Privacy Policy
Last updated: August 23, 2026
1. Introduction
Aetheris ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Aetheris platform, website, mobile applications, and related services (collectively, the "Service").
Aetheris is an open-source billing and virtualization management platform. When you self-host Aetheris, you control your own data. This policy applies to data processed by our hosted services and marketing website.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, password (hashed), and organization details - Billing information: payment method details (processed by Stripe), invoice addresses, VAT numbers - Server configuration: game server settings, node configurations, user permissions - Communications: support tickets, Discord messages, email correspondence - Content: custom themes, addon configurations, whitelabel settings
2.2 Information Collected Automatically
- Usage data: pages visited, features used, actions performed within the panel - Device information: browser type, operating system, screen resolution, device type - Network data: IP address, geolocation (country/city level), referral source - Log data: server access logs, error logs, API request logs - Analytics: anonymous usage patterns via Vercel Analytics
2.3 Information from Third Parties
- OAuth providers: profile information from Google, Discord, or Apple when you sign in - Payment processors: transaction confirmations and status from Stripe, PayPal, or Mollie - Hosting providers: server resource metrics from Proxmox VE, VirtFusion, or Pterodactyl
3. How We Use Your Information
We use collected information for the following purposes:
- Service delivery: To provide, maintain, and improve the Aetheris platform - Authentication: To verify your identity and manage access to your account - Billing: To process payments, generate invoices, and manage subscriptions - Server management: To provision, monitor, and control virtual servers and game servers - Communication: To send service notifications, security alerts, and support responses - Analytics: To understand usage patterns and improve platform performance - Security: To detect and prevent fraud, abuse, and unauthorized access - Legal compliance: To fulfill legal obligations and respond to lawful requests
4. Data Processing Basis
We process your data under the following legal bases:
- Contract performance: Processing necessary to deliver the Service you subscribed to - Legitimate interest: Improving the platform, ensuring security, and preventing abuse - Consent: Where you have explicitly agreed (e.g., marketing emails, analytics) - Legal obligation: Where required by applicable law (e.g., tax records, court orders)
5. Data Sharing
We do not sell your personal data. We may share information with:
- Service providers: Vercel (hosting), Stripe (payments), SendGrid (emails), Cloudflare (CDN/DNS) - Infrastructure partners: Proxmox, VirtFusion, Pterodactyl APIs for server management - Analytics: Vercel Analytics (anonymous, aggregated data only) - Legal authorities: When required by law, subpoena, or court order - Community: Public information you choose to share on GitHub or Discord
All third-party processors are bound by data processing agreements and are required to maintain appropriate security measures.
6. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Duration of account + 30 days | Service delivery and account recovery |
| Billing records | 7 years | Tax and accounting compliance |
| Server logs | 90 days | Security monitoring and debugging |
| Analytics data | 26 months | Performance trend analysis |
| Support tickets | 2 years | Service quality improvement |
| Payment tokens | Until deleted by user | Recurring payment processing |
| Backups | 30 days rolling | Disaster recovery |
7. Data Security
We implement industry-standard security measures:
- Encryption: All data in transit is encrypted via TLS 1.3. Sensitive data at rest is encrypted with AES-256. - Authentication: Passwords are hashed with bcrypt (12 rounds). Session tokens are cryptographically random. - Access control: Role-based access with principle of least privilege. All admin actions are audited. - Infrastructure: Hosted on Vercel (SOC 2 Type II certified) with Cloudflare DDoS protection. - Database: PostgreSQL with encrypted connections and regular automated backups. - Secrets: API keys and credentials are stored in encrypted environment variables, never in source code. - Monitoring: Real-time alerting for suspicious activity, failed authentication attempts, and anomalies.
No system is 100% secure. If you discover a vulnerability, please report it responsibly via hello@another-horizon.eu or our GitHub Security Advisories.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you - Rectification: Request correction of inaccurate or incomplete data - Erasure: Request deletion of your personal data ("right to be forgotten") - Restriction: Request limitation of processing in certain circumstances - Portability: Receive your data in a structured, machine-readable format - Objection: Object to processing based on legitimate interests - Withdraw consent: Withdraw previously given consent at any time
To exercise these rights, contact us at hello@another-horizon.eu. We will respond within 30 days.
If you are self-hosting Aetheris, your data is on your own infrastructure. You have full control and can export or delete it at any time via the admin panel.
9. International Data Transfers
Aetheris is operated from the European Union. If you access the Service from outside the EU, your data may be transferred to and processed in the EU.
We ensure appropriate safeguards for international transfers through: - Standard Contractual Clauses (SCCs) with third-party processors - Adequacy decisions where applicable - Your explicit consent where other mechanisms are not available
10. Cookies and Tracking
We use cookies and similar technologies as described in our Cookie Policy. Key points:
- Strictly necessary cookies are required for authentication and security - Functional cookies remember your preferences (theme, language) - Analytics cookies collect anonymous usage data - You can manage cookie preferences through your browser settings
11. Children's Privacy
The Aetheris platform is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at hello@another-horizon.eu and we will promptly delete such information.
12. Open Source and Self-Hosting
Aetheris is open source under the AGPL-3.0 license. When you self-host the platform:
- All data remains on your infrastructure - We have no access to your self-hosted instance data - You are responsible for your own data protection compliance - You can configure data retention, backup, and deletion policies through the admin panel - The Android app connects directly to your panel instance; no data passes through our servers unless you use our hosted panel
The self-hosted platform includes built-in tools for data export (GDPR Article 20) and account deletion (GDPR Article 17).
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. The "Last Updated" date at the top indicates when this policy was last revised.
For material changes, we will notify you via: - Email to the address associated with your account - Dashboard notification in the Aetheris panel - Prominent notice on our website
We encourage you to review this policy periodically.
14. Contact Us
For questions about this Privacy Policy or our data practices:
Data Controller: Leonardo Galli (Leo-Galli), Aetheris Project Email: hello@another-horizon.eu #FAFAFA] font-medium">Discord: [discord.gg/6GcfebuT2A #FAFAFA] font-medium">GitHub: [github.com/aetheris-project
For EU residents, you also have the right to lodge a complaint with your local data protection authority.
This Privacy Policy is complemented by our Cookie Policy. By using Aetheris, you agree to the collection and use of information as described in this policy.