Loading...

Legal

Privacy Policy

Last updated August 7, 2026

No account is required to use Aegis BI. The Service operates without individual user sign-in: your data is stored on your own device, and any subscription is tied to an anonymous device identifier rather than a personal account. This Policy describes our practices as they apply today.

Athena Analytics LLC ("Athena," "we," "us," or "our") operates Aegis BI, a financial-intelligence application powered by our Glaukos AI engine (the "Service"). This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. By accessing or using the Service you agree to this Policy. If you do not agree, do not use the Service.

This Policy should be read together with our Terms of Service.

In short

Your workbooks stay on your device. There is no account and no sign-in — your data is sent to our servers only to compute a result, and is not kept there. AI features pass the relevant part of your data to Anthropic (Claude) to generate the answer you asked for. We never sell your information, and we never send your uploaded data to payment or notification providers. Usage analytics are anonymous and you can turn them off on the Account page; deleting your account erases the records tied to your device. Separately, our own cookieless page counts record which pages are visited; they store nothing in your browser and honour "Do Not Track".

This summary is for orientation only — the full text below is what applies.

Contents

1. Who we are; controller and processor roles

The entity responsible for the Service is Athena Analytics LLC, Ada, Michigan, U.S.A. For privacy questions, contact info@athenadatalabs.com.

For personal information contained in the data you upload or connect ("Customer Data"), you are the data controller and Athena acts as a data processor processing that data on your documented instructions to provide the Service. You are responsible for having a lawful basis to upload Customer Data and for the notices and consents required from the individuals it concerns. For usage and any contact information about you, Athena is the controller.

2. Information we collect

a. Information you provide. - Contact details (where applicable): if you email us or request support, we receive your name, email address, and anything else you choose to include. There are no individual user accounts; the Service works without a personal login. - Customer Data. Spreadsheets, exports, links (e.g., Google Sheets/CSV URLs), and the financial and operational records they contain, which may include transaction records, revenue and expense figures, and client/vendor names. - Communications. Messages, prompts, and questions you send to Glaukos or to our support team.

b. Information collected automatically. - Usage and device data such as pages viewed, features used, how long the app is open, approximate location derived from IP address, browser type, and timestamps. - Anonymous product analytics. The Service records feature-usage events (for example "page viewed," "data source added," "chat message sent," or how long the app was open and in the foreground) under a random identifier generated on your device. These events contain no Customer Data — never your uploaded values, file names, or prompts — and the identifier is not derived from, or linked to, your billing identifier. You can turn analytics off at any time on the Account page; deleting your account also removes the identifier from your device. See Section 11. - First-party page analytics. We record the page viewed, the referring site, browser and general device type, and country, using a cookieless analytics program (Umami) that runs on our own server. No cookie is set, no identifier is created, nothing is stored in your browser, and nothing is sent to an analytics company. This is separate from the product analytics above, is not covered by the Account-page toggle, and honours your browser's "Do Not Track" preference. See Section 11. - Local storage / cookies used to keep the Service working (e.g., session state, your active data source, unlock status, preferences, and the analytics identifier and opt-out choice described above). See Section 11.

c. Subscription and payment information. If you subscribe, we store a random device identifier together with your subscription status, plan, and renewal dates so the Service knows whether to unlock Pro features. We never receive or store your full card number or Apple ID credentials. Payment details are collected and processed directly by our payment providers: - Stripe for web purchases (see stripe.com/privacy); and - Apple for purchases made in the Aegis BI app for iPhone, iPad, or Mac, which are billed through your Apple ID under Apple's own privacy policy (see apple.com/legal/privacy). We receive only the transaction receipt and entitlement status from Apple — not your name, email, or payment method.

d. Push notification token. If you turn on briefing notifications in the Aegis BI app, Apple issues a device push token which we store so we can send you a notification when a new briefing is ready. It identifies the device, not you, contains no Customer Data, and is deleted when you turn notifications off, delete your account, or uninstall the app. You can revoke notifications at any time in your device's system settings.

e. Sensitive data. We do not want and ask that you not upload special-category or highly sensitive personal data (such as health, biometric, precise geolocation, government-ID, or full payment-card/bank-account credentials). You are responsible if you choose to include such data.

3. How we use your information

We use the information to: provide, operate, secure, and maintain the Service; process Customer Data to generate dashboards, analytics, forecasts, and AI insights at your direction; respond to your requests and provide support; monitor, debug, and improve the Service and develop new features; detect, prevent, and address fraud, abuse, security, and technical issues; and comply with legal obligations and enforce our agreements.

Legal bases (where GDPR/UK GDPR applies): performance of a contract; our legitimate interests in operating, securing, and improving the Service; your consent (where required); and compliance with legal obligations.

4. AI processing and third-party subprocessors

Some features (the Glaukos engine, column mapping, briefings, and chat) transmit relevant portions of your prompts and Customer Data to a third-party AI provider — Anthropic (Claude) — solely to generate the requested output and return it to you. Your use of these features is also subject to that provider's terms and privacy practices (see anthropic.com). We do not authorize subprocessors to use your Customer Data to train their general models except as permitted by their applicable enterprise/API terms, and we configure integrations to limit such use where that option is available.

The full set of subprocessors we rely on, and what each one receives:

Provider — Purpose — What they process

Anthropic — Glaukos AI: chat, column mapping, briefings — The prompt and the relevant portion of Customer Data for that specific request

Amazon Web Services — Cloud hosting, storage, infrastructure — Service traffic and server-side state, encrypted in transit

Stripe — Payment processing for web purchases — Card details and billing address (entered directly with Stripe), subscription state. No Customer Data.

Apple — App Store subscription billing; push delivery for briefing notifications — Purchase receipts and entitlement status; the device push token. No Customer Data.

No Customer Data is ever sent to payment or notification providers. This list is current as of the "Last updated" date above; write to info@athenadatalabs.com to be notified of changes.

5. Automated processing

The Service uses AI to generate analytics and suggestions. These outputs are decision-support tools; the Service does not make legally or similarly significant decisions about individuals on an automated basis. You remain responsible for reviewing outputs and for any decision you make. See the "No professional advice" section of our Terms of Service.

6. How we share information

We do not sell or "share" (as defined under California law) your personal information or Customer Data for cross-context behavioral advertising. We disclose information only: - to subprocessors and service providers acting on our behalf under appropriate confidentiality and data-protection obligations; - to comply with law, legal process, or enforceable governmental requests, and to establish, exercise, or defend legal claims; - to protect the rights, property, safety, or security of Athena, our users, or the public, and to enforce our agreements; and - in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy.

7. Data storage, security, retention, and incidents

We use administrative, technical, and organizational measures designed to protect information appropriate to its sensitivity. However, no method of transmission or storage is completely secure, and we cannot and do not guarantee absolute security. You are responsible for safeguarding any credentials and for keeping your own backup copies of important data; the Service is not a backup service.

We retain Customer Data for as long as your data source is active or as needed to provide the Service, and thereafter only as required for legitimate business or legal purposes. You may delete or replace your active Customer Data at any time within the Service, and may request deletion as described below; on termination we will delete or de-identify Customer Data within a commercially reasonable period, subject to legal retention requirements. Anonymous analytics events (Section 2(b)) are retained for product-improvement purposes; they are not linked to your identity and cannot be used to identify you. Subscription records (Section 2(c)) are retained while your subscription is active and afterwards only as needed for tax, accounting, and audit obligations. Deleting your account from the Account page erases the trial, billing, and push records held for your device and every dataset stored on it.

In the event of a data breach affecting your information, we will notify you and relevant authorities to the extent and within the timeframes required by applicable law.

8. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal information, to object to certain processing, and to withdraw consent. Residents of the EEA/UK (GDPR) and U.S. states including California (CCPA/CPRA), Virginia, Colorado, and others have specific rights, including the right not to receive discriminatory treatment for exercising them. The categories of personal information we collect, the purposes, and the recipients are described in Sections 2–6. We do not sell personal information and do not offer financial incentives for it.

To exercise any right, contact info@athenadatalabs.com. We will verify your request and respond within the time required by applicable law. Where Athena processes Customer Data as a processor, requests from data subjects should be directed to the relevant controller (our customer), and we will reasonably assist.

9. International transfers

We may process and store information in countries other than your own, including the United States. Where required, we implement appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.

10. Children's privacy

The Service is intended for business use and is not directed to individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us so we can delete it.

11. Cookies, local storage, and "Do Not Track"

The Service uses strictly necessary cookies and browser local storage to function (for example, to maintain your session, remember your active data source, and store preferences). Local storage also holds the optional anonymous-analytics identifier and your opt-out choice described in Section 2(b); the toggle on the Account page controls both, and no product-analytics events are sent while it is off. We do not use cookies or local storage for cross-site advertising. You can control cookies through your browser settings, though some features may not work without them.

The first-party page analytics described in Section 2(b) are separate. They are cookieless, store nothing in your browser, and are not governed by the Account-page toggle. They do honour your browser's "Do Not Track" preference, and no page analytics are recorded while it is on. Other parts of the Service do not respond to "Do Not Track" signals, as there is no industry-standard interpretation of them.

12. Third-party links

The Service may link to third-party sites or services we do not control. We are not responsible for their content or privacy practices, and this Policy does not apply to them.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance.

14. Contact us

Terms of Service · Support · Back to dashboard