Privacy Policy
Last Updated: July 12, 2026
Aetheris AI LLC · 30 N Gould St Ste R, Sheridan, WY 82801 · asia@aetherisai.online
1. Introduction
Who We Are. Aetheris AI LLC ("Aetheris," "we," "us," or "our") is a Wyoming limited liability company that provides an AI-powered real estate chatbot platform and a marketplace connecting freelancers with AI-powered tools. Our website is https://aetherisai.online (the "Site"). Our services include conversational AI bots for real estate professionals and a subscription-based platform for freelancers (collectively, the "Services").
Our Commitment. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and safeguard your information when you visit our Site, use our Services, or interact with our AI chatbot. It also describes your rights under applicable privacy laws, including the General Data Protection Regulation (GDPR) for visitors in the European Economic Area and the California Consumer Privacy Act (CCPA) for California residents.
Scope. This policy applies to:
- Visitors to our Site
- Real estate agents and brokers who use our AI chatbot ("Clients")
- End-users who interact with our AI chatbot on behalf of our Clients ("End-Users")
- Freelancers who use our platform ("Freelancer Users")
- Anyone who subscribes to our newsletters or marketing communications
By using our Site or Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Services.
Responsible Party. The data controller responsible for your personal data is:
2. Information We Collect
We collect information that you provide directly, information generated through your use of our Services, and information collected automatically.
2.1 Information You Provide Directly
| Category | What We Collect | Purpose |
|---|---|---|
| Account & Profile Data | Full name, email address, phone number, business name, professional license number (if applicable), password | Account creation, identity verification, communication |
| Payment Information | Credit/debit card details (processed by Stripe; we do not store full card numbers) | Billing, subscription management |
| Client API Keys | Third-party API keys you voluntarily enter into our platform (e.g., OpenAI API keys) | Powering your chatbot instance |
| Chatbot Conversations | Message content, timestamps, conversation transcripts, property preferences, lead contact details | Delivering AI responses, lead capture, conversation history |
| Support Communications | Email content, support tickets, feedback | Customer support, service improvement |
| Marketing Preferences | Subscription status, email open/click data | Marketing communications (CAN-SPAM compliant) |
2.2 Information Collected Automatically
| Category | What We Collect | Purpose |
|---|---|---|
| Device & Browser Data | IP address, browser type, operating system, screen resolution, language preference | Security, analytics, troubleshooting |
| Usage Data | Pages visited, features used, session duration, click patterns | Service improvement, analytics |
| Cookies & Tracking Data | See Section 6 below | Analytics, personalization, security |
| Log Files | Server logs, error reports, access times | System monitoring, debugging, security |
2.3 Information from Third Parties
- Payment Processor (Stripe): Transaction confirmation, subscription status, billing history.
- Analytics Providers (Google, Microsoft): Aggregated usage statistics (see Section 6).
- Social Media Platforms: If you connect via social login (if applicable), we receive profile information as authorized by you.
Important Note on API Keys: When you (as a Client) enter your own third-party API key (e.g., OpenAI API key) into our platform, that key is stored securely in our database and is used only to route your chatbot's requests to the respective API provider. You are responsible for all usage charges, token costs, and compliance with that API provider's terms. We do not use your API key for any other purpose, and we do not share it with other users.
3. How We Use Your Information
We use your information for the following lawful purposes:
3.1 To Provide and Operate Our Services
- Train and operate your AI chatbot instance
- Process and respond to End-User conversations in real time
- Route chatbot requests to third-party AI providers using your supplied API key
- Send lead notifications and conversation summaries to Clients
- Manage your account, subscription, and billing
3.2 To Improve and Develop Our Services
- Analyze usage patterns to improve chatbot accuracy and features
- Conduct research and development on our AI models and platform
- Test new features and functionality
- Monitor service performance and reliability
3.3 To Communicate With You
- Send transactional emails (account creation, password resets, billing receipts)
- Send service-related announcements (maintenance, updates, security alerts)
- Respond to your support requests
- Marketing emails: We send promotional emails only to users who have opted in, and every email includes an unsubscribe link. We comply fully with the CAN-SPAM Act (see our CAN-SPAM Checklist in Part III).
3.4 For Security and Legal Compliance
- Detect, prevent, and address fraud, unauthorized access, and abuse
- Enforce our Terms of Service
- Comply with legal obligations, court orders, or regulatory requirements
- Protect the rights, safety, and property of Aetheris, our users, and the public
3.5 Legal Bases for Processing (GDPR)
For individuals in the European Economic Area, our legal bases for processing personal data are:
| Purpose | Legal Basis |
|---|---|
| Providing Services | Performance of a contract (Art. 6(1)(b) GDPR) |
| Marketing (with consent) | Consent (Art. 6(1)(a) GDPR) |
| Analytics & Improvement | Legitimate interest (Art. 6(1)(f) GDPR) |
| Legal Compliance | Legal obligation (Art. 6(1)(c) GDPR) |
| Fraud Prevention | Legitimate interest (Art. 6(1)(f) GDPR) |
4. Data Storage & Security
4.1 Where We Store Your Data
All data is stored in Supabase, a cloud-hosted PostgreSQL database. Our infrastructure is hosted in secure data centers within the United States.
| Data Type | Storage Location | Retention Period |
|---|---|---|
| Account data | Supabase (US) | Until account deletion + 7 years (tax records) |
| Chat transcripts | Supabase (US) | 12 months from conversation date |
| API keys | Supabase (US), encrypted at rest | Until removed by user or account closure |
| Payment records | Stripe (US) | Per Stripe's data retention policy |
| Server logs | Supabase (US) | 90 days |
| Marketing data | Email service provider (US) | Until unsubscribed + 2 years |
4.2 Security Measures
We implement industry-standard security measures to protect your data:
- AES-256 Encryption: All sensitive data, including API keys and chat transcripts, is encrypted at rest using AES-256 encryption.
- Row Level Security (RLS): Supabase Row Level Security policies ensure that users can only access their own data. No user can access another user's conversations, API keys, or account information.
- TLS/SSL: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Access Controls: Strict role-based access controls limit who at Aetheris can access production data. Only Asia Algarni (Owner) and authorized technical personnel have database access.
- Regular Backups: Automated daily backups with point-in-time recovery capability.
- Security Audits: Periodic security reviews and dependency updates.
- No Plain Text Storage: API keys are never stored or transmitted in plain text.
4.3 Data Breach Response
In the unlikely event of a data breach, we will: 1. Contain and investigate the breach within 72 hours of discovery 2. Notify affected users via email within 72 hours if their personal data was compromised 3. Report to relevant supervisory authorities as required by GDPR Article 33 (within 72 hours) 4. Cooperate fully with law enforcement if criminal activity is suspected 5. Take all reasonable steps to mitigate harm and prevent recurrence
4.4 International Data Transfers
If you are located outside the United States, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA to the US. We ensure that all third-party service providers who process your data offer adequate protections.
5. Client API Keys — How We Handle Them
5.1 Your API Key, Your Responsibility
Our platform allows Clients to enter their own third-party API keys (such as OpenAI API keys) to power their chatbot instances. This is a core design principle: you bring your own API key, and you pay the AI provider directly for token usage.
5.2 What We Do With Your API Key
| Action | Detail |
|---|---|
| Storage | Encrypted at rest using AES-256; stored in your isolated row in our database |
| Usage | Used exclusively to route your chatbot's API requests to the relevant provider |
| Access | Accessible only to your account's chatbot instance; no other user can see or use your key |
| Sharing | Never shared with third parties, other users, or used for any purpose other than your chatbot |
| Visibility | Never displayed in full after initial entry; shown masked (e.g., `sk-...abc12`) in the UI |
5.3 Your Responsibilities
- Secure your API key: Do not share your API key with unauthorized parties.
- Monitor usage: Regularly check your usage dashboard with the API provider to detect anomalies.
- Rotate keys: We recommend rotating your API key every 90 days.
- Compliance: Ensure your use of the API provider's services complies with their terms of service.
- Costs: You are solely responsible for all charges incurred through your API key, including token usage fees.
- Revocation: You may delete or replace your API key at any time from your dashboard.
5.4 API Key Deletion
- When you remove an API key from our platform, it is permanently deleted from our database within 24 hours.
- If you close your account, all associated API keys are deleted immediately as part of account termination.
- Deleting your key from our platform does not deactivate the key at the API provider — you must do that separately.
6. Cookies & Tracking Technologies
6.1 What Are Cookies?
Cookies are small text files stored on your device that help us recognize you and improve your experience. We also use similar technologies such as pixel tags and local storage.
6.2 Cookies We Use
| Category | Provider | Purpose | Duration |
|---|---|---|---|
| Essential | Aetheris | Authentication, security, session management | Session / 30 days |
| Analytics | Google Analytics 4 | Website traffic analysis, user behavior, conversion tracking | 2 years |
| Analytics | Microsoft Clarity | Session recordings, heatmaps, user interaction analysis | 1 year |
| Functional | Aetheris | Remember preferences (language, theme) | 1 year |
| Security | Supabase Auth | Prevent fraud, secure login sessions | Session |
6.3 Your Choices
- Browser Settings: You can configure your browser to refuse all cookies or alert you when cookies are being sent. However, some features of our Site may not function properly without essential cookies.
- Google Analytics Opt-Out: You can install the Google Analytics Opt-Out Browser Add-on.
- Microsoft Clarity: For more information, visit Microsoft's Privacy Statement.
- Do Not Track: Our Site currently does not respond to "Do Not Track" signals, but we do not engage in cross-site tracking for advertising purposes.
