Privacy Policy
Last updated: August 17, 2026
Aeon (“Aeon,” “we,” “us,” or “our”) operates a personal life-management application (the “Service”) covering scheduling, tasks, notes, finances, health and nutrition tracking, journaling, habits, and related productivity tools. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
By creating an account or otherwise using the Service, you agree to the collection and use of information described in this Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Account information
When you register, we collect your email address, a hashed password (we never store your password in plain text), display name, and — if provided — a profile picture, character class, phone number, occupation, institution, bio, and referral code.
1.2 Content you create
The Service is built around letting you store your own data. Depending on which features you use, this may include:
- Schedule & tasks: time blocks, recurring routines, task lists, projects, and goals you create.
- Notes: note content, folders, and — if you use sharing — the email addresses of people you invite and the role you assign them.
- Financial data: account names, self-reported balances, and transactions you manually enter. We do not connect to your bank and cannot see your real account credentials or transaction history unless you type it in yourself.
- Health & nutrition data: food logs, sleep, water intake, body metrics, and habit tracking you choose to log.
- Journal entries: personal reflections, mood logs, and gratitude entries.
- Password vault: credentials for other services that you choose to store in Aeon. These are encrypted (AES-256-GCM) before being written to our database; see Section 4.
- Social features: friend connections, workspace collaborators, and chat messages within shared workspaces.
- Other content: code snippets, language-learning progress, coding-problem submissions, and similar feature-specific data.
1.3 Information from third-party sign-in and integrations
If you sign in or link an account with Google, we receive basic profile information (name, email, Google account ID) needed to authenticate you. If you separately connect Google Calendar, we request access to your calendar events so we can sync them with your Aeon schedule — this is a distinct, revocable permission from Google sign-in, and you can disconnect it at any time from Settings. We store your Calendar access and refresh tokens encrypted (AES-256-GCM) and use them only to read and write calendar events on your behalf.
1.4 Technical & usage information
Our servers automatically log standard technical data when you use the Service, including IP address, browser type, device information, and timestamps of requests, for security, debugging, and abuse-prevention purposes.
1.5 Push notifications
If you enable push notifications, we store the browser-provided subscription endpoint and encryption keys needed to deliver notifications to your device, along with your notification-timing preferences.
1.6 Cookies & local storage
We use your browser’s local storage (not tracking cookies) to keep you signed in between visits by storing a session token. We do not use third-party advertising cookies or cross-site tracking.
2. How We Use Your Information
- To provide, operate, and maintain the Service and the features you choose to use.
- To authenticate you and keep your account secure.
- To send transactional email (password resets, verification codes, welcome messages, collaboration invites) via our email provider, Resend.
- To send push and in-app notifications you’ve opted into (reminders, habit check-ins, schedule alerts).
- To sync your schedule with Google Calendar, if you’ve connected it.
- To process subscription payments and manage billing, via our payment processor, Stripe, if you subscribe to a paid plan.
- To detect, prevent, and address technical issues, fraud, or abuse.
- To improve and develop the Service.
We do not use your personal content (notes, financial entries, health logs, journal entries, etc.) to train third-party AI models, and we do not sell your personal information.
3. How We Share Information
We do not sell your personal information. We share information only in these limited circumstances:
- With people you choose to share with: if you invite a collaborator to a note or workspace, that person can see the content and role you’ve granted them.
- Service providers: we use third-party infrastructure providers to operate the Service, including hosting/database providers, Resend (transactional email), Google (sign-in and Calendar sync, only for accounts that connect it), and Stripe (payment processing, only for accounts on a paid plan). These providers process data on our behalf under their own privacy and security terms. We never store your card number or other payment credentials ourselves — Stripe handles that directly.
- Legal requirements: if required to comply with a legal obligation, protect our rights, or respond to a valid legal request.
- Business transfers: if Aeon is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we’ll notify you before your data becomes subject to a different privacy policy.
4. Data Security
- Passwords are hashed with bcrypt and are never stored or transmitted in plain text.
- Sensitive stored secrets — password-vault entries and Google Calendar OAuth tokens — are encrypted at rest using AES-256-GCM.
- All traffic between your browser and our servers is encrypted in transit via HTTPS/TLS.
- Access to production systems is restricted to authorized personnel.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your account password confidential and for using a strong, unique password.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within a reasonable period, except where retention is required for legal, security, or legitimate business purposes (for example, fraud prevention or dispute resolution).
6. Your Rights & Choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information (most content is directly editable within the app).
- Request deletion of your account and associated data.
- Export a copy of your data.
- Withdraw consent for optional integrations (e.g., disconnect Google Calendar) or notifications at any time.
To exercise any of these rights, contact us using the details in Section 11. We will respond within a reasonable timeframe and consistent with applicable law.
7. Children’s Privacy
The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
8. International Data Transfers
Your information may be processed and stored in countries other than your own, including the United States, where our hosting infrastructure is located. By using the Service, you consent to this transfer, storage, and processing.
9. Health & Financial Data — Important Note
Aeon’s nutrition, health, and finance tools are self-tracking tools, not medical devices, financial advisory services, or a substitute for professional advice. This data is provided entirely by you and is treated with the same security measures as your other account content, but Aeon is not a “covered entity” under HIPAA and this Service should not be used to store data that requires HIPAA-level protections.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through an in-app notice before the changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
11. Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at privacy@aeonos.app. For general account or billing help, contact support@bloxsocial.live.
This document is a template drafted based on Aeon’s actual features and data practices as of the date above. It is provided for general informational purposes and does not constitute legal advice. Given the Service handles health, financial, and credential data, we recommend having this policy reviewed by a qualified attorney familiar with applicable privacy laws (e.g., GDPR, CCPA/CPRA, and any state-specific health data laws) before relying on it for compliance purposes.