Privacy Policy
This policy explains how AEGIS OS (“AEGIS OS”, “we”, “us”) handles information when you use the website at aegisos.ccand the AEGIS OS dashboard and services (together, the “Service”). Questions: [email protected].
1. Information we collect
- Account information — your name, email address, organisation name and sign-in credentials (passwords are handled by our authentication provider and are never stored in plain text).
- Content you provide — project briefs, messages to the AEGIS OS agents, uploaded files, approvals and settings.
- Connected-account data — data from third-party accounts you choose to connect, described in sections 3 and 4.
- Usage and technical data — log data such as IP address, browser type, pages visited and error reports, used to operate, secure and debug the Service.
- Billing data — if you pay for the Service, payment details are collected and processed by our payment processor; we do not store full card numbers.
2. How we use information
- To provide, operate and maintain the Service, including running the AI agents you direct.
- To authenticate you and keep your organisation’s data separate from other customers’ data.
- To send service messages (sign-in links, invitations, alerts you have opted into, billing notices).
- To secure the Service, prevent abuse and comply with legal obligations.
We do not sell personal information and we do not use your data for third-party advertising.
3. Google user data
You can optionally connect your own Google account in Dashboard → Settings → Connections so that AEGIS OS can report on the search and analytics performance of your own website. This section describes exactly what we access and what we do with it.
What we access
- Basic profile and email (
openid,email) — your Google account identifier and verified email address, used only to confirm which Google account is connected and to show it on your connection card. - Google Search Console, read-only (
webmasters.readonly) — the list of Search Console sites your account can see, and search performance data (such as clicks, impressions, click-through rate, average position, queries and pages) for the one site you select. - Google Analytics 4, read-only (
analytics.readonly) — the list of GA4 properties your account can see, and traffic and engagement reports (such as sessions, users and page views) for the one property you select.
Both data scopes are read-only. AEGIS OS cannot change your Search Console settings, your Analytics configuration, or any other Google data, and we do not request access to Gmail, Drive, Contacts or any other Google service.
How we use it
Google user data is used only to show and analyse the performance of the site and property you selected, for you and the members of your AEGIS OS organisation — for example, SEO reports and recommendations produced by AEGIS OS’s SEO agents. It is not used for any other purpose, and it is never used to serve advertisements.
How we store it
The OAuth access token and refresh token Google issues are encrypted at rest (AES-256-GCM) before they are stored, and are decrypted only on our servers at the moment a read is made on your behalf. Report data derived from your Search Console and Analytics reads is stored with your organisation’s data and is protected by the same per-organisation access controls as the rest of your workspace.
Sharing
We do not sell Google user data, and we do not share or transfer it to third parties, except (a) to service providers that host and run the Service for us (for example our database and cloud hosting providers) under confidentiality obligations and solely to provide the Service, (b) where you direct us to, or (c) where required by law. Humans at AEGIS OS do not read your Google user data unless you give us permission for a specific support request, it is needed for security purposes (such as investigating abuse), or it is required by law.
AI and model training
Google user data may be processed by AI models only to generate the reports and recommendations you ask for. We do not use Google user data to develop, improve or train generalised or non-personalised AI and/or ML models, and we do not allow our AI providers to do so.
Retention and deletion
- You can revoke AEGIS OS’s access at any time from your Google account at myaccount.google.com/permissions. Once access is revoked, AEGIS OS can no longer read your Google data and marks the connection as revoked.
- You can also ask us to remove the connection by emailing [email protected].
- Stored Google tokens, and your selected site and property, are deleted within 30 days of a revoke or a deletion request.
- If you delete your AEGIS OS account or organisation, all Google tokens and Google-derived data held for it are deleted.
Limited Use
AEGIS OS’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Other connected accounts
Connections are made by authorising AEGIS OS through each provider’s own sign-in and consent screen; you never paste passwords or API keys for these services into AEGIS OS. Each grant is used only for the purpose you connected it for, tokens are encrypted at rest, and you can revoke access at any time from the provider’s own account settings or by emailing [email protected].
- X (Twitter), LinkedIn and Instagram — to read basic profile information for the account you connect and to publish or schedule posts you or your approved workflows create, and to read engagement on those posts. We do not read your private messages.
- Stripe (Stripe Connect) — to link your Stripe account so that payments for products AEGIS OS builds for you are taken in your account, and to read the payment and payout status needed to report on them. We never see or store full card numbers.
- Cloudflare — to manage DNS and related settings for the domains you choose, so that sites AEGIS OS builds for you can be connected to your domain.
- GitHub, Vercel and Supabase — where offered, to create and deploy the code repositories, hosting and databases for products AEGIS OS builds for you.
5. Service providers and AI processing
We use carefully selected sub-processors to run the Service, including cloud hosting, database and authentication, email delivery, payment processing and AI model providers. They process data only on our instructions and only to provide the Service. Content you send to AEGIS OS agents is processed by AI model providers to produce the output you requested; we do not permit them to train their models on your data where the provider offers that control.
6. Security
We use encryption in transit (TLS) and at rest, per-organisation access controls, role-based permissions and audit logging. No system is perfectly secure, but we work to protect your information and will notify you of a breach affecting your data as required by law.
7. Retention
We keep account and workspace data for as long as your account is active. When you delete your account, we delete or anonymise your personal data within 30 days, except where we must keep it longer to meet legal, tax or accounting obligations or to resolve disputes.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, email [email protected]. You may also complain to your local data protection authority.
9. International transfers
Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
11. Changes
We may update this policy. We will post the new version here with a new “Last updated” date and, for material changes, notify account holders by email or in the dashboard.
12. Contact
AEGIS OS — [email protected]. See also our Terms of Service.