ReMail Legal
Back to the admin
Legal

Aeropage — Privacy Policy

Last updated: 29 July 2026

This Privacy Policy explains how Aeropage Limited ("Aeropage", "we", "us") collects and uses personal information in connection with the Aeropage / vibekit platform (the "Service"). It forms part of, and is incorporated into, our Terms of Service.

Capitalised terms not defined here have the meaning given in the Terms.

1. Two different roles, and why it matters

The Service is a tool that developers ("Customers") use to build their own applications ("Customer Applications"). Personal information reaches us in two distinct ways, and our role differs in each:

2. Information we collect

2.1 Customer account data

2.2 End-user data (processed for our Customers)

If a Customer enables vibekit's optional sign-in features, we process, on their behalf:

2.3 What we receive from Google

When a Customer enables Google sign-in, we request only the openid and email scopes. That means Google discloses to us the person's email address and whether it has been verified — nothing else. We do not receive or request their name, profile picture, contacts, calendar, files, or any other Google data.

That email address is used for one purpose: to determine whether the person appears in the Customer's own user list and may therefore sign into that Customer's application. We do not use it for advertising, we do not sell or share it, we do not use it to build profiles, and we do not use it to train machine-learning models. Data obtained through Google APIs is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements.

Where a Customer supplies their own Google OAuth client instead of using ours, their Google project's own terms apply to that relationship in addition to this Policy.

2.4 What we do not collect

We do not use advertising cookies, cross-site tracking, analytics pixels, or third-party trackers on the Service. The administrative application stores your sign-in session in your browser's local storage so that you stay signed in; that is not used for tracking. We do not knowingly collect information from children under 13, and the Service is not directed to them.

3. How we use information

We use personal information to: operate, maintain, and secure the Service; authenticate Customers and, on a Customer's instructions, their end users; deliver configuration and data to Customer Applications; send transactional messages such as sign-in links and, where a Customer has enabled them, alert digests; detect, investigate, and prevent abuse, fraud, and security incidents; comply with legal obligations; and diagnose and fix faults.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

For Customer account data we rely on: performance of a contract (providing the Service you have signed up for); legitimate interests (securing the Service, preventing abuse, and improving reliability); and legal obligation where applicable. Where we act as a processor for end-user data, the Customer is responsible for establishing the legal basis for that processing.

5. Service providers and international transfers

We use a small number of infrastructure providers to run the Service. They process personal information only to provide their services to us, under contractual confidentiality and security obligations:

Provider Purpose
Cloudflare Hosting, edge compute, storage, and databases for the Service
Supabase Customer account authentication and project records
Google Google sign-in, only where a Customer has enabled it
Resend Delivery of transactional email, such as sign-in links
Airtable The Customer's own data source, connected under credentials the Customer supplies and controls

Aeropage Limited is established in the United States, and these providers may process data in the United States and other countries. Where personal information is transferred out of the UK or EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses where applicable.

6. Security

We apply technical and organisational measures appropriate to the risk, including: encryption in transit (TLS) and encryption at rest for stored credentials and stored end-user records; encrypted request and response payloads between an application and our servers; short-lived, cryptographically signed session tokens; opaque identifiers so that a Customer's underlying data-source identifiers are never exposed to a browser; per-application isolation of data and credentials; rate limiting; and restricted, audited administrative access.

No system is perfectly secure. As set out in Section 9.3 of the Terms, the optional authentication features are provided "as is", and Customers remain responsible for assessing their suitability and for any notifications required by law in the event of an incident affecting their end users.

7. Retention

We retain Customer account data and project configuration for as long as your account is active. Operational and sign-in records are retained while they remain useful for security, abuse prevention, and diagnosing faults.

When you delete an application or close your account, we delete or irreversibly render inaccessible the associated configuration and stored credentials. We may retain limited records where required for legal, accounting, or security purposes. A Customer may request deletion of end-user records processed on their behalf at any time, and we will action it without undue delay.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing; to withdraw consent where processing is based on consent; and to complain to your data-protection authority (in the UK, the Information Commissioner's Office). Residents of California and other US states with comprehensive privacy laws have comparable rights, including the right not to be discriminated against for exercising them — noting that we do not sell personal information or share it for cross-context behavioural advertising.

To exercise any of these rights over data we hold as a controller, contact privacy@aeropage.io. We will respond within the period required by applicable law. If your request concerns data held within an application built by one of our Customers, please contact that Customer directly — they control it, and we will support them in responding.

9. Changes to this Policy

We may update this Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where appropriate, notify you through the Service. Your continued use after a change takes effect constitutes acceptance of the updated Policy.

10. Contact

Aeropage Limited
1111B S Governors Ave STE 7987, Dover, DE 19904, United States
Privacy: privacy@aeropage.io
Legal: legal@aeropage.io