Aera
FeaturesUse CasesPricingNewsMarketplaceCommunity
Sign in
Download

Privacy Policy

Last Updated: 2026-09-11

This Privacy Policy describes how Quixet LLC ("Quixet", "we", "us", "our") handles information when you use Aera Browser ("Aera", "the Browser", "the Software"). We are committed to protecting your privacy and being transparent about our data practices.

Contents

  1. Privacy Overview
  2. Data Stored Locally
  3. AI Agent & Third-Party Data
  4. MCP Server Data
  5. Extensions Data
  6. Skills Marketplace Data
  7. Security & Prompt Injection Risks
  8. What We Don't Collect
  9. Third-Party Services
  10. Data Security
  11. Your Rights & Controls
  12. Children's Privacy
  13. Changes to This Policy
  14. Contact Us

1. Privacy Overview

Aera Browser is designed with privacy as a core principle. Here's a quick summary:

  • Local-First Design: Your browsing data, history, bookmarks, and preferences are stored locally on your device
  • No Browsing Data Collection: While we operate servers for account authentication and updates, we do not collect or store your browsing data, history, or page content
  • Model Choice: Requests go to the model endpoint you configure or to third-party AI providers through OpenRouter
  • Direct AI Communication: When you use chat or an automation you create or ask the Agent to create, the prompts and page context needed for that task are sent to the selected model provider for processing; we do not store that content on our servers for inference
  • You're In Control: You can clear all your local data at any time from Privacy settings

2. Data Stored Locally

Aera stores the following data locally on your device:

Data TypePurposeYour Control
Browsing HistoryDisplay recent pages, enable history searchClear in browser settings
BookmarksSave and organize your favorite pagesAdd, edit, or delete anytime
PreferencesRemember your settings (theme, search engine, etc.)Modify in settings
Chat/Conversation HistoryPersist your AI Agent conversationsClear conversations anytime
Extension DataStore extension configurations and stateRemove extensions in settings
Scheduled TasksStore your automated task configurationsDelete tasks anytime
Background ImagesCustom theme backgroundsRemove in appearance settings

All locally stored data remains on your device and is not transmitted to Aera servers for collection. You can clear all local data at once using the "Clear All Local Data" option in Privacy settings. We do not have access to any of this data.

3. AI Agent & Model Data

Important: Data sent to model providers is not controlled by Aera.

3.1 How AI Features Work

AI requests are made when you use chat, create an automation, or ask the Agent to create an automation for you. Those automations can then run on their schedule or configured triggers without another click. Opening or reading a page on its own does not send that page to a model. For these tasks, requests are sent directly to the selected model endpoint. Local model requests go to the OpenAI-compatible endpoint you configure, and requests for models provided through OpenRouter go to third-party AI services through OpenRouter. They never pass through Aera's servers. This process involves:

  • Your message/instruction is sent directly to the selected model provider
  • Page content the Agent needs to read is sent to the selected model provider
  • Screenshots or extracted page elements may be sent for analysis
  • Your conversation history may be included for context

3.2 Data Sent to Model Providers

For a chat or automation you initiate as described above, the following data may be transmitted to the selected model provider when needed for the task:

  • Your Instructions: The prompts and messages you send to the Agent
  • Page Content: Text, HTML structure, and metadata from pages the Agent reads
  • Visual Data: Screenshots or images when visual analysis is needed
  • Context Information: Current URL, page title, and conversation history
  • Attachments: Files or images you explicitly attach to messages

3.3 Models & Training Data

Aera does not use models that train on your data. Requests through OpenRouter exclude endpoints that train on request data.

When you use chat or an automation you initiate, the instructions, page content, and conversation history needed for that task reach the provider serving your selected model. What that provider does with the request, including any retention or logging, is governed by its own policies, which we do not control. See section 3.4.

Local model requests are sent to the endpoint you configure and are governed by that endpoint's behavior. This routing configuration applies to requests routed through Aera's OpenRouter account. Requests to an endpoint you configure use that endpoint's settings.

