LEGAL
Privacy Policy
Last updated August 31, 2026
Who this covers
Aegis AI is operated by Prerak Nain, an individual (not a registered company) based in India. Any reference to “we”/“us” below means Prerak Nain operating Aegis AI.
What we collect
Account information: your name and email address, collected when you sign up (via Clerk, our authentication provider).
The files you upload: when you submit a network flow file to /analyze, it is read into memory, processed, and discarded — the original file itself is not written to disk or retained anywhere. Only the results derived from it (see below) are stored.
Derived analysis results: for each upload, we store the filename, detected format, flow/attack counts, and — for the flows our AI agent narrates — the attack classification, confidence score, severity, AI-generated narrative text, and recommended action. This is what powers your history page and PDF exports.
Usage and billing data: your subscription tier, how many analyses you’ve run this billing period, and (if you subscribe) billing identifiers from our payment processor. We do not see or store your card or PayPal details ourselves — those are handled entirely by our payment processor.
Alert settings you opt into: if you configure a Slack webhook URL or an alert email address, we store exactly that — nothing else.
Who else sees it (our subprocessors)
We don’t sell or share your data. The following third parties process it strictly to run the service:
- Clerk — authentication, account/session management.
- Neon — hosts our Postgres database (encrypted at rest, in a managed cloud environment).
- Anthropic — the text of an attack’s classification and attribution context is sent to Anthropic’s Claude API to generate the plain-language narrative and recommendation. Your raw uploaded file is never sent to Anthropic — only derived, per-flow classification data.
- Gumroad — processes subscription payments as merchant of record. We receive only your tier and subscription status, never your payment details.
- Resend — sends CRITICAL-severity alert emails, only if you’ve opted in with an alert email.
- Render and Vercel — host the backend API and the website you’re reading this on.
How long we keep it
Account and derived analysis data is kept for as long as your account is active. If you want your account and all associated data deleted, email us (below) and we’ll delete it — there’s no self-serve deletion flow yet.
Your rights
You can ask us at any time to see what we have on file for you, correct it, or delete it. Since this is a one-person-operated service, expect a personal response by email rather than an automated portal.
Cookies
Clerk sets session cookies to keep you signed in. We don’t run our own tracking/advertising cookies beyond what Clerk requires for authentication.
Changes to this policy
If this changes materially, the “last updated” date above will change and, for significant changes, we’ll note it somewhere visible on the site.
Contact
Questions about any of this: nainprerak15@gmail.com