Privacy Policy
Last updated: August 31, 2026
1. Scope
This policy explains how AetheriumOS processes information when you visit our website, create an account, use AetheriumOS account features, use Aetherium Cloud, or use related applications and services.
2. Information we process
Depending on the feature, we may process a username, email address, phone number, password-derived authentication data and salts, session information, device identifiers, device names, manufacturer and model information, Cloud plan and subscription information, storage usage and file metadata, application activity records that a client sends, IP addresses, security logs, and technical request information.
We do not intentionally collect payment card numbers through our application. Payment details are handled by the applicable payment processor, such as Paddle, under its own payment and privacy terms.
3. Purposes
- Provide accounts, authentication, sessions, devices, Cloud storage, and activity features.
- Enforce quotas, rate limits, fraud controls, and security measures.
- Operate subscriptions, trials, billing, cancellations, and refunds.
- Maintain, troubleshoot, secure, and improve the Service.
- Comply with applicable legal obligations and respond to legitimate requests.
4. Legal bases
Where required by applicable law, processing may rely on performance of a contract, legitimate interests such as security and abuse prevention, consent where required, or compliance with legal obligations. The relevant basis depends on the processing activity and jurisdiction.
5. Cookies and sessions
We use an HttpOnly, Secure session cookie to keep you signed in. Authentication session tokens are not intentionally stored in browser localStorage or exposed to ordinary page scripts.
6. Aetherium Cloud
Files uploaded to Aetherium Cloud are processed to store, retrieve, secure, enforce quotas, and administer the account. Cloud storage infrastructure may use Cloudflare R2 and other providers necessary to operate the Service. File metadata may be processed for storage management and integrity features.
You remain responsible for the content you upload and should keep independent backups of important data.
7. Android devices and activity
When an Android client uses the Service, it may send a device identifier, device name, manufacturer, model, and application activity data. This information is associated with the authenticated account and device so that requested device and activity features can function.
8. Security and abuse prevention
We may process IP addresses, request metadata, authentication events, rate-limit events, and security logs to detect abuse, protect accounts, investigate technical incidents, and maintain the security of the Service. Cloudflare Turnstile and related infrastructure may process technical information needed for bot and abuse detection.
9. Service providers
Depending on the service used, providers may include Cloudflare for Workers, D1, R2, Turnstile, and related infrastructure, and Paddle for Merchant of Record payment processing, subscription management, tax handling, invoicing, and refund processing. These providers handle information under their applicable terms and privacy notices.
10. International processing
Service providers may process information in countries other than your own. Where required, appropriate safeguards for international transfers will be used.
11. Retention
Information is retained only as long as reasonably necessary for account operation, service delivery, security, legitimate business purposes, dispute handling, or legal obligations. Retention periods can differ by data type. Expired authentication sessions may be removed automatically.
12. Your rights
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where consent is the legal basis. We may reasonably verify identity before processing a request.
13. Account deletion
You may request account deletion and applicable data deletion using the support contact published by the AetheriumOS project. Some information may be retained where legally required or reasonably necessary for security, fraud prevention, disputes, accounting, or other lawful record-keeping.
14. Children's privacy
The Service is not intentionally directed at children where applicable law requires parental consent. We do not knowingly process children's personal information in violation of applicable law. Concerns about possible improper collection can be reported through our published support contact.
15. Security
Reasonable technical and organizational safeguards are used, including secure transport, protected session handling, server-side validation, access controls, rate limiting, and protected cloud infrastructure. No online service can guarantee absolute security.
16. Changes
We may update this policy as the Service, infrastructure, data practices, or legal requirements change. The latest version will be published on this page with an updated date.
17. Contact
For privacy requests or security concerns, use the current support contact published by the AetheriumOS project. Do not send passwords, authentication codes, or payment card details in support requests. For Paddle transaction questions, use the support and receipt information provided by Paddle.