Privacy Policy
Last updated: 10 July 2026
Aith3r OS is a platform for the startup ecosystem. Organisations trust us with sensitive company information, so this page explains plainly what we collect, why, who it is shared with, and the control you have over it.
1. Who we are
Aith3r OS ("Aith3r", "we", "us") provides a multi-tenant platform on which startups, accelerators, investors, and public innovation bodies operate. For data you enter about your own organisation, we act as a data processor; your organisation is the controller. For your account and billing data, we act as a data controller.
Questions or requests: hello@aithereon.com.
2. What we collect
- Account data — name, email address, and profile details from sign-up or your identity provider (e.g. LinkedIn) when you choose to sign in with it.
- Organisation data — the information you or your team enter or upload: company profile, business model canvas, OKRs, roadmap, risks, go-to-market plans, documents (pitch decks, plans, spreadsheets), and any files you import.
- Usage data — product analytics and event logs (pages used, features used, errors) so we can operate and improve the service.
- Billing data — subscription and payment status. Card details are handled by Stripe; we never see or store full card numbers.
3. How we use it
- To provide the platform and the features you use.
- To run AI-assisted features you trigger — for example, extracting a structured company profile from a document you upload.
- To operate, secure, debug, and improve the service.
- To communicate with you about your account and the service.
- To meet legal and accounting obligations.
We do notsell your data, and we do not use your organisation's private content to advertise to you.
4. Tenant isolation — the core promise
Each organisation sees only its own data. This is enforced in the database itself through row-level security policies on every table, not merely by application code. There is no cross-organisation visibility except where you explicitly create it — for example when a startup is assigned to a partner, or is linked to a public body's portfolio. Administrator access is a restricted, audited role.
5. AI processing
When you use an AI feature, the relevant text (for example, the document you uploaded) is sent to our AI provider to produce the result you asked for. AI calls happen only on our servers; our provider keys are never exposed to your browser. Every AI operation is metered against your plan.
We treat the content of your documents as data, never as instructions. Your organisation's document text is never shared with another tenant. If we ever publish ecosystem-level intelligence, it is limited to anonymised aggregates with a minimum group size, so no individual organisation can be identified.
6. Sub-processors
We rely on a small number of established providers to run the service:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting and delivery.
- Stripe — subscription billing and payments.
- Resend — transactional email.
- LLMAPI.ai — access to the AI models behind our AI features.
- Sentry and product analytics — error monitoring and usage insight.
Some providers process data outside the UK/EEA. Where that happens, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
7. Retention
We keep your organisation's data for as long as your account is active. If your trial or subscription ends, your data is preserved in a read-only state rather than deleted, so you do not lose your work. When you ask us to delete your account, we delete your organisation's data within 30 days, except where we must retain records (for example, invoices) to meet legal obligations.
8. Your rights
Under UK and EU data protection law you have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing.
To export your data or delete your account, email hello@aithereon.com and we will action it within 30 days. (Self-service export and deletion are on our roadmap; until then this is handled by our team on request.) You also have the right to complain to your local supervisory authority, such as the ICO in the UK.
9. Security
Data is encrypted in transit and at rest by our infrastructure providers. Access is restricted by role and enforced at the database layer. Significant actions — status changes, assignments, entitlement changes, administrator activity — are written to an append-only audit trail. No system is perfectly secure, but tenant isolation and least-privilege access are designed into the platform rather than added afterwards.
10. Cookies
We use cookies that are necessary to sign you in and keep your session secure, plus limited analytics to understand product usage. We do not use advertising cookies.
11. Data processing agreements
If your organisation — particularly a public body or enterprise — requires a formal Data Processing Agreement, contact us and we will put one in place.
12. Changes
We will update this page as the platform evolves and will change the "last updated" date above. For material changes affecting how we handle your data, we will notify account holders directly.