AEGIN

// PROTOCOL · PRIVACY POLICY

What we see, and what we don’t.

LAST UPDATED · 20 AUG 2026EFFECTIVE · 20 AUG 2026JURISDICTION · INDIA · GLOBAL

This policy sets out what Aegin collects, why, who else receives it, how long it is kept, and what you can do about any of it. Two sections are worth reading properly even if you skip the rest: what the enforcement layer actually sees on your device, and what we will and will not tell you about the decisions the system takes automatically. It is written to meet the General Data Protection Regulation, India's Digital Personal Data Protection Act 2023 and its 2025 Rules, the California Consumer Privacy Act, Quebec's Law 25, Brazil's Lei Geral de Proteção de Dados, and the equivalents elsewhere.

01.

Who processes your data

Aegin is operated from India under the trading name "Aegin Labs" (the "operator"). The operator is the data controller for all personal data processed through the aegin.live website, the Aegin mobile applications, and the services attached to them (together, the "Services").

For any question, request, or complaint about your personal data, write to support@aegin.live. We reply within thirty days where the law requires it and within ninety days otherwise, and we may extend that where a request is complex or where you have made several.

02.

What we collect

Aegin is a behavioral system. It cannot limit what it cannot observe, so the categories below are broad by design rather than by accident. Each one is described at the level of the category rather than the field, because the fields change as the product changes.

IDENTITY
Account identifiers, including your email address, the username you choose, and any identifier passed to us by a sign-in provider you elect to use.
BEHAVIORAL
How you use your device and how you use Aegin. Screen-time totals, per-app usage, the times of day activity happens, requests you make to be let past a limit and how they were decided, sessions, and interactions inside the app.
DEVICE AND APP INVENTORY
A list of the applications installed on your device that can be placed under a limit, so the app picker has something to show and so a limit can be attached to the right target. On Android this is package identifiers and the labels the operating system reports. On iOS it is opaque references only, described in the Screen time and enforcement section below.
COMMUNICATIONS
What you write inside the Services. Messages to other users, messages to the assistant, notes and journal entries, and anything you publish on your profile.
HEALTH AND BIOMETRIC
Only where you connect a wearable or a health source yourself: derived summaries of signals such as sleep, movement, and heart-rate variability supplied by that source. We read what the platform gives us and nothing more.
INFERRED
What the system works out about you from everything above. This covers scores such as your willpower index, assessments of how likely you are to lose control of your use of a particular app, patterns in your attention and routine, and comparisons between what you said you wanted and what you actually did. Some of these are inferences about your health, and they are treated as such throughout this policy. The specific signals, models, and weights involved are not itemized here, for the reasons given in the Automated decision-making section.
TECHNICAL
Operational data such as IP address, device and installation identifiers, operating system, app version, language, timezone, and crash and diagnostic logs.
AI QUALITY
For each answer the assistant gives, a short-lived structured trace: the surface, the intent and time range requested, which data sources were asked for and loaded, how fresh the evidence was, where the answer came from, which model ran, review status, latency, and any failure code. The trace holds no text from your question or the answer. If you rate an answer we store the rating, the reasons you selected, and any comment. The question and answer themselves are attached only when you tick the box to include them, for that one submission.
TRANSACTIONAL
Subscription tier, billing status, and the transaction identifiers our processors issue. Card numbers and bank details are handled by the payment processors and never reach our systems.
03.

Why we process it

The purposes below apply across the categories above. The legal basis varies with where you live, and the description given is the one that applies under the EU and UK GDPR, with equivalents elsewhere.

Running the product. Delivering the Services, keeping your account working, computing your scores and reports, operating messaging and the social features (which means passing what you send to the people you send it to), and running the assistant, including remembering context you have chosen to let it keep. Legal basis: performance of a contract. Persistent assistant memory is on by default so it carries context between conversations. You can turn it off in the app under Settings and then Privacy, which stops new notes being kept and stops the assistant reading the ones already held, leaving it with the current conversation only. Turning it off does not delete them. Deletion is a separate action on the same screen, and single notes can be deleted from the assistant’s memory screen.

