Privacy Policy
Last updated 29 August 2026
This policy explains what personal data Aether collects when you use a service hosted on it, why, and what you can do about it. It is written to describe what the software actually does rather than to cover every hypothetical.
Who is responsible
The data controller is Andreas Zita, reachable at andreas.zita@gmail.com. If you have a question about your data, that address is the fastest route to a human.
Tavastgatan 15118 24 Stockholm
Sweden
What we collect
When you sign in. Aether uses Sign in with Google (and, where a service offers it, Microsoft). We never see or handle your password. From the identity token the provider returns, we store:
- a stable identifier for your account with that provider;
- your email address;
- your display name;
- the time you were last active, updated at most every few minutes.
What you submit. If a service lets you post something, we store what you wrote, your identifier and display name from above, and the time you wrote it.
Visits. We count page views, and we do it without identifying you. There is no tracking cookie and no advertising network. For each view we record the path, the website you arrived from if any (the domain only, never the full address), and whether the request came from a desktop, a phone or a bot. To count returning visitors within a single day we compute a one-way hash of your IP address and browser identification, salted with a secret that changes every day; the IP address itself is discarded immediately and is never written down, and because the salt rotates, the resulting number cannot be used to recognise you tomorrow.
Cookies. Visitors get none. If you are an operator with an administrative account, a single cookie holds your session; it is strictly necessary for signing in and is not used for analytics or advertising.
Why, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Signing you in and knowing who wrote what | Performance of a contract — you asked to use the service |
| Storing and publishing what you submit | Performance of a contract |
| Aggregate visit counts | Legitimate interest in knowing whether anything is used, balanced by collecting nothing that identifies you |
| Keeping the service secure and working | Legitimate interest |
Automated processing by AI
Some services on Aether use a large language model to turn submissions into published writing. Where they do, the text you submit is sent to that provider for processing, together with other people's submissions from the same period. What gets published is a new piece of writing that blends the themes; it is not attributed to you, and your name and email are not sent to the model or shown alongside the result.
These are ordinary automated processes and they do not make decisions with legal or similarly significant effects about you.
Who else sees it
We do not sell personal data and we do not share it for advertising. We rely on a small number of providers to run the service:
| Provider | Role |
|---|---|
| Sign-in, and the language model used for text synthesis | |
| Microsoft | Sign-in, where a service offers it |
| Cloudflare | Traffic proxy and TLS in front of the servers |
| Contabo | Server hosting |
Servers are located in Germany (EU). Where a provider processes data outside the EEA, that transfer relies on the European Commission's standard contractual clauses or an equivalent safeguard.
How long we keep it
- Account record — for as long as you use the service, and deleted when you ask.
- Submissions — kept indefinitely, because the published writing derived from them is a permanent record. Deleting your account removes your name and identifier from the submission; the published piece it contributed to remains, since it is a blend of many people's contributions and is not attributed to anyone.
- Visit counts — aggregate numbers only; nothing identifying survives the day it was recorded.
Your rights
Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, hand it to you in a portable form, restrict what we do with it, or object to processing based on legitimate interest. Write to andreas.zita@gmail.com and we will respond within one month.
If you think we have handled your data badly, you can complain to your national data protection authority. In Sweden that is Integritetsskyddsmyndigheten (IMY).
Children
These services are not directed at children and we do not knowingly collect data from anyone under 13. If you believe a child has given us data, write to us and we will remove it.
Changes
If this policy changes we will update the date at the top. Material changes affecting how your data is used will be announced on the service itself.