This Privacy Policy describes how Quixet LLC ("Quixet", "we", "us", "our") handles information when you use Aera Browser ("Aera", "the Browser", "the Software"). We are committed to protecting your privacy and being transparent about our data practices.
1. Privacy Overview
Aera Browser is designed with privacy as a core principle. Here's a quick summary:
- Local-First Design: Your browsing data, history, bookmarks, and preferences are stored locally on your device
- No Browsing Data Collection: While we operate servers for account authentication and updates, we do not collect or store your browsing data, history, or page content
- Model Choice: Requests go to the model endpoint you configure or to third-party AI providers through OpenRouter
- Direct AI Communication: When you use chat or an automation you create or ask the Agent to create, the prompts and page context needed for that task are sent to the selected model provider for processing; we do not store that content on our servers for inference
- You're In Control: You can clear all your local data at any time from Privacy settings
2. Data Stored Locally
Aera stores the following data locally on your device:
| Data Type | Purpose | Your Control |
|---|
| Browsing History | Display recent pages, enable history search | Clear in browser settings |
| Bookmarks | Save and organize your favorite pages | Add, edit, or delete anytime |
| Preferences | Remember your settings (theme, search engine, etc.) | Modify in settings |
| Chat/Conversation History | Persist your AI Agent conversations | Clear conversations anytime |
| Extension Data | Store extension configurations and state | Remove extensions in settings |
| Scheduled Tasks | Store your automated task configurations | Delete tasks anytime |
| Background Images | Custom theme backgrounds | Remove in appearance settings |
All locally stored data remains on your device and is not transmitted to Aera servers for collection. You can clear all local data at once using the "Clear All Local Data" option in Privacy settings. We do not have access to any of this data.
3. AI Agent & Model Data
Important: Data sent to model providers is not controlled by Aera.
3.1 How AI Features Work
AI requests are made when you use chat, create an automation, or ask the Agent to create an automation for you. Those automations can then run on their schedule or configured triggers without another click. Opening or reading a page on its own does not send that page to a model. For these tasks, requests are sent directly to the selected model endpoint. Local model requests go to the OpenAI-compatible endpoint you configure, and requests for models provided through OpenRouter go to third-party AI services through OpenRouter. They never pass through Aera's servers. This process involves:
- Your message/instruction is sent directly to the selected model provider
- Page content the Agent needs to read is sent to the selected model provider
- Screenshots or extracted page elements may be sent for analysis
- Your conversation history may be included for context
3.2 Data Sent to Model Providers
For a chat or automation you initiate as described above, the following data may be transmitted to the selected model provider when needed for the task:
- Your Instructions: The prompts and messages you send to the Agent
- Page Content: Text, HTML structure, and metadata from pages the Agent reads
- Visual Data: Screenshots or images when visual analysis is needed
- Context Information: Current URL, page title, and conversation history
- Attachments: Files or images you explicitly attach to messages
3.3 Models & Training Data
Aera does not use models that train on your data. Requests through OpenRouter exclude endpoints that train on request data.
When you use chat or an automation you initiate, the instructions, page content, and conversation history needed for that task reach the provider serving your selected model. What that provider does with the request, including any retention or logging, is governed by its own policies, which we do not control. See section 3.4.
Local model requests are sent to the endpoint you configure and are governed by that endpoint's behavior. This routing configuration applies to requests routed through Aera's OpenRouter account. Requests to an endpoint you configure use that endpoint's settings.
3.4 Model Provider Privacy
Data sent to model providers is subject to their privacy policies or to the configuration of the local endpoint you choose. We recommend reviewing:
- OpenRouter Privacy Policy
- The privacy policies of underlying AI models you select
- The data handling of any local model server you configure
We have no control over how model providers or local endpoints handle, store, or use data sent through their services.
4. MCP Server Data
Aera's Model Context Protocol (MCP) server allows external AI tools to interact with the browser.
4.1 MCP Data Exposure
Only when you explicitly enable the MCP server can connected external tools access:
- Page content and structure of open tabs
- Screenshots of browser content
- Ability to navigate, click, and type in the browser
- List of open tabs and their URLs
4.2 Local Network Only
The MCP server operates on your local machine and is not exposed to the internet by default. However:
- External tools on your machine can connect only when you have enabled the MCP server
- Data exchanged with external tools is subject to those tools' privacy practices
- You control when the MCP server is enabled or disabled
4.3 Companion Device Connections
Companion-device connections are disabled and do not ship in current Aera releases. The mobile companion app has not been released.
The planned feature will require you to explicitly enable it. When enabled, local-network discovery will announce that Aera is available to connect. Registered devices will use an encrypted connection.
5. Extensions Data
You choose which browser extensions to install or import into Aera, as with other Chromium browsers. Extensions you explicitly install or import may have their own data collection practices.
