Aeropage — Privacy Policy
Last updated: 29 July 2026
This Privacy Policy explains how Aeropage Limited ("Aeropage", "we", "us") collects and uses personal information in connection with the Aeropage / vibekit platform (the "Service"). It forms part of, and is incorporated into, our Terms of Service.
Capitalised terms not defined here have the meaning given in the Terms.
1. Two different roles, and why it matters
The Service is a tool that developers ("Customers") use to build their own applications ("Customer Applications"). Personal information reaches us in two distinct ways, and our role differs in each:
- Customer account data — we are the controller. Information about the developer who signs up for vibekit: their account, their projects, their configuration. We decide how this is used, and this Policy governs it.
- End-user data — we are a processor. Information about the people who sign into a Customer Application. We process it on the Customer's instructions, to deliver the features they switched on. The Customer decides what is collected and why, is the controller of that data, and is responsible for giving their own users a privacy notice and obtaining any consents required. If you are an end user of an application built with vibekit and want to exercise your rights, contact the operator of that application; we will assist them in responding.
2. Information we collect
2.1 Customer account data
- Account details — the email address and password you register with. Passwords are handled by our authentication provider (Supabase) and are stored only as salted hashes; we never see or store your password in readable form.
- Project and application configuration — project names, briefs, plans, chosen technology stack, themes and design settings, the data queries you register, and your authentication settings.
- Credentials you connect — such as an Airtable personal access token, and any Google OAuth client secret or email-provider API key you choose to supply. These are encrypted at rest (AES-256-GCM) before storage and are never returned to a browser, an AI agent, or any log once saved.
- Operational records — request logs, query statistics, alert events, and a change log of configuration edits (including edits made on your behalf by an AI agent you have connected over MCP). Configuration change records are redacted so they never contain secret values.
2.2 End-user data (processed for our Customers)
If a Customer enables vibekit's optional sign-in features, we process, on their behalf:
- Email address — the identifier used to sign in and to match the person against the Customer's own user list in Airtable.
- The matched record from the Customer's Airtable user list, together with any access groups the Customer has defined. This record is encrypted at rest in our database.
- Sign-in events — the time, method (Google, magic link, or the Customer's own development impersonation tool), and outcome of each attempt, successful or not. Customers rely on this to detect unauthorised access attempts against their application.
- Session state — short-lived, cryptographically signed session tokens.
2.3 What we receive from Google
When a Customer enables Google sign-in, we request only the openid and email scopes. That means Google discloses to us the person's email address and whether it has been verified — nothing else. We do not receive or request their name, profile picture, contacts, calendar, files, or any other Google data.
That email address is used for one purpose: to determine whether the person appears in the Customer's own user list and may therefore sign into that Customer's application. We do not use it for advertising, we do not sell or share it, we do not use it to build profiles, and we do not use it to train machine-learning models. Data obtained through Google APIs is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
Where a Customer supplies their own Google OAuth client instead of using ours, their Google project's own terms apply to that relationship in addition to this Policy.
2.4 What we do not collect
We do not use advertising cookies, cross-site tracking, analytics pixels, or third-party trackers on the Service. The administrative application stores your sign-in session in your browser's local storage so that you stay signed in; that is not used for tracking. We do not knowingly collect information from children under 13, and the Service is not directed to them.
3. How we use information
We use personal information to: operate, maintain, and secure the Service; authenticate Customers and, on a Customer's instructions, their end users; deliver configuration and data to Customer Applications; send transactional messages such as sign-in links and, where a Customer has enabled them, alert digests; detect, investigate, and prevent abuse, fraud, and security incidents; comply with legal obligations; and diagnose and fix faults.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
4. Legal bases (where the UK/EU GDPR applies)
For Customer account data we rely on: performance of a contract (providing the Service you have signed up for); legitimate interests (securing the Service, preventing abuse, and improving reliability); and legal obligation where applicable. Where we act as a processor for end-user data, the Customer is responsible for establishing the legal basis for that processing.
5. Service providers and international transfers
We use a small number of infrastructure providers to run the Service. They process personal information only to provide their services to us, under contractual confidentiality and security obligations:
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, edge compute, storage, and databases for the Service |
| Supabase | Customer account authentication and project records |
| Google sign-in, only where a Customer has enabled it | |
| Resend | Delivery of transactional email, such as sign-in links |
| Airtable | The Customer's own data source, connected under credentials the Customer supplies and controls |
Aeropage Limited is established in the United States, and these providers may process data in the United States and other countries. Where personal information is transferred out of the UK or EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses where applicable.
6. Security
We apply technical and organisational measures appropriate to the risk, including: encryption in transit (TLS) and encryption at rest for stored credentials and stored end-user records; encrypted request and response payloads between an application and our servers; short-lived, cryptographically signed session tokens; opaque identifiers so that a Customer's underlying data-source identifiers are never exposed to a browser; per-application isolation of data and credentials; rate limiting; and restricted, audited administrative access.
No system is perfectly secure. As set out in Section 9.3 of the Terms, the optional authentication features are provided "as is", and Customers remain responsible for assessing their suitability and for any notifications required by law in the event of an incident affecting their end users.
7. Retention
We retain Customer account data and project configuration for as long as your account is active. Operational and sign-in records are retained while they remain useful for security, abuse prevention, and diagnosing faults.
When you delete an application or close your account, we delete or irreversibly render inaccessible the associated configuration and stored credentials. We may retain limited records where required for legal, accounting, or security purposes. A Customer may request deletion of end-user records processed on their behalf at any time, and we will action it without undue delay.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing; to withdraw consent where processing is based on consent; and to complain to your data-protection authority (in the UK, the Information Commissioner's Office). Residents of California and other US states with comprehensive privacy laws have comparable rights, including the right not to be discriminated against for exercising them — noting that we do not sell personal information or share it for cross-context behavioural advertising.
To exercise any of these rights over data we hold as a controller, contact privacy@aeropage.io. We will respond within the period required by applicable law. If your request concerns data held within an application built by one of our Customers, please contact that Customer directly — they control it, and we will support them in responding.
9. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where appropriate, notify you through the Service. Your continued use after a change takes effect constitutes acceptance of the updated Policy.
10. Contact
Aeropage Limited
1111B S Governors Ave STE 7987, Dover, DE 19904, United States
Privacy: privacy@aeropage.io
Legal: legal@aeropage.io