Aether

Privacy Policy

Last updated: 28 September 2026

Aether is an agent-native financial-search service operated by EBD Sweden AB (“EvidInvest”, “we”, “us”). This policy explains what we collect when you use the Aether website, API, and MCP connector, how we use it, and the choices you have.

Information we collect

  • Account data — the email address you register and, for SSO, basic profile identifiers from your provider.
  • Authentication data — OAuth clients, authorization codes, and access/refresh tokens. Tokens are stored only as salted hashes; we never store them in clear text.
  • Usage data — the queries you send, the tools you call, result counts, latency, and tier/quota counters, used to operate, debug, and improve the service.
  • Technical data — your IP address and user-agent, used for security, rate-limiting, and abuse prevention.

Aether searches public source documents (e.g. SEC filings, earnings-call exhibits, EU regulation). We do not ask you to submit personal data in your search queries and recommend you do not.

Analytics & cookies

We measure site traffic with Umami, which we self-host on our own infrastructure at umami.ebdsweden.com. It is cookieless: it sets no cookies, stores nothing in your browser’s local or session storage, does not fingerprint your device, and does no cross-site or cross-device tracking. Visits are counted anonymously in aggregate, and the data is never shared with or sold to an advertising network. Because nothing is stored on or read from your device, this measurement needs no consent banner. We use no advertising or third-party tracking cookies on this site.

How we use it

  • To provide, authenticate, and operate the service.
  • To enforce rate limits and quotas and to prevent abuse and fraud.
  • To diagnose problems and improve search quality and reliability.
  • To comply with legal obligations.

How we share it

We do not sell your personal data, and we do not use it to train machine-learning models. We share it only with the sub-processors that run the service, each bound by a data-processing agreement, and where required by law.

Sub-processors

  • Amazon Web Services (us-east-1) — application hosting, database, search index, and Amazon SES for transactional and security-notification email.
  • Vercel — hosting and CDN for this website and the developer dashboard.
  • Stripe — payment processing for credit top-ups. Stripe collects and holds your card details directly; we never see or store card numbers. We keep only the resulting transaction record.

Authentication is first-party: accounts, passwords, OAuth clients and tokens are handled by our own service, not by a third-party identity provider. If you choose Google or Microsoft single sign-on, that provider receives the fact of your sign-in and returns basic profile identifiers to us.

Connecting Aether to a third-party AI client

When you connect Aether as an MCP connector to a third-party AI assistant (for example ChatGPT, Claude, or Cursor), you authorize that client through OAuth and it holds an access token issued by us. From that point the client sends us the queries it decides to send, and we return search results to it. What that assistant then does with the results — including whether it retains or trains on them — is governed by that provider’s privacy policy, not this one. You can revoke a connected client at any time from your dashboard, which immediately invalidates its tokens.

International transfers & legal basis

EBD Sweden AB is the data controller. We process your data to perform our contract with you (providing the service), on our legitimate interest in securing and improving it, and to meet legal obligations. Our infrastructure runs in the United States (AWS us-east-1), so personal data is transferred outside the EEA under the European Commission’s Standard Contractual Clauses and our providers’ supplementary safeguards.

Retention

Account and authentication data are kept for the life of your account. Usage logs are retained for a limited period for security and service-improvement purposes and then deleted or aggregated. You may request deletion of your account at any time.

Security

Access is over HTTPS; credentials are hashed at rest; OAuth grants are gated behind email verification and scoped least-privilege. No method of transmission or storage is perfectly secure, but we work to protect your data using industry-standard measures.

Your rights

Subject to applicable law (including the EU GDPR), you may request access to, correction of, or deletion of your personal data, and may object to or restrict certain processing, and to receive your data in a portable form. To exercise these rights, contact us at privacy@evidinvest.com, or delete your account yourself from your developer dashboard. If you are in the EEA and believe we have handled your data improperly, you may also lodge a complaint with your national supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (IMY).

Children

Aether is not directed to children and is intended for professional use. The service is not for anyone under 18: our Terms of Service require you to be at least 18 years old, and we do not knowingly collect personal data from anyone under that age. If you believe a minor has given us personal data, contact us at privacy@evidinvest.com and we will delete it.

Changes

We may update this policy; we will revise the “last updated” date above and, for material changes, provide reasonable notice.

Contact

Questions or requests: aether@evidinvest.com.