Limiting your device. Working out where you are overusing something, deciding what limit should apply, applying it, escalating or easing it over time, and deciding requests to be let past one. This is the core function of the product and the reason most of the behavioral data exists. Legal basis: performance of a contract, and our legitimate interest in operating a restriction system you installed in order to be restricted by it.

Inferences about your health. Where the system produces inferences that bear on your health, including assessments of compulsive use and anything derived from biometric inputs you have connected, we rely on your explicit consent under Article 9(2)(a) of the EU and UK GDPR and the equivalent condition under your own law. That consent is taken at sign-up by a separate affirmative action, distinct from accepting the Terms. If you connect a wearable or health source, consent for those inputs is taken separately again, immediately before the connection. Either consent can be withdrawn by deleting your account from in-app settings, which stops all processing of biometric inputs and health-related inferences. Withdrawal does not make earlier processing unlawful.

Security and fraud prevention. Detecting, preventing, and responding to abuse, account takeover, tampering with the app, and payment fraud. Legal basis: legitimate interest and legal obligation.

Aggregate analytics. Understanding how the product is used in aggregate so we can improve it, using anonymized or pseudonymized data only. Legal basis: legitimate interest. On by default, and you can turn it off in the app under Settings and then Privacy.

Model improvement. Training and improving our own models using pseudonymized behavioral signals and de-identified numeric embeddings derived from your activity. This does not use the raw text of your conversations. Legal basis: legitimate interest. On by default, and you can turn it off in the app under Settings and then Privacy. Turning it off stops your activity being used this way from that point on. What is stored is a de-identified numeric embedding rather than anything that reads back as you, and a signal already folded into a trained model cannot be pulled back out of it.

Service quality. Catching answers that were ungrounded, stale, failed, or sent to the wrong place, and measuring whether a fix worked. This uses the structured traces described above, which exclude conversation text, plus any rating or comment you choose to send. Legal basis: legitimate interest. A question-and-answer snapshot is included only when you opt in for that individual submission.

Legal compliance. Meeting the tax, accounting, regulatory, and law-enforcement obligations that apply to us. Legal basis: legal obligation.

We do not sell personal data. We do not share it for cross-context behavioral advertising. We do not give it to data brokers, and we do not run advertising in the product.

04.

Screen time and enforcement

Aegin cannot limit a device without watching it. This section sets out what the enforcement layer actually sees on each platform, what stays on your phone, and what reaches us. It is the part of this policy worth reading closely.

ANDROID · FOREGROUND DETECTION
The app uses the Android accessibility service (BIND_ACCESSIBILITY_SERVICE), requested only after a prominent in-app explanation and your own action to grant it. It does two things. It reads the package name of whichever app is currently in the foreground, so a block can appear before the app is usable. And for a small, named set of browsers, it reads that browser’s address-bar field, so that opening the website of an app you have locked is caught as well without you having to configure anything. It does not read the content of any web page, any other text field, or your keystrokes. It takes no actions on your behalf. It is expressly not declared as an accessibility tool.
ANDROID · SUPPORTING PERMISSIONS
Usage access (PACKAGE_USAGE_STATS) as a fallback detector and to compute screen-time totals. Display over other apps (SYSTEM_ALERT_WINDOW) to draw the block screen above the app being blocked. A foreground service to keep enforcement alive while it is running, and a boot receiver (RECEIVE_BOOT_COMPLETED) to restart it after a reboot. Where the manufacturer kills background work aggressively, the app will point you at your own system settings to exempt it from battery optimization or to enable auto-start. Those changes are made by you, in your device settings, and only if you choose to make them.
IOS · SCREEN TIME API
On iOS, enforcement runs through Apple’s Screen Time frameworks (Family Controls, Device Activity, and Managed Settings) after you grant authorization to Apple, not to us. You pick apps in Apple’s own picker, and iOS hands back opaque tokens that we cannot resolve into app names or bundle identifiers. What we send to our servers is a one-way hash of that token, which is meaningless anywhere except on your device. Our servers reject app labels and encoded Screen Time tokens outright.
IOS · WHAT STAYS ON THE PHONE
The per-app breakdown of your day on iOS is produced inside an Apple-sandboxed reporting extension that has no network access. It is drawn on your screen and it does not reach us. That is a limitation Apple imposes and we have not tried to work around it.
WHAT LEAVES THE DEVICE
Durations, counts, and timestamps of app usage, tied to a package identifier on Android and to an opaque hash on iOS. The inventory of apps that can be limited. Events from the enforcement layer, such as a limit being applied, a block being shown, or a request being made. That is what the server needs to decide anything, and it is the whole of it.
WHAT WE NEVER COLLECT
Screen contents. Screenshots. Keystrokes. Form input. Passwords. The contents of your messages or feeds inside other apps. Web page content. Camera, microphone, contacts, or precise location. None of these are collected through the enforcement layer, and none of them are collected anywhere else in the app.
TURNING IT OFF
Every permission above can be revoked from your device’s own system settings at any time, and the app can be uninstalled at any time. Either disables or degrades enforcement. Neither closes your account or affects the rest of your data.

