This Policy explains how Aster processes personal data across its website, dashboard, WhatsApp assistant, affiliate program and related features.
1. Controller, scope and contact
Aster ("Aster", "we" or the "Platform"), available at getaster.co, controls processing for accounts, subscriptions, support, its own marketing and the affiliate program. Vendors may act as processors or, for parts of their services, independent controllers.
For privacy questions or rights requests, contact contato@getaster.co. We may verify the requester's identity and authority before responding.
2. Sources and third-party profiles
We receive data from the data subject, account administrators, linked profiles, authentication and AI service, messaging service, payment processor, affiliates and technical use events. An account may enter information about relatives, caregivers, recipients or other people.
Anyone entering another person's data must have authority and a valid legal basis, inform that person as required and use only what is necessary.
3. Data we process
- Account and identity: internal ID, name, email, photo, authentication and AI service ID, language, estimated country/region, account status, plan and subscription dates.
- Profiles and contact: name, WhatsApp number, caregiver number, birthday, currency, language, time zone, permissions, tags and verification status.
- Service content: recent text/audio conversation context, commands, reminders and delivery history, lists, memories, locations, preferences, financial entries, budgets, goals and recurrences.
- Files: original object, name, MIME type, size, tags, storage path, indexing state and AI-created OCR/text, transcript, summaries, entities, keywords and search vectors.
- Billing: payment processor customer, checkout, subscription, price, invoice and event IDs; plan, currency, region, status and cancellation feedback. Aster does not receive or store full card numbers or security codes.
- Affiliates: identity, authentication and AI service ID, referral code, affiliate payout method email, click data, truncated IP hash, user agent, referrer, country, referrals, conversions, commissions, balances, payout requests and proof.
- Usage and security: IP, headers, user agent, URL, referrer, cookies, session/request IDs, events, errors, message metrics, audit records, rate limits and support communications.
- Marketing: opt-out state, email delivery/open events, campaigns, clicks and conversion attribution.
4. Purposes and legal bases
- Contract and requested steps: authenticate, store content, interpret commands, send reminders, create reports, share files, provide support and manage billing.
- Legal obligations and legal claims: accounting, fraud and chargeback handling, valid orders, litigation and authority requests.
- Legitimate interests where applicable: security, observability, abuse prevention, service measurement and improvement, related communications and affiliate attribution, subject to balancing and user rights.
- Consent where required: certain marketing, non-essential technologies and sensitive-data processing that relies on consent. Withdrawal does not invalidate earlier lawful processing.
- Other lawful bases, including vital interests, are used only when genuinely applicable. Aster is not an emergency or medical service.
5. Sensitive and financial data
Medication reminders, medical documents, audio or memories may reveal health or other sensitive data. Do not provide a full medical history or unnecessary information. Aster does not diagnose or make treatment decisions.
Financial descriptions and amounts are application-encrypted before database storage. Categories, dates, payment methods, links and operational metadata may remain in structured fields outside that encryption.
6. AI processing
AI service receives messages, limited context and necessary data for intent detection, extraction, categorization, answers, translation, generation and embeddings. WhatsApp audio is preferably sent to transcription service for transcription and may fall back to AI service.
Compatible files may be downloaded and sent to AI service inline, by temporary provider upload or batch processing. Processing may include OCR, text extraction, transcription, video chunking, multilingual summaries, entities, keywords and embeddings stored in managed database service and managed vector database.
AI output is probabilistic and may be wrong. Review names, dates, times, values and extracted content. Aster does not train its own model on user content; providers process API data under their applicable terms and settings.
Do not submit content you are not authorized to share with these providers.
7. Storage, encryption and security
- managed database stores relational data and metadata; cache and queue service supports revocation, queues, caches, recent context, deduplication and limits.
- Selected fields use application-level AES-256-GCM. Legacy plaintext may remain for migration compatibility, and not every column or metadata field is covered.
- Current binary files are private private object storage objects without Aster application-level AES encryption. Short-lived signed URLs and TLS protect transfers. Provider encryption at rest is not user-controlled end-to-end encryption.
- Controls include httpOnly cookies, expiring JWTs, cache and queue service revocation, trusted-origin checks, signed webhooks, rate limits, CSP/Helmet, logical user scoping, sensitive-log redaction and revocable share links.
No system is completely secure; we do not guarantee absolute security or perfect recovery.
8. File sharing
Users may create public file links lasting 1 hour to 7 days, with optional password and download limit. Anyone holding the link and any required password can obtain a signed object storage URL; file name, type, size, expiry and remaining downloads may be public.
Share passwords are salted hashes. The user remains responsible for recipients, transmission channel, revocation and authority to share.
9. International transfers
Global vendors may process data outside Brazil or the user's country. We rely on mechanisms permitted by applicable law, such as adequacy, contractual clauses, certifications or other valid safeguards, as available for each vendor.
10. Cookies, analytics and ads
Essential cookies support authentication, security, language, country, OAuth and affiliate attribution; referral cookies may last 30 days. Third-party measurement identifiers may also be set.
Measurement and advertising scripts may load after interaction or page load and are not all conditioned on a granular Aster cookie preference. Third parties may receive IP, user agent, URL, referrer, cookie IDs and events; server events may include hashed email, phone or user ID plus IP/user agent.
Browser and third-party controls can block or delete these technologies. Blocking essential cookies may break login or features.
11. Email and WhatsApp
We send service and transactional messages. Promotional email honors the marketing opt-out and includes unsubscribe; essential contract and security notices may continue.
messaging service and internal queues process WhatsApp payloads, IDs, attempts and delivery results for asynchronous delivery, idempotency and audit. Sending "PARE" disables the WhatsApp profile flow but does not necessarily delete the account or cancel billing.
12. Retention
- Core account and content: while needed for service, until user deletion or a valid request, then as needed for legal obligations, fraud, billing and claims; we do not apply one post-account period to every category.
- Delivery logs: 90 days. Recent cache conversation context: up to 1 hour/10 turns. Demo finances: 2 hours.
- File shares: 1 hour to 7 days; signed URLs generally 5–10 minutes.
- Messaging inbox: completed payloads 30 days, dead letters 90 days, technical deduplication IDs up to 730 days.
- Messaging delivery ledger: accepted items 90 days, dead letters 365 days. Email queue: status 7 days, dead letters 30 days.
- Affiliate, billing, chargeback and tax records: as needed for the program, contract and applicable legal/accounting duties.
Third-party logs, backups and legally retained copies may follow separate cycles and prevent instantaneous erasure of every copy.
13. Deletion
Individual and bulk file deletion removes database metadata and requests deletion of object storage objects and vectors. Distributed operations may partially fail and require reconciliation or support.
Dashboard account deletion attempts to cancel the linked subscription, locks the account, deletes multiple operational tables and revokes the session. Caches, vectors, objects, anti-fraud records, financial events, third-party logs and backups may require additional cleanup or lawful retention. Contact contato@getaster.co to confirm deletion of linkable residual data.
14. Data-subject rights
- Confirmation and access; correction; deletion, anonymization or blocking where applicable; portability subject to regulation and technical feasibility.
- Information about sharing and consent consequences; consent withdrawal; objection; and review of solely automated decisions where legally available.
- Complaint to Brazil's ANPD or another competent authority and exercise of consumer rights.
Send requests to contato@getaster.co. We may retain data where authorized or required by law.
15. Children, incidents and updates
Aster is intended for adults 18+. An adult may enter a minor's data only with proper authority and legal basis, in the child's best interests and using the minimum necessary.
We maintain incident-response procedures and will notify users and authorities when required. We may update this Policy; the date above identifies the current version and material changes will be communicated by reasonable means when required or appropriate.
Privacy questions, requests and complaints: contato@getaster.co.