AERPrivacy Policy

Policy

Privacy Policy

Last updated: 13 July 2026

This policy explains what AER records, what it deliberately does not record, how long it keeps data and how you can have it removed. AER is operated by Ad Astra Computing. It is in an early-access phase and can change.

This policy is provided by the operator of AER, Ad Astra Computing. Enterprise customers can request a Data Processing Agreement. Contact us at privacy@adastracomputing.com.

What we collect

The auto-instrumentation collector captures metadata only. It records model names, token counts, tool names, hostnames, process names and timing. Each completed session becomes a signed record. At signup we collect an email address to send the activation link.

What the collector deliberately does not capture

This is the strongest privacy fact about AER, so we state it plainly. The collector never captures prompts, model completions, tool arguments, request or response bodies or headers. It sees the shape of what your agent did, not the content it read or wrote.

Retention

Agent execution events are retained indefinitely by default. Tenant-configurable retention is on our roadmap and is not available yet, so we do not promise it today. If you need data removed before then, use the deletion path described below.

Signed records

Each completed session produces a signed AER bundle stored in Cloudflare R2 object storage. A bundle is reachable by anyone who has its unguessable record ID (a UUIDv7). There is no public index and no listing of records. Verification pages are public by design so a third party you share a record with can check its signature independently.

Transparency log and permanence

A record's cryptographic hash and signature are anchored to Sigstore Rekor, a public, permanent, append-only transparency log operated by the Linux Foundation. Only the hash and signature are sent to Rekor. Event content is never sent. Because Rekor is public and permanent, an anchored hash cannot be deleted, including by an erasure request. This is a deliberate design choice that lets anyone prove a record existed and has not changed, and it is the one thing our deletion path cannot reach.

Email and API keys

Your email is collected at signup only to send the activation link. It is stored only until activation completes, then discarded. Signup is rate limited.

API keys are shown once at creation and stored only as an Argon2id hash. AER can never recover the plaintext of a key. In the console, your tenant key lives in the browser's localStorage, not in cookies.

Deletion and your rights

An operator erasure path exists. It soft-deletes a tenant immediately and hard-purges its data (sessions, events, bundles, findings and audit) after a short grace period. To request erasure, contact privacy@adastracomputing.com.

One honest caveat: hashes already anchored to Rekor are permanent and outside AER's control. Erasure removes your event content and bundles from AER, but it cannot remove an anchored hash from a public transparency log.

European users (GDPR)

If you are in the European Economic Area, you have the right to access the data we hold about you, to have inaccurate data rectified, to erasure through the mechanism above, to portability of your data and to object to processing. We honour these requests through the same contact address. The single exception is a hash already anchored to Rekor: it is public and permanent, so it cannot be erased.

Sub-processors

We use the following sub-processors to run the service. There are no others today.

ProviderPurposeData in scope
CloudflareHosting, storage and edge network (Workers, D1, Durable Objects, R2)All service data
Sigstore Rekor (Linux Foundation)Public transparency anchoring of record hashes and signaturesRecord hash and signature only, never event content

Cookies, localStorage and tracking

The marketing site and console use no third-party analytics and no advertising or tracking cookies. The console stores a tenant API key in localStorage for its own operation only. Our Content-Security-Policy restricts connections to AER's own API.

Data location

AER runs on Cloudflare (Workers, D1, Durable Objects and R2), a global network. The primary database region is Eastern North America with read replication. If you visit from the EU, your data may be processed on Cloudflare's global network.

Changes to this policy

AER is in a pilot phase and the service can change. When we change this policy we update the date at the top of the page. Material changes will be reflected here.

Contact

For privacy questions or a data request, email privacy@adastracomputing.com. AER is operated by Ad Astra Computing.