Privacy policy
Last updated: 26 August 2026
Reference version. This document is a translation. In the
event of any discrepancy between language versions, the
French version prevails.
This page describes precisely the data processed by Aetherion Capital LLC when
you use aetherion-capital.net. It is written to be
verifiable: every item listed corresponds to what the service actually records.
What we do not collect. No email address, no phone number, no
identity document, no proof of address. Opening an account requires only a
username and a password.
1. Data controller
Aetherion Capital LLC, 22262 Schoolcraft St, Canoga Park, CA 91303,
United States. Contact:
hello@aetherion-capital.net.
See the legal notice.
2. Data collected
Account data
- Username — freely chosen by you. It may be a pseudonym.
- Password — never stored in clear text. Only a cryptographic fingerprint (scrypt, with a random salt) is stored. We are technically unable to recover your password.
- Country — optional, only if you choose to provide it.
- Two-factor authentication secret — only if you enable this option.
Service-related data
- Crypto-asset deposit addresses assigned to you. By their nature, these addresses appear on public blockchains.
- Balances, deposits, withdrawals and performance of your account.
- Activity log: actions carried out on your account, with timestamps.
- Messages exchanged through the internal messaging system. Their content is encrypted in the database.
Technical data
- Sessions: a fingerprint of the session token (never the token itself), together with its creation, last-activity and expiry dates.
- Web server logs: IP address, date and time, page requested, declared browser. These serve the security of the service (detection of abuse and intrusion attempts) and technical diagnostics.
3. Purposes
- Providing the service: account access, deposits, performance tracking.
- Ensuring security: detecting unauthorised access attempts, limiting abuse.
- Meeting our legal and accounting obligations.
Your data is neither sold, nor rented, nor passed on for advertising or
commercial profiling purposes.
4. Cookies
The site sets a single cookie, named aetherion_session.
It is strictly necessary for the client area to work: without it, you cannot
stay logged in. It is inaccessible to JavaScript (httpOnly),
transmitted only over HTTPS (secure) and expires after 24 hours.
No advertising cookie, no tracker, no third-party analytics tool
is used. The site's content security policy technically prevents the browser
from issuing requests to third-party servers.
5. Recipients and processors
- The server host, for the provision of the infrastructure.
- Google Fonts (Google LLC): the site's typefaces are loaded from
fonts.googleapis.com and fonts.gstatic.com. As a result, your IP address is visible to Google when pages load.
- Public blockchains: deposit and withdrawal transactions are, by their nature, public and permanent. We have no means of erasing them.
Market data and transaction status are queried by our server, never by your
browser: the providers concerned therefore do not receive your IP address.
6. Retention periods
- Sessions: 24 hours, then automatic deletion.
- Database backups: a rolling 30 days, then automatic deletion.
- Account data: kept for the lifetime of the account.
To be completed. Specify how long data is kept after an
account is closed, as well as the retention period for server logs, in line
with your accounting obligations.
7. Security
- End-to-end encryption of transport (HTTPS, TLS 1.2 and 1.3 only).
- Passwords hashed with a salt; constant-time comparison.
- Session tokens stored as fingerprints, never in clear text.
- Messages encrypted in the database.
- Application run under an unprivileged system account; database unreachable from the web.
- Login attempts rate-limited and abusive addresses banned automatically.
8. Your rights
You may request access to your data, its rectification or erasure, or object to
its processing, by writing to
hello@aetherion-capital.net.
Two limits stem from the nature of the service. First, transactions recorded on
a blockchain are irreversible and cannot be erased. Second, since we collect no
identity data, we can only identify you by your account username: a request can
therefore only be handled from an account you have access to.
To be completed. Depending on the jurisdictions from which you
accept users, specific wording may be required (GDPR for the European Union,
CCPA/CPRA for California), as well as the possible appointment of a
representative. To be reviewed by legal counsel.
9. Changes
This policy may change. The date of the last update appears at the top of this
page.