Privacy Policy
Private Messaging & Collaboration Platform
1.Introduction
Welcome to Aero (package name: com.aryankaushik.aero), a private messaging and collaboration application developed by Aryan Kaushik ("we", "us", or "our"). Aero is available on the Android and Web platforms and enables users to communicate through chat, voice notes, file sharing, and real-time collaboration tools. The application also includes AI-powered features designed to help organise messages and surface useful insights.
This Privacy Policy explains what personal data we collect, how we use and protect it, and the rights you have concerning your information. It applies to all users of the Aero application and any related services we provide, regardless of the platform or device used to access them.
This policy has been drafted to comply with the General Data Protection Regulation (GDPR), the India Digital Personal Data Protection Act, 2023 (DPDP Act), and the Google Play Developer Program Policies, including the Google Play Data Safety disclosure requirements.
By creating an account or using Aero, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of the application.
2.Data We Collect
We collect only the data that is necessary to provide, maintain, and improve the Aero application. The categories of personal data we collect are set out below.
2.1 Account Information
When you create an Aero account, we collect:
- Email address
- Username
- Full name
- Password (stored exclusively as a cryptographically hashed value; we never store or have access to your plaintext password)
2.2 Profile Information
You may optionally provide additional profile details, including:
- Profile picture
- Bio / status message
- Preferred language
- Timezone
- Country
2.3 User-Generated Content
Content you create or share within Aero may include:
- Chat messages (text, formatted text)
- Images and photographs
- Videos
- Audio messages and voice notes
- Documents and files
- GIF selections
- Stories
- Workspace data (tasks, notes, calendar events)
- Files and folders you store in Aero Drive, together with their file names, sizes, and formats (see Section 2.8)
2.4 Communication & Social Data
To deliver messaging and social features, we process:
- Friend and contact lists within the app
- Message metadata (sender, recipient, timestamp, delivery and read status)
- Call metadata (call type, duration, participants, timestamp)
- Online / last-seen status
2.5 Device & Technical Information
When you access Aero, we automatically collect certain technical data, including:
- IP address
- Device platform and operating system
- User-Agent string
- Push notification token: a device identifier used solely for delivering push notifications to your device
2.6 Subscription & Billing Data
If you subscribe to a paid plan, we collect:
- Subscription plan and tier selected (Apex, Pro or Max)
- Grace credit pack purchases, including the pack bought, the credits granted, and their expiry date
- Recurring Aero Drive storage add-on tier, where purchased
- Premium @handle purchase records, including the handle bought, the price tier, the billing provider used, and the payment status
- Payment status and billing cycle
We do not collect, process, or store your credit card number, bank account details, or other financial instrument data. All payment transactions are handled by our third-party payment processor and are subject to their own privacy policy.
2.7 AI Feature Data
If you use Aero's AI-powered features (such as message organisation and insights), we may process:
- Messages submitted for AI organisation
- Memory and insight data generated by the AI features
- AI interaction and preference data
AI processing is performed using a trusted third-party AI service provider. Messages sent to the AI service are used solely for the purpose of providing the requested feature and are not used to train third-party AI models.
2.8 Aero Drive Data
Aero Drive is our cloud file storage and file-sharing feature. If you use Aero Drive, we process:
- The file content you upload, together with file and folder names, file sizes, declared and detected file formats, and integrity checksums.
- Storage usage and quota accounting for your account, including the storage tier you are entitled to and the space you have consumed.
- Sharing records: the Aero users you grant access to, whether a shareable link exists for a file, and when a grant or link is created or revoked.
- Safety-scanning results for each uploaded file, and file lifecycle states such as active, trashed, or quarantined.
Automated safety scanning. Files uploaded to Aero Drive are automatically scanned before they can be shared or downloaded. This scanning also compares the file format you declare against the format detected from the file content, because a mismatch is a common malware indicator. Files that do not pass scanning are quarantined and cannot be served. This process is automated and is carried out for security and abuse-prevention purposes; it does not involve routine human review of your file content.
Important: Aero Drive is not end-to-end encrypted
The End-to-End Encryption described in Section 6.2, which is in final testing, is planned for 1:1 Direct Messages and Private Docks only and will not apply to Aero Drive. Aero Drive files are encrypted in transit and at rest, but they are not end-to-end encrypted, because Aero must be able to process the file to run safety scanning and generate previews. You should not treat Aero Drive as a zero-knowledge store.
Shared links. Where you create a shareable link, only a cryptographic hash of the link token is stored on our servers, never the token itself. Recipients must sign in to an Aero account before a shared file is resolved or downloaded, so shared files are never served anonymously. Download links issued for a share are short-lived and expire automatically. If you revoke a share, no new download links can be issued for it.
