Approved version: August 18, 2026
Effective date: Upon AfterFlyte public launch
This AfterFlyte Privacy Policy explains how Sporadic Media LLC, doing business as Aero Digital Media (“Aero Digital Media,” “we,” “us,” or “our”), collects, uses, discloses, and retains information when you use the AfterFlyte website, account, billing, activation, update, support, and desktop software services (collectively, “AfterFlyte”).
This policy applies only to AfterFlyte. Our separate Privacy Policy for Drone Service Inquiries governs Aero Digital Media’s drone-service website and communications.
Information We Collect
We may collect the following categories of information:
- Account information: Your email address, name if provided, account identifier, authentication status, and related security metadata through Clerk.
- Subscription and transaction information: Stripe customer, Checkout, subscription, price, invoice, payment status, cancellation, and refund information. Stripe processes payment-card details; we do not store complete card numbers.
- Activation and device information: A random device identifier, device label, operating-system or platform details, app version, activation status, entitlement status, active-device count, and timestamps. Activation and device-refresh secrets are stored as hashes where applicable.
- Starter allowance information: Account-linked grant status, remaining balance, and related timestamps; hashed credential and device associations; and keyed pseudonymous records used to recognize a prior export of the same project-image entry. A raw project-image identifier may pass through an online authorization request, but we do not retain it in raw form.
- Support information: Messages, email address, troubleshooting details, and other information you choose to provide when requesting help or a refund.
- Website and security information: Internet Protocol address, browser, device, pages requested, timestamps, referral or campaign information, cookie choices, security events, and similar server or consent records.
- Desktop reliability telemetry: When enabled, Sentry may receive allowlisted crash, exception, app-version, operating-system, packaged-build, and diagnostic context.
- Desktop product telemetry: When enabled, PostHog may receive an app-generated random installation identifier and allowlisted events about launches, feature use, activation outcomes, update outcomes, and a coarse Starter balance category rather than the exact balance.
Files and Annotation Data We Do Not Collect
AfterFlyte is designed to process your property images and project data locally. Our AfterFlyte telemetry is not intended to collect:
- Image data, thumbnails, or derived visual content
- File names, file paths, folder names, or project names
- Annotation coordinates, shapes, labels, or project contents
- Raw project-image identifiers after an authorization request is completed
- Raw account credentials, authentication tokens, activation secrets, or entitlement payloads
- Email addresses, account names, operating-system account names, or hostnames
- Raw AI inputs or outputs, session replay, autocapture data, or identified user profiles
Do not include sensitive information in a support request or other free-text field.
How We Use Information
We use information to:
- Create and secure accounts
- Process subscriptions, cancellations, refunds, and billing support
- Activate devices and enforce the named-user, one-active-device license
- Issue and refresh paid-feature entitlements
- Provide downloads, updates, support, and service notices
- Diagnose crashes, failures, fraud, abuse, and security events
- Measure privacy-safe product usage and improve AfterFlyte
- Maintain records, enforce our AfterFlyte Software Terms, and comply with legal obligations
We do not use customer images, project data, or annotation data to train AI models.
Desktop Telemetry Choices
AfterFlyte presents a first-run disclosure before configuring desktop telemetry. Anonymous reliability telemetry through Sentry and anonymous product telemetry through PostHog are on by default after that disclosure is recorded.
The two services are separate controls. You can turn either one off at any time in AfterFlyte Preferences. Disabling a service stops AfterFlyte’s telemetry helpers from submitting new events to that service. Disabling telemetry does not delete records already received; you may contact us to request deletion where applicable.
Optional PostHog balance categories are separate from essential account and Starter authorization records stored in Neon. Turning PostHog off does not disable or delete the essential records needed to authorize exports and show the account balance.
Website Cookies and Optional Tracking
The AfterFlyte website uses essential storage and requests needed for authentication, security, billing, and account functionality.
The website requests a first-party server bootstrap before optional measurement is authorized. The bootstrap applies the stored privacy choice and Global Privacy Control before returning the current Analytics and Advertising state. If the server bootstrap or stored privacy state cannot be validated, optional measurement fails closed; account, billing, activation, download, and product access remain available without optional measurement.
On public marketing pages, Analytics and Advertising are on when you have no stored choice and do not send a Global Privacy Control signal. A persistent Privacy Choices footer control lets you turn Analytics and Advertising off or on separately. A stored choice remains in effect until you change it or clear site storage.
Global Privacy Control forces Advertising off before advertising providers load and prevents a stored choice from turning it back on while the signal is active. It does not turn Analytics off by itself, but you can turn Analytics off separately. Withdrawing a choice stops new authorization and admission for that purpose. One already-authorized bounded sending request may finish, but no new optional measurement is admitted after withdrawal.
Crisp chat remains off until you explicitly select Chat with us. Account, sign-up, sign-in, checkout, activation, dashboard, and legal routes do not load optional analytics, advertising, or chat providers.
We do not sell or rent personal information. Where applicable, you may use Privacy Choices or Global Privacy Control to opt out of sharing for cross-context behavioral advertising.
Website Measurement, Attribution, and Advertising
Analytics and Advertising are separate measurement purposes. Analytics supports neutral funnel and product-performance reporting. Advertising supports advertising measurement and, only on public marketing pages, Advertising-authorized Google Tag Manager retargeting.
