AETERNUM // PRIVACY POLICY
Privacy Policy
STATUSEffective September 2, 2026
VERSION2026-09-02
This policy explains what Aeternum processes, why, where it goes, how long it remains, and what choices are available. It distinguishes the public website and connected customer services from Praesidium’s routine on-device operation.
This is Aeternum’s currently published Privacy Policy. It is written from the reviewed production design and official provider or regulator guidance, but it is not a substitute for jurisdiction-specific legal advice.
Privacy at a glance
Aeternum collects and uses information to run the website, customer accounts, payments, licensing, downloads, support, reviews, security, and related product services. Routine Praesidium diagnostic and maintenance evidence stays on the customer’s Windows device unless the customer deliberately uses a connected workflow.
Praesidium settings, journals, system evidence, logs, and local AI work remain on the device during ordinary use.
Remote communication is used for accounts, licensing, updates, checkout and refunds, downloads, support, reviews, and other user-requested services.
Stripe handles payment details. Aeternum receives transaction references, status, and the information needed to administer the purchase.
Customers can manage account security, request deletion, control website measurement on their browser, and contact Aeternum about applicable privacy rights.
Who operates these services and what this policy covers
Aeternum IT Solutions LLC (“Aeternum,” “we,” “us,” or “our”) operates aeternumit.com, the Aeternum customer portal and Director-controlled service, the commerce and licensing gateway, public review and reviewer-program features, support workflows, and connected Praesidium services.
This policy covers personal information processed through those services. It does not replace the privacy terms of an external service that a customer visits directly, such as Stripe or GitHub. It also does not describe personal files or routine local system evidence that Praesidium does not transmit to Aeternum.
Information we process
| Category | Examples | Why we use it |
|---|---|---|
| Account | First and last name, email, display name, verification and account state, password hash | Create, verify, secure, and administer the account |
| Authentication and security | Session-token hash, machine hash, truncated user agent, salted IP hash, sign-in and administrative events, request identifiers | Authenticate users, preserve sessions, limit abuse, investigate incidents, and keep an audit record |
| Commerce | Stripe customer, checkout, payment, invoice, tax, refund, and billing-portal references; transaction state | Complete and account for purchases, administer refunds, and prevent fraud |
| Licensing and devices | Product, edition, entitlement, license, activation state, device limit, activation-credential hash, hashed device identity | Issue and validate licenses and manage authorized devices |
| Downloads and updates | Product and release requested, entitlement, time, release metadata | Deliver installers and updates and protect gated downloads |
| Support | Subject, messages, product, status, timestamps, and a sanitized diagnostic bundle only when the user creates and submits it | Respond to requests and diagnose problems |
| Reviews and programs | Chosen public display name, rating, review, product, eligibility and license provenance, moderation state, application responses | Verify eligibility, publish approved public content, disclose complimentary access, and administer programs |
| Website measurement | Page path, browser/device and interaction data, cookies or similar identifiers, session-replay and heatmap information when enabled | Understand site use, diagnose interface problems, and improve performance |
We do not design our systems to store plaintext account passwords or complete payment-card details.
Why we use information
We use information to provide requested products and services; authenticate users; connect a purchase to the correct account; issue, validate, and revoke licenses; deliver downloads and updates; respond to support; operate reviews and reviewer programs; maintain security and auditability; understand website performance; prevent misuse and fraud; keep financial records; and comply with applicable law.
Depending on where a person is located and the service involved, the legal basis may be performance of a contract, steps requested before entering a contract, legitimate interests such as security and service improvement, consent where required, or compliance with a legal obligation. We do not use this sentence to claim that every legal regime applies to every user.
Google Analytics, Microsoft Clarity, and browser controls
The public site uses Google Analytics 4 to measure site use and Microsoft Clarity to help diagnose interface behavior through tools that may include session replay and heatmaps. These services may use cookies or similar technologies and receive page-path, browser/device, interaction, and network information under their own terms. Aeternum configures analytics page locations without query strings or fragments.
You can disable these tools for this browser using Disable website analytics. The site stores that choice in browser storage and a preference cookie and attempts to clear Aeternum’s Clarity cookies. You can reverse the choice with Enable website analytics. Browser privacy controls, content blockers, and provider controls may offer additional choices.
Local-development hosts disable these tools automatically. Where law requires consent before non-essential measurement begins, Aeternum must use an appropriate consent mechanism. The production consent configuration is reviewed as services and applicable requirements change.
Accounts, sign-in, and security records
Account creation requires a first name, last name, email, and password. We store a one-way password hash rather than the plaintext password. Verification codes expire and are limited by attempt controls. Signed-in sessions use scoped tokens; the website’s current session cookie is configured for 14 days unless revoked sooner.
