Aethros

Updated February 2026

Privacy policy

This policy explains what data we process, for what purpose and for how long, in accordance with the LGPD and the GDPR where applicable.

Data we collect

  • Account: name, email and password (stored only as an Argon2 hash).
  • Content: the conversations, code snippets and scopes you submit.
  • Usage: token volume, cost and model per request — required for credit billing.
  • Security: IP and browser user agent on audit events.
  • Payment: processed by Stripe. We never receive or store card numbers.

Why we process it

To perform the contract (operate the service and bill for it), to comply with legal obligations, and to serve the legitimate interest of keeping the platform safe from abuse.

Sharing

We send the content of your conversations to the model provider solely to generate the response you asked for. We use Stripe for payment and infrastructure providers for hosting. We do not sell data, and we do not use it to train models.

Retention

Content stays while the account exists; you can delete conversations at any time. Audit and billing records are retained for the applicable statutory period, even after account deletion.

Your rights

You have the right to confirmation of processing, access, correction, portability, anonymization and deletion of your data, as well as withdrawal of consent. To exercise them, write to privacy@aethros.io; we respond within 15 days.

Security

Secrets are encrypted at rest, traffic uses TLS, and access to production data is restricted and logged. In the event of an incident with material risk, we notify data subjects and the supervisory authority within the required deadlines.

Data protection officer

Data protection officer (DPO): privacy@aethros.io.