Mobile operating systems change, and the mechanisms available for this work change with them. We may add, replace, or drop a detection or enforcement mechanism, and we may ask for a different permission if a platform requires it. Where a change means collecting a category of data not described here, we will update this section before it ships.

05.

Artificial intelligence

Aegin runs on a mix of models we operate ourselves and models operated by third-party providers. What that means for your data is set out here.

Part of the reasoning runs on our own infrastructure using models we built ourselves, and nothing in those requests leaves our systems. Where a request needs a large language model, the text of your message and a pseudonymized summary of the relevant behavioral context go to a third-party AI provider acting as our processor. Your email address, your name, and your account identifier are not sent. User-supplied text passes through a redaction step before it leaves us, and it is fenced so that anything inside it is treated as content rather than as instructions.

Our AI providers are bound by written terms that prohibit using your data to train their own foundation models and that limit retention to what is needed to return the answer and meet their own abuse-monitoring obligations. We may add, remove, or substitute a provider, or move a workload between providers, at any time and without notice. The list in force at any given moment is published at /legal/privacy/recipients.

Assistant memory is tiered. Behavioral outcomes, meaning what happened rather than what was said, are part of running the product. Notes the assistant keeps about you between conversations are a paid-tier feature and can be switched off, which stops them being added to and stops them being read, but does not delete them. Deleting them is a separate action you can take at any time. Anything that contributes to improving our models across users is limited to de-identified numeric embeddings and outcomes, never raw text from one user shown to another, and that too can be switched off.

Conversations with the assistant are not read in real time by a person. We may review a conversation where you report a problem, where an automated signal flags possible abuse or a safety risk, or where the law requires it.

Nothing you tell the assistant is used to advertise to you, is sold, or is disclosed to another user.

06.

Messages, reports and moderation

Aegin has private messages and group messages. This is what we do and do not read, and what happens when someone reports something.

We do not scan your conversations. Messages between people who follow each other are not inspected by us or by any model. There is one exception: a first message from someone you do not follow back is checked against a list of terms before it reaches you, and if it matches it goes to a separate requests folder instead of your inbox. That check happens on our servers, produces nothing more than a category label, and no person sees the message because of it.

When someone reports a conversation, a profile or a message, that changes. We read the reported content, the messages around it, and, where a person reviews the case, the conversation between the two of you. We also look at the account histories on both sides, meaning previous reports, previous restrictions, and how many people have blocked each account. We cannot assess a report without seeing what was reported. The lawful basis is our legitimate interest in keeping the service safe for other people, and in the case of unlawful content, compliance with a legal obligation.

Reported content may be sent to a third-party AI provider acting as our processor for classification, under the same terms and the same redaction and fencing described under Artificial intelligence. Reports concerning a risk of self-harm are never sent to a model and are handled by a person.

Reports are assessed automatically, and that assessment decides the outcome for most of them. Serious cases and cases the assessment is not confident about are decided by a person. Where a decision restricts your ability to send messages, you are told, and you can ask for it to be reviewed by a person from the notice itself. That review can remove the restriction.

