Privacy policy.

What aeon.fun, Aeon Connect and the aeon plugin collect, why, how long we keep it, and the choices you have. Plain language, no dark patterns.

This policy covers the aeon.fun website, Aeon Connect (the hosted dashboard at aeon.fun/connect, including the connection apps like ChatGPT use), and the aeon plugin for coding agents and ChatGPT. aeon itself is open-source software that runs on your own GitHub account; how your agent handles data is governed by your own keys and configuration, not by us.

Last updated October 7, 2026

What we collect

We keep data collection to the minimum needed to run and improve the site. We do not ask for an account to read it, and we do not sell personal data to anyone.

The aeon plugin

The aeon plugin (listed for Codex, ChatGPT, and other coding agents) has two parts. Its skills are instructions and one helper script that run inside your own coding agent, on your own machine; Aeon Inc receives no data from them: no prompts, files, chat history, repository contents, or keys. Its connection to your agent goes through Aeon Connect and is described in the next section.

When it helps you set up or run an agent, it uses tools like git and gh against your own GitHub repository with your own credentials. The optional chat-mining step reads the coding-agent session transcripts already stored on your computer to suggest skills worth automating; it reads them locally and sends nothing to us. The company behind your coding agent (for example OpenAI) processes your conversation under its own privacy policy. If the plugin points you to a page on aeon.fun, that visit is covered by the rest of this policy.

Aeon Connect and connected apps

Aeon Connect lets you run your agent from the browser, and lets apps like ChatGPT, Claude, and Codex connect to it. You sign in with GitHub and choose which of your repos it may use, through the Aeon Connect GitHub App.

  • Sign-in. We keep your GitHub username, avatar, and GitHub sign-in token in a server-side session. Your browser holds only a random session id. Logging out deletes the session.
  • Your repo. Connect reads and writes the repo you picked through the GitHub App: your aeon.yml, skills, memory, and run logs and output. It commits changes you make and starts runs on GitHub Actions. It does not copy your repo to our servers.
  • Keys you paste. Model keys and other secrets go straight to GitHub, encrypted with your repo's key, and are stored as Actions secrets in your repo. Connect keeps no copy and cannot read them back.
  • Connected apps. When you connect an app such as ChatGPT, we store the app's registration (its name and return address) and your approval: your GitHub username, your GitHub sign-in token (used to re-check that you still have access), and the one repo you picked. The app gets its own access tokens, which we store only in hashed form. A connected app can see your skills, runs, and run output, start runs, and turn skills on or off. It cannot read or change your secrets or reach any other repo. What it shows in a chat is then handled by that app's company (for example OpenAI) under its own privacy policy.
  • Disconnecting. Remove the app in its own settings, or revoke Aeon Connect at github.com/settings/applications. Either way the connection stops working within an hour.

Analytics

We use analytics tools to understand aggregate traffic - which pages are visited and roughly where visitors come from. This includes Umami and PostHog, which capture usage events and basic device/browser information and help us catch errors. We use these signals in aggregate to improve the site, not to identify you individually.

We also use Google Analytics to measure aggregate traffic - page views, referrers, and approximate location - using first-party cookies (such as _ga) set in your browser. Google processes this data under its own privacy policy, and you can opt out with the Google Analytics opt-out browser add-on or any tracker-blocking extension.

Session recordings

PostHog also records browsing sessions on this site: the pages you move through, clicks, scrolling, and console errors. A recording is a reconstruction of the page, not a video of your screen, and we use them to find broken flows and dead ends rather than to watch individual people.

Anything you type into a form field is masked in your browser before it is sent, so we never receive it. The Privy sign-in and wallet interface runs in a separate embedded frame that recordings cannot capture at all, which means passwords, one-time codes, and wallet recovery material are never recorded. Recordings are deleted automatically after 30 days, and any browser or extension setting that blocks analytics blocks recording along with it.

Wallet sign-in & swaps

The optional “Buy $aeon” feature uses Privy for authentication and wallet management. If you choose to sign in, Privy processes the identifier you provide (such as an email, Google, or X login) and your wallet address to create and secure your session. Swaps are routed through the 0x Swap API via a same-origin proxy. Onchain transactions are, by nature, public and permanent on the Base blockchain. If you never sign in or swap, none of this applies.

Cookies & local storage

We use cookies and browser local storage to remember your wallet session and to measure aggregate analytics, including the Google Analytics _ga cookies, which are not strictly necessary to use the site. You can clear them at any time in your browser settings; the site still works without a signed-in wallet.

Who receives data

Data you share with the site may be processed by the providers that power these features - website hosting (Vercel), Aeon Connect session storage (Upstash), GitHub (where your agent and its secrets live), analytics and session recording (Umami, PostHog, Google Analytics), wallet and auth (Privy and its wallet partners), and swap routing (0x). Each has its own privacy policy governing its handling of that data. We do not sell personal data or share it for advertising.

How long we keep data

  • Session recordings: deleted automatically after 30 days.
  • Analytics events (Umami, PostHog, Google Analytics): kept for up to 14 months, then deleted.
  • Wallet sign-in data: kept by Privy while your session or account exists, and deleted on request. Onchain transactions are public and permanent and cannot be deleted.
  • Emails you send us: kept as long as needed to answer you, then deleted within 12 months.
  • Aeon Connect sign-in sessions: deleted on log out, or after 7 days without use.
  • Connected apps: an app's access expires after 1 hour, and its renewal after 30 days without use. App registrations are deleted after 180 days without use.
  • Cached explanations of failed runs: deleted after 1 day.
  • The aeon plugin's skills: nothing is collected, so nothing is kept.

Your choices

  • Browse without signing in - wallet features are entirely opt-in.
  • Use browser or extension controls to block analytics or clear storage.
  • Request access to or deletion of any personal data we hold by emailing aaron@aeon.fun. We answer within 30 days.

Data controller & contact

The data controller for aeon.fun, Aeon Connect, and the aeon plugin is Aeon Inc. For any privacy request, contact aaron@aeon.fun - see the contact page for more ways to reach us.

Changes

We may update this policy as the site and plugin evolve. Material changes will be reflected here with a new “last updated” date.