Legal & Privacy

Privacy Policy

How Microbix Labs collects, uses, stores, and protects your personal data when you use Aether.

📅 Effective: January 1, 2025 🔄 Last Updated: July 2025 🏢 Microbix Labs

Our Privacy Commitment

Microbix Labs ("we", "us", "our") built Aether on a foundation of trust. This policy explains what data we collect when you use Aether, why we collect it, how we protect it, and what controls you have over it.

By using Aether, you agree to the collection and use of information in accordance with this policy. If you disagree with any part of it, you should not use the service.

Our core promise: Your conversation content is never sold, never used to train AI models without your explicit opt-in, and never shared with advertisers.

Data We Collect

We only collect data that is necessary to provide you with a working, personalized, and secure AI workspace.

Account Data

Data TypePurposeRequired?
Email addressAuthentication, account recoveryYes
UsernameWorkspace personalizationYes
Password hashSecure authentication (bcrypt, never stored plaintext)Yes
GitHub / Google IDOAuth sign-in linkageOnly if using OAuth
AgeAge verification (must be 13+)At onboarding

Usage Data

Data TypePurposeRetained
Chat messagesDelivering AI responses, history syncUntil you delete them
Custom instructions / MemoryPersonalizing AI behavior per your rulesUntil you clear them
mX credit balance & transactionsBilling and usage trackingAs required by law
Model selections, thinking levelRouting AI requests correctlySession only

Technical Data

  • IP address — used for rate limiting and abuse prevention, not linked to identity
  • Browser / device type — used for compatibility and analytics (anonymised)
  • Aether version / session identifiers — for debugging and support
ℹ️ We do not collect payment card details directly. All billing is processed by our payment provider under their own PCI-compliant systems.

How We Use Your Data

  • Providing the service: Authenticating you, routing your messages to AI models, streaming back responses.
  • Personalisation: Applying your Memory & Rules instructions in every response.
  • Safety & security: Detecting and blocking jailbreak attempts, rate-limiting abuse, and preventing account takeover.
  • Billing: Tracking mX credit consumption and enforcing plan limits.
  • Product improvement: Aggregated, anonymised analytics to understand which features are used. Your message content is never included in analytics.
  • Legal compliance: Retaining certain records as required under applicable law.
⚠️ AI training: We do not use your conversations to fine-tune or train any AI models unless you have explicitly opted in through a future Beta programme with a separate, clear consent flow.

Data Storage & Security

Your data is stored in a PostgreSQL database hosted on a managed cloud provider with the following protections:

  • Encryption at rest: AES-256 for all stored data including chat messages.
  • Encryption in transit: All connections between your browser and Aether's backend use TLS 1.2+.
  • Password hashing: Passwords are hashed with bcrypt (cost factor ≥ 10) and never stored in plaintext.
  • JWT authentication: Session tokens are signed with a secret key and expire after 30 days.
  • Rate limiting: All API endpoints are rate-limited to prevent brute force and denial-of-service attacks.
  • Access controls: Database access is restricted to backend services only; no direct public exposure.

While we implement industry-standard safeguards, no transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

Data Sharing & Third Parties

We do not sell your personal data. We share data only in these limited circumstances:

AI Model Providers

When you send a message, its content is forwarded to third-party AI model providers (e.g., Groq, Google Gemini, OpenRouter) to generate a response. These providers process your message under their own privacy policies. We recommend reviewing:

Infrastructure & Hosting

Our backend runs on Render (hosting) and our frontend on Vercel. These providers may have access to server logs and metrics. We do not share your user profile or message content with them beyond what is required to operate the infrastructure.

Legal Requirements

We may disclose personal data if required to do so by law, court order, or governmental authority, or to protect our users' safety and rights.

Cookies & Local Storage

Aether does not use traditional advertising or tracking cookies. We use:

Storage KeyPurposeType
aether-tokenAuth session token (JWT)localStorage
aether-themeLight/dark theme preferencelocalStorage
aether_guest_memoryCustom instructions for guest sessionslocalStorage
aether_cookie_consentRecords your consent choicelocalStorage
aether_* (settings)Font size, language, layout prefslocalStorage

All storage is in your browser's localStorage. You can clear it at any time via your browser's developer tools or privacy settings.

Data Retention

  • Active accounts: Data is retained for as long as your account is active.
  • Chat history: Retained until you delete specific conversations or your whole account.
  • Inactive accounts: Accounts with no activity for 18+ months may be scheduled for deletion, with email notice 30 days prior.
  • Deleted accounts: Personal data is purged within 30 days of account deletion. Anonymised aggregate analytics may be retained.
  • Legal holds: Data subject to legal proceedings may be retained beyond the standard period.

Your Privacy Rights

Regardless of where you are located, Microbix Labs honours the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Ask us to correct inaccurate data.
  • Erasure ("Right to be Forgotten"): Request deletion of your account and all associated data.
  • Portability: Request an export of your data in a machine-readable format (JSON).
  • Restriction: Request that we restrict processing of your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, use the Privacy & Data tab in your Aether settings, or email us at privacy@microbix.io. We will respond within 30 days.

🇪🇺 If you are in the EEA/UK, you also have the right to lodge a complaint with your local data protection authority.

Children's Privacy

Aether is not directed at children under the age of 13. We do not knowingly collect personal information from anyone under 13. During onboarding, we require age verification and reject users who indicate they are under 13.

If you believe a child under 13 has provided us with personal data, please contact us at privacy@microbix.io and we will delete that data promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Post a notice in the Aether workspace for signed-in users.
  • For significant changes affecting how we use data, send an email notification to registered users.

Your continued use of Aether after changes are published constitutes your acceptance of the revised policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out:

📧

Privacy & Data Requests

privacy@microbix.io — we respond within 30 days

🏢

Microbix Labs

Registered company operating Microbix Aether OS

← Back to Aether Workspace