EARLY ACCESS
New check

Aither Watch · Version 8 September 2026

Privacy policy

This notice covers the current free preview, account assistant, support and agency-pilot enquiries. Paid subscriptions are not open. It explains the service as implemented; it is not a certification of GDPR compliance.

Who is responsible

Aither Watch is a product of Aither, trading as Aither Growth, the sole proprietorship of Max Geurtsen, Netherlands Chamber of Commerce (KvK) 99470160. Correspondence address supplied for this service: Hospitalstrasse 67, Hamburg, Germany. Email: max@aithergrowth.com. This correspondence address is not a statement of the registered business address.

Max is the contact for privacy requests and the controller for service accounts, support and pilot research. No data protection officer has been appointed. If you need Aither to process personal data on behalf of your agency, contact us to agree the necessary processing terms before providing that data.

What we use and why

  • Sign-in and account: your account identifier and email are received from ChatGPT sign-in. We use these to provide the account you request and to separate your records from other users. The basis is providing the service under our agreement.
  • Website checks: submitted URLs, settings, findings, report history, privately saved client-update drafts and follow-up notes let us provide checks and keep track of your work. A check fetches a limited public HTML sample and public DNS information. Full fetched HTML is processed transiently and is not stored in the report database. URLs, titles and findings can contain personal data, so avoid private links or personal information in submissions. The basis is providing the requested service.
  • Support and privacy: messages, replies and request dates allow us to respond, handle complaints and meet data-protection duties. The bases are providing support under our agreement and complying with legal obligations, as applicable.
  • Pilot enquiries: agency name, website-count range, current workflow, obstacles, price preference and link campaign labels help evaluate the pilot. We record your permission to reply, and use the details for the enquiry and the requested pre-contract discussion. Optional follow-up contact is based on your permission. You are not added to a newsletter. You may withdraw permission at any time.
  • Safety and reliability: request counts, job results, errors and access checks prevent abuse and investigate faults. We rely on our legitimate interests in keeping the service secure and usable, while limiting what is retained.

Information is normally supplied by you, your sign-in provider or the public website you ask us to check. For individually researched business enquiries, we may use a published business contact and the source of an invitation to contact it. You may object to marketing at any time. We do not sell account information or run behavioural advertising in this application.

Email delivery and suppression

For service emails, we verify signed notifications from our email provider and retain the event type, message reference and timing. We do not retain the callback’s full payload. Recipient-server acceptance does not establish inbox placement or reading. Permanent bounces, spam complaints and provider suppression stop further automatic email to that address and unsubscribe any newsletter preference.

Delivery events are normally kept for 30 days; an open privacy request can hold associated records for review. A minimal suppressed address, reason and date can remain to prevent unwanted contact while retention and privacy handling are reviewed. It is included in the signed-in privacy export. Application erasure does not silently remove this suppression or delete the provider’s records. Contact Max about correcting a suppression or exercising your rights.

Astra and automated actions

Astra is an AI assistant, not a person. When AI conversation is enabled, OpenAI receives your message, relevant conversation history and the account or report details needed for the request. API response storage is disabled in our requests; that does not mean the provider retains nothing. Application copies of messages and proposed actions are stored as described below.

You may attach a small screenshot or text file to a chat message. Files stay in the current browser draft until you press Send. Images are resized and re-encoded in your browser, then sent to OpenAI for that turn; Aither does not save the original image or provide a file library. Text-file content and attachment names are saved with the conversation and included in its privacy export and retention rules. Replies can contain information from attachments. Reopened conversations do not restore original images. Only attach material you have permission to share, and remove secrets or confidential client data before sending.

The account assistant has tools scoped to your signed-in account. It cannot read another customer’s records or the operator’s inbox. Changes proposed in the assistant require the confirmation shown in the interface. Automated website findings and AI replies can be wrong or incomplete. They do not determine credit, employment or other similarly significant decisions. Ask Max to review a concern or disputed result. Support automation can acknowledge requests and answer exact matches to reviewed product questions. Complaints, non-routine questions and privacy decisions remain open for review.

Business evidence, optional Google checks and feedback

A new report includes business names, descriptions, contact details, addresses and profile references declared in the public page you ask us to inspect. They are unverified first-party claims and follow the same access and retention rules as the report. No full-page copy or independent profile lookup is stored.

If you explicitly choose an optional Google check, we send the saved report’s public page URL to Google PageSpeed Insights or Chrome UX Report. PageSpeed loads and executes the target page to run its performance test. Chrome UX Report returns aggregated eligible public performance data when available. We display a small result in your current page and do not save it in your report. Google processes the request under its service arrangements; request counts are retained for abuse prevention. These optional requests are not automatically triggered by opening a report.

