1. Who we are
Aliax (“we”, “us”) operates the Aliax browser-automation execution layer at aliax.xyz. For questions about this policy, contact privacy@aliax.xyz.
2. Data we collect
- Account data: email address, hashed password, OAuth subject ID (if you sign in with Google).
- Billing data: handled by Paystack / Flutterwave / Stripe. We store only the transaction reference, amount, and currency — not your card.
- SDK telemetry: capture metadata (timestamps, action tier, success/stuck flag) and the screenshots your SDK uploads.
- Operational logs: IP address and user-agent on auth and webhook endpoints for abuse prevention. Rotated after 30 days.
Lawful basis (GDPR): account and billing data is processed under contract performance (Art. 6(1)(b)). Operational logs are processed under legitimate interest (Art. 6(1)(f)) for abuse prevention and are rotated within 30 days.
3. What we don't do
- We do not sell personal data.
- We do not train models on customer screenshots or captures.
- We do not share your data with advertisers.
- We do not set tracking or advertising cookies. The only cookies set by aliax.xyz are first-party session cookies required for authentication.
4. Sub-processors & data residency
Customer data flows through the following sub-processors. Per-vendor DPAs available at privacy@aliax.xyz.
Supabase Inc.Postgres + Authus-east-1
Cloudflare Inc.Edge compute + R2 storageglobal · pinned-region available (enterprise)
PaystackPaymentsNG / GH / ZA / EG
FlutterwavePaymentsAfrica / global
Stripe Inc.PaymentsUS / EU
5. Retention
Screenshots default to 30 days. Account and ledger data persist for the life of the account plus 7 years for billing compliance. You can request full deletion at any time; we purge within 30 days.
6. Your rights
If you are in the EU/UK or California, you have rights of access, correction, deletion, and portability. Email privacy@aliax.xyz from the account address and we'll respond within 30 days.
7. Security
See our security page for technical detail on authentication, encryption, and incident response.
8. Changes
We'll email account holders at least 14 days before material changes to this policy.