INVESTOR PREVIEW · DRAFT — NOT EFFECTIVE LEGAL TERMS

Privacy Notice

Review version: 2026-09-23-investor.1 · Effective date: Not effective — draft

Review item: Replace the operator description with the responsible person’s full legal name and address, confirm the actual website data flows, and obtain global privacy review before adoption as an effective notice.

Who is responsible

Aestus Value Lab is currently operated by an individual and is not yet incorporated. The responsible operator is [FULL LEGAL NAME / ENTITY — APPROVAL REQUIRED], at [LEGAL ADDRESS — APPROVAL REQUIRED].

Privacy questions and requests: herman@aestusvaluelab.com.

Information we collect

We do not intentionally collect payment information, user uploads, or private prompts in the current beta. If that changes, this Notice will be updated before the relevant feature launches.

Browser storage and account access

Authentication uses session cookies. Local browser storage holds interface preferences and guest-invitation counts. Declining four invitations pauses guest browsing in that browser for 24 hours; registration or sign-in ends the pause. This count is not a cross-device identity. Optional Google sign-in uses Google account information. These investor-preview documents are not effective agreements. Registration does not request or record acceptance of these drafts.

Data-flow review required: account authentication, Google OAuth, traffic/marketing measurement, feedback processing, public wallet research and each research feed must be included in the provider/source inventories. Do not read the original Cloudflare/Polymarket provider list below as a complete, verified inventory.

How we use information

We use information to provide and secure the service, authenticate users, improve reliability, respond to support requests, prevent abuse, comply with law, and operate account preferences. We do not use private user content for model training by default.

Our current providers and data sources

We use Cloudflare for website hosting, content delivery, DNS, and security. Cloudflare may process website requests, technical metadata, security logs, and website content under its applicable service terms and data-processing addendum.

We obtain public market and event data from Polymarket public APIs. This data supports the research-terminal functionality. Aestus does not send user account data to Polymarket for that purpose.

International users and transfers

Users may access Aestus from anywhere in the world. Information may be processed internationally by Cloudflare. The legal basis, transfer mechanism, local notice, and representative requirements for each relevant jurisdiction must be confirmed before public launch.

Retention — proposed policy, not verified enforcement

The following periods are Legal's proposed beta defaults. Automated deletion and vendor/backup retention have not been verified against every deployed system. These are review items, not a claim that all deletion controls already operate.

CategoryCurrent beta default
Account dataActive account plus 30 days after deletion
Support records24 months after case closure
Security logs90 days, except relevant incident records
Product analytics12 months, using pseudonymous identifiers where possible
Prompts/uploadsNot retained by default; if introduced, 30 days maximum unless preservation is requested
Consent and Terms recordsAccount life plus 7 years, subject to counsel confirmation
BackupsRolling 35 days

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to opt out of certain sharing or targeted advertising. Send a request to herman@aestusvaluelab.com. We may need to verify the request and will respond within the period required by applicable law.

Children

Aestus is not directed to children and the beta is intended for adults. We do not knowingly collect personal information from children where parental consent is required. Contact us if you believe this has occurred.

Security and incidents

The proposed safeguards include access controls, MFA for administrative accounts, encryption where supported, logging, backups and incident procedures. Administrator MFA, backup restore testing and operational ownership still require verification. No service can be guaranteed completely secure.

Changes

We may update this Notice by posting a revised version and, where required, providing additional notice. The effective date will identify the current version.