Privacy Policy
Last updated: July 30, 2026
This policy explains what AeroJess collects, why it collects it, and what you can do about it. We keep it in plain language on purpose — if anything here is unclear, ask us.
What this policy covers
This policy covers the AeroJess application: the account you create, the dashboard where you build sites, the files you upload, and any third-party account you choose to connect to it.
It does not cover the websites our customers publish with the service. Each published site is controlled by the customer who built it, and anything a visitor submits there is that customer's to handle — we only store it on their behalf. See “Data collected through published sites” below.
What we collect
We collect only what running the service requires:
- Account details — your email address, your name if you give one, and either a hashed password or the basic profile Google returns when you sign in with Google.
- Site content — the text, settings, colors, and images you put into your sites, including the files you upload to your asset storage.
- Connected social accounts — the profile and recent posts of a social account you choose to link. This is optional and is described in full below.
- Billing details — your plan, your subscription status, and the customer identifier created by our payment processor. We never see or store your full card number.
- AI usage records — the prompts you send to the AI site generator and the configuration it returns, kept as an audit log so we can investigate failures and apply plan limits.
- Technical data — server logs, IP address, browser type, and aggregate performance measurements collected by our hosting provider.
AI processing
The site generator sends your prompt, your current site configuration, and — if you enabled it — context from your connected social account to our AI provider (OpenAI or Anthropic, depending on how the service is configured), purely to produce the site content you asked for. These providers act as processors under their business terms and do not use the data to train their models.
We keep a record of AI requests and their results for a limited period, so we can investigate errors, prevent abuse, and account for usage against your plan.
How we use your information
We use the information above to:
- create and secure your account and keep you signed in;
- build, preview, publish, and host the websites you create;
- process subscription payments and issue receipts;
- send transactional email such as email verification and password resets;
- detect, investigate, and prevent abuse, fraud, and security incidents;
- diagnose faults and improve the reliability and features of the service.
We do not sell personal information, and we do not use it for advertising.
Who we share data with
We do not sell personal information. We share it only with the service providers that operate the platform, each limited to what its role requires:
- MongoDB Atlas — application database.
- Google Cloud Storage — the images and files you upload.
- Vercel — application hosting, delivery, and performance measurement.
- Stripe — subscription payments and card processing.
- Resend — transactional email delivery.
- Google — sign-in with Google, if you use it.
- Meta (Instagram) — only if you connect an Instagram account.
- OpenAI or Anthropic — AI generation, as described above.
We may also disclose information where the law requires it, or where it is necessary to protect our rights, our users, or the security of the service.
Data collected through published sites
When a visitor submits a contact form on a website published with the service, we store that submission and make it available to the site owner. The owner decides what the form asks and what happens to the answers; we act only as their processor.
If you are a visitor to one of these sites and want your submission corrected or deleted, contact the owner of that site. If you cannot reach them, write to us and we will pass your request on.
How long we keep data
We keep data only as long as the purpose it was collected for lasts:
- Account and site data — while your account is active.
- Deleted sites — held for a short grace period so they can be restored, then permanently purged along with their assets.
- Social connections — until you disconnect the account or close your account, whichever comes first.
- Billing records — for as long as tax and accounting law requires.
Closing your account deletes your sites, your uploaded files, and any connected social account; backups age out shortly afterwards.
Security
Traffic is served over HTTPS, passwords are stored only as bcrypt hashes, and third-party access tokens are encrypted at rest with a key held outside the database. Access to production data is limited to the people who need it to operate the service.
No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and the relevant authority as the law requires.
Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct information that is wrong or incomplete;
- delete your account and the data attached to it;
- receive an export of your data in a portable format;
- object to or restrict certain processing;
- withdraw consent you gave — for example by disconnecting a social account.
Most of these you can do yourself in the dashboard. For anything else, contact us at the address below and we will respond within the period the applicable law allows.
Children
The service is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal information from children, and we delete it if we learn that we have.
Changes to this policy
We may update this policy as the service changes. The date at the top always reflects the current version, and we will give notice in the dashboard before a material change takes effect.
Contact us
Questions about this policy, or want to exercise one of the rights above? Get in touch and we will help.