Skip to main content

Privacy

How Aestus handles data

This notice explains what data Aestus handles, why it is used, and the choices available to people and organizations that use the service.

Effective

1. Scope

This notice covers the Aestus website, product, and related support. A connected service has its own privacy terms. Your organization can also set rules for how its members use Aestus.

2. Data we handle

The service can handle these kinds of data:

  • Account and identity data, such as your name, email address, profile image, login provider, session data, IP address, and browser information.
  • Organization and workspace data, such as members, roles, projects, plans, tasks, comments, policies, workflows, agent activity, approvals, audit records, and uploaded files.
  • Connected-service data, such as repository names, installation details, selected resources, connection scopes, and data returned by an integration that you ask Aestus to use. Work-tracker connections are described in their own section below.
  • Billing data, such as plan, subscription status, billing period, seat count, and payment-service identifiers. Payment providers handle the details needed to process a purchase.
  • Messages you send through waitlist, contact, support, invitation, notification, or inbound-email features.
  • Website and product-use data, such as page path, referring page without its query, campaign tags, device class, theme, feature events, and performance measurements.

3. Work-tracker connections (Jira and Linear)

An administrator of your Aestus organization can connect one Jira Cloud site or one Linear workspace with OAuth. Aestus then copies work between that tracker and your Aestus workspace. Only an administrator can make or remove the connection, and the connection is bound to the one site or workspace that was authorized.

Aestus stores the access token and the refresh token for the connection in encrypted form. Aestus never asks for or stores a tracker password.

To show who did what, Aestus copies a small amount of personal data about the people in the connected tracker:

  • The account identifier the tracker gives a person: an Atlassian account ID for Jira, or a user id for Linear.
  • The display name on that account.
  • The email address on that account, when the tracker returns one. Jira hides the email address when the account privacy setting hides it. Aestus then holds no email address, and an administrator maps the person by hand.
  • The account identifier of the person who made a change, recorded on each synchronized event, so the record shows who changed what.
  • The name shown for the author of an imported comment, when that author is not also an Aestus member.
  • Issue and project identifiers, keys, and links, together with the titles, descriptions, comments, and fields that a project pair syncs.

4. Leaving a work-tracker connection

Aestus keeps work-tracker data for as long as the connection lasts. No fixed period applies and nothing is removed on a timer. Disconnecting is the event that removes the profile data.

An administrator disconnects the integration in Settings, Integrations. When the disconnect completes, Aestus deletes the whole people mapping for that connection: every stored account identifier, display name, and email address for that tracker is deleted outright, not hidden. That deletion is the first thing a disconnect does, so it happens even when a later step cannot reach the provider. Aestus also deletes the webhooks it registered at the provider and deletes the stored access token and refresh token.

Aestus also ends the authorization at the provider where the provider offers a way to end it. Atlassian offers no way to end a Jira Cloud authorization from our side, so Aestus deletes its copy of the tokens and the authorization lapses at Atlassian. You can also remove the authorization in your Atlassian account settings.

Disconnecting does not delete work. The administrator chooses one of two results for the tickets and projects that the import created: keep them as ordinary Aestus work, or archive them. Archive hides them and can be undone. Aestus has no option that deletes imported work. The records that say which remote issue a ticket came from are archived, not deleted, so a later reconnect recognizes the same work. The synchronization record also stays, and so do imported comments, including the author name copied onto a comment whose author was not an Aestus member.

To remove the copied data for one person, an administrator deletes that person's row on the people-mapping screen in Settings, Integrations. That deletes the stored account identifier, display name, and email address for that person. An organization owner can also request erasure of the whole organization, which removes the data copied from a connected tracker with the rest of the organization's data.

Aestus takes part in Atlassian's personal data reporting. On a schedule, Aestus sends Atlassian the Atlassian account identifiers it holds data for, with the date it last read that data, and Atlassian answers with the accounts that were closed or changed. For a closed account, Aestus deletes the mapping row and removes the copied author name from the imported comments that record that account. For a changed account, Aestus drops the stored display name and email address, so the next synchronization reads them again. Comments imported before Aestus began recording the tracker account on a comment carry no account identifier, so this cycle cannot reach them; they go when the comment, the ticket, or the organization goes. Linear publishes no equivalent signal, so a Linear account is removed by an administrator, by disconnecting, or by a request to Aestus.

For a request about a person whose data reached Aestus through a connected tracker, write to Aestus at aestus.app/contact?topic=privacy, or use the contact page and say that the message is a privacy request. Aestus acts on the instruction of the organization that owns the connection, and will pass a request to that organization when the organization is the one that decides.

5. How we use data

We use data to provide and protect the service. This includes:

  • Authenticating users and applying organization, workspace, and role controls.
  • Running workflows, agents, integrations, approvals, notifications, and billing.
  • Answering contact and support requests.
  • Measuring reliability, performance, product use, and marketing results.
  • Finding abuse, investigating failures, enforcing policies, and keeping audit evidence.

6. AI and automation

Aestus can send prompts, relevant workspace context, files, and instructions through an AI gateway to a selected model provider. Coding agents can also work in hosted sandboxes and use connected repositories or tools when a user or workflow asks them to do so.

AI output can be incomplete or wrong. Review important output before you accept it or use it. Do not submit data that you are not allowed to process through the selected model or connected service.

7. When data is shared

Aestus can share data in the limited cases below. Aestus does not use marketing analytics as a second customer identity database.

Aestus runs on hosted platform and database services and uses other vendors for the functions listed below. Contact Aestus for the current list of the vendors that process data for the service.

  • With vendors that help run hosting, storage, authentication, email, notifications, analytics, billing, AI, model routing, sandboxes, and security.
  • With a connected service when you or your organization enables it or asks a workflow to use it.
  • With members and administrators of the organization that owns the workspace.
  • When disclosure is required by law or is needed to protect users, the service, or others.

8. Retention, export, and deletion

Retention varies by data type, workspace policy, service need, and legal or security requirement. No single retention period applies to all data. Some governance records use bounded identifiers, counts, dates, and hashes so they can remain as evidence after tenant content is deleted.

Where lifecycle controls are enabled, organization settings can support data exports, retention policies, legal holds, and organization erasure. Roles, recent sign-in checks, active legal holds, and provider verification can limit or delay an action.

9. Choices and requests

You can update some account and workspace data in the product. Organization owners and administrators can manage members, integrations, and available lifecycle controls.

Privacy rights differ by location. To ask about access, correction, export, or deletion, write to Aestus at aestus.app/contact?topic=privacy, or use the contact page and say that the message is a privacy request. Aestus can ask for identity and authority checks before acting.

10. Security

The product includes tenant filters, role checks, private file access, secret redaction, audit controls, and guarded export and deletion operations. No system is fully secure. Contact Aestus to report a suspected security problem.

11. Children

Aestus is a work service. Do not submit a child's personal data unless you have the authority and a lawful reason to do so. Contact Aestus if you believe a child's data was submitted by mistake.

12. Changes to this notice

This notice can change as the product and its data practices change. The effective date at the top shows when this text was last revised. A revised notice will show a new effective date.

Questions? Contact Aestus.