Privacy Policy
Last updated: March 19, 2026
Welcome to Aperiodic ("we", "us", "our"). We are committed to protecting and respecting your privacy in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website located at aperiodic.io (the "Site") and use our services (the "Service"). By using our Site and Service, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Data Controller
The data controller responsible for your personal data is Aperiodic. You can contact us at info@aperiodic.io.
2. Information We Collect
We may collect and process the following types of information:
- Personal Data: Information that identifies you as an individual, such as your name, business name, address, email address, and payment details.
- Account Data: Information related to your account, including account settings, team membership, roles, and permissions.
- Authentication Data: Information from third-party authentication providers (such as Google or GitHub) if you choose to sign in using these services, including your name, email, and profile picture as provided by the authentication provider.
- Usage Data: Information about your interaction with our Site and Service, including your IP address, browser type, device information, operating system, access times, pages viewed, API usage patterns, data downloads, and referring website addresses.
- Payment Information: Details of transactions you carry out through our Site, including payment method information, which are processed by third-party payment processors such as Stripe. We do not store your full credit card details on our servers.
3. Legal Basis for Processing Personal Data
We process your personal data based on the following legal grounds:
- Contract Performance: To fulfill our contractual obligations to you, including providing our services and processing your transactions.
- Legitimate Interests: To improve our Site and Service, communicate with you, monitor API usage for fair use compliance, and ensure the security and integrity of our operations.
- Consent: We may process your personal data based on your consent, for example, when you subscribe to our newsletter. You have the right to withdraw your consent at any time.
- Legal Obligations: To comply with applicable laws, regulations, and legal requests.
4. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain our Site and Service.
- To process your transactions and manage your subscriptions.
- To manage your account, including team accounts, roles, and permissions.
- To monitor API usage and enforce fair use policies and rate limits.
- To communicate with you, including sending service updates, account information, and promotional materials.
- To improve our Site and Service based on usage data and feedback.
- To detect, prevent, and address fraud, security issues, and technical problems.
- To ensure compliance with legal obligations and to protect the rights and safety of our users and Aperiodic.
5. How We Share Your Information
We do not sell or trade your personal data to third parties. However, we may share your information in the following circumstances:
- Service Providers: We may share your information with third-party service providers who perform services on our behalf, such as payment processing (Stripe), cloud infrastructure and database hosting (Supabase, cloud providers), email delivery, analytics, and customer support. These service providers are required to maintain the confidentiality of your information and are restricted from using it for any purpose other than as directed by us.
- Team Account Members: If you are part of a team account, certain profile information (such as your name and email) may be visible to other members of your team as required for team collaboration.
- Legal Obligations: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).
- Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred to the new owners as part of the transaction.
6. International Data Transfers
Your information may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. If you are located outside the European Economic Area (EEA) and choose to provide information to us, please note that we transfer the data, including personal data, to the EEA and process it there.
We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your personal data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
7. Data Security
We implement appropriate technical and organizational measures to protect your information against unauthorized access, loss, or misuse, including encryption in transit and at rest, access controls, and regular security assessments. However, no method of transmission over the internet, or method of electronic storage, is 100% secure, and we cannot guarantee the absolute security of your information.
7.1 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
8. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws. When your information is no longer needed, we will securely delete or anonymize it. Specifically:
- Account Data: Retained for the duration of your account and deleted upon account closure, subject to legal retention requirements.
- Transaction Data: Retained for the period required by applicable tax and accounting laws.
- Usage and API Data: Retained in anonymized or aggregated form for analytics and fair use monitoring purposes.
9. Your Rights Under GDPR
If you are a resident of the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data.
- Right to Erasure: You have the right to request that we delete your personal data, subject to certain legal obligations.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances.
- Right to Data Portability: You have the right to request that we transfer your personal data to another organization, or directly to you, in a structured, commonly used, and machine-readable format.
- Right to Object: You have the right to object to the processing of your personal data in certain circumstances.
- Right to Withdraw Consent: If we are processing your personal data based on your consent, you have the right to withdraw your consent at any time.
- Right Regarding Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
To exercise any of these rights, please contact us using the contact information provided below.
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- Right to Opt-Out: We do not sell your personal information. If this changes, we will provide you with the right to opt out.
To exercise these rights, please contact us using the contact information provided below.
11. Children's Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete such information promptly. If you believe that we may have collected information from a child under 18, please contact us.
12. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track the activity on our Site and store certain information. Cookies are files with a small amount of data that are stored on your device. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Site.
12.1 What Are Cookies?
Cookies are small text files that are stored on your device (computer, smartphone, or tablet) when you visit a website. They help the website remember your preferences, enhance your browsing experience, and provide information to the website owners.
12.2 Types of Cookies We Use
We use the following types of cookies on our Site:
- Essential Cookies: These cookies are necessary for the proper functioning of our Site. They enable core functionalities such as security, network management, and accessibility. Without these cookies, the Site would not function properly.
- Performance Cookies: These cookies collect information about how you use our Site, such as which pages you visit most often. This helps us improve the Site and provide a better user experience. The information collected is aggregated and anonymous.
- Functionality Cookies: These cookies allow our Site to remember your preferences and choices (such as your username, language, or region) to provide a more personalized experience.
12.3 How We Use Cookies
We use cookies for the following purposes:
- To provide and improve our Site and Service.
- To remember your preferences and settings to enhance your user experience.
- To analyze how our Site is used and to monitor performance to provide a high-quality experience.
12.4 Managing Cookies
You can control and manage cookies in various ways. Please note that removing or blocking cookies may impact your user experience and parts of our Site may no longer be fully accessible.
- Browser Settings: Most web browsers allow you to manage your cookie preferences through their settings. You can set your browser to block cookies or delete existing cookies. Please refer to your browser's help section for instructions on how to do this.
- Opt-Out Tools: Some third-party cookies can be managed through opt-out tools provided by the third parties themselves. For more information, please visit the websites of the respective third-party services.
12.5 Do Not Track
Some browsers offer a "Do Not Track" (DNT) setting. There is currently no universally accepted standard for how to respond to DNT signals, and we do not currently respond to DNT signals. We will update this policy if a standard is established.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top. We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the Site and Service after any modifications to the Privacy Policy will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise any of your rights, please contact us at:
Aperiodic
Email: info@aperiodic.io
15. Right to Lodge a Complaint
If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or where the alleged infringement took place. For more information on how to lodge a complaint, please contact your local data protection authority.