A record of reports and of decisions taken is kept for as long as the account exists and for the period set out under How long we keep it, because a pattern across time is the only way to tell a one-off from repeated behavior, and because we have to be able to show why a decision was taken. Reports are not deleted when they are resolved.

The person you reported is not told who reported them. If you are reported, you are not told what the outcome was for the other person.

07.

Who receives it

Personal data is shared with the categories of recipient below. Service providers act on our instructions under written data-processing agreements and may not use your data for their own purposes.

OTHER USERS
When you send a message or publish something through the social features, it goes to the people you sent it to. That is the feature working.
INFRASTRUCTURE
Providers that host the database, the authentication layer, and the application itself.
AI PROCESSORS
Third-party model providers that process prompts and return output, on the terms described in the Artificial intelligence section above.
PAYMENTS
The payment processors and subscription-management providers that bill you and validate purchases. They receive only what is needed to take the money and confirm the entitlement.
SIGN-IN PROVIDERS
If you sign in with Apple or Google, that provider takes part in the authentication exchange and receives the identifiers it needs to complete it.
OPERATIONAL PROVIDERS
Providers that deliver transactional email, deliver push notifications, and receive crash and error reports so we can find and fix faults.
LEGAL AND COMPLIANCE
Tax authorities, law enforcement, courts, and regulators, where we are compelled by valid legal process or where disclosure is necessary to protect rights, safety, or the integrity of the Services.
CORPORATE TRANSACTIONS
A buyer, investor, or successor entity, where the operator is involved in a merger, acquisition, financing, reorganization, or sale of assets. Any recipient takes the data subject to this policy.

Every named sub-processor that receives personal data on our behalf is listed on the Recipients page below, along with what each one receives, the agreement that governs the relationship, where they process, and the transfer mechanism we rely on. The list is version-controlled and every change ships as a public commit, so what it said on any past date can be checked.

That page is the current answer, not a permanent one. We add, remove, and substitute providers as the product changes, and we update the page when we do rather than announcing each change individually. Continuing to use the Services after a change is made means accepting the list as it then stands.

The page satisfies our obligation to identify specific recipients on request, including under the Court of Justice of the European Union’s January 2023 ruling in Case C-154/21 (RW v. Österreichische Post) on the scope of Article 15 GDPR, and is consistent with the February 2025 ruling in Case C-203/22 (Dun & Bradstreet) on the explainability of automated decisions.

View the recipients list
08.

International transfers

Aegin is operated from India and our providers may process data in countries other than yours. Where personal data is transferred out of your jurisdiction, we rely on the safeguards available under your own law, which may include Standard Contractual Clauses, an adequacy decision, provider-level certification, or your explicit consent where nothing else applies.

If you are somewhere that requires a specific transfer mechanism, write to us and we will tell you which one covers your transfer.

09.

How long we keep it

We keep personal data for as long as your account is open, and afterwards for as long as we need it to meet legal, accounting, tax, and dispute-resolution obligations. Inferred data and behavioral history may be kept for the whole life of the account, because the system reasons over long stretches of time and cannot do its job from a short window.

Structured AI quality traces, which contain no conversation text, expire after ninety days. Ratings, selected reasons, and feedback comments expire after one hundred and eighty days. Where you chose to attach a question and answer to feedback, that snapshot expires after thirty days. Any of these end sooner if the account or the trace is deleted first.

When you ask us to delete your account it first enters a ninety-day restricted period: hidden from other users, all behavioral and AI processing stopped, and the data kept only so the account can be brought back if you sign in. If you do not sign in within ninety days, it is erased. Asking by email does not change that. The full process is at /legal/delete-account.

Backups are a separate matter. Copies of deleted data can persist in encrypted backups until they rotate out, which takes up to ninety days after erasure.

Where a specific retention period is not stated above, we keep the data for as long as the purpose it was collected for still applies, and then delete or anonymize it.

10.

