Aether Labs

Privacy Policy

Effective date: August 24, 2026

This Privacy Policy explains how Aether Labs (“we,” “us” or “our”) collects, uses, shares and protects personal information when you visit our website, create an account, place an order, or use our research tools (together, the “Platform”).

We have written this policy to describe what actually happens to your data in our systems, rather than to describe every practice we might one day adopt. It should be read alongside our Terms of Service.

1. Scope and controller

This policy applies to personal information we process as a controller through the Platform. It does not apply to third-party websites we link to, or to products fulfilled by affiliate partners on their own sites — those are governed by the operator’s own privacy policy.

The controller responsible for your personal information is Aether Labs, Aether · 1209 Orange St, Wilmington, DE 19801, USA. You can reach our privacy contact at privacy@theaetherexperience.com.

2. Information we collect

2.1 Information you provide

  • Account and identity data — your email address, display name, and the date of birth we use to verify you meet our 21+ age requirement. We also record the fact and timestamp of your certification that you are 21 or older and accept our Terms and this Privacy Policy.
  • Profile data — any optional biography, avatar, phone number or preferences you choose to add.
  • Order and fulfilment data — items ordered, order value, shipping and billing address, recipient name, delivery method, tracking details and order history.
  • Communications — messages you send us through contact forms, support email, in-app messaging, reviews, comments and forum posts.
  • Content you create — saved items, notes and bookmarks you keep in your account.

2.2 Information collected automatically

  • Usage data — pages and products viewed, features used, search terms, referring pages, and interaction events.
  • Device and technical data — IP address, browser type and version, operating system, device type, language and approximate location inferred from IP.
  • Security and integrity data — sign-in events, rate-limiting counters keyed to your email address or IP, and administrative audit logs recording privileged actions taken on the Platform.
  • Email engagement — delivery, bounce and open/click events for messages we send you.

2.3 What we do not collect

We do not collect or store full payment card numbers — see Section 10. We do not ask for government identification documents, and we do not knowingly collect information from anyone under 21.

3. Research logs and sensitive data

Please keep research logs impersonal

Our free-text surfaces — reviews, comments, forum posts, messages to us and saved notes — are for discussing laboratory research activity, consistent with the research-use-only restrictions in our Terms. They are not health records, and we do not intend for them to hold health information about you or any other identified person.

Because these are free-form fields, it is technically possible to type personal or health-related details into them. We ask that you do not. Do not record information about any individual’s health, medical history or personal circumstances, and do not enter information about any third party who has not consented.

Where you nonetheless submit information that qualifies as sensitive or special category data under applicable law, you do so voluntarily and, where the law requires a basis of consent, you consent to our processing it for the purpose of providing the feature you entered it into. You can delete this content at any time, or ask us to delete it.

4. How we obtain information

We obtain personal information:

  • directly from you, when you provide it;
  • automatically, through your use of the Platform;
  • from our payment processors, who confirm transaction outcomes and provide the billing and shipping details you gave them; and
  • from carriers, who provide delivery and tracking status for your orders.

5. How we use information

  • to create and administer your account and authenticate you;
  • to verify that you meet our 21+ age requirement and eligibility criteria, and to maintain a record of the certifications you made — a compliance obligation arising from the nature of the Products we sell;
  • to process, fulfil, ship and support your orders, and to communicate about them;
  • to respond to your enquiries and provide customer support;
  • to send transactional messages about your account and orders, and — only where you have opted in — marketing;
  • to operate loyalty points, order history and other account features;
  • to measure and improve the Platform, understand which features are used, and debug problems;
  • to protect the Platform — detecting and preventing fraud, abuse, unauthorised access and rate-limit evasion; and
  • to comply with legal obligations, enforce our Terms, and establish, exercise or defend legal claims.

We do not sell your personal information, and we do not use it for automated decision-making that produces legal or similarly significant effects about you.

6. Legal bases for processing

For individuals in the European Economic Area, the United Kingdom and other jurisdictions with equivalent rules, we rely on the following legal bases:

  • Performance of a contract — to create your account, process and deliver your orders, and provide the features you request.
  • Legal obligation — to keep tax, accounting and transaction records, and to retain evidence of the age and eligibility certifications required for the sale of research materials.
  • Legitimate interests — to secure the Platform, prevent fraud and abuse, understand and improve how our features are used, and defend legal claims. We balance these interests against your rights and freedoms.
  • Consent — for optional analytics cookies, marketing preferences and any sensitive information you volunteer. You may withdraw consent at any time, without affecting processing already carried out.

7. How we share information

We do not sell your personal information. We share it only as described here:

  • Service providers — the processors listed in Section 9, who act on our instructions under contract and may not use your data for their own purposes.
  • Shipping carriers — the recipient name, address and contact details needed to deliver your order.
  • Professional advisers — auditors, accountants and lawyers, where necessary and subject to confidentiality.
  • Legal and safety — regulators, law enforcement or other parties where we are legally required to disclose, or where disclosure is reasonably necessary to enforce our Terms, investigate suspected violations, or protect the rights, property or safety of any person. Given the nature of our Products, this includes responding to lawful requests from regulatory or enforcement authorities.
  • Corporate transactions — an acquirer or successor in connection with a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply.
  • Publicly, at your direction — content you choose to post publicly, such as reviews or forum posts, along with the display name you have chosen.

8. Service providers

We rely on the following categories of provider to operate the Platform. Each processes only what it needs for its function.

