Aedex
Legal

Privacy Policy

What Aedex collects, what it deliberately does not, and where each piece of it lives.

Placeholder — not yet reviewed by counsel

This is a working draft written 27 July 2026 so that sign-in has something to link to. It has not been reviewed by a lawyer, it is not legal advice, and it is not a binding agreement. Treat it as a description of how Aedex currently intends to operate, which is useful, and nothing more than that. Counsel-reviewed terms will replace this page before Aedex is offered commercially.

01What Aedex is

Aedex is a research terminal for institutional commercial real estate. It tracks buildings, portfolios, owners, lenders and recorded transactions, and shows where every figure came from. Almost everything in the catalog is information about companies, properties and public records — not about you.

This policy covers the personal information Aedex holds about the people who use it.

02Information you give us

When you create an account, authentication is handled by Clerk, our identity provider. Clerk stores the credentials; Aedex receives a user identifier and the basic profile fields you chose to share.

  • Email address, and name if you provide one.
  • The identity provider you signed in with, if you used a social or SSO login.
  • Organization or team membership, if you are invited into one.
  • Anything you type into a workspace: saved screens, watchlists, notes, custom assets, alert rules.

Aedex never receives or stores your password. If you sign in through a third-party provider, that provider's own privacy policy governs what it collects on its side.

03Your own API keys

Aedex lets you connect your own model provider key so the agent runs on your account rather than ours. That key is handled deliberately and narrowly:

  • It is stored in your browser's local storage, on your device, and nowhere else.
  • It is sent only in a request header, only to the provider host it belongs to, and never in a URL or query string.
  • It is never written to our database, never written to our logs, and never retained after the request that used it completes.
  • Clearing it in settings, or clearing your browser storage, removes it completely.

Usage billed to that key is between you and your provider. Prompts you send through it are subject to your provider's data-retention policy, not ours.

04Information collected automatically

Ordinary operational data: request logs containing IP address, timestamp, requested route and user agent, kept for security, abuse prevention and debugging. Error reports when something breaks. Rate-limiting counters keyed to your account.

Aedex does not run third-party advertising or cross-site tracking, and does not sell or rent personal information to anyone.

05Cookies and local storage

  • A session cookie set by Clerk, which is what keeps you signed in. Removing it signs you out.
  • Local storage on your device for interface state: theme, watchlist, comparison sets, pinned views, and your provider key if you have set one.

Local storage never leaves your browser unless you are signed in and have explicitly chosen to sync a workspace.

06How the information is used

  • To sign you in and keep you signed in.
  • To show you your own saved work, and to sync it across your devices when you ask for that.
  • To apply entitlements — which data tiers your plan reaches.
  • To prevent abuse, enforce rate limits, and investigate security incidents.
  • To contact you about the service. Product email is separate from marketing email, and marketing email is opt-in.

Your queries, screens and saved work are not used to train models.

07Who else touches it

Aedex relies on a small number of processors, each doing one job: Clerk for identity, our hosting and database providers for running the application, and the model provider you select when you use the agent. Each receives only what that job requires.

We do not otherwise disclose personal information, except where we are legally compelled to and, where the law permits, after telling you.

08Retention and deletion

Account and workspace data is kept while your account is open. Operational logs are kept for a limited period and then discarded.

You can delete your account at any time, which removes your profile and workspace content. Records we are required to keep — for example, the append-only evidence ledger that underpins verification, which contains sourced facts about properties rather than facts about you — are unaffected by account deletion.

09Your rights

Depending on where you live, you may have the right to access, correct, export or delete the personal information we hold, and to object to certain processing. Ask and we will do it; we will not make you jump through hoops for it.

10Security

Traffic is encrypted in transit. Access to production systems is restricted and audited. Secrets are held in managed environment configuration and are never committed to source control.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to us before disclosing it publicly, and we will work with you.

11Changes and contact

This draft will be replaced by a counsel-reviewed policy before Aedex is offered commercially. Material changes will be announced in the product rather than quietly published.

Questions about privacy: reach us through the feedback control in the application, or at the contact address published at launch.