Legal

Privacy Policy

Last updated: [Insert Date]  ·  Aero GTM AI Limited  ·  2323 Broadway, Oakland, CA 94612

Aero GTM AI Limited ("Aero," "we," "our," or "us") provides an AI-powered investment research platform. This Privacy Policy explains what information we collect, how we use it, how we share it, and the choices you have regarding your data. By using Aero, you agree to the practices described in this policy. Aero is intended solely for use by residents of the United States who are 18 years of age or older.

01

Overview

We believe privacy is foundational to trust. We collect only the data we need to operate Aero and provide you with useful insights. We do not sell your personal data, serve you ads, or use your data to train AI models.

If you have questions about this policy, contact our privacy team at [email protected] or by phone at +1 415 720 8304.

02

Information we collect

We collect the following categories of information:

Account information

When you sign in with Google, we receive your name and email address. We do not collect or store your Google password.

Portfolio data (via Plaid)

With your explicit permission, we access your investment holdings, cost basis, and related portfolio structure through Plaid. We do not access or store your banking credentials, account numbers, login information, or payment details.

User-generated data

We store watchlists, strategies, preferences, and other configurations you create within the platform.

Usage data

We collect information about how you interact with Aero, including pages visited, features used, and session activity. This helps us improve the product and diagnose issues.

Derived data

We generate derived insights based on your portfolio and inputs — such as portfolio scores, risk assessments, and strategy outputs. These are generated for your use and are not sold or shared with third parties for commercial purposes.

03

How we collect it

We collect information in three ways:

  • Directly from you — when you create an account, connect integrations, build watchlists, or configure strategies
  • From third parties — Google provides your name and email during authentication; Plaid provides your portfolio data when you connect your brokerage
  • Automatically — through cookies, analytics tools, and usage tracking as you interact with the platform
04

How we use your data

We use your data to operate and improve Aero. Specifically, we use it to:

  • Authenticate your account and maintain secure sessions
  • Analyze your portfolio and generate AI-powered research insights
  • Produce derived outputs including portfolio scores and risk assessments
  • Improve product performance, diagnose technical issues, and understand feature usage
  • Maintain platform security and prevent fraudulent or harmful activity
  • Communicate with you about your account and the platform
We do not sell your personal data. We do not use your data for advertising, ad targeting, or to profile you for commercial purposes unrelated to operating Aero.
05

AI processing

Aero uses third-party AI providers, including OpenAI and Anthropic, to generate insights. When you request AI-powered analysis, relevant data may be transmitted to these providers for processing. This includes publicly available third-party content — such as X (formerly Twitter) posts and profile metadata surfaced through our integrations — which may be sent to AI providers for sentiment analysis, summarization, and related processing. The following applies to all AI processing:

  • Data sent to AI providers is governed by strict data handling agreements
  • We do not use your personal data or portfolio data to train AI models
  • AI outputs are generated based on your inputs and are not retained by providers beyond the processing window
  • AI-generated insights are for informational purposes only and do not constitute financial advice
06

Google data

We use Google Sign-In for authentication only. We access your name and email address to create and identify your account. We do not access Gmail content, Google Drive files, Google Calendar, or any other Google service content. We do not use your Google data for advertising or profiling.

Aero's use of Google API Services complies with the Google API Services User Data Policy, including the Limited Use requirements.

07

Plaid integration

When you connect your portfolio, we use Plaid as a secure intermediary. Plaid is a trusted financial data infrastructure provider used by thousands of financial applications. Your brokerage login credentials are entered directly into Plaid's secure interface and are never transmitted to, stored by, or visible to Aero.

Through Plaid, Aero accesses only your investment holdings and related portfolio data. We do not access checking accounts, savings accounts, transaction history, or payment information. You can disconnect your Plaid connection at any time from your account settings, at which point we stop receiving data from that connection.

08

X (formerly Twitter) data

Aero integrates with the X API (operated by X Corp) to surface publicly available posts and profile information alongside the stocks you research. This data is public, third-party content — accessing or displaying it does not imply any affiliation with, endorsement by, or relationship with the X users whose posts are shown.