2.9 Public Handle & Handle Purchase Data
Aero operates a single global namespace of public handles (@usernames) shared by user accounts and Docks. In connection with this we process:
- The handle itself, its claim status, and which account or Dock currently holds it.
- Handle history, including when a handle was reserved, activated, released, or placed on hold.
- For purchased premium handles: a record of the purchase, the price tier, the billing provider used, and the payment status.
- The results of automated handle screening carried out to prevent impersonation, trademark infringement, and unsafe or policy-violating names.
Please note that a handle is a public identifier. Your handle and any Dock handle you hold are visible to other users and may be visible to anyone who can view the relevant profile or Dock.
3.How We Use Your Data
We use the data we collect for the following purposes:
- Account creation and authentication - to register your account, verify your identity, and maintain secure access.
- Messaging and communication - to deliver messages, media, files, and other content between users.
- Voice and video calls - to establish and maintain real-time voice and video call sessions.
- Push notifications - to alert you of incoming messages, calls, and other relevant activity.
- AI-powered features - to organise messages, generate insights, and provide AI-driven assistance within the app.
- Profile and social features - to display your profile to other users, manage friend lists, and enable social interaction.
- Subscription management - to process, manage, and fulfil paid subscription plans, storage add-ons, and premium handle purchases.
- File storage and sharing - to store the files you upload to Aero Drive, track your storage usage against your quota, and deliver those files to the people you choose to share them with.
- Safety and integrity scanning - to automatically scan files uploaded to Aero Drive for malware and file-format mismatches before they can be shared or downloaded.
- Public handle management - to operate the public handle namespace, settle competing claims to a handle, process premium handle purchases, and screen handles for impersonation, trademark conflicts, and policy violations.
- Customer support - to respond to your enquiries, troubleshoot issues, and provide assistance.
- Security and fraud prevention - to detect, prevent, and respond to abuse, fraud, security threats, and violations of our terms of service.
- Service improvement - to analyse usage patterns, diagnose technical issues, and improve the performance and reliability of the application.
We do not use your personal data for targeted advertising, user profiling for advertising purposes, or the sale of personal data to third parties.
4.Legal Bases for Processing
Where the GDPR applies, we rely on the following legal bases to process your personal data:
- Performance of a contract - (Article 6(1)(b) GDPR): Processing is necessary to provide you with the Aero service as described in our Terms of Service.
- Legitimate interests - (Article 6(1)(f) GDPR): Processing is necessary for our legitimate interests in maintaining the security of the application, preventing abuse, and improving our services, provided those interests are not overridden by your fundamental rights.
- Consent - (Article 6(1)(a) GDPR): Where you have given explicit consent, for example when opting in to AI-powered features or providing optional profile information. You may withdraw consent at any time.
- Legal obligation - (Article 6(1)(c) GDPR): Processing is necessary to comply with applicable legal requirements.
Where the India DPDP Act applies, we process your personal data on the basis of your consent provided at the time of account creation and use of the application, or as otherwise permitted under the Act for legitimate uses.
5.Data Sharing & Third-Party Services
We do not sell, rent, or trade your personal data. We share data only with trusted third-party service providers who assist us in operating and delivering the Aero application. These providers are contractually obligated to protect your data and to use it solely for the purposes we specify.
The categories of third-party service providers we engage include:
- Push notification provider - to deliver push notifications to your device. Your device push token is shared with this provider for delivery purposes only.
- AI service provider - to power AI-assisted message organisation and insight features. Only the content you explicitly submit to AI features is processed.
- Cloud storage and content delivery providers - to securely store and deliver media files (images, videos, documents, and audio) that you share within the app.
- Payment processor - to handle subscription payments and billing. We do not receive or store your payment instrument details.
- Transactional email provider - to send essential service emails such as account verification, password reset, and important notifications.
- Real-time communication provider - to enable voice and video calling functionality within the app.
- Security and rate-limiting provider - to protect the service against abuse, brute-force attacks, and other security threats.
- GIF and sticker search provider - to provide in-app animated content search. Your search queries are sent to this provider to return relevant results.
We may also disclose your data if required to do so by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect our rights, the safety of our users, or the integrity of the service.
6.Data Storage & Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction.
6.1 Storage Infrastructure
- User account data and message data are stored in an encrypted database with access controls and authentication.
- Media files (images, videos, documents, audio) are stored in secure cloud storage with appropriate access policies.
- Media delivery is accelerated through a content delivery network (CDN) for performance and reliability.
6.2 Encryption
- Encryption in transit - All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security).