Security records can include a salted one-way hash derived from an IP value, a shortened user-agent value, machine or device hashes, event type, result, and time. Hashing reduces direct exposure but does not make every record anonymous. We use these records to protect accounts, investigate abuse, and maintain accountability.
Purchases, Stripe, taxes, and refunds
Stripe hosts checkout and processes payment details. Aeternum receives identifiers and status information needed to associate the transaction with the customer account, issue the product entitlement, display billing history, support an eligible refund, account for taxes and payments, and investigate fraud or disputes.
Stripe’s own privacy materials govern information it collects directly. Aeternum does not use the customer portal to collect complete card numbers or card-security codes.
What Praesidium keeps local and when it connects
| Ordinarily local | Connected only for a named operation |
|---|---|
| Settings, action journal, reports, logs, system-health evidence, browser/privacy inventory, performance samples, and local AI prompts/results | Account sign-in and verification; license activation/validation/deactivation; checkout and refunds; update and installer retrieval; support conversations; review and reviewer-program requests |
| Machine evidence used to form a device identity before hashing | The derived hashed device identity and license state needed to enforce entitlement and device limits |
| Sanitized support bundle until the user chooses to submit it | A submitted support bundle and related conversation after a deliberate user action |
Praesidium does not need to upload personal document contents for routine diagnostics. Its local AI uses a local Ollama or bundled local runtime and has no remote AI fallback in the reviewed implementation. Advisory AI cannot independently authorize protected system changes.
Support conversations, public reviews, and reviewer programs
Support messages are private to the authenticated customer and authorized Aeternum personnel, subject to service security and legal access. Do not submit passwords, verification codes, full license secrets, private keys, complete payment data, or unrelated personal information. A Praesidium support bundle is created locally only when the user requests it and is designed to exclude those secrets, cookies, personal file contents, and raw hardware identifiers.
Approved reviews display the reviewer’s chosen public display name, rating, review text, product, and applicable verification or complimentary-license disclosure. Eligibility and license provenance are checked privately against authoritative records. Reviewer-program application responses are not published as part of the review.
Service providers and processing locations
We use service providers for website hosting, gateway hosting through Fly.io, payment processing through Stripe, email delivery, website measurement through Google Analytics 4 and Microsoft Clarity, and public release downloads or metadata through GitHub. Each receives only the information involved in its function, subject to configuration and its own terms.
These providers may process information in the United States and other locations where they operate. Where applicable law requires safeguards for an international transfer, Aeternum and the provider must use an approved transfer mechanism. We do not name an unverified mail-delivery vendor or promise a transfer mechanism that has not been confirmed.
How long information remains and what deletion does
We keep information only while it is reasonably needed for the service and the purpose described, including account and license administration, security, fraud prevention, support, moderation, accounting, taxes, disputes, audits, and legal obligations. Fixed periods apply where the system or provider enforces them; otherwise we use those criteria rather than promise an unimplemented deletion date.
A customer may request account deletion from the portal. The current deletion workflow disables access, revokes sessions, removes the password hash, clears names and display name, and replaces the email with a non-deliverable internal alias. Minimized transaction, security, fraud-prevention, accounting, licensing, review-authenticity, and audit records may remain where needed for the purposes above.
Your privacy rights and choices
Depending on applicable law, a person may have rights to request access, correction, deletion, restriction, portability, or objection; withdraw consent where processing depends on consent; opt out of certain sale, sharing, or targeted-advertising activity; or appeal a denied request. Aeternum does not sell account records or use them for targeted advertising. Website measurement can still be treated as “sharing” under some laws, so we do not make a blanket statutory no-sharing claim.
Use the customer portal for account controls or email AeternumIT@proton.me. We may verify identity and authority before acting. We will respond in the manner and period required by the law that applies to the request. You may also complain to the relevant privacy regulator where that right exists.
Children’s privacy
Aeternum’s website, customer services, and Praesidium are not directed to children under 13, and we do not knowingly seek personal information from them. A parent or guardian who believes a child provided information should contact us so we can review and take appropriate action. This statement does not invent a broader contractual minimum age where one has not been approved.
How we protect information
Safeguards include encrypted transport, one-way password hashing, protected or hashed credentials, scoped sessions, role-based authorization, request and origin validation, rate limiting, security headers, signed release and license checks, administrative confirmation controls, and audit records. We review the service and improve safeguards as the system changes.
No online or local system can guarantee absolute security. If you believe an account or Aeternum service is at risk, contact us promptly without sending passwords, verification codes, private keys, or complete payment data.
Policy changes and privacy contact
We will post a revised version here when this policy changes and will identify its version and effective date. A material change may also receive an in-product, account, or email notice where appropriate. The version shown on this page is the currently effective Privacy Policy.
Email AeternumIT@proton.me or call (470) 785-5109. These are Aeternum’s approved public privacy and legal contact channels.
