Skip to content
Aeologic AI

Legal

Privacy Policy

Last updated 12 August 2026

This policy explains what personal data Aeologic AI Technologies collects, why we collect it, how long we keep it, and the rights you have over it. It covers our website, the Aeologic AI platform and our managed services.

1. Data we collect

Account data: name, work email, company, role and billing details, provided when you create an account or request a demo.

Usage data: pages viewed, features used, prompts tracked and jobs run, collected to operate and improve the service.

Customer content: the domains, URLs, briefs, drafts and prompt sets you add to the platform. This is yours; we process it only to provide the service.

Technical data: IP address, browser, device type and approximate location derived from IP, retained in server logs for 30 days.

2. How we use it

To provide, secure and support the service, including running crawls, prompt sampling and content generation on your instruction.

To bill you, and to detect fraud or abuse of the platform.

To send service messages you cannot opt out of (security, billing, material changes to terms) and marketing messages you can, with one click.

To produce aggregated, de-identified statistics about how the service is used. These never identify you or your content.

3. What we never do

We do not sell personal data, and we do not share it with advertising networks.

We do not use your customer content to train third-party foundation models. Where the platform calls a third-party model to generate output for you, we use enterprise endpoints configured with training disabled and zero data retention where the provider offers it.

We do not read your customer content except where you explicitly ask support to look at a specific item, or where we are legally compelled to.

4. Legal bases for processing

Contract: processing necessary to provide the service you have signed up for.

Legitimate interests: security, fraud prevention, service improvement and direct marketing to business contacts, balanced against your rights.

Consent: optional cookies and marketing email, withdrawable at any time.

Legal obligation: tax, accounting and lawful requests from authorities.

5. Sub-processors

We use a small number of sub-processors for hosting, payments, email delivery, error monitoring and model inference. A current list, with locations and roles, is available on request and is provided to all Enterprise customers as an annex to the DPA.

We give 30 days' notice before adding a sub-processor that processes customer content, and Enterprise customers may object.

6. International transfers

Data is hosted in the United States by default, with EU hosting available on Enterprise plans.

Where personal data is transferred out of the UK or EEA, we rely on Standard Contractual Clauses together with a transfer risk assessment.

7. Retention

Account data is retained while your account is active and for six years afterwards where required for tax and accounting.

Customer content is deleted within 30 days of account closure, or immediately on written request, except where retained in encrypted backups for a further 35 days.

Server logs are retained for 30 days.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, port or restrict the processing of your personal data, and to object to processing based on legitimate interests.

California residents have the right to know, delete, correct and opt out of sale or sharing. We do not sell or share personal data as those terms are defined under the CCPA.

To exercise any right, email hello@aeologic.ai. We respond within 30 days and do not charge a fee for reasonable requests.

You may also complain to your local supervisory authority. In the UK that is the Information Commissioner's Office.

9. Security

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access to production systems requires SSO with hardware-backed multi-factor authentication and is logged.

We hold SOC 2 Type II and are audited annually. Penetration testing is conducted twice a year by an independent firm.

We notify affected customers of a personal data breach without undue delay and within 72 hours of becoming aware where legally required.

10. Changes and contact

We update this policy as the service changes. Material changes are announced by email at least 30 days before they take effect.

Questions or requests: hello@aeologic.ai, or write to 2 Embarcadero Center, Suite 800, San Francisco, CA 94111, United States.

This document is provided as part of a demonstration website and is not legal advice. Before using it on a live commercial service, have it reviewed by qualified counsel in every jurisdiction where you operate.