1. Introduction
The Aelira platform and website are operated by Aelira AI Pty Ltd (an Australian proprietary company), referred to in this Policy as “Aelira,” “we,” “us,” or “our.”
At Aelira, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
We are committed to protecting your personal data and your right to privacy. If you have any questions or concerns about our policy or our practices, please contact us at [email protected].
2. Information We Collect
2.1 Information You Provide
- Email Address: When you join our waitlist or create an account
- Account Information: Username, password, and profile information
- Payment Information: Processed securely through third-party payment processors (we do not store credit card details)
- Communication Data: Your interactions with our support team
2.2 Scan Data and Uploaded Documents
When you submit a website URL or upload a document (PDF, Word, PowerPoint, Excel, LaTeX, or other supported formats) to Aelira for accessibility scanning or remediation, we collect and process the following data:
- URLs and Uploaded Documents: The web addresses and files you submit for accessibility scanning and remediation
- Scan Results: Detected accessibility issues, scores for implemented checks, and the page or document elements analysed. These scores do not establish WCAG conformance.
- Remediated Output Files: Where supported changes produce a saved candidate, that output and its recorded outcomes. Human review is required; some inputs need manual work or return no remediated file.
- HTML/CSS Data (web scans): Temporarily processed during web scans to detect accessibility issues; not stored permanently
- Stored Documents: Uploaded files and supported output files are processed to provide the Service. Retention and deletion are described in Section 7. Aelira does not train its own models on your uploads or sell them for marketing; content sent to an AI provider is also subject to the provider terms described in Section 10.
- Scan History: Date/time of scans, scanner results over time, issue tracking
- Access and deletion: Use the available dashboard controls to access supported reports and outputs. Contact [email protected] for export or deletion requests that those controls do not cover.
- Browser connections: The hosted service uses HTTPS/TLS for browser connections. Internal service traffic and provider transfers require separate deployment review.
2.3 Automatically Collected Information
- Usage Data: How you interact with Aelira (features used, frequency, session duration)
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP address, timestamps, error logs for debugging
- Cookies: Small data files to maintain sessions and preferences
2.4 Device Recognition for Demo Rate Limiting
For our free demo feature, we use privacy-preserving device recognition to limit scans to 3 per device. This helps us prevent abuse while allowing legitimate users to try our service.
- Browser Identifier: A randomly generated identifier stored in your browser's local storage
- Hashed Browser Characteristics: We collect and hash (one-way encrypt) browser rendering characteristics. We never store or transmit the raw data, only a cryptographic hash
- Purpose: Used solely for rate limiting demo scans. Not used for tracking, advertising, or any other purpose
- No Cross-Site Tracking: This identifier is unique to Aelira and cannot be used to track you across other websites
Legal Basis (GDPR): Legitimate interest in preventing abuse of our free service. You can clear this data by clearing your browser's local storage.
3. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Aelira service
- Improve and personalize your experience
- Process transactions and manage subscriptions
- Send you updates, newsletters, and marketing communications (with your consent)
- Respond to support requests and customer inquiries
- Monitor and analyze usage patterns to improve our service
- Detect, prevent, and address technical issues or security vulnerabilities
- Comply with legal obligations
4. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
4.1 Service Providers
We may share data with trusted third-party service providers who assist us in operating our service:
- Cloud infrastructure providers (database hosting, storage)
- Payment processors (Stripe, PayPal)
- Email service providers (for transactional and marketing emails)
- AI providers for selected content-processing tasks, as described in Section 10
- Analytics infrastructure for consented website usage measurements, as described in Section 11
4.2 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or to protect our rights, property, or safety.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
5. Data Security
The hosted service uses HTTPS for browser connections. Institutional security review also needs to assess the actual deployment:
- Transmission and storage: Review protection for internal service traffic, stored files, databases and backups separately from browser HTTPS.
- Access controls: Review account permissions, tenant access, administrative access and logging for the intended deployment.
- Operational controls: Confirm monitoring, patching, recovery and incident-response arrangements in the service agreement.
- Assurance evidence: A hosting provider's certification does not establish Aelira's certification. We have not published an independent security assessment or SOC 2 certification here.
- Data minimisation: Scan results, source files, candidate outputs, logs and backups can have different retention rules. Section 7 describes the current remediation-file expiry settings and how to request deletion.
Request current technical and contractual evidence before submitting sensitive institutional material. Security requirements and provider data flows need review for the actual service and configuration.
6. Your Privacy Rights
Depending on your location, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and associated data
- Data Portability: Export your data in a machine-readable format
- Objection: Object to processing of your personal data for certain purposes
- Withdraw Consent: Opt out of marketing communications at any time
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
7. Data Retention
Retention depends on the record type and deployment. The hosted beta's current remediation-file settings are:
- Candidate remediation files: Expire 30 days after creation. Approval starts a new 30-day expiry window.
