Privacy
Last updated: September 2026 • AION Analytics
What We Store
AION collects and stores the minimum information required to provide and secure the service:
- Account identifiers — email address and passkey credential used to authenticate your account
- Device-linked access state — passkey registration is device-linked; we store the credential identifier, not biometric data
- Subscription status — active plan, billing cycle state, and Razorpay subscription identifier, managed in PostgreSQL
- Usage metadata — API request counts, rate limit counters, and model access logs used for abuse prevention and plan enforcement, including a one-way hash of each query, linked to your account for quota metering and billing
- Registration attempts — when you try to register an account we record the time of the attempt and a keyed one-way hash of your IP address, so that attempts can be limited to five per address per 24 hours. The address itself is not stored in that record, and the hash cannot be reversed to recover it. A successful registration is stored separately with the account it creates
- Free-plan signup — when you start the free plan, our page creates a random device pass, keeps it in your browser's local storage (you can delete it from your browser settings at any time) and sends it with the request. We record a keyed one-way hash of that pass together with a keyed one-way hash of your IP address, and use them only to limit free keys: one per device, one per device-and-network pair, and two per network, in any 30 days. Because many people can share one network address, a shared address can reach its limit before you sign up. Neither the pass nor the address is stored in that record, and neither hash can be reversed to recover them
- Queries the engine cannot classify — if a headline you send through the API cannot be classified, or has to be resolved through a fallback, we retain the headline text so that we can improve the engine, including by training its classifier. These records are linked to your API key by a one-way hash. The engine’s own quality log records only a truncated one-way hash of such a headline, the model’s prediction and confidence, a timestamp and the source label you supply; it holds no text and no account identifier. We do not store the text of any other API query.
What We Do Not Do
- We do not build personal financial profiles. AION does not store or infer information about your trading activity, portfolio, or investment history.
- We do not sell, share, or rent account data to third parties for marketing or analytics purposes.
- We do not sell or share your API queries. Other than the retained unclassified headlines described above, query data is kept only as a one-way hash, for rate limiting, quota metering, billing, access control and quality monitoring.
- We do not use third-party behavioral tracking scripts (e.g., Meta Pixel, Google Analytics behavioral tracking) on authenticated surfaces.
Platform State Use
The data we collect is used for three purposes only:
- Access control — verifying that the right account can reach the right model features
- Accountability — maintaining an audit trail of API access for security and compliance
- Service integrity — rate limiting, abuse prevention, and billing state management
Data Retention
Account data is retained for the duration of your account. API access logs are retained for 90 days for security purposes; registration-attempt records (a timestamp and a one-way hash) and free-plan signup records (a pair of one-way hashes) are retained for 30 days; this period does not apply to the unclassified headlines described above, which are not deleted automatically. Subscription records are retained as required for billing and tax compliance.
To request deletion of your account and associated data, contact us at [email protected]. Deletion requests are processed within 30 days.
Open-Source Package Users
The AION Indian Market Calendar Python package operates entirely offline after installation. No network requests are made to AION servers during normal usage. No usage data is collected from package installations or queries.
Public Demo
The public demo has two parts, and they collect different things.
The Highest Risk Companies list is free to read and collects nothing. No key, no email, no account.
The two interactive tools require a demo key, and we issue that against an email address. This is the only point at which the demo collects personal data, and it is collected with your explicit consent — you tick a box saying we may contact you, and the request is refused without it. We store the address to send you the key and to contact you about AION. We do not sell it, do not share it with third parties, and do not combine it with any tracking. The key itself is stored only as a one-way hash. Ask us at [email protected] and we will delete your address.
There is still no cookie and no password. Beyond the address you gave us, we do not know who you are.
The demo allows two company lookups and three analyses per device, for the life of that device pass — these are not daily allowances. Only a request that returns a result counts against them. The Highest Risk Companies list is free and unmetered; reading it never counts against your allowance.