ProviderPurposeData involved
SupabaseDatabase, authentication and file storageAccount, profile, order and research-log data
VercelApplication hosting, edge delivery and analyticsRequest metadata, IP address, aggregate usage
StripeCard payment processingName, email, billing and shipping address, payment details
BitPayCryptocurrency payment processingEmail address, order reference, transaction details
ResendTransactional and notification email deliveryEmail address, message content, delivery events
UpstashRate limiting and abuse prevention (when configured)Hashed request keys, counters

This list may change as our infrastructure evolves. We will update this policy when it does.

9. Payment information

Card payments are processed by Stripe, and cryptocurrency payments, where offered, by BitPay. Your card details are submitted directly to the payment processor and are never transmitted to or stored on our servers. We receive only what we need to reconcile your order: a transaction reference, the outcome, the amount, and the billing and shipping details you provided.

Cryptocurrency transactions are recorded on a public blockchain by design. We do not control that ledger, and transactions recorded on it cannot be altered or erased by us or by you. Your use of a payment provider is also subject to that provider’s own privacy policy.

10. Cookies and analytics

We use a small number of cookies and similar technologies:

  • Strictly necessary — to keep you signed in, maintain your session, remember your cart and shipping selection, and protect against abuse. The Platform cannot function without these.
  • Analytics — to understand which pages and features are used, so we can improve them. We use Vercel Analytics for this purpose.

We do not use advertising cookies, and we do not permit third parties to track you across other websites for advertising purposes.

Most browsers let you refuse or delete cookies through their settings. Blocking strictly necessary cookies will prevent sign-in and checkout from working. We also honour Global Privacy Control and similar browser opt-out signals where applicable law requires it.

11. Email communications

We will always send you transactional messages relating to your account and orders — sign-in links, order confirmations, shipping updates and important service notices. These are necessary to provide the service and cannot be opted out of while you hold an account.

We do not currently send marketing email, and we do not send SMS at all. If we introduce marketing messages we will send them only to recipients who have opted in, every such message will carry a one-click unsubscribe link, and we will update this policy before doing so.

12. International transfers

We are based in the United States, and our service providers may process your information in the United States and other countries whose data protection laws differ from those of your own.

Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards — typically the European Commission’s Standard Contractual Clauses together with supplementary technical and organisational measures. You may request details of these safeguards using the contact details in Section 1.

13. Data retention

We keep personal information only for as long as we need it for the purposes described in this policy, and then delete or anonymise it. In practice:

  • Account and profile data — for as long as your account is open, and for a reasonable period afterwards to handle disputes.
  • Order, transaction and tax records — for the period required by tax, accounting and commercial law, typically seven years.
  • Age and eligibility certification records — for as long as we may need to evidence that a sale was made to a certified, eligible purchaser. Because these records exist to demonstrate regulatory compliance, they may be retained after account closure and may survive a deletion request.
  • Research content you create — until you delete it or close your account.
  • Security and audit logs — for a limited period proportionate to their security purpose.
  • Analytics data — in pseudonymous or aggregated form, which we may retain indefinitely as it no longer identifies you.

14. Security

We take reasonable technical and organisational measures to protect personal information, including encryption in transit, row-level database access controls that scope records to their owner, role-based administrative permissions, audit logging of privileged actions, rate limiting, and passwordless authentication that removes the risk of a reused or leaked password.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Because sign-in is passwordless, the security of your email account is critical to the security of your Platform account — protect it accordingly, and tell us promptly at privacy@theaetherexperience.com if you suspect unauthorised access.

Where a breach of personal information is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law.

15. Your privacy rights

Depending on where you live, you may have some or all of the following rights in relation to your personal information:

  • Access — to obtain a copy of the information we hold about you.
  • Rectification — to correct information that is inaccurate or incomplete.
  • Erasure — to have your information deleted, subject to the retention obligations in Section 14.
  • Restriction and objection — to limit or object to processing based on our legitimate interests.
  • Portability — to receive information you gave us in a structured, machine-readable format.
  • Withdraw consent — where processing is based on consent, at any time.
  • Complain — to your local data protection authority.

To exercise any of these rights, email privacy@theaetherexperience.com. We will respond within the period required by applicable law — generally thirty (30) days, and no later than forty-five (45) days where U.S. state law applies, with an extension where permitted. We may need to verify your identity, usually by confirming control of the email address on the account. We will not discriminate against you for exercising your rights.

16. U.S. state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia or another U.S. state with comprehensive privacy legislation, you have the rights described in Section 16, including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of its sale or sharing.

We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, as amended.

California residents may designate an authorised agent to make a request on their behalf; we will require proof of authorisation and may still verify your identity directly. If we decline a request, we will explain why, and you may appeal by replying to our response — we will inform you of the outcome of any appeal and of your right to contact your state attorney general.

17. Age restrictions

The Platform is intended exclusively for Qualified Researchers aged 21 and over. It is not directed at children, and we do not knowingly collect personal information from anyone under 21.

If we become aware that we have collected information from a person under 21, we will delete that information and close the account. If you believe a minor has provided us with personal information, contact us immediately at privacy@theaetherexperience.com.

18. Changes to this policy

We may update this Privacy Policy to reflect changes to our practices, technology or legal obligations. When we do, we will revise the effective date at the top of this page.

If we make a material change to how we use your personal information, we will provide additional notice — for example by email to registered account holders or a prominent notice on the Platform — and, where the law requires it, obtain your consent.