AERPrivacy Policy

Policy

Privacy Policy

Last updated: 26 July 2026

This policy explains what AER records, what it deliberately does not record, how long it keeps data and how you can have it removed. AER is operated by Ad Astra Computing. It is in an early-access phase and can change.

This policy is provided by the operator of AER, Ad Astra Computing. Where we process personal data on a customer's behalf, our published Data Processing Agreement governs and needs no signature. Contact us at privacy@adastracomputing.com.

What we collect

The auto-instrumentation collector captures metadata only. It records model names, token counts, tool names, hostnames, process names, timing and any principal identifiers you attach to a session. Each completed session becomes a signed record.

When you request access we collect your name, work email, organisation and a short description of your use case, plus a hashed IP address and a truncated browser user-agent string for abuse prevention. Pending requests expire after 30 days. Denied or expired requests are scrubbed of personal data immediately and the remaining row is deleted within 90 days. Your email is used only to send the activation link and is deleted once activation completes.

What the collector deliberately does not capture

This is the strongest privacy fact about AER, so we state it plainly. The collector never captures prompts, model completions, tool arguments, request or response bodies or headers. It sees the shape of what your agent did, not the content it read or wrote.

Our role

For the telemetry your agents send us, your organisation is the data controller and Ad Astra Computing is a data processor acting on your instructions. For the data we collect when you request access or manage your account, Ad Astra Computing is the controller.

Retention

By default we retain execution events and signed bundles until you delete them. You can set a retention window from 1 to 3650 days in Settings. When a record ages out we delete the bundle and the underlying events. We keep a minimal metadata row (record ID, hash, timestamps) so verification requests for a deleted record fail cleanly rather than ambiguously.

Signed records

Each completed session produces a signed AER bundle stored in Cloudflare R2 object storage. A bundle is reachable by anyone who has its unguessable record ID (a UUIDv7). There is no public index and no listing of records. Verification pages are public by design so a third party you share a record with can check its signature independently.

You can set your records to private in Settings. A private record is visible only to your tenant and to anyone you give a time-limited share link.

If you attach a principal (a user or service identity) to a session, it becomes part of the signed record. Set your records to private if principals identify real people.

Transparency log and permanence

A record's cryptographic hash and signature are anchored to Sigstore Rekor, a public, permanent, append-only transparency log operated by the Linux Foundation. Only the hash and signature are sent to Rekor. Event content is never sent. Because Rekor is public and permanent, an anchored hash cannot be deleted, including by an erasure request. This is a deliberate design choice that lets anyone prove a record existed and has not changed, and it is the one thing our deletion path cannot reach.

Email and API keys

Your email is collected at signup only to send the activation link. It is stored only until activation completes, then discarded. Signup is rate limited.

API keys are shown once at creation and stored only as an Argon2id hash. AER can never recover the plaintext of a key. The console never stores an API key in the browser: sign-in uses a server-side session held in a secure cookie that page scripts cannot read.

Deletion and your rights

An operator erasure path exists. It soft-deletes a tenant immediately and hard-purges its data (sessions, events, bundles, findings and audit) after a short grace period. To request erasure, contact privacy@adastracomputing.com. We keep a minimal record that a deletion was performed.

One honest caveat: hashes already anchored to Rekor are permanent and outside AER's control. Erasure removes your event content and bundles from AER, but it cannot remove an anchored hash from a public transparency log.

European users (GDPR)

If you are in the European Economic Area, you have the right to access the data we hold about you, to have inaccurate data rectified, to erasure through the mechanism above, to portability of your data and to object to processing. We honour these requests through the same contact address. The single exception is a hash already anchored to Rekor: it is public and permanent, so it cannot be erased.

Personal data breaches

If we become aware of a personal data breach affecting your data we will notify affected customers without undue delay and will support them in meeting their own notification obligations.

Sub-processors

We use the following sub-processors to run the service. There are no others today.

ProviderPurposeData in scope
CloudflareHosting, storage and edge network (Workers, D1, Durable Objects, R2)All service data
Sigstore Rekor (Linux Foundation)Public transparency anchoring of record hashes and signaturesRecord hash and signature only, never event content

The authoritative list, entity details and change-notice process live on the subprocessors page.

Cookies, localStorage and tracking

The marketing site and console use no third-party analytics and no advertising or tracking cookies. The console uses one first-party session cookie for sign-in and stores no API key or other secret in the browser. Our Content-Security-Policy restricts connections to AER's own API.

Data location

AER runs on Cloudflare (Workers, D1, Durable Objects and R2), a global network. The primary database region is Eastern North America with read replication. If you visit from the EU, your data may be processed on Cloudflare's global network.

Ad Astra Computing is a US company. Where personal data of EU or UK individuals is transferred to the US we rely on the European Commission's Standard Contractual Clauses, incorporated into our Data Processing Agreement, together with Cloudflare's own data processing addendum. Transfers from the United Kingdom are covered by the Information Commissioner's international data transfer addendum to the same clauses.

If we contacted you about AER

We sometimes write to people at companies building or running AI agents, to ask whether AER is relevant to their work. If you received such a message, this section is the one that applies to you. It is separate from everything above, which describes what AER records for its customers.

What we hold. Your name, your work email address, your employer and your role, plus the message we sent and your reply if you send one. Nothing else. We do not build a profile, we do not enrich the record from data brokers, and we do not track whether you opened the message: our outreach carries no tracking pixel and no click redirect.

Where we got it. From a public source, which the message itself names in its footer. Usually that is your employer's website, your public professional profile or a public repository. We do not buy lists.

Why we may do this. Our legitimate interest in reaching people whose work AER is built for, balanced against the limited and professional nature of the details we hold. In jurisdictions that require prior consent for unsolicited business email, we do not send at all rather than rely on that basis.

How long. Until you ask us to stop, or two years after the last message, whichever comes first. If you ask us to stop we keep your email address on a suppression list indefinitely, because that is the only way to guarantee we do not contact you again by mistake.

Stopping it, and your rights. Reply with “stop” or write to unsubscribe@adastracomputing.com and we will remove you the same day. You can object to this processing at any time, and you can ask for a copy of what we hold or have it deleted, at privacy@adastracomputing.com. You do not have to give a reason and we will not ask for one.

Changes to this policy

AER is in a pilot phase and the service can change. When we make a material change to this policy, we email every registered account holder in advance of the date it takes effect. Minor clarifications that do not change how we handle your data are reflected by updating the date at the top of the page, without a separate email.

Contact

For privacy questions or a data request, email privacy@adastracomputing.com. AER is operated by Ad Astra Computing.