- Files successfully written back to a connected system: The hosted remediation copy expires seven days after writeback. The destination system controls its own copy.
- Expired files: Become unavailable for download and are eligible for scheduled cleanup. Cleanup timing can depend on service operation and outstanding review or writeback activity.
- Other records: Source uploads, scan history, account records, operational logs and backups have separate lifecycles. These settings do not establish a universal deletion period for them. Request the current retention and backup schedule before submitting sensitive institutional material.
- Self-hosting: Your institution controls deployment settings and must define its own retention, backup and deletion policy.
Deletion requests. Contact [email protected] to request deletion of your data. We will confirm the scope, applicable legal retention and handling of backups or provider-held data. Export any needed files before their expiry; account closure does not provide an indefinite archive.
8. International Data Transfers
Our primary hosting is in Sydney, Australia. AI processing, email delivery and other service providers may process data in other countries. Contact [email protected] for the current provider list, processing locations and contractual transfer arrangements before submitting data subject to institutional or cross-border restrictions. A Sydney hosting location does not mean every processing step stays in Australia.
9. Hosted Beta Eligibility
Hosted beta accounts and AI-enabled evaluation tools are intended for faculty, staff and institutional administrators aged 18 or older, using the Service for professional purposes. They are not intended as student-facing tools or for use by anyone under 18. Do not invite under-18 users or submit student personal information without institutional authorisation and an agreed data-processing scope. Contact [email protected] if you believe an under-18 user has provided personal data so we can investigate and arrange appropriate removal.
10. Third-Party Services
Aelira uses the following services to provide our accessibility compliance platform:
- Axe-core: Open-source accessibility testing engine (runs in our infrastructure; no data shared with third parties)
- Google Gemini API: Our hosted service uses an API project with paid billing enabled. Selected AI tasks can send document text, images or other excerpts to Google for processing. Google's paid-service terms exclude use of prompts and responses to improve its products, while allowing limited safety logging and processing in other countries. Self-hosted deployments must confirm their own account and provider terms. Review the applicable processing arrangements before submitting sensitive content. See Google's API Terms.
- Ollama (self-hosted option): Local inference can keep AI processing on institution-controlled infrastructure when local providers are configured. Confirm the actual provider, fallback services, network egress, logs and backups; selecting Ollama alone does not establish that content never leaves the deployment.
- Payment processors: Stripe for secure payment processing (subject to their privacy policy)
- Cloud hosting: Vultr Cloud Compute. Our primary infrastructure is hosted in Sydney, Australia.
- Email services: Self-hosted Mailcow / Postfix on our infrastructure for transactional emails (account confirmations, magic-link sign-in, scan notifications). Outbound delivery is relayed via MXroute.
- Analytics: Umami (self-hosted at analytics.aelira.ai), privacy-focused, with no third-party data sharing
We do not sell or share your website URLs, uploaded documents, scan results, or any personal data with third parties for marketing or advertising purposes.
11. Cookies and Tracking
We use cookies and similar tracking technologies to:
- Essential cookies: Required for authentication and security
- Functional cookies: Remember your preferences (theme, language, region)
- Analytics: Understand how you use our service (see details below)
11.1 Umami Analytics
We use Umami, a privacy-focused, self-hosted analytics platform. Umami is specifically designed to respect user privacy:
- Self-hosted: All analytics data is stored on our own servers at analytics.aelira.ai, never shared with third parties
- No cookies: Umami itself does not use cookies or collect personal identifiers
- Consent-based: Analytics only load after you consent via our cookie banner
- Anonymised data: No IP addresses or personal information are stored
- Privacy review: Analytics settings and consent handling form part of the deployment's privacy review; using Umami does not by itself establish legal compliance.
11.2 Data Collected by Analytics
When you consent to analytics, we collect:
- Page views: Which pages you visit on our site
- Referrer: How you arrived at our site (e.g., search engine, direct link)
- Device information: Browser type, operating system, screen size (anonymised)
- Country/Region: General geographic location (not precise location)
- Session duration: How long you spend on the site
- Custom events: Feature usage (e.g., "demo started", "signup clicked")
11.3 Cookie Consent
When you first visit our site, we display a cookie consent banner. You can accept all cookies, reject optional cookies, or customise your preferences. You can change your preferences at any time by clicking "Manage Preferences" in the cookie banner or contacting us. Disabling analytics cookies will not affect site functionality.
12. Updates to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or through the service. The “Last reviewed” date at the top identifies the latest policy review.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us:
- Email: [email protected]
- Website: https://aelira.ai
14. GDPR Compliance (EU Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Right to be informed about data processing
- Right to restrict processing
- Right to lodge a complaint with a supervisory authority
Our legal basis for processing your data is your consent, contractual necessity, and legitimate interests.
15. CCPA Compliance (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your rights