AIONSEC
Courses About
Sign in Start the course ›››

AionSec · Legal

Privacy Policy

How personal information moves through AionSec — what we collect, why we need it, who processes it, and the choices you retain.

Effective date · September 3, 2026

Who is responsible for your information?

Stephanus Rossouw, doing business as AionSec.ai (“AionSec,” “we,” “us”), is responsible for personal information in AionSec's custody or control. This Policy applies when you visit AionSec.ai, create an account, purchase or take a course, use AionSec Labs, join the mailing list, or contact us.

Privacy Officer: Faan Rossouw
Email: info@aionsec.ai
Mailing address:
Stephanus Rossouw
#253 — 2160 Highway 7, Unit 6
Vaughan, ON L4K 1W6
Canada

Contact the Privacy Officer to ask a question, make a complaint, or request access, correction, deletion or portability where applicable.

Information we collect

Account information

When you create or claim an account, we collect your email address, an optional display name, and account identifiers and timestamps. Supabase provides authentication and stores the password verifier and session information used to secure your account. AionSec does not receive or store your plaintext password.

Purchase information

Stripe processes Checkout, payment credentials, billing details, receipts, refunds and disputes. We receive limited transaction information needed to provide and support your purchase, including your email address, Stripe identifiers, amount, currency and purchase, refund or dispute status and time. AionSec does not receive or store your full card number or CVC.

Course and Labs information

We store lessons you mark complete and related progress timestamps. To authorize and deliver AionSec Labs and private course artifacts, we process pseudonymous licence and installation identifiers, operating-system target, Labs version, entitled content, activation times and counts, and an audit of download decisions.

System labs use a model provider or local model you choose. Under the intended architecture, your model API key, prompts, requests and responses go directly from your computer to that provider and are not sent to AionSec. The provider's own terms and privacy practices apply.

Optional Discord community access

If you choose to link private student access in Discord, we process your Discord user and server identifiers, the connection to your active course purchase, role status, claim status, and limited pseudonymous security outcomes. The one-use claim is hashed before storage. We do not store the plaintext claim or your Discord display name. Discord also processes your use of its service under its own terms and privacy policy.

Course video delivery

Mux hosts and streams course videos. To deliver and protect playback, Mux and its delivery infrastructure receive technical request information such as your IP address, browser or device information, the requested video resources, and time-limited playback authorization. Optional Mux viewing analytics are disabled in our course player. This does not prevent the processing of technical information needed to deliver, secure and operate the video service.

Mailing-list and support information

If you join the mailing list, we collect your email address, an optional name, and consent or subscription status. MailerLite processes this information for us. You can unsubscribe using the link in each marketing email. Unsubscribing does not stop necessary account, purchase, security or support messages.

If you contact us, we receive your address and message contents and metadata. Do not email us passwords, security-key PINs, model keys, payment-card numbers or other secrets.

Technical and security information

Our hosting, authentication, payment, email and abuse-prevention providers may process IP address, date and time, requested page or action, browser or device information, and security signals. Essential authentication cookies keep you signed in. Cloudflare Turnstile processes information needed to distinguish legitimate users from abusive automated traffic.

We do not currently use advertising cookies, behavioural advertising or product analytics.

Why we use personal information

  • Create, authenticate, recover and secure accounts.
  • Process purchases and administer receipts, access, promotions, refunds and disputes.
  • Deliver course content, remember progress and provide entitled Labs downloads.
  • Operate, troubleshoot and protect the service and its users.
  • Respond to support, legal and privacy requests.
  • Maintain accounting, tax, fraud-prevention and compliance records.
  • Send marketing only with the consent or other authority required by law.

Information required for an account, purchase or requested feature is necessary to provide that part of the service. Marketing is optional and is not required to buy or take the course.

Who receives personal information?

  • Supabase — authentication, accounts, entitlements, progress and Labs records.
  • Stripe — Checkout, payments, receipts, refunds, disputes and reconciliation.
  • Vercel — website hosting and operational or security logs.
  • Mux — course video hosting, streaming and playback delivery security.
  • Cloudflare — Turnstile abuse prevention.
  • MailerLite — consented mailing-list administration and delivery.
  • Discord — optional public or private community participation, interaction delivery and course-role management when you choose to link access.
  • Porkbun and its email infrastructure — support and account email delivery.
  • Professional advisers, regulators, law enforcement or others when required or permitted by law.

Some processing occurs outside Canada, where information can be subject to local laws. We do not sell personal information or disclose it for cross-context behavioural advertising.

How long do we keep information?

  • Labs download-audit records are configured for deletion after 90 days.
  • Discord claim records are deleted 30 days after their latest expiry, use or revocation; rate-limit buckets after one day; and pseudonymous outcome records after 180 days. The purchase-to-Discord binding remains while needed to restore or remove private access.
  • Transaction and accounting records are generally kept for six years from the end of the last related tax year, or longer when required for an unresolved matter or legal hold.
  • Mailing-list information remains until unsubscribe or another lawful endpoint, subject to limited suppression and consent evidence needed to honour opt-out and demonstrate compliance.
  • Account, entitlement and progress information remains while the account and purchased access are active, then is deleted or de-identified when no legal, security, transaction or dispute reason requires it.
  • Provider logs and backups follow applicable provider schedules. Deletion from active systems may not immediately remove protected backup copies, which expire through normal rotation.

How we protect information

Safeguards include restricted administrative access, multifactor authentication and hardware security keys for key provider accounts, encryption in transit, row-level database rules, private Labs artifact storage, signed and time-limited downloads, audit records, backups and incident-response procedures. No system can guarantee absolute security. We will notify affected people and regulators when required by law.

Your choices and rights

Subject to applicable law, you may ask us to:

  • Confirm whether we hold personal information about you and provide access to it.
  • Correct inaccurate or incomplete information.
  • Provide eligible information in a structured, commonly used technological format.
  • Delete information that no longer must be retained.
  • Explain or withdraw consent, subject to legal and contractual limits.
  • Review and respond to a privacy complaint.

Email info@aionsec.ai and identify your request. We may need to verify your identity, but we will not ask for your account password or security-key PIN. You can unsubscribe from marketing through each marketing message. Blocking essential authentication cookies may prevent account and course features from working.

Children

AionSec is not intended for children. If you believe a child provided personal information without the consent required by applicable law, contact the Privacy Officer.

Changes to this Policy

We may update this Policy when the service or our practices change. We will post the updated version with its effective date and provide any additional notice required for a material change.

AIONSEC Learn Agentic Security Engineering
Course About Help Email updates Terms Privacy