- Encryption at rest - Chat messages stored on our servers are encrypted using AES (Advanced Encryption Standard) encryption.
- End-to-End Encryption (E2EE): in final testing - End-to-end encryption for 1:1 Direct Messages and Private Docks is in final testing and is not yet generally available. Until it is made available to you, these messages are protected by encryption in transit and at rest as described above, and Aero manages the keys used for that encryption. When E2EE becomes available and you enroll, the encryption keys will be generated and held exclusively on your devices, and Aero will not be able to decrypt or read the contents of your E2EE communications.
- Password security - User passwords are cryptographically hashed using industry-standard algorithms and are never stored in plaintext.
6.3 Security Practices
- Secure authentication with token-based session management.
- Rate limiting and abuse detection mechanisms to prevent brute-force attacks and service abuse.
- Regular security reviews and updates of dependencies.
While we strive to use commercially acceptable means to protect your personal data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents in accordance with applicable law.
6.4 Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authorities without undue delay and, where feasible, within 72 hours of becoming aware of it, in compliance with the GDPR and the DPDP Act.
7.International Data Transfers
Aero's primary hosting and storage infrastructure is located in India. Certain third-party service providers we rely on (described in Section 5) operate from other jurisdictions, including the United States and the European Economic Area. By using Aero, you acknowledge that your personal data may be transferred to, stored, and processed in countries whose data protection laws differ from those of your own jurisdiction.
7.1 Transfers from the European Economic Area
India is not currently the subject of an adequacy decision by the European Commission under Article 45 of the GDPR. Accordingly, where personal data is transferred from the EEA to Aero in India, or onward to a service provider in a country without an adequacy decision, that transfer is made under the Standard Contractual Clauses (SCCs) adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, incorporating Module Two (Controller to Processor) where we appoint a provider as our processor, and Module One (Controller to Controller) where a provider acts as an independent controller.
Where a service provider is established in, or the data is transferred to, a country that is covered by a European Commission adequacy decision, we rely on that adequacy decision under Article 45 GDPR instead of the SCCs.
In addition to the SCCs, we apply supplementary technical and organisational measures to protect transferred data, including encryption in transit (TLS), encryption at rest, access controls and authentication, and data minimisation, as described in Section 6.
7.2 Transfers from the United Kingdom and Switzerland
For transfers subject to the UK GDPR, we rely on the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018. For transfers subject to the Swiss Federal Act on Data Protection, we rely on the SCCs as amended and recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC).
You may request a copy of the safeguards we rely on for a given transfer by contacting us using the details in Section 13. We may redact commercially confidential terms from any copy we provide.
7.3 Transfers under the India DPDP Act
For users in India, transfers of personal data outside India are made in accordance with Section 16 of the Digital Personal Data Protection Act, 2023 and the rules issued thereunder. We do not transfer personal data to any territory that the Central Government has restricted by notification for this purpose.
8.Data Retention & Account Deletion
We retain your personal data only for as long as is reasonably necessary to provide the Aero service and to comply with our legal obligations.
Important: You have 30 days to change your mind. After that, deletion is permanent.
Account deletion happens in two stages. When you confirm deletion with your password and an OTP, your account is immediately deactivated and permanent deletion is scheduled for 30 days later. During those 30 days your data still exists on our systems, and you can recover your account. Once the 30 days elapse, deletion is finalised and cannot be undone.
Stage 1 — Immediately on confirmation
- All of your active sessions are revoked and you are signed out on every device.
- Your account is deactivated and your profile stops being reachable by other users.
- Permanent deletion is scheduled for 30 days from the moment you confirm.
Changed your mind? Simply sign in again with your credentials at any point during the 30-day window. Your account is restored with the same account identity and your data intact. A short cooldown applies before you can request deletion again.
Stage 2 — After 30 days, permanent and irreversible
If you do not sign back in, your account is permanently deleted. At this point the following happen irreversibly:
- Your user record and all remaining sessions are permanently dropped.
- All your messages, voice notes, and calls are deleted.
- All media stored in cloud storage (profile pictures, chat attachments, dock files) is completely cleared.
- All files stored in Aero Drive, including files held in Trash, are deleted, and every active share link and access grant for those files stops working.
- All AI embeddings, memories, and RAG data associated with your account are securely wiped.
- Any public handle held by your account, including a purchased premium handle, is released back into the public handle namespace and may later become available to other users.
- If you are the owner of a Dock, the entire Dock and all its contents are deleted with no transfer of ownership.
- Technical and log data - Retained for a limited period (typically no longer than 90 days) for security monitoring, debugging, and service improvement purposes.
