01
Scope
This notice covers aegistrustlayer.com, the Aegis account and billing endpoints served from that domain, and information you deliberately send to Aegis for product support or security reporting.
02
Data we handle
GitHub sign-in provides the identity boundary for account and paid-access flows. Depending on the feature you use, Aegis may process a GitHub identity identifier and login, session state, subscription and entitlement state, transaction references, support correspondence, and limited operational security logs needed to protect the service.
The public marketing site is intentionally small in scope. Aegis does not need advertising profiles or cross-site behavioral tracking to explain the product.
03
Payments
Paid checkout is provided by Paddle Checkout. Aegis does not receive or store your full payment-card number. Paddle may provide Aegis with customer, transaction, subscription, tax, and payment-status information needed for fulfillment, fraud prevention, support, reconciliation, and entitlement.
A browser redirect after checkout is not treated as proof of payment. Paid access is derived from authenticated identity and server-side billing state after the relevant Paddle event has been verified.
04
Product and source-code data
The supported deterministic developer path is local-first. When you choose a model-backed workflow, the configured model provider receives the context required for that request according to the route you selected. Provider use is not presented as a local-only operation.
Do not submit secrets, credentials, regulated data, or material you are not authorized to process through third-party model providers.
05
Service providers
Aegis currently relies on infrastructure and services that may include Vercel for website and serverless hosting, GitHub for authentication and developer distribution, Paddle for billing as Merchant of Record, the Visual Studio Marketplace for extension distribution, and model providers that you explicitly configure for model-backed workflows.
06
Retention and security
We retain account, entitlement, billing, and security records only for as long as reasonably needed for the service, legal obligations, dispute handling, fraud prevention, and auditability. Security controls reduce risk but no internet service can promise absolute security.
07
Your choices
You may contact hello@aegistrustlayer.com about access, correction, deletion, or other privacy requests that apply to your information. Billing-specific questions may be sent to billing@aegistrustlayer.com.