6.4 Third-Party Analytics Disclosures
Google Analytics 4:
- We use GA4 to understand how visitors interact with our Site.
- GA4 collects IP addresses (anonymized where possible), device information, and usage patterns.
- Google may use this data to contextualize and personalize ads on its own advertising network.
- For more information, see Google's Privacy Policy.
Microsoft Clarity:
- We use Microsoft Clarity to record user sessions (with anonymized data where possible) and generate heatmaps.
- This helps us identify usability issues and improve our Site.
- For more information, see Microsoft's Privacy Statement.
We do not sell your personal information to third parties for advertising purposes.
7. Your Rights
7.1 For All Users
Regardless of your location, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (subject to legal retention requirements).
- Export: Request your data in a structured, machine-readable format.
- Objection: Object to certain types of processing (e.g., marketing).
- Withdraw Consent: Withdraw consent for processing based on consent at any time.
7.2 GDPR Rights (European Economic Area Residents)
If you are in the EEA, you have the following additional rights under GDPR:
| Right | Description | How to Exercise |
|---|---|---|
| Right to Access (Art. 15) | Obtain confirmation of processing and a copy of your data | Email asia@aetherisai.online with subject "GDPR Access Request" |
| Right to Rectification (Art. 16) | Have inaccurate data corrected without undue delay | Email asia@aetherisai.online with subject "GDPR Rectification Request" |
| Right to Erasure (Art. 17) | Have your data deleted ("right to be forgotten") | Email asia@aetherisai.online with subject "GDPR Deletion Request" |
| Right to Restrict Processing (Art. 18) | Limit how we use your data in certain circumstances | Email asia@aetherisai.online with subject "GDPR Restriction Request" |
| Right to Data Portability (Art. 20) | Receive your data in a structured, commonly used format | Email asia@aetherisai.online with subject "GDPR Portability Request" |
| Right to Object (Art. 21) | Object to processing based on legitimate interests or direct marketing | Use unsubscribe link in emails or email asia@aetherisai.online |
| Right to Lodge a Complaint | File a complaint with your local supervisory authority | Contact your national data protection authority |
We will respond to all GDPR requests within 30 days of receipt. There is no fee for making a request unless it is manifestly unfounded or excessive.
7.3 CCPA Rights (California Residents)
If you are a California resident, you have the following rights under the CCPA/CPRA:
| Right | Description | How to Exercise |
|---|---|---|
| Right to Know | Request disclosure of categories and specific pieces of personal information collected | Email asia@aetherisai.online with subject "CCPA Know Request" |
| Right to Delete | Request deletion of personal information collected from you | Email asia@aetherisai.online with subject "CCPA Delete Request" |
| Right to Opt-Out of Sale | We do not sell personal information. If this changes, we will provide an opt-out mechanism. | N/A — we do not sell data |
| Right to Non-Discrimination | We will not discriminate against you for exercising your CCPA rights | Protected by policy |
| Right to Correct | Request correction of inaccurate personal information | Email asia@aetherisai.online with subject "CCPA Correction Request" |
| Right to Limit Use of Sensitive PI | Limit use of sensitive personal information to necessary purposes | Email asia@aetherisai.online |
Authorized Agents: You may designate an authorized agent to make CCPA requests on your behalf. The agent must provide signed written permission, and we may verify your identity directly.
Shine the Light Request: California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes. Email asia@aetherisai.online with subject "California Shine the Light Request."
7.4 How to Exercise Your Rights
To exercise any of these rights, please contact us:
Verification: For your protection, we will verify your identity before fulfilling any request. We may ask you to confirm your email address or provide account details.
Response Time: We aim to respond to all requests within 30 days. If we need more time, we will notify you.
8. Children's Privacy
Our Services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
If we learn that we have collected personal information from a child under 13 without verified parental consent, we will: 1. Delete that information as quickly as possible 2. Terminate the associated account if applicable 3. Notify the parent/guardian if contact information is available
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at asia@aetherisai.online.
COPPA Compliance: We comply with the Children's Online Privacy Protection Act. Our chatbot is designed for real estate professionals and their adult clients, not for children.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings.
- Material Changes: If we make material changes, we will notify you by email (if we have your email) and post a prominent notice on our Site at least 30 days before the changes take effect.
- Non-Material Changes: Minor changes (typographical errors, clarifications) may be posted without advance notice.
- Effective Date: The "Effective Date" at the top of this policy indicates when the current version became effective.
We encourage you to review this Privacy Policy periodically. Your continued use of our Services after any changes constitutes acceptance of the updated policy.
10. Contact Information
For questions, concerns, or requests related to this Privacy Policy or our data practices, please contact:
Data Protection Officer (DPO): Asia Algarni serves as the designated privacy contact for Aetheris AI LLC. For GDPR-related matters, you may contact this address or email.
EU Representative (if applicable): If required under GDPR Article 27, we will designate an EU representative and post their contact details here.