5.1 Extension Permissions
An extension you choose to install can request permissions, including:
- Access to your browsing history
- Ability to read and modify page content
- Access to cookies and other browser data
- Network access to send data to external servers
5.2 Third-Party Extensions
Extensions are developed by third parties. We do not control and are not responsible for:
- What data extensions collect
- How extensions use or share your data
- Extension privacy policies or practices
Review each extension's privacy policy before installation and only install extensions from trusted sources.
6. Skills Marketplace Data
Skills are reusable instruction snippets you can invoke in chat (e.g. /analyze-competitors). Skills you create are stored locally on your device like your other data, and are not transmitted to Aera unless you choose to publish them.
6.1 Publishing a Skill
When you explicitly choose to publish a skill to the Skills Marketplace, that skill's contents (its name, description, and instruction body) are uploaded to and stored on Aera servers. This is the one case where content you author in Aera is stored on our servers. Published skills are reviewed by the Aera team before they become visible to other users, and you are shown this notice before publishing.
- Attribution is your choice: when publishing, you may credit the skill to your account name or publish anonymously.
- Visibility: approved skills are publicly available to other Aera users through the in-browser Marketplace.
- Don't include secrets: do not put passwords, personal data, or confidential information in a skill you publish; its full contents are shared publicly once approved.
6.2 Installing a Skill
When you add a skill from the Marketplace to your browser, we record an anonymous, aggregate install count for that skill so the Marketplace can rank popular skills. The installed skill is then stored locally on your device like any skill you create yourself.
6.3 Removal
To remove a published skill from the Marketplace, contact us at [email protected]. Deleting a skill from your local browser does not remove a copy you previously published.
7. Security & Prompt Injection Risks
Important: AI agents interacting with web content face inherent security risks.
7.1 Prompt Injection
Malicious websites may contain hidden content designed to manipulate AI agents. This could potentially cause:
- The Agent to reveal information from other pages or your conversations
- Unintended actions to be performed
- Sensitive data to be included in AI requests
7.2 Data Leakage Risks
When the Agent reads page content, that content is sent to the selected model provider. If you visit a malicious site, any data visible on that page could be transmitted. This includes:
- Content from other tabs if the Agent is instructed to access them
- Information from pages containing your personal data
- Details about your browsing session and context
7.3 Your Responsibility
You accept responsibility for the risks associated with using AI Agent features. We recommend:
- Being cautious about what pages you allow the Agent to access
- Not using the Agent on pages with sensitive personal, financial, or medical information
- Reviewing Agent actions, especially on unfamiliar websites
- Understanding that model provider policies or local endpoint behavior govern data once it leaves Aera
8. What We Don't Collect
This list is about the Browser and the data it handles. Our website is measured, and section 9.4 says exactly how. Quixet LLC and Aera do not:
- Track your browsing: We don't collect your browsing history, URLs, or page content
- Store browsing data on servers: While we operate servers for authentication and updates, we do not collect or store your browsing data
- Store AI prompts on our servers: Content you send for AI processing is not stored on our servers for inference (it is handled by AI providers as described above). The one exception is a skill you explicitly publish to the Skills Marketplace; see "Skills Marketplace Data" above
- Sell your data: We don't sell or share personal data with third parties for marketing
- Access your conversations: Your AI chat history remains on your device
9. Third-Party Services
Aera integrates with various third-party services. Each has its own privacy practices:
9.1 AI Services and Local Model Endpoints
When you select a model provided through OpenRouter, your request is processed by OpenRouter and the underlying model provider. Our OpenRouter account is configured to exclude endpoints that train on request data from routing, so requests routed through that account are not delivered to them. When using local models, your data is sent to the endpoint you configure and is governed by that endpoint's behavior.
9.2 Search Engines
When you submit a search, your query is sent to the search engine you selected, such as Google, Bing, or DuckDuckGo. That search engine handles the request under its own privacy policy. Aera does not receive a copy of your search query on its servers.
9.3 Websites You Visit
When you visit a website, your browser connects to that site as it would in any other browser. The site may receive your IP address, requests, cookies, and information you submit, under its own privacy policy. This applies when you visit the site yourself or ask an automation to visit it. It does not give Aera a record of the pages you visit.
9.4 Our Website and Attribution
This section is about getaera.app, our website, and not about the Browser. The two are separate: nothing described here reads your browsing history, your chats, or any page you visit in Aera.