3.4 Model Provider Privacy

Data sent to model providers is subject to their privacy policies or to the configuration of the local endpoint you choose. We recommend reviewing:

  • OpenRouter Privacy Policy
  • The privacy policies of underlying AI models you select
  • The data handling of any local model server you configure

We have no control over how model providers or local endpoints handle, store, or use data sent through their services.

4. MCP Server Data

Aera's Model Context Protocol (MCP) server allows external AI tools to interact with the browser.

4.1 MCP Data Exposure

Only when you explicitly enable the MCP server can connected external tools access:

  • Page content and structure of open tabs
  • Screenshots of browser content
  • Ability to navigate, click, and type in the browser
  • List of open tabs and their URLs

4.2 Local Network Only

The MCP server operates on your local machine and is not exposed to the internet by default. However:

  • External tools on your machine can connect only when you have enabled the MCP server
  • Data exchanged with external tools is subject to those tools' privacy practices
  • You control when the MCP server is enabled or disabled

4.3 Companion Device Connections

Companion-device connections are disabled and do not ship in current Aera releases. The mobile companion app has not been released.

The planned feature will require you to explicitly enable it. When enabled, local-network discovery will announce that Aera is available to connect. Registered devices will use an encrypted connection.

5. Extensions Data

You choose which browser extensions to install or import into Aera, as with other Chromium browsers. Extensions you explicitly install or import may have their own data collection practices.

5.1 Extension Permissions

An extension you choose to install can request permissions, including:

  • Access to your browsing history
  • Ability to read and modify page content
  • Access to cookies and other browser data
  • Network access to send data to external servers

5.2 Third-Party Extensions

Extensions are developed by third parties. We do not control and are not responsible for:

  • What data extensions collect
  • How extensions use or share your data
  • Extension privacy policies or practices

Review each extension's privacy policy before installation and only install extensions from trusted sources.

6. Skills Marketplace Data

Skills are reusable instruction snippets you can invoke in chat (e.g. /analyze-competitors). Skills you create are stored locally on your device like your other data, and are not transmitted to Aera unless you choose to publish them.

6.1 Publishing a Skill

When you explicitly choose to publish a skill to the Skills Marketplace, that skill's contents (its name, description, and instruction body) are uploaded to and stored on Aera servers. This is the one case where content you author in Aera is stored on our servers. Published skills are reviewed by the Aera team before they become visible to other users, and you are shown this notice before publishing.

  • Attribution is your choice: when publishing, you may credit the skill to your account name or publish anonymously.
  • Visibility: approved skills are publicly available to other Aera users through the in-browser Marketplace.
  • Don't include secrets: do not put passwords, personal data, or confidential information in a skill you publish; its full contents are shared publicly once approved.

6.2 Installing a Skill

When you add a skill from the Marketplace to your browser, we record an anonymous, aggregate install count for that skill so the Marketplace can rank popular skills. The installed skill is then stored locally on your device like any skill you create yourself.

6.3 Removal

To remove a published skill from the Marketplace, contact us at [email protected]. Deleting a skill from your local browser does not remove a copy you previously published.

7. Security & Prompt Injection Risks

Important: AI agents interacting with web content face inherent security risks.

7.1 Prompt Injection

Malicious websites may contain hidden content designed to manipulate AI agents. This could potentially cause:

  • The Agent to reveal information from other pages or your conversations
  • Unintended actions to be performed
  • Sensitive data to be included in AI requests

7.2 Data Leakage Risks

When the Agent reads page content, that content is sent to the selected model provider. If you visit a malicious site, any data visible on that page could be transmitted. This includes:

  • Content from other tabs if the Agent is instructed to access them
  • Information from pages containing your personal data
  • Details about your browsing session and context

7.3 Your Responsibility

You accept responsibility for the risks associated with using AI Agent features. We recommend:

  • Being cautious about what pages you allow the Agent to access
  • Not using the Agent on pages with sensitive personal, financial, or medical information
  • Reviewing Agent actions, especially on unfamiliar websites
  • Understanding that model provider policies or local endpoint behavior govern data once it leaves Aera

8. What We Don't Collect

This list is about the Browser and the data it handles. Our website is measured, and section 9.4 says exactly how. Quixet LLC and Aera do not:

  • Track your browsing: We don't collect your browsing history, URLs, or page content
  • Store browsing data on servers: While we operate servers for authentication and updates, we do not collect or store your browsing data
  • Store AI prompts on our servers: Content you send for AI processing is not stored on our servers for inference (it is handled by AI providers as described above). The one exception is a skill you explicitly publish to the Skills Marketplace; see "Skills Marketplace Data" above
  • Sell your data: We don't sell or share personal data with third parties for marketing
  • Access your conversations: Your AI chat history remains on your device

9. Third-Party Services

Aera integrates with various third-party services. Each has its own privacy practices:

9.1 AI Services and Local Model Endpoints

When you select a model provided through OpenRouter, your request is processed by OpenRouter and the underlying model provider. Our OpenRouter account is configured to exclude endpoints that train on request data from routing, so requests routed through that account are not delivered to them. When using local models, your data is sent to the endpoint you configure and is governed by that endpoint's behavior.

9.2 Search Engines

When you submit a search, your query is sent to the search engine you selected, such as Google, Bing, or DuckDuckGo. That search engine handles the request under its own privacy policy. Aera does not receive a copy of your search query on its servers.

9.3 Websites You Visit

When you visit a website, your browser connects to that site as it would in any other browser. The site may receive your IP address, requests, cookies, and information you submit, under its own privacy policy. This applies when you visit the site yourself or ask an automation to visit it. It does not give Aera a record of the pages you visit.

9.4 Our Website and Attribution

This section is about getaera.app, our website, and not about the Browser. The two are separate: nothing described here reads your browsing history, your chats, or any page you visit in Aera.

On our website we use:

  • Google Analytics 4: Google processes website measurement events for us. Google Analytics uses the cookies _ga and _ga_<id>. We do not share data with third parties for advertising.
  • Our own attribution cookie: we set a first-party cookie named __aera_attr, valid for 90 days, holding a random identifier. Against that identifier we store the page you landed on, the site that referred you, and any campaign parameters in the link you followed, including the advertising click identifiers gclid, gbraid, wbraid, fbclid, and msclkid.
  • A device fingerprint on the download page: when you start a download we compute a hash of hardware and system signals reported by your browser (screen size, colour depth, device pixel ratio, processor count, timezone, language, platform, and graphics driver capability limits) and store it in a short-lived cookie named __aera_fp. Its purpose is to match a download to the install that followed it, carry the referral or discount code you chose, and help prevent abuse of offers.
  • Server-side records: for each step of that path (page visit, download started, first launch of the Browser, sign-up, subscription) we store an event with the identifier above, your IP address, and your user agent string. We also send a matching event to Google Analytics from our server.

The Browser carries the same random identifier through the installer, so the first launch of a new install can be matched to the download it came from. What the Browser sends is limited to that identifier, the device fingerprint, your Aera version, and your platform. It carries no URL and no page content. Our security page lists every request the Browser makes to us.

We use these records to carry referral or discount codes from links you choose, match downloads to installations and accounts, prevent abuse of offers, and understand how people reach Aera. Session checks also confirm account access. We do not sell this information or share it with third parties for advertising, and we do not use it to build a profile of what you browse.

You can block the Google Analytics script with a content blocker. This does not stop the account, download, and offer records described above. Attribution identifiers are also kept in local storage, so clearing a cookie alone does not remove all attribution state. Contact [email protected] with questions about records associated with your account.

9.5 Companies That Process Data For Us

These are every company that handles your data on our behalf, what each one gets, and why. If a company is not on this list, we do not send it your data.

  • OpenRouter: routes requests for models included with paid access to AI providers. It receives what section 9.1 describes: your prompt and the page content you chose to send. Local model requests never reach it.
  • Stripe: takes payment and holds your subscription record. Stripe receives your payment details directly and we never see or store a card number. We keep the identifiers Stripe gives us so we can tell which account a subscription belongs to.
  • Zoho (ZeptoMail): sends our transactional email. It receives your email address and the contents of the message, for account and service messages, including sign-up confirmation, password reset, and policy-update notices. We do not send marketing through it.
  • Google: two separate roles. Google Analytics measures use of our website, as described in section 9.4. Separately, if you choose to sign in with Google, Google confirms your identity to us and we receive your email address and name from it. Signing in with an email and password does not involve Google.
  • Cloudflare: serves our website and hosts the installer downloads. It sits in front of our servers, so requests to us pass through it, including your IP address.
  • Amazon Web Services: runs the servers and the database that hold everything described in this policy.

This list covers the data we hold. It says nothing about the sites you visit in the Browser, because we never receive those.

10. Data Security

10.1 Local Storage Security

Aera is a Chromium fork, so your data is stored locally using the storage mechanisms Chromium provides: the profile directory on your disk, plus SQLite databases inside it for chats, tasks, and run history. The security of this data depends on:

  • Your device's security measures (encryption, access controls)
  • Your account passwords and security practices
  • Physical security of your device

10.2 Transmission Security

When data is sent to AI providers:

  • Connections use HTTPS encryption
  • Data in transit is encrypted

10.3 No Guarantees

No system is completely secure. While we design Aera with security in mind, we cannot guarantee absolute security of your data, especially data transmitted to third-party services.

11. Your Rights & Controls

You have control over your data in Aera:

11.1 Access & Deletion

  • History: View and clear browsing history in settings
  • Bookmarks: Add, edit, or delete bookmarks
  • Conversations: View and delete AI conversation history
  • Preferences: Modify or reset your preferences
  • Extensions: Remove extensions and their data
  • Clear All Data: Use "Clear All Local Data" in Privacy settings to erase all local data at once

11.2 Feature Controls

  • MCP Server: Enable or disable the MCP server
  • Extensions: Enable or disable individual extensions
  • Scheduled Tasks: Create, modify, or delete automated tasks
  • Skills: Create, edit, or delete skills in Settings → Skills; published Marketplace skills can be removed by contacting support

11.3 Account Policy Records

When you accept terms or acknowledge a policy notice, we record your account, the exact document revisions, the action, the time, and whether you reviewed it through the website or browser. We also keep delivery status for policy-update emails. These records document your agreement and the service notices sent to your account.

For access or deletion requests concerning information we hold about your account, contact [email protected]. Clearing local browser data does not delete server-side account records.

11.4 Third-Party Data

For data sent to third-party services (AI providers, search engines), you must contact those services directly to exercise any data rights they may offer.

12. Children's Privacy

Aera Browser is not intended for children under 13 years of age (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children.

If you believe a child has used Aera and provided personal information to third-party services through the browser, please contact those services directly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

  • We will update the "Last Updated" date at the top of this policy
  • Material changes may be communicated through the Software, our website, or a service email to your account
  • If updated terms require your agreement, we will ask you to accept them separately. A privacy notice explains how information is handled and does not grant a new permission by itself

We encourage you to review this policy periodically.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

Email: [email protected]

By using Aera Browser, you acknowledge that you have read and understood this Privacy Policy.

Aera

One manager for the work behind your business.

Product

DownloadPricingFeaturesUse CasesMarketplaceFAQ

Use Cases

For Growth EngineersFor FoundersFor Developers

Resources

CommunityDocsNewsChangelogComparisonsSecurityArchitecturePress kit[email protected]

Legal

Privacy PolicyTerms of Service
© 2026 Aera. All rights reserved.
XDiscord