← Back to home

Privacy Policy

Last updated: July 30, 2026

This policy explains what AeroJess collects, why it collects it, and what you can do about it. We keep it in plain language on purpose — if anything here is unclear, ask us.

What this policy covers

This policy covers the AeroJess application: the account you create, the dashboard where you build sites, the files you upload, and any third-party account you choose to connect to it.

It does not cover the websites our customers publish with the service. Each published site is controlled by the customer who built it, and anything a visitor submits there is that customer's to handle — we only store it on their behalf. See “Data collected through published sites” below.

What we collect

We collect only what running the service requires:

Social accounts you connect

Connecting a social account is optional — everything else in the service works without it. Today we support Instagram, through Meta's official Instagram API with Instagram Login. The connection is read-only: it uses the instagram_business_basic permission, which cannot post, edit, delete, or send messages on your behalf.

While an account is connected, we can access:

We use it for one thing: building your website. Your recent captions and images give the AI site generator real context about your business, so the copy and imagery it drafts match what you actually post. This context is sent to our AI provider only while the Instagram context switch is on, and only as part of a generation you started. Any photo you accept into a site is copied into your own site storage and served from there, so your published site keeps working even after you disconnect.

How it is stored: the access token Instagram issues is encrypted before it is written to our database, never leaves our servers, and is never sent to your browser. It is a long-lived token that we refresh automatically while the connection is active. Recently fetched posts are cached for a short time so one editing session does not refetch them on every message.

You stay in control:

We never sell social account data, never use it for advertising or profiling, and never share it with anyone other than the AI provider processing a generation you asked for. Our use of Instagram data follows the Meta Platform Terms and Developer Policies.

AI processing

The site generator sends your prompt, your current site configuration, and — if you enabled it — context from your connected social account to our AI provider (OpenAI or Anthropic, depending on how the service is configured), purely to produce the site content you asked for. These providers act as processors under their business terms and do not use the data to train their models.

We keep a record of AI requests and their results for a limited period, so we can investigate errors, prevent abuse, and account for usage against your plan.

How we use your information

We use the information above to:

We do not sell personal information, and we do not use it for advertising.

Cookies

We use only the cookies the service needs to function: a session cookie that keeps you signed in, short-lived cookies that protect the sign-in flow, and a preference cookie (NEXT_LOCALE) that remembers your dashboard language.

We do not use advertising or cross-site tracking cookies. Our hosting provider collects aggregate page-load performance measurements, which are not used to identify individual visitors.

Who we share data with

We do not sell personal information. We share it only with the service providers that operate the platform, each limited to what its role requires:

We may also disclose information where the law requires it, or where it is necessary to protect our rights, our users, or the security of the service.

Data collected through published sites

When a visitor submits a contact form on a website published with the service, we store that submission and make it available to the site owner. The owner decides what the form asks and what happens to the answers; we act only as their processor.

If you are a visitor to one of these sites and want your submission corrected or deleted, contact the owner of that site. If you cannot reach them, write to us and we will pass your request on.

How long we keep data

We keep data only as long as the purpose it was collected for lasts:

Closing your account deletes your sites, your uploaded files, and any connected social account; backups age out shortly afterwards.

Security

Traffic is served over HTTPS, passwords are stored only as bcrypt hashes, and third-party access tokens are encrypted at rest with a key held outside the database. Access to production data is limited to the people who need it to operate the service.

No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and the relevant authority as the law requires.

Your rights

Depending on where you live, you may have the right to:

Most of these you can do yourself in the dashboard. For anything else, contact us at the address below and we will respond within the period the applicable law allows.

Children

The service is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal information from children, and we delete it if we learn that we have.

Changes to this policy

We may update this policy as the service changes. The date at the top always reflects the current version, and we will give notice in the dashboard before a material change takes effect.

Contact us

Questions about this policy, or want to exercise one of the rights above? Get in touch and we will help.

no-reply@aerojess.com