Legal
Privacy Policy
This policy explains what Aura OS (aibusiness.fun), operated by Ninty LLC, collects when you use the product — including payments via Stripe.
Last updated August 11, 2026
1. Who we are
Controller: Ninty LLC (Ninty), operating Aura OS at https://aibusiness.fun. Contact: founders@aibusiness.fun. Team: /team. Impressum: /impressum.
Ninty LLC
Attn: Laszlo Bihary
Registered office address is on file with Ninty LLC. Email founders@aibusiness.fun for the current statutory address, or it will be published here once confirmed.
founders@aibusiness.fun
2. What we collect
Depending on how you use Aura OS, we may process:
- Account details (email, display name, claimed @handle, auth identifiers).
- Company profile data you enter (name, strategy, products, tasks, knowledge).
- Connected service credentials (mailbox, social channels, wallets) stored encrypted so agents can act on your behalf.
- Usage and product analytics (page views, funnel events, feature events) to improve the product and prevent abuse.
- Payment records for founding seats and other products: Stripe customer / session IDs, amount, currency, status, invoice/receipt metadata, and seat entitlement — not full card numbers.
- Technical logs for APIs, authentication, webhooks, and fraud prevention.
- Identity-verification status (approved / declined / in review) when you complete KYC. Document images and biometric captures stay with Didit — we do not store them.
3. Payments & Stripe
Fiat payments are processed by Stripe, Inc. and its affiliates. When you open Checkout, Stripe collects payment method details and billing information needed to complete the transaction under Stripe's privacy policy. We receive confirmation of payment, limited customer identifiers, and metadata required to unlock your founding seat or subscription.
We do not store complete card numbers, CVC, or full bank account numbers on Aura OS servers. For disputes, refunds, and accounting we retain Stripe payment references and entitlement records.
Stripe may process data in the United States and other countries with appropriate safeguards. See Stripe's documentation and privacy policy for processor details.
4. Identity verification (Didit)
When you start KYC we open Didit's hosted flow (in-page or redirect — ID, liveness, face match as configured in our workflow). Didit is the processor for those documents. We keep a session id, vendor user id, and the resulting status so we can gate the token sale and live trading. The software seat does not require KYC. The signed webhook is the approval record — the in-app callback is not.
Webhook: /api/webhooks/didit. You can start or resume verification from /identity.
5. How we use data
We use this information to:
- Provide and secure Aura OS and your company workspace.
- Process payments, refunds, chargebacks, and tax-related records.
- Run AI agents, tasks, outreach, and channel publishing you enable.
- Attribute referrals and founding-cohort progress.
- Send transactional email (receipts, security, access, product notices).
- Comply with law and protect the service against abuse and fraud.
We do not sell your personal data.
6. Legal bases (EEA/UK where applicable)
Depending on the activity: performance of a contract (account + paid seat), legitimate interests (security, product improvement, fraud prevention), consent (optional marketing or non-essential cookies where required), and legal obligation (tax, accounting, dispute records).
7. Connected accounts
When you connect Google Mail, Outlook, X, LinkedIn, Meta, TikTok, or Farcaster, we store the tokens needed for the features you turn on. You can disconnect channels anytime; we then stop using those credentials for new actions.
8. Cookies & local storage
We use essential cookies and local storage for authentication, sessions, and attribution. Stripe Checkout may set its own cookies when you pay. See the Cookie Policy.
9. Sharing
We share data only with:
- Processors that run the product (hosting, database, email, auth, AI providers).
- Stripe for payments, fraud tools, and invoicing.
- Didit for identity verification when you start KYC.
- Authorities when required by law.
We do not sell personal data to advertisers.
10. Retention
Account and company data are kept while your account is active. Payment and entitlement records are retained as needed for accounting, tax, chargebacks, and legal claims (typically several years). You may request deletion from Settings or by emailing founders@aibusiness.fun; residual backups and mandatory records may persist for a limited period.
11. Your choices
You can update profile data in-product, disconnect integrations, and request access, correction, or deletion by emailing founders@aibusiness.fun. Depending on your location you may have additional rights (access, erasure, portability, objection, complaint to a supervisory authority).
12. International transfers
We and our processors may process data in the EU, US, and other countries. Where required, we rely on appropriate safeguards (e.g. standard contractual clauses) with vendors.
13. Changes
We may update this policy as the product evolves. Material changes will be reflected here with a new “Last updated” date.
Questions: founders@aibusiness.fun