What data we access
  • Public X posts and associated metadata, including engagement counts, timestamps, and detected language
  • Public profile data, including handle, display name, avatar, follower count, and verified status
  • Data is fetched only for profiles or searches that you initiate within the product
How it is used
  • Displayed alongside stocks in the product to provide additional research context
  • Transmitted to our AI providers (OpenAI and Anthropic) for sentiment analysis and summarization when you request AI-powered insights
  • We do not use X data to train machine learning models.
Retention and caching
  • Short-term caching only — approximately 15 minutes for timelines and up to 24 hours for search results
  • If content is deleted, protected, or removed on X, we remove it from our cache within 24 hours
What we do not do
  • We do not access direct messages or any private or protected content
  • We do not resell or redistribute X data
  • We do not use X data for ad targeting or sensitive profiling
  • We do not use X data to train machine learning models
Third-party attribution

All X data displayed in Aero is sourced from X Corp through the X API and remains subject to X's own terms and privacy practices. For more information, see the X Terms of Service and the X Privacy Policy.

09

Cookies and analytics

We use cookies and similar tracking technologies to keep you authenticated, understand how the product is used, and improve performance. We may use Google Analytics or similar tools to collect aggregated usage statistics.

We do not use cookies or tracking technologies for advertising, ad retargeting, or cross-site behavioral tracking. You can configure your browser to block or delete cookies, though doing so may affect your ability to use certain features of Aero.

10

How we share data

We share data only with trusted service providers that help us operate Aero. These providers are contractually required to use your data only as necessary to provide their services to us:

  • AWS — cloud infrastructure and data storage
  • Plaid — secure financial data access
  • OpenAI and Anthropic — AI insight generation
  • Google — authentication and analytics
  • X Corp — third-party data source for public X posts and profile metadata, accessed via the X API
  • Financial data providers — market data display, subject to their respective licensing terms

We do not sell, rent, or share your personal data with third parties for their own marketing, advertising, or commercial purposes. We may disclose data if required to do so by law or in response to a valid legal process.

11

Data storage

All personal data collected by Aero is stored securely in the United States on AWS infrastructure. We implement appropriate technical and organizational measures to protect your data from unauthorized access, disclosure, alteration, or destruction.

12

Data retention

We retain your personal data for as long as your account is active and as long as necessary to provide you with the services. When you delete your account, we process the deletion promptly and remove your personal data from our systems. Some data may be retained for a limited period to comply with legal obligations, resolve disputes, or enforce our agreements.

13

Your rights (CCPA)

If you are a California resident, the California Consumer Privacy Act ("CCPA") grants you the following rights with respect to your personal information:

Right What it means
Right to Know You may request information about the personal data we collect, use, and share about you.
Right to Delete You may request that we delete the personal data we have collected about you, subject to certain exceptions.
Right to Correct You may request that we correct inaccurate personal information we hold about you.
Right to Opt-Out We do not sell personal data. There is nothing to opt out of.
Non-Discrimination We will not discriminate against you for exercising any of your CCPA rights.

To exercise any of these rights, contact us at [email protected]. We will respond to verifiable requests within the timeframes required by applicable law.

14

Data deletion

You can delete your Aero account at any time from your account settings. You can also disconnect your Plaid integration independently without deleting your account. Deletion requests are processed promptly. Upon deletion, your personal data is removed from our active systems and is not retained in backups beyond the period required by our data retention policies.

To submit a deletion request directly, email [email protected] from the address associated with your account.

15

Children's privacy

Aero is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from users under 18. If we become aware that we have collected personal data from a user under 18, we will take steps to delete that data promptly. If you believe we have inadvertently collected data from a minor, contact us at [email protected].

16

Security

We implement industry-standard security practices to protect your data, including:

  • Encryption in transit using TLS and encryption at rest
  • Secure, token-based API authentication
  • Strict internal access controls and role-based permissions
  • Hosting on AWS with enterprise-grade infrastructure and monitoring

No method of transmission over the internet or electronic storage is completely secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security. If you discover a potential security issue, please notify us immediately at [email protected].

17

Changes to this policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. For material changes, we will provide notice through the platform or by email. Your continued use of Aero after any changes constitutes your acceptance of the updated policy.

Questions? Contact us at [email protected] or +1 415 720 8304.