Privacy Policy

Last updated: Not yet finalized — draft placeholder

Placeholder text — not final. Draft placeholder — not legal advice and not final. This text has not been reviewed by a lawyer and must be replaced with counsel-drafted language before public launch.

How AETOS handles the data stored for your account and organisation.

1. What this covers

This Privacy Policy explains what the AETOS platform stores about an account, why, and what controls you have over it.

2. Data we store

Account data: your email address, role, and the organisation created for you at signup. Authentication is handled by the platform's managed auth provider.

Research data you create: watchlist entries and theses, thesis reviews, decision contracts, capital readiness, portfolio positions, generated reports and AI narratives, and an audit log of administrative changes.

Billing data: subscription tier and status, invoice records, and payment-method metadata such as card brand and last four digits. Full card details are handled by the payment provider and are never stored by AETOS.

Operational data: data-job runs and provider health used to keep the pipeline observable.

3. Data we do not store

No brokerage credentials, no bank connections, no full payment card numbers, and no trading authority of any kind. Portfolio positions are manually entered by you.

4. How data is used

Solely to operate the platform for your organisation: computing scores, generating reports and narratives, and providing billing. Your research data is not sold, and is not used to influence market data or scores shown to other accounts.

5. Processors and third parties

Market and macro data providers, the managed cloud database and auth provider, the AI model gateway used for narratives, the transactional email sender, and the payment provider. Report snapshots sent to the AI gateway contain aggregated platform data, not your credentials or billing details.

6. Isolation and security

Every tenant-scoped table enforces row-level security keyed to your organisation. Roles (owner, admin, analyst, viewer, billing admin) restrict what each member may read or change. Billing-only roles cannot read research data.

7. Your rights

Export: Settings › Account data lets you download everything stored about your account as a structured file.

Deletion: Settings › Account data permanently deletes your organisation, its records and your login. This is irreversible.

Other requests (correction, restriction, objection, or questions about lawful basis) can be sent to legal@aetos.live.

8. Retention

Account and research data is retained while the account exists. Deletion removes it immediately from the live database; managed platform backups age out on the provider's own retention cycle.

9. Contact

Privacy questions: legal@aetos.live.