Automated decision-making

Aegin decides things about you automatically. It decides when a limit should apply and how strict it should be, whether to grant a request to be let past one, when to escalate, what your scores are, and how much of your AI allowance a request consumes. These decisions are taken by software, without a person involved, and they are the mechanism by which the product works rather than an incidental feature of it.

The logic in general terms: the system reads your recent and historical usage, the context surrounding the request or the moment, the goals you set when you signed up, patterns it has learned from your own past behavior, and, where you have consented, signals derived from a connected health source. It weighs those into a score, compares the score against a threshold, and acts. Both the weights and the thresholds move over time, per user, as it learns.

What we will not disclose. We do not publish, and will not disclose on request, the thresholds, budgets, weights, scoring functions, model parameters, timings, or escalation rules behind any individual decision. Two reasons. They are our trade secrets. And a restriction system whose exact numbers are known is a restriction system that can be planned around, which would defeat the purpose for you and for everyone else using it. This is the limit recognized in Recital 63 of the GDPR, which provides that the right of access should not adversely affect the rights and freedoms of others, including trade secrets and intellectual property, and by the equivalent carve-outs in other data-protection laws. What we will always tell you is that a decision was automated, what it did, and which categories of data fed it.

What these decisions are not. They concern your use of Aegin and nothing else. They are not decisions about credit, employment, housing, insurance, education, immigration, benefits, or policing, they produce no legal effect on you outside the product, and they are neither designed nor validated for any such purpose.

Where your law gives you a right to have an automated decision reviewed by a person, write to support@aegin.live and we will review it and tell you the outcome. Disagreeing with a decision is not on its own a reason for review, and a review does not extend to the parameters described above.

11.

Cookies

We use strictly necessary cookies only. The Services set first-party authentication and session cookies, issued by our authentication provider with the "sb-" prefix, that keep you signed in, hold your session across pages, and protect against cross-site request forgery. Without them you could not sign in or stay signed in.

We do not use cookies or any similar technology for analytics, advertising, retargeting, marketing profiles, cross-site tracking, or audience measurement. There is no Google Analytics, Meta Pixel, TikTok Pixel, Mixpanel, Amplitude, PostHog, Hotjar, FullStory, or Microsoft Clarity tag on this site, no equivalent of any of them, and no session-replay technology.

Because the cookies are strictly necessary, prior consent is not required under the EU ePrivacy Directive (2002/58/EC as amended), the UK Privacy and Electronic Communications Regulations 2003, or the equivalent provisions elsewhere that exempt strictly necessary cookies. You can block or delete cookies in your browser at any time, which will sign you out and may prevent you signing back in.

If we ever introduce a non-essential cookie or a third-party tracking technology, we will update this section, present a consent interface that lets you accept or refuse each non-essential category before anything loads, and change the effective date at the top of this page.

12.

Your rights

Which of these you have depends on where you live. We honor them in line with the law that applies to you, and we honor several of them everywhere regardless.

ACCESS
You can ask whether we process your personal data and get a summary of the categories we hold, why we hold them, who receives them, and how long they are kept. Write to support@aegin.live.
CORRECTION
You can ask us to correct an identity field that is wrong. Behavioral history is recorded by the system rather than entered by you, so it cannot be edited. Where you think a particular record is wrong, write to support@aegin.live and we will look at it.
DELETION
You can delete your account at any time from your settings, or by writing to support@aegin.live if you cannot get in. Either way starts a ninety-day restricted period during which the account is hidden and processing stops. Signing back in inside that window restores it in full. If you do not, erasure completes at ninety days and the retention timelines above take over.
PORTABILITY
Where your law grants a statutory right to portability, including in the European Union, the United Kingdom, the European Economic Area, Quebec, Brazil, China, California, and other places with equivalent rights, we will give you a structured, machine-readable export of the raw and observed personal data you provided. Inferred and derived data falls outside statutory portability rights and is not included. Write to support@aegin.live.
OBJECTION AND RESTRICTION
Where your law grants a right to object to or restrict processing, write to support@aegin.live and we will assess the request against the basis for the processing concerned. Two of the activities we run on legitimate interest are already in your hands: aggregate analytics and model improvement can both be switched off in the app under Settings and then Privacy, with no need to contact us. Switching off model improvement stops that use from the point you switch it off. It does not undo what was already derived.
WITHDRAW CONSENT
Where processing rests on consent you can withdraw it at any time. The behavioral and health-inference consent the product depends on is withdrawn by deleting your account, and requesting deletion stops that processing immediately even though final erasure completes at the end of the ninety days. Withdrawal does not affect the lawfulness of what was processed beforehand.
COMPLAIN
You can complain to your data-protection authority. In India that is the Data Protection Board of India. In the European Union and the European Economic Area it is your national supervisory authority. Elsewhere it is whichever regulator has jurisdiction over your data. We would rather you came to us first, but nothing requires you to.

We respond within thirty days where the law requires it and within ninety days otherwise, which matches the window under India’s Digital Personal Data Protection Rules, 2025. We have to verify who you are before acting on a request, and we may ask for more information to do that. Where a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or decline it, and we will say which.

There is no self-service export tool. Rights are exercised by written request to support@aegin.live. Where you have no statutory right to a particular outcome, we will honor the request where we can and decline it where we cannot, and we will tell you which of the two happened.

13.

Children

Aegin is not for anyone under eighteen. We do not knowingly collect personal data from anyone under eighteen, and where we find that we have, we delete it. The floor is set at eighteen to clear the highest threshold across the places we operate, including the requirement under India’s Digital Personal Data Protection Act 2023 for verifiable parental consent before processing the personal data of anyone under eighteen.

If you are a parent or guardian and think a minor in your care has an account, write to support@aegin.live and we will close it and purge the data.

14.

California residents

This section supplements the policy for residents of California and applies where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, covers our processing of your personal information.

The categories of personal information we collect are those set out in the What we collect section: Identity, Behavioral, Device and app inventory, Communications, Health and biometric, Inferred, Technical, AI quality, and Transactional. Sources are you, your device, a wearable or health source you connect, and our payment processors. The business and commercial purposes are those set out in the Why we process it section. The categories of third party we disclose to are those set out in the Who receives it section.

We do not sell personal information for monetary or other valuable consideration, and we do not share it for cross-context behavioral advertising. We have not done either in the preceding twelve months.

Sensitive personal information. We collect two categories. First, biometric information from a wearable or health source you choose to connect, used only to compute derived behavioral signals and never used to identify you as a consumer. Second, information concerning health, in the form of inferences the system draws about compulsive use and related behavioral-health signals from the activity you have chosen to provide. We use and disclose sensitive personal information only for the purposes permitted by California Code of Regulations, title 11, section 7027(m): performing the services you asked for, detecting and responding to security incidents and malicious or illegal activity, and verifying or maintaining the quality of the Services. Because our use is confined to those purposes, the right to limit under California Civil Code section 1798.121 does not apply to our processing and no "Limit the Use of My Sensitive Personal Information" link is provided. If that ever changes, we will provide one.

California residents may exercise the right to know, to delete, to correct, to portability, to opt out of sale or sharing, and to limit the use of sensitive personal information. We honor the opt-out by default, since we do neither. Send requests to support@aegin.live. An authorized agent may act for you with proof of authorization.

We do not discriminate against anyone for exercising these rights.

15.

Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, row-level authorization in the database, isolation of server-only credentials, and monitoring. Access to production data is limited to what is needed to operate the Services.

No system is perfectly secure and we will not pretend otherwise. If there is a breach affecting personal data we will notify the relevant authorities and, where the law requires it, you, within the timeframes the law sets.

Keeping your own credentials safe is your part of this. Use a password you do not use anywhere else, and tell us at support@aegin.live if you think someone else has your account.

16.

Changes

We update this policy as the product changes. The version in force is always the one on this page, with the date it took effect at the top. Where a change is material we will tell active subscribers by email or in the app, and we will flag it at the top of this page.

Continuing to use the Services after a change takes effect means you accept the updated policy. Where a change requires your consent under the law that applies to you, we will ask for it before the change reaches you.