- Billing data - Retained for as long as necessary to manage your subscription and to comply with financial record-keeping and tax obligations.
8.1 Aero Drive Retention
Files you store in Aero Drive are retained until you delete them or until your Aero account is permanently deleted. Files you move to Trash remain recoverable by you until you restore them or delete them permanently. When your account is permanently deleted, your Aero Drive contents, including files held in Trash, are deleted and every active share link and access grant for those files stops working.
If your storage entitlement is reduced — for example because you cancel a storage add-on or your paid plan ends — and the space you are using then exceeds your remaining quota, the following applies:
- Your Aero Drive is placed in a read-only recovery state for 30 days. Your files remain intact and downloadable during this period, but you cannot upload new files.
- If you are still over quota after 30 days, we prepare a deletion plan and make it visible to you before anything is deleted, followed by a further waiting period of at least 72 hours.
- Only enough files to bring you back within your quota are deleted. We never delete your entire Drive for being over quota. Files are selected in order of Trash first, then unstarred files oldest-first, and starred files last. You may override this selection and choose what to keep.
- If you restore your quota at any point before deletion runs, by renewing, upgrading, or deleting files yourself, the deletion plan is cancelled and your Drive returns to normal.
We may also retain a file where we are required to do so by law or where it is subject to a legal hold, notwithstanding the above.
9.Your Rights & Choices
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
9.1 Rights Under GDPR (EEA Users)
- Right of access - You may request a copy of the personal data we hold about you.
- Right to rectification - You may request correction of inaccurate or incomplete personal data.
- Right to erasure ("Right to be forgotten") - You may request deletion of your personal data, subject to legal exceptions.
- Right to restriction of processing - You may request that we limit the processing of your personal data in certain circumstances.
- Right to data portability - You may request a copy of your data in a structured, commonly used, machine-readable format.
- Right to object - You may object to processing based on legitimate interests.
- Right to withdraw consent - Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
9.2 Rights Under the India DPDP Act
- Right to access information - You may request a summary of the personal data being processed and the processing activities undertaken.
- Right to correction and erasure - You may request correction of inaccurate data or erasure of data that is no longer necessary for the purpose for which it was collected.
- Right to grievance redressal - You may raise concerns about the processing of your data by contacting us using the details in Section 13.
- Right to nominate - You may nominate another individual to exercise your rights on your behalf in accordance with applicable regulations.
9.3 Exercising Your Rights
You can exercise many of these rights directly within the Aero application:
- Update your information - Edit your profile, username, bio, and other details from the Settings screen.
- Delete your account - You may delete your account from within the app settings. Account deletion is permanent and results in the removal of your personal data from our systems.
- Manage privacy settings - Control your online status visibility, read receipts, and other privacy preferences from the Privacy Settings screen.
For any requests that cannot be fulfilled through the app, or to exercise your rights formally, please contact us at founder@intridium.com. We will respond to your request within 30 days (or such shorter period as required by applicable law).
10.Children's Privacy
To comply with the India Digital Personal Data Protection Act (DPDP Act, 2023), Aero restricts usage to individuals who are 18 years of age or older in India. Globally, where permitted, users must be at least 13 years of age. We do not incorporate any parental consent verification mechanisms, so users affirm they meet these age requirements by creating an account.
If we become aware that we have inadvertently collected personal data from a user under these age limits, we will take immediate steps to permanently delete that account and all associated data from our servers. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at founder@intridium.com so we can take appropriate action.
12.Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our data practices, the introduction of new features, legal requirements, or other operational reasons. When we make material changes to this policy, we will notify you by:
- Posting the updated policy on this page with a revised "Effective Date".
- Sending you an in-app notification or email where appropriate.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data. Your continued use of Aero after the revised policy becomes effective constitutes your acknowledgement of and agreement to the updated terms.
13.Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
- Data Fiduciary: Aryan Kaushik, operator of Aero
- Grievance Officer: Aryan Kaushik
- Email: founder@intridium.com
Grievance redressal (India). Aryan Kaushik is the designated Grievance Officer for Aero for the purposes of the Digital Personal Data Protection Act, 2023 and the rules issued thereunder. If you have a grievance about how your personal data is handled, you may contact the Grievance Officer at the email address above. We will acknowledge your grievance and work to resolve it as quickly as possible, and in any event within 90 days of receiving it.
For users in India, if your grievance remains unresolved, you may escalate it to the Data Protection Board of India in accordance with the DPDP Act.
For users in the European Economic Area, you also have the right to lodge a complaint with your local Data Protection Authority (DPA) if you believe your data has been processed in violation of the GDPR.