Skip to document
aimbud.Back to aimbud
Terms of ServicePrivacy Policy

On this page

  • 1. About this notice
  • 2. The short version
  • 3. Processing on the device
  • 4. Information handled by the service
  • 5. Purposes and legal grounds
  • 6. Providers and recipients
  • 7. Staff and moderator access
  • 8. Cookies, browser storage and external content
  • 9. Promotions and screenshot contributions
  • 10. International processing
  • 11. Retention
  • 12. Requests and choices
  • 13. Younger users
  • 14. Security, checks and support
  • 15. Changes and contact
On this page
  • 1. About this notice
  • 2. The short version
  • 3. Processing on the device
  • 4. Information handled by the service
  • 5. Purposes and legal grounds
  • 6. Providers and recipients
  • 7. Staff and moderator access
  • 8. Cookies, browser storage and external content
  • 9. Promotions and screenshot contributions
  • 10. International processing
  • 11. Retention
  • 12. Requests and choices
  • 13. Younger users
  • 14. Security, checks and support
  • 15. Changes and contact

aimbud / Legal

Privacy Policy

Information, device processing and your choices.

Published 7 September 2026Version 2026-09-07.2

1. About this notice

This Privacy Policy covers aimbud.net, accounts, device-connected services, purchases, membership and support. It describes current processing and identifies planