either. It is a fixed arithmetic tally of the options you selected, computed in your own browser.

We do not make decisions producing legal or similarly significant effects about you by automated means. A person decides whether to approve a partner application and how to act on a readiness review.

What we do not do

Policies are usually vague here, which makes the commitments worthless. Specifically, as of the effective date of this policy:

  • We do not sell or rent personal information, and we never have.
  • We do not share personal information with advertising networks or data brokers.
  • We do not send marketing email, or any automated email at all. The site has no email sending capability. If you hear from us, a person wrote to you.
  • We do not use third party advertising or social media tracking pixels.
  • We do not attempt to identify you from analytics data, and the analytics we use makes that impossible.

How long we keep it

We keep information for as long as it serves the purpose it was collected for, and then for as long as we need it to resolve disputes and meet legal obligations. In practice:

  • Enquiries and readiness reviews are kept while the opportunity is live and for a reasonable period afterwards as a record of what was discussed.
  • Partner records, referral attribution and the partner audit log are kept for the life of the partnership and afterwards as long as needed for commission, tax and accounting purposes.
  • Rejected partner applications are kept as a record of the decision, so we can explain it if asked.
  • Account records are deleted when the account is closed, other than what an audit trail requires.
Stated plainly: we do not currently run automatic time based deletion. Records persist until they are no longer needed or until you ask us to erase them. If you want your information removed, ask, and we will do it.

Your rights

Depending on where you live you may have some or all of the following rights. We extend them to everyone who asks, regardless of location, because operating two standards is not worth the complexity.

  • Access. Get a copy of the personal information we hold about you.
  • Correction. Have inaccurate information fixed.
  • Deletion. Have your information erased, subject to records we must keep by law.
  • Portability. Receive your information in a structured, machine readable format.
  • Objection and restriction. Object to processing based on legitimate interests, or ask us to limit it while a dispute is resolved.
  • Withdraw consent. Where we rely on consent, you can withdraw it at any time without affecting what happened before.
  • No discrimination. We will not treat you differently for exercising any of these.

Write to privacy@aethora.ai or call (307) 317-9755. We respond within 30 days. We may need to confirm your identity first, which usually means replying from the address that submitted the information. You may also lodge a complaint with your local data protection authority, though we would rather you gave us the chance to fix it first.

How we protect it

Concretely, and limited to what is actually in place rather than what sounds reassuring:

  • The site is served over HTTPS only.
  • Passwords are stored hashed with scrypt. We never store or transmit them in readable form, and we cannot recover yours.
  • Session cookies are HttpOnly, Secure and SameSite=Lax, so scripts cannot read them and they are not sent on cross-site requests.
  • Accounts cannot be created from the public site. Access is by invitation, and invitation links are stored only as a hash, expire in seven days and can be used once.
  • Every read and write of stored data is authorised on the server. Partner approval is rechecked on each request, so revoking access takes effect immediately.
  • Every form submission is validated and length limited on the server before it is stored.
  • Partner lifecycle actions are written to an audit log recording who did what and when.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information we will notify you and the relevant regulator where the law requires it.

Where it is processed

We operate from the United States and our service providers process information there. If you are in the United Kingdom, the European Economic Area or Switzerland, this means your information is transferred outside your home jurisdiction. Where that transfer needs a safeguard, we rely on the European Commission's Standard Contractual Clauses, or the UK Addendum, in our contracts with the providers listed above.

Children

This is a service sold to businesses. It is not directed at children and we do not knowingly collect information from anyone under 16. If you believe a child has given us information, write to privacy@aethora.ai and we will delete it.

Changes to this policy

When we change this policy we update the effective date at the top. If a change materially affects your rights, or if we begin doing something this policy currently says we do not do, we will say so prominently rather than quietly editing the text.

See also our Terms of Service.