On our website we use:
- Google Analytics 4: Google processes website measurement events for us. Google Analytics uses the cookies
_ga and _ga_<id>. We do not share data with third parties for advertising. - Our own attribution cookie: we set a first-party cookie named
__aera_attr, valid for 90 days, holding a random identifier. Against that identifier we store the page you landed on, the site that referred you, and any campaign parameters in the link you followed, including the advertising click identifiers gclid, gbraid, wbraid, fbclid, and msclkid. - A device fingerprint on the download page: when you start a download we compute a hash of hardware and system signals reported by your browser (screen size, colour depth, device pixel ratio, processor count, timezone, language, platform, and graphics driver capability limits) and store it in a short-lived cookie named
__aera_fp. Its purpose is to match a download to the install that followed it, carry the referral or discount code you chose, and help prevent abuse of offers. - Server-side records: for each step of that path (page visit, download started, first launch of the Browser, sign-up, subscription) we store an event with the identifier above, your IP address, and your user agent string. We also send a matching event to Google Analytics from our server.
The Browser carries the same random identifier through the installer, so the first launch of a new install can be matched to the download it came from. What the Browser sends is limited to that identifier, the device fingerprint, your Aera version, and your platform. It carries no URL and no page content. Our security page lists every request the Browser makes to us.
We use these records to carry referral or discount codes from links you choose, match downloads to installations and accounts, prevent abuse of offers, and understand how people reach Aera. Session checks also confirm account access. We do not sell this information or share it with third parties for advertising, and we do not use it to build a profile of what you browse.
You can block the Google Analytics script with a content blocker. This does not stop the account, download, and offer records described above. Attribution identifiers are also kept in local storage, so clearing a cookie alone does not remove all attribution state. Contact [email protected] with questions about records associated with your account.
9.5 Companies That Process Data For Us
These are every company that handles your data on our behalf, what each one gets, and why. If a company is not on this list, we do not send it your data.
- OpenRouter: routes requests for models included with paid access to AI providers. It receives what section 9.1 describes: your prompt and the page content you chose to send. Local model requests never reach it.
- Stripe: takes payment and holds your subscription record. Stripe receives your payment details directly and we never see or store a card number. We keep the identifiers Stripe gives us so we can tell which account a subscription belongs to.
- Zoho (ZeptoMail): sends our transactional email. It receives your email address and the contents of the message, for account and service messages, including sign-up confirmation, password reset, and policy-update notices. We do not send marketing through it.
- Google: two separate roles. Google Analytics measures use of our website, as described in section 9.4. Separately, if you choose to sign in with Google, Google confirms your identity to us and we receive your email address and name from it. Signing in with an email and password does not involve Google.
- Cloudflare: serves our website and hosts the installer downloads. It sits in front of our servers, so requests to us pass through it, including your IP address.
- Amazon Web Services: runs the servers and the database that hold everything described in this policy.
This list covers the data we hold. It says nothing about the sites you visit in the Browser, because we never receive those.
10. Data Security
10.1 Local Storage Security
Aera is a Chromium fork, so your data is stored locally using the storage mechanisms Chromium provides: the profile directory on your disk, plus SQLite databases inside it for chats, tasks, and run history. The security of this data depends on:
- Your device's security measures (encryption, access controls)
- Your account passwords and security practices
- Physical security of your device
10.2 Transmission Security
When data is sent to AI providers:
- Connections use HTTPS encryption
- Data in transit is encrypted
10.3 No Guarantees
No system is completely secure. While we design Aera with security in mind, we cannot guarantee absolute security of your data, especially data transmitted to third-party services.
11. Your Rights & Controls
You have control over your data in Aera:
11.1 Access & Deletion
- History: View and clear browsing history in settings
- Bookmarks: Add, edit, or delete bookmarks
- Conversations: View and delete AI conversation history
- Preferences: Modify or reset your preferences
- Extensions: Remove extensions and their data
- Clear All Data: Use "Clear All Local Data" in Privacy settings to erase all local data at once
11.2 Feature Controls
- MCP Server: Enable or disable the MCP server
- Extensions: Enable or disable individual extensions
- Scheduled Tasks: Create, modify, or delete automated tasks
- Skills: Create, edit, or delete skills in Settings → Skills; published Marketplace skills can be removed by contacting support
11.3 Account Policy Records
When you accept terms or acknowledge a policy notice, we record your account, the exact document revisions, the action, the time, and whether you reviewed it through the website or browser. We also keep delivery status for policy-update emails. These records document your agreement and the service notices sent to your account.
For access or deletion requests concerning information we hold about your account, contact [email protected]. Clearing local browser data does not delete server-side account records.
11.4 Third-Party Data
For data sent to third-party services (AI providers, search engines), you must contact those services directly to exercise any data rights they may offer.
12. Children's Privacy
Aera Browser is not intended for children under 13 years of age (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children.
If you believe a child has used Aera and provided personal information to third-party services through the browser, please contact those services directly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Last Updated" date at the top of this policy
- Material changes may be communicated through the Software, our website, or a service email to your account
- If updated terms require your agreement, we will ask you to accept them separately. A privacy notice explains how information is handled and does not grant a new permission by itself
We encourage you to review this policy periodically.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us: