Privacy Policy
Last updated September 2026
Aetheria is a social media scheduling and analytics application. This policy explains what information the app handles, why, and the choices you have. It applies to the hosted app at aetheriia.vercel.app and to any self-hosted deployment of the open-source project.
Information we collect
We collect only what the product needs to work:
- Account details. Your name, email address and a securely hashed password when you create an account.
- Connected social accounts. When you connect a network (X, Facebook, Instagram, LinkedIn), we receive an OAuth access token, an optional refresh token, and your public handle and display name on that network. Tokens are stored encrypted and are used only to act on your behalf.
- Content you create. Draft posts, schedules, per-network variants and any media you upload for publishing.
- Performance metrics. Engagement and impression figures for posts you published through Aetheria, retrieved from the connected network's API to build your analytics.
- Technical data. Standard server and request logs (IP address, timestamp, user agent) used for security, rate limiting and debugging.
How we use information
- To authenticate you and keep your session secure.
- To draft, schedule and automatically publish your posts to the networks you connect.
- To refresh expiring OAuth tokens so scheduled posts do not fail.
- To calculate the analytics shown in your dashboard.
- To send transactional email you have asked for (welcome, password reset, publish failure notices).
We do not sell your data, we do not use it for advertising, and we do not share social platform data with third parties except the service providers listed below.
Social platform data
When you connect a network we request only the permissions required to publish content and read the analytics for your own account. You can review and revoke Aetheria's access at any time from that network's app or connected-apps settings, or by disconnecting the channel inside Aetheria, which deletes the stored tokens. Your use of each network through Aetheria is also subject to that network's own terms and privacy policy.
Service providers
The hosted app relies on a small number of processors, each receiving only what it needs:
- Vercel for application hosting and logs.
- MongoDB Atlas for the database.
- Resend for transactional email delivery.
- Cloudinary for storing and serving uploaded media.
- X, Meta (Facebook and Instagram) and LinkedIn when you publish or read analytics on those networks.
A self-hosted deployment may use different providers depending on how it is configured.
Retention and deletion
Content and metrics are kept while your account is active. Disconnecting a channel deletes its tokens immediately. Deleting your account removes your profile, connected-account records, drafts, schedules and collected metrics. Backups and server logs age out on a rolling basis.
Security
Passwords are hashed with bcrypt. OAuth tokens are encrypted at rest with AES-256-GCM. All traffic is served over HTTPS. No system is perfectly secure, but access to stored credentials is limited and encrypted.
Your rights
You can access and update your profile in settings, export your content, and delete your account at any time. If you self-host, you control the data directly. For requests on the hosted app, use the contact channel below.
Demo mode
With no database or network credentials configured, Aetheria runs on a synthetic seeded dataset. In demo mode nothing is published to real networks and no personal data is collected beyond a local demo session.
Changes
We may update this policy as the project evolves. Material changes will be reflected in the "last updated" date above.
Contact
Aetheria is an open-source project. For privacy questions or data requests, open an issue at github.com/Abudora-0/Aetheria/issues.