Skip to content
Aerethis
← Aerethis Home Contact
Home Privacy guide Terms Contact Log in

Privacy Policy

Effective Date: February 24, 2026 · Last updated: September 6, 2026

Looking for the practical version? The privacy guide walks every feature: what it can see, where the data goes, and the switch that turns it off.

1. Our Approach

Aerenium is designed as a local-first desktop application. Your conversations, memory, and settings are stored on your own device. We collect the absolute minimum data necessary to provide licensing, subscriptions, and support.

2. What We Collect

  • Account information: If you create an account, we store your email address and a hashed password (or OAuth identity).
  • Sign-in providers: If you sign in with Google or GitHub, the provider sends us your email address, its account identifier and, if you allow it, a display name and avatar for Community. We never see your password there and cannot read or post anything on your behalf.
  • License data: Hardware ID, subscription tier, activation status, and credit balance for license enforcement.
  • Payment data: Processed by Stripe. We do not store your full credit card number. For each purchase we retain the coarse billing country Stripe determines (for tax, fraud prevention, and understanding where our users are) — never your IP address or full address on payment records.
  • Anonymous token: For token-based accounts, we store a randomly generated token to associate your subscription with your device. Tokens carry no email and are deliberately designed so they cannot be connected back to a person — by us or anyone else. Empty tokens that never receive any value are deleted automatically after 7 days.
  • Anti-abuse logs (IP addresses): To rate-limit anonymous endpoints and block spam, our servers temporarily record the requesting IP address: rate-limit counters are deleted within a day, IPs attached to proxy request metadata and contact messages are scrubbed after 30 days, and spam-offender records expire after 90 days. These logs exist only for abuse prevention — they are never used for profiling, analytics, or advertising, and are never linked to purchases.
  • Country and display-currency lookup: Unless you choose a currency yourself, the website uses your IP address to estimate a country and show local-currency prices. Our server asks ipwho.is for the country code and caches the result, keyed by IP, in process memory for up to one hour; it does not add that result to your account or payment record. If the first-party lookup fails, your browser may contact ipwho.is or api.country.is directly. Those providers then receive your IP address under their own privacy policies.

3. What We Do NOT Collect

  • Your conversation logs, prompts, or AI outputs.
  • Your files, documents, or local data.
  • Your browsing history or desktop activity.
  • Biometric data or voice recordings.

4. Third-Party Services & LLM Routing

Aerenium can reach AI models two ways, with different data paths:

  • Your own API key (BYOK) or a local model. When you configure your own provider key, your prompts go directly from your machine to that provider — we do not intermediate, see, or log them. With a local provider (Ollama, LM Studio) nothing leaves your machine at all.
  • The Aerenium proxy (credits). If you choose to spend Aerenium credits, your requests are rerouted through our infrastructure to upstream providers (via OpenRouter). To meter credits and operate the service we log request metadata — model, token counts, timestamps, and status — but we do not sell your content or use it to train models.

In both cloud cases, the upstream model providers that actually run the model have their own privacy and data-retention policies. Some upstream providers may retain prompt and output data, outside Aerenium's control. For maximum privacy, use a local model or a provider you trust directly.

Website delivery. Fonts, scripts and images on this site are served from our own server: no Google Fonts, no analytics, no advertising pixels, no social embeds. The only third parties a page visit can reach are the country lookup described above (ipwho.is or api.country.is) and, when our own rates endpoint is unavailable, a fallback exchange-rate source (open.er-api.com, then jsDelivr). Those fallback requests reveal your IP address to that provider but carry no account, payment, prompt, or license data.

5. Cookies & Local Storage

Our website sets one essential cookie: the session that keeps you signed in (marked Secure, HttpOnly and SameSite). It also keeps your chosen language, display currency, cached exchange rates, a short-lived estimated country, and the contents of your cart in your browser's local storage. None of this is used for tracking or advertising, so no consent banner is needed; clearing your browser storage removes it all.

6. Data Retention & Deletion

We keep account and license data for as long as you have an account, and payment records for as long as tax law requires. Proxy metering records keep the model, token counts, credit cost, timestamp, status, and error details for operations and billing, but their IP address and user-agent fields are scrubbed after 30 days.

You can download everything we hold about your account and delete the account yourself from the Security section of your account page. Deleting stops any running subscription at once and removes your licenses, devices, cloud backups, support messages and sign-in identities. Payment and invoice records stay on our books because the law requires it, but they no longer point at you. If you prefer, email support@aerethis.com and we will do it for you within 30 days.

7. Your Rights

Wherever you live, you can ask us what personal data we hold about you, correct it, receive a copy in a portable format, restrict or object to how we use it, withdraw a consent you gave, and have it deleted. The account page covers access, portability and deletion directly; for anything else, email us and we answer within 30 days. We never sell personal data, never share it for advertising, and never make automated decisions about you that have legal effects.

European Economic Area, United Kingdom and Switzerland. Our legal bases are: performing our contract with you (accounts, licensing, purchases, support), our legitimate interests (abuse prevention, security, understanding where our customers are), legal obligations (tax and accounting records), and your consent where we ask for it. You may complain to your local data-protection authority; we would appreciate the chance to help first.

California. You have the right to know what we collect, to delete it, to correct it, and to equal service whether or not you exercise those rights. We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and have not done so in the past 12 months. Requests can be made from your account page or by email; an authorized agent may act for you with your written permission.

8. Where Your Data Is Processed

Our servers are located in the United States. Stripe, OpenRouter and our sign-in providers also process data in the United States. If you use the service from elsewhere, your data is transferred there; our providers offer data-processing agreements that include the EU Standard Contractual Clauses where they apply, and we keep the data we hold to the minimum described above.

9. Children

Aerenium and this website are for people aged 13 and over. We do not knowingly collect personal data from anyone under 13; if you believe a child has created an account, email us and we will delete it.

10. Security & Breaches

We use TLS to protect data in transit, hash account passwords, sign license keys with RSA, offer two-step verification, and restrict access to production systems and backups. However, no system is completely secure. If a breach affects your personal data, we will notify you and the relevant authorities without undue delay, as the law requires.

11. Changes to This Policy

When this policy changes materially, we update the date at the top, tell account holders by email before the change takes effect, and ask you to accept the new version on your account page. This policy is written in English; a translation is for convenience only, and if the two differ the English text governs.

12. Where You Live

Privacy law where you live can give you more than the rights in Section 7. The section for your region applies on top of everything above. We show the region we detected from your connection; switch it if we got it wrong, or show every region.

Show every region

No region-specific section applies to you; Sections 1 to 11 are the complete policy. Your local privacy law still applies where it is mandatory.

European Union, United Kingdom & Switzerland

  • Controller. The company named at the end of this page is the controller of your personal data. We have not appointed a representative in the EU or UK; contact us directly at support@aerethis.com.
  • Legal bases are listed in Section 7: contract, legitimate interests, legal obligation, and consent where we ask for it. Where we rely on legitimate interests you may object at any time.
  • Your rights under the GDPR and the UK GDPR: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. The account page handles access, portability and erasure directly; we answer other requests within one month.
  • Transfers. Your data is processed in the United States. We rely on the Standard Contractual Clauses in our providers' data-processing agreements and on the minimisation described in Section 2; you may ask us for a copy of the safeguards.
  • Complaints. You may lodge a complaint with your national data protection authority, the UK Information Commissioner's Office, or the Swiss Federal Data Protection and Information Commissioner.

United States

  • Notice at collection. We collect identifiers (email address, hardware ID, IP address for abuse prevention), commercial information (your purchases and billing country), and internet activity limited to proxy request metadata, for the purposes in Sections 2 and 4. We keep them for the periods in Section 6.
  • No sale, no sharing. We do not sell personal information or share it for cross-context behavioral advertising, and have not in the preceding 12 months. We do not use or disclose sensitive personal information beyond what the service needs.
  • Your rights under the California Consumer Privacy Act and the privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other states: to know, access, correct, delete, and obtain a portable copy, and to appeal a refused request by replying to our answer. We never discriminate for exercising them. An authorized agent may act for you with written permission.
  • Do Not Track. We do not track visitors across other sites, so there is nothing for a browser signal to switch off; we honor Global Privacy Control signals by default because we never sell or share data.

Australia & New Zealand

  • We handle personal information in line with the Australian Privacy Principles and the New Zealand Privacy Act 2020. Sections 2 to 6 describe what we collect, why, and for how long.
  • Your data is disclosed to and stored with providers in the United States, as Section 8 explains.
  • You may access and correct your information from the account page or by email. If you are unhappy with our answer, you may complain to the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner.

China

  • If you use the service from mainland China, your account data, purchase records and proxy metadata are transferred to and processed in the United States. By creating an account or making a purchase you separately consent to that cross-border transfer for the purposes in Section 2, as the Personal Information Protection Law requires.
  • You may withdraw that consent by deleting your account from the account page; the service cannot be provided without it.
  • Your rights to access, copy, correct, delete and restrict your personal information are exercised from the account page or by email; we answer within 15 working days.

Mexico & Latin America

  • Mexico (aviso de privacidad). The party responsible for your personal data is the company named at the end of this page, at the address shown there. Purposes: providing licenses, subscriptions, purchases and support (primary); understanding where our customers are (secondary, you may object). No sensitive personal data is collected. Your data is transferred to service providers in the United States for those purposes. You may exercise your rights of access, rectification, cancellation and opposition (ARCO), and withdraw consent, from the account page or by writing to support@aerethis.com; we answer within 20 business days. Changes to this notice are announced on this page and by email as Section 11 describes. You may complain to the INAI.
  • Brazil. The LGPD rights of confirmation, access, correction, anonymisation, portability, deletion and information about sharing are exercised the same way. Our contact for data matters is the support address above.
  • Elsewhere in the region, the rights in Section 7 apply, and you may complain to your national data protection authority.

13. Contact

For privacy questions, access or deletion requests, email support@aerethis.com.

Operated by Aerethis.

© Aerethis
HomeAereniumTerms