Logo
ainr

Privacy Policy

We collect what running ainr needs and nothing for advertising. There are no trackers on this site, and nothing here is sold.

Last updated 11 September 2026

Who this is

ainr operates ainr.pro. Where this policy says “we”, it means ainr.

If anything here is unclear, or you want something done with your information, write to privacy@ainr.pro. A person reads it.

What we collect

Your account: the name and email address you sign up with, and a password that is stored as a hash we cannot reverse. If you sign in with Google or a passkey instead, we hold the identifier that service gives us, not your password.

What you put in: projects, briefs, watchlists, the artists you research, the reference tracks you save, and everything you say to ATHENA. This is the working material of the product.

What the product produces: dossiers, briefings, scout reports, listening passes and chain results, filed against your projects.

Billing: a record of what each operation cost and what you paid. Card details go straight to Stripe and never reach us — we hold their reference to the payment, not the card.

Technical records: ordinary server logs, kept short, so that errors can be found and abuse can be stopped.

What we do not collect

There is no advertising network on this site, no analytics product, no pixel, no fingerprinting and no cross-site profile of you. We do not sell your information and we do not share it for anyone else’s advertising.

We do not use what you research or what you say to ATHENA to train our own models.

Why we use it

To run the product you asked for: to research an artist, listen to a record, compile a file, and keep it where you left it.

To bill accurately for work that was actually done, and to show you what each operation spent.

To keep accounts secure — sign-in, two-factor, and spotting abuse of a paid pipeline.

To answer you when you write to us.

Who else sees it

The companies that run the service underneath, each seeing only what its job needs: Vercel hosts the application, Neon runs the database and sign-in, Cloudflare R2 stores files you upload, Stripe takes payment, and Resend delivers the email we send you.

AI model providers, whenever an operation needs one — which is most of them. Prompts reach them through Vercel’s AI Gateway. Today the text work runs on DeepSeek’s models and the listening work on Google’s, and the gateway is allowed to fall through to another host when one is unavailable, so we cannot promise a single named provider for every call. What goes with a prompt is the task and the material it is working on, which for Comms means what you said to ATHENA. We do not have a signed no-training term with every host the gateway can reach, and we will say so here rather than imply one we do not have.

Two search indexes: Pinecone holds embeddings of our own product documentation, and Chroma holds embeddings of listening reports so that similar records can be found. Both are vendor-hosted.

Research and data sources, when you send an operation into the field. A search, a scrape or a catalogue lookup necessarily tells that source what was asked — the artist name, the query — and nothing about you.

Anyone you deliberately share a project with, and nobody else. We do not hand your information to anyone for their own purposes, and we would only ever disclose it to a public authority where the law requires it.

Cookies and local storage

Sign-in and security cookies are always on. They are what keeps you signed in and what stops a request from another site acting as you, so there is no version of the product that works without them and we do not offer them as a choice.

Your browser also holds small preferences locally, like whether the sidebar is collapsed. Those stay on your device.

Embedded players are the one real choice, which is why you are asked. A Spotify or YouTube player is that company’s page running inside a frame on ours, and it sets its own cookies the moment it loads. Until you accept, we do not load one at all.

You can change your mind whenever you like: “Cookies” at the bottom of any public page, or in your account menu once you are signed in. Turning players off stops us loading any more of them. Cookies a player already set live in your browser under that company’s name, so clearing those is done in your browser’s own settings — we have no way to reach them.

Our record of your choice is one first-party cookie holding one word. We ask your browser to keep it for six months and then ask you again — but Safari and iOS shorten anything stored this way to about a week, so on those you will see the question again sooner. That is the browser’s rule, not a trick, and it is the only reason you would be asked twice in a month.

One thing the choice does not cover, said plainly because the honest version is more useful than a clean one: cover art and the thirty-second previews on a catalogue load from Spotify’s own servers whether or not you allow players. Those requests set no cookie, but they do tell Spotify your address and which page asked. If that matters to you, tell us and we will look at proxying them.

How long we keep it

Your account and its work stay while the account exists.

Ask us to close your account, or to delete a single project, and we do it and delete what it holds. That is done by writing to privacy@ainr.pro today rather than by a button in the product — when the button exists this sentence will say so. Billing records outlive a deletion, because tax and accounting rules require it; those are records of payments, not of research.

Server logs are kept for a short operational window and then discarded.

What you can ask for

A copy of what we hold, a correction to it, or its deletion. Also: to take your work elsewhere, or to object to something we are doing with it.

Write to privacy@ainr.pro. There is no form and no ticket queue. We will not charge you for asking and we will not make you explain why.

Depending on where you live you may also have the right to complain to a data protection authority. Please tell us first — most things are a misunderstanding we can fix the same day.

Where it is held

What we store — your account, your projects, the files you upload and everything the product has filed — is held on servers in the United States.

Processing is a wider circle than storage, and we will not pretend otherwise. A model provider, a search index or a research source runs wherever that company runs it, which is not always the United States and is not always somewhere we choose. If you need a specific region for a specific vendor, ask us before you put anything sensitive in.

Children

ainr is a professional tool and is not for anyone under 18. We do not knowingly collect anything from a child. If you believe we have, write to privacy@ainr.pro and it will be deleted.

Changes to this policy

We will change this as the product changes. The date at the top of this page moves when the wording does.

If a change materially affects what we do with your information, we will tell you before it takes effect rather than quietly editing the page.

Contact

privacy@ainr.pro