AfterFlyte records independent first-touch attribution and conversion-touch attribution rather than combining them into one touch. It does not backfill historical activity that occurred before authorization. Aggregate spend reporting is computed from retained identity-free measurement and billing facts.
Provider references such as advertising click identifiers are retained in encrypted form and resolved only for requests to authorized server conversion APIs. A server conversion destination participates only when it is enabled, supports the requested operation, and the event is provider-eligible. Customer-list matching, advanced matching, and enhanced matching are not used.
Advertising-authorized events may support a public visitor retargeting audience and server-derived Starter and purchaser audiences. These audience paths operate only when the relevant destination is enabled, supported, and provider-eligible. The configured provider-native windows are a 30-day public visitor window, a 30-day Starter window, and a 90-day purchaser exclusion window. Audience evaluation uses authorized events rather than customer lists and does not perform member-by-member upload or removal operations. Provider-native members expire under the configured windows and provider rules; withdrawal does not represent immediate provider-native deletion.
Service Providers
We use service providers to operate AfterFlyte, including:
- Clerk for account authentication and session management
- Stripe for Checkout, subscription billing, invoices, refunds, and the customer portal
- Neon for essential AfterFlyte account, Starter grant, balance, authorization, activation, entitlement, subscription, and device records
- Netlify for website hosting, server functions, logs, and content delivery
- Cloudflare for production DNS, proxying, security, content delivery, and related network reporting
- Sentry for optional desktop and server reliability monitoring
- PostHog for optional product analytics and funnel measurement
- Google, Meta, and TikTok for optional website analytics and advertising measurement
- Crisp for optional website chat
- GitHub for software release and installer delivery
- Amazon Web Services for business email and related service delivery
These providers process information for us under their own service terms and privacy commitments. Google, Meta, and TikTok website processing follows the Analytics, Advertising, and Global Privacy Control choices described above. Crisp loads only when you request chat. We may also disclose information when required by law; to investigate fraud, abuse, or security threats; to protect rights and safety; or as part of a merger, financing, acquisition, or sale of business assets.
Data Retention
We retain information only as long as reasonably needed for the purposes described above:
- After a verified account-deletion request, we target deletion or de-identification of AfterFlyte account, Starter grant, balance, authorization, activation, entitlement, and device records within 30 days, subject to legal, fraud-prevention, security, transaction-record, and backup requirements.
- We target a maximum retention period of 90 days for Sentry event data.
- We target a maximum retention period of 12 months for PostHog event data.
- Authoritative website privacy receipts are retained for 13 months from creation or the latest explicit update.
- Neutral journey, touch, provider-reference, and attribution-bridge records use non-sliding windows capped at 90 days.
- Canonical measurement events, neutral attribution snapshots, and billing facts use a 12-month window from occurrence.
- Delivery retry eligibility, source bindings, producer outbox records, and spend-import staging use a 7-day window where applicable.
- Terminal delivery diagnostics, terminal Google conversion staging, and cleanup receipts use a 30-day window.
- Campaign mappings, daily spend facts, completed spend-import batches, the spend data available to aggregate reports, and replay tombstones use a 13-month boundary.
- Unresolved spend quarantine is capped at 90 days and is not part of the 13-month group.
- Stripe transaction, invoice, refund, tax, and accounting records may be retained longer when required for financial or legal recordkeeping.
- Security and support records may be retained as reasonably necessary to resolve a request, prevent abuse, enforce agreements, or comply with law.
We configure provider settings to match these stated retention periods.
Your Choices and Privacy Rights
Depending on where you live and subject to applicable exceptions, you may request that we:
- Confirm whether we process personal information about you
- Provide access to or a copy of that information
- Correct inaccurate information
- Delete information
- Receive portable information in a reasonably usable format
- Explain the categories of information and service providers involved
- Honor an applicable opt-out request
- Appeal our decision about an applicable privacy request
You can also:
- Change separate Sentry and PostHog choices in AfterFlyte Preferences
- Manage essential account information through Clerk
- Manage billing and cancel a subscription through the AfterFlyte dashboard and Stripe customer portal
- Use Privacy Choices to control website analytics and advertising separately
- Open website chat only when you choose Chat with us
- Send a Global Privacy Control signal through a supported browser
We will not discriminate against you for exercising an applicable privacy right. We may need to verify your identity before completing a request.
Security
We use reasonable administrative, technical, and organizational safeguards intended to protect information. No application, network, database, or transmission method can guarantee absolute security.
You are responsible for protecting your account credentials and device. Notify us promptly if you believe your account or information has been compromised.
United States Service and Adults
AfterFlyte is offered only in the United States for professional and business property-photo workflows and is intended for adults who are at least 18 years old. Do not use AfterFlyte for children’s information or regulated sensitive-data workflows. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this policy as AfterFlyte, our providers, or legal requirements change. We will post and archive dated versions. When practical, we will provide at least 30 days’ notice before a material change takes effect and request renewed consent when legally appropriate.
Contact
To ask a privacy question or submit a request, contact:
Sporadic Media LLC d/b/a Aero Digital Media
- Address: 782 SW County Road 300, Mayo, FL 32066
- Phone: 1 (386) 703-8077
- Email: support@aerodigital.media