To stop one visitor exhausting the demo for everyone, we enforce that limit per visitor. That requires distinguishing between callers, which we do in the least identifying way available to us:
- Your browser generates a random session token when the page loads. It is held in memory only and disappears when you close the tab.
- We combine that token with your IP address, hash the pair, and keep only the first 32 characters of the hash. Your IP address is never written to disk. The hash is one-way and cannot be reversed to recover it.
- The hash is stored in Redis with a 24-hour expiry and then deleted automatically.
- One value is written to your browser’s local storage: a device pass. It is a random identifier this page generates so a lifetime allowance can be counted at all. It is not derived from your device — no canvas rendering, no WebGL, no font or hardware enumeration, nothing biometric. It means nothing on any other site, it is never combined with an account, and you can delete it at any time from your browser’s site-data settings, which resets the pass.
- No cookies and no session storage are used.
- Because the pass is resettable, a second daily limit is applied to a truncated one-way hash of your IP address alone. That is what stops the allowance being reset endlessly, and it expires after 24 hours. It is a rate limit on an address, not a record of a person.
We do not fingerprint your device. No canvas rendering, no WebGL probing, no font or hardware enumeration, no cross-site identifier. This was a deliberate choice: fingerprinting would give us stronger abuse control at the cost of tracking people who have not asked to be tracked, and we are not willing to make that trade for a demo.
Demo requests are recorded in an access log containing a timestamp, the endpoint, the truncated caller hash, a hashed user agent, and the response status. The usage record for each demo request also includes a one-way hash of the submitted text. It contains no IP address, no user agent string, and no request content. Text you submit to the Market Intelligence demo is analysed and returned; it is not stored and is not used to train or update any model.
Know Your Rights pilot
The Know Your Rights pilot works differently in one respect, and it is the respect that matters most, so it is stated first: the questions you ask it are stored, and so are the answers you get. That is the entire purpose of the pilot. We cannot find out which legal questions this system answers badly without keeping the ones it answered.
What is kept for each question: the question text, the answer text, the language it was detected as, the identifiers of the legal sections it drew on, whether it declined to answer, and a timestamp. If you leave feedback, the rating and any comment are kept as a separate record linked to that question.
What is not kept: anything that identifies you. No IP address, no user agent, no session token, no cookie, no account, no device fingerprint. Rate limiting uses the same truncated one-way hash described above, expiring after 24 hours; the service that answers your question and writes the log is never given your IP address at all, so it has no way to record one.
Because the questions are read by us, please do not type anything that identifies you or anyone else — no names, phone numbers, case numbers or addresses. Describe the situation, not the people. The pilot page says the same thing above the box.
This log is used to find and fix failures in the pilot. It is not sold, not shared with third parties, and not used to build a profile of anyone — there is nothing in it to build a profile from. The pilot closes once it has gathered the feedback it was opened to collect.
Know Your Rights provides legal information, never legal advice, and has not been reviewed by practising advocates. It is not a substitute for a qualified lawyer or a legal aid service.
Newsletter
If you subscribe to product updates, we store your email address and the date you subscribed. We use it to send occasional product announcements. We do not sell it, do not share it, and you can unsubscribe at any time using the link in every email. You are added only after you click the link in a confirmation email. We also keep a one-way hash of your IP address and browser for abuse prevention; the raw IP address is never stored.
Analytics
We use a privacy-respecting analytics tool that does not use cookies and does not collect personal data. It records aggregate page views and referral sources. It is self-hosted under our own domain, so page views go to us, not to a third party.
Proprietary Methodology
AION does not publish the internal methodology behind its models and platforms — including retrieval architecture, feature derivation, evaluation methodology and governance layers. These details are withheld pending intellectual property protection.
Public model and platform pages describe what a system does and who it serves; they do not describe how it is built. Research partners and institutional collaborators may request a technical briefing under confidentiality: [email protected]
Changes to This Policy
If we make material changes to how we collect or use data, we will update this page and notify active subscribers by email. Continued use of AION services after notification constitutes acceptance of the updated policy.
Contact
For privacy questions or data deletion requests: [email protected]