Tester feedback is attached to your owned report and saved as a support case with your usefulness response, comment, account email and permission timestamp. Permission covers a reply about that feedback only. It creates no newsletter subscription or sale and follows support-case retention and privacy controls. The operator may attach a private review stage, evidence note and next-review date to pilot enquiries and report feedback. These help handle your request and are included in your account export; they do not establish new marketing permission.

The operator sees aggregate service-account registrations and retained report, pilot and feedback activity to improve the service. This uses existing service records under our legitimate interest in understanding product use. We do not add advertising cookies, fingerprint visitors or identify anonymous visitors for these metrics. Accounts may not represent unique people. Retention and deletion can reduce the totals.

Widgets, invitation links and the optional newsletter

The agency widget is a plain link or HTML form. It has no Aither script, remote image or tracking pixel. Following it opens Aither; submitting the form sends the website address and an optional campaign label to Aither. Confirm permission before starting a check. A successful saved report may include the supplied source and campaign label. These labels are not verified referrals, are retained with that report and are used in private aggregate product analysis. No report or account information is shared back with the embedding website.

The newsletter is optional and uses separate explicit consent. We store your signed-in account email, subscription status, consent wording version, consent time and preference-change time to honor that choice. The wording promises at most two product-update or practical-tips emails per month. Signup does not launch delivery, create a purchase or subscribe your existing support and pilot contacts. When delivery is enabled, each newsletter includes an unsubscribe link that works without sign-in and supports email-client one-click requests. You can also unsubscribe in the newsletter controls or email Max. Unsubscribe and privacy objections stop new newsletter processing; an email already accepted by a provider cannot be recalled.

Preference and consent evidence remain with your account while the preference applies, including a minimal unsubscribe record to prevent accidental re-enrollment. You can request reviewed erasure; scoped application erasure includes this table, while provider and backup records require separate review. Newsletter delivery has not launched and will require tested unsubscribe links, suppression reconciliation and verified sending before any campaign.

Providers and international processing

The service uses ChatGPT Sites for hosting and sign-in, with a Cloudflare runtime and application database. Public DNS checks use Cloudflare. Gmail is used for business correspondence. OpenAI processes AI requests when enabled. Resend is intended for application emails after its sending domain is verified. Stripe is intended for hosted checkout and billing after paid launch; this preview does not collect card details.

These providers may process data outside the EEA under their own service arrangements. A complete account-specific review of processing agreements, locations, subprocessors and transfer safeguards is still a launch requirement. We do not currently promise EU-only storage. Contact Max for the arrangements applicable to your enquiry; do not upload sensitive or confidential client data during the preview.

How long records remain

  • Reports, AI messages and action records: the cleanup job deletes application copies older than 30 days. Cleanup depends on successful scheduled execution. If it stops, records remain until cleanup resumes or a deletion request is handled. Records associated with an open privacy request are held for review instead of being removed by this routine cleanup.
  • Saved websites and follow-ups: remain while you use them. Removing a saved website removes its associated reports and follow-ups. Report expiry alone does not remove progress notes.
  • Support and pilot enquiries: resolved records without an active enquiry follow-up are removed by the cleanup job after 180 days from submission or the last saved closed-case review, unless linked to an open privacy request. Open cases remain available for handling and are reviewed by the operator.
  • Privacy requests: remain until handled, then are reviewed for deletion or restricted retention where needed to document the response or a legal claim. Max will explain any continued retention in the response.
  • Operational records: successful email-queue records and payment-event deduplication identifiers are removed after 30 days by cleanup. Newsletter reservations remain through their UTC calendar month so cleanup cannot reset the two-message limit. Cancelled and expired campaign copy is removed after 180 days when no retained delivery record references it. Daily request counters are kept for the current and previous day. Failed or uncertain mail remains until investigated. Job-run history is removed after 30 days and ordinary operational review records after 180 days; privacy decision evidence is reviewed with the privacy case.

Removing application data does not instantly remove copies in provider systems or backups. Provider retention must be checked separately. Any records required for tax, disputes or another legal obligation may need longer retention; paid billing retention will be specified before launch.

Your choices and rights

You can download your current account records and submit a privacy request, or email Max without signing in. Depending on the circumstances, you can ask for access, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. You can also object to direct marketing.

We normally respond within one month. If a lawful extension is necessary, we will explain it within that first month. We may request proportionate identity checks when necessary; do not send a passport, password or verification code unsolicited. A deletion or restriction request pauses scheduled website checks and new website/AI processing immediately. Reviewed application erasure removes scoped content; the minimal account identity and privacy case remain pending retention and provider review. It is a request for review, not an automatic confirmation of deletion or cancellation of a subscription.

You may complain to the Dutch Autoriteit Persoonsgegevens, or the supervisory authority where you live, work or believe an infringement occurred. You do not have to contact us first.

Cookies and changes

See the cookie notice for application storage and sign-in. Material changes to this policy will be published with a new date. New optional uses requiring consent will be offered separately.