Privacy Policy
This policy describes what information AION collects, why we collect it, who sees it, and what you can do about it. Short version: we collect the minimum needed to run the service, we don't sell your personal data, you own what you post, and you can delete your account whenever you want. The longer version follows.
1. What we collect
- Account info. Username, display name, email, hashed password, anything you put in your profile (bio, links, avatar, cover image), and OAuth identifiers if you sign in with Google, GitHub, Apple, or Facebook.
- Content you post. Posts, comments, replies, reactions, uploads (images / video / audio), group memberships, follows, blocks, bookmarks, and direct messages.
- Engagement signals. Likes, views, shares, dwell time on a post, search queries you submit, and the news/search items you click. We use these to rank what you see and to compute creator earnings.
- Technical data. IP address, browser and device info, screen size, and basic access logs used to keep the service running, prevent abuse, and debug bugs you report.
- Cookies. A session cookie to keep you logged in, a CSRF cookie, small preference cookies (theme, grid columns, beta-banner-dismissed). No third-party advertising cookies.
2. How we use your data
- To operate the service — show your posts to other users, deliver notifications, enforce moderation rules.
- To rank content — fresh news, search relevance, recommended posts. Ranking uses the engagement signals above and never sells them.
- To secure the service — detect brute-force logins, spam signups, abusive accounts, and fraud against creator monetization.
- To compute creator earnings — for ad revenue share, we count impressions and clicks on the ads adjacent to your posts. For bonuses, we measure follower counts, post engagement, and milestone events; we run anti-fraud checks (suspect bot/AI-agent inflation can disqualify earnings).
- To contact you when necessary — verification email, password resets, security alerts, and major service changes. We do not send marketing email without your opt-in.
We do not sell your personal data. We do not run third-party ad-tracking pixels. AION's own ads are served from AION's own infrastructure based on aggregate context (the page, the topic), not on cross-site behavioral profiling of you as an individual.
3. Direct messages
Direct messages between AION users are private to the participants. AION administrators access message content only when (a) investigating an active abuse report, (b) responding to a valid legal process, or (c) preventing immediate harm. Automated systems may scan message content for spam, malware, or content that violates our rules — those scans do not produce profiles for advertising.
SMS, email, and push delivery channels are planned. If you opt in to those channels in the future, the carrier or push provider involved (e.g. Twilio for SMS, APNs/FCM for push) will see your message in transit; AION will tell you which provider before you opt in.
4. Search, news, and the publisher network
AION operates a web crawler over a curated list of approved domains (we don't crawl the open web indiscriminately) and an RSS aggregator for news. Public AION posts are searchable from inside AION; private group posts are not. AION offers an opt-in Publisher Network for third-party websites — when a publisher embeds AION analytics or AION ad code, that publisher sees only the data their own site generates. AION does not share your AION account, posts, or activity with publishers.
5. Who can see what
- Public posts are visible to anyone on the internet and can appear in AION search and news surfaces.
- Private group posts are visible only to the group's members.
- Direct messages are visible only to the participants.
- Your email and IP address are never shown to other users.
- Aggregate engagement totals (post like count, share count, etc.) are visible. Per-user reaction lists are visible in the same way other social platforms show them.
6. Third parties
AION uses a small number of standard infrastructure providers. As of the date above:
- Hosting and database. The site runs on a U.S.-based hosting provider; data is stored in the U.S.
- Email delivery. Transactional email (verification, password reset, alerts) is sent through a standard delivery service.
- Captcha (Cloudflare Turnstile). The signup form uses Turnstile to keep bots out. Turnstile receives your IP and basic browser fingerprint signals to make its decision; it does not produce a profile for advertising.
- OAuth providers (Google, GitHub, Apple, Facebook). When you sign in with one of these, AION receives only the identifiers and basic profile fields the provider returns (typically: provider user id, name, email, avatar URL).
- Payment processors (Stripe, PayPal — for creators). Tips and subscriptions go directly to a creator's own Stripe or PayPal account; AION does not handle the funds and does not receive payment-card data. For ad revenue share payouts, AION uses Stripe to send earnings to creators.
- RSS sources for AION News. AION fetches public RSS feeds from ~99 reputable news publishers; the publishers see only AION's request, not your identity.
These providers process data on AION's behalf under written agreements that prohibit them from using it for their own purposes. We update this list as the service evolves.
7. How long we keep data
We keep your account and content for as long as your account exists. When you delete your account, your profile is removed from public view immediately and the underlying records are purged within 30 days. Daily backups containing deleted data age out within the same 30-day window.
Audit logs of admin actions are retained indefinitely for forensic and legal compliance — these contain action metadata, not the content of your messages or posts.
8. Children
AION is not intended for users under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us at privacy@aionsocial.com and we will delete the account and its data. If you are a parent or guardian and believe your child gave AION personal information without your consent, contact us. (COPPA compliance — 16 C.F.R. Part 312.)
9. Your rights
Depending on where you live, you have one or more of the following rights:
- Access. See what we have about you. Most of it is visible in your profile and settings; for the rest, contact us.
- Correction. Edit your profile, posts, and comments anytime. For data you can't edit yourself, contact us.
- Deletion (right to erasure). Delete individual posts and comments yourself; full account deletion is available from settings (or by contacting us during the closed-beta period).
- Portability. Request a machine-readable export of your account data by emailing privacy@aionsocial.com.
- Objection / restriction. If you're in the EU/UK, you can object to or request restriction of processing under GDPR Articles 18 and 21.
- Do Not Sell / Share (CCPA). California residents can request that AION not sell or share their personal information. AION does not sell personal information; this control is here for completeness.
- Complain. If you're in the EU/UK, you can lodge a complaint with your data protection authority. We'd appreciate a chance to address it first.
We respond to verifiable rights requests within 30 days.
10. Security
We use standard practices: bcrypt password hashing, HTTPS everywhere, prepared SQL statements, HTTP-only and SameSite session cookies, server-side request validation, and SSRF protections on URL fetchers. The signup flow uses Cloudflare Turnstile and IP-based rate limiting to keep bots out. No system is perfectly secure — if you discover a vulnerability, please report it to security@aionsocial.com rather than disclosing publicly first.
11. Breach notification
If a security incident affects your personal data, we will notify you and any required regulator within the timelines required by applicable law (e.g. 72 hours under GDPR, "without unreasonable delay" under most U.S. state laws). Notification will include what happened, what data was involved, what we're doing about it, and what you can do.
12. International transfers
AION is operated from the United States. If you access AION from outside the U.S., your data is transferred to and processed in the U.S. We rely on the European Commission's Standard Contractual Clauses where required for EU/UK transfers.
13. Changes to this policy
If we change this policy in a material way, we will announce it on the site and update the "Last updated" date above. Continued use after a change means you accept the new policy.
14. Contact
Questions, data requests, security reports: privacy@aionsocial.com. For DMCA notices, see the Terms of Service.