Privacy Policy
Last updated: July 30, 2026
Overview
This policy explains what Aemulus (the “Service”) collects, how it is used, and who it is shared with. We collect only what is needed to run the Service.
What we collect
• Wallet address. Your Solana public key, used to authenticate you and scope your data. We never receive your private keys.
• Invoice data. Files you upload and the fields extracted from them (vendor, invoice number, date, amount, currency), plus the ledger and audit entries you create.
• Usage. Sealed audit events (what was reviewed, decided, and entered) and basic operational counts used for tier limits.
• Cookies. A single session cookie that keeps you signed in. We do not use third-party advertising or tracking cookies.
How we use it
To provide the Service: to read your invoices, let you review and enter them, produce a verifiable audit trail, and enforce access tiers. We do not sell your data.
Who we share it with
• AI extraction provider. Invoice images/PDFs you upload are sent to our model provider to read their fields. They are not used to train models on your behalf.
• Your accounting software. If you connect QuickBooks Online, entered invoices are sent there at your direction; connection tokens are stored encrypted.
• Infrastructure. Our database and hosting providers, and Solana RPC providers used to read on-chain balances for tier gating.
On-chain data
Solana wallet addresses, token balances, and any on-chain receipts are public blockchain data by nature and are not controlled by us.
Retention
The audit log is append-only and tamper-evident by design; entries are retained to preserve the integrity of the record. You can request deletion of your account data via the channels in the footer; some sealed records may be retained where required to keep the audit trail verifiable.
Security
Sessions are signed and stored in httpOnly cookies; connection tokens are encrypted at rest; data is scoped per wallet so accounts cannot read each other’s records. No system is perfectly secure, and you are responsible for safeguarding your wallet.
Browser extension (Aemulus Recorder)
The Aemulus Recorder extension records and replays browser tasks in your own browser, on your instruction, and sends results only to your own Aemulus account on the server you configure.
• What it accesses. Page content on the tab you are recording or running - element selectors, the field values you type, and a proof screenshot per step - only while you have explicitly started a recording or a run. When idle, it reads nothing. It also stores the Aemulus server URL and API key you enter, locally in the browser (chrome.storage.local).
• What it sends, and to whom. Recorded traces and run results (including proof screenshots) are sent only to the Aemulus server URL you configure- your own deployment. Nothing is sent to the extension author or any third party. When a recorded selector no longer matches, the current page's candidate elements and a screenshot are sent to your Aemulus server so its vision fallback can pick the element - again, only to your configured server.
• What it never captures. Secret fields (passwords, one-time codes, card numbers, API keys, and similar) are detected and never captured or transmitted - they are recorded as empty, flagged inputs so the skill asks for them per run instead.
• No analytics, no tracking. The extension contains no analytics, telemetry, ads, or third-party trackers, and makes network requests only to the Aemulus server URL you configure.
• Storage & retention.Settings and a transient action buffer live in your browser's local storage; uninstalling the extension removes them. Recordings and runs are stored on your Aemulus server under your account, governed by that deployment - not by the extension.
Changes and contact
We may update this policy; material changes will be reflected by the “last updated” date. Questions or data requests can be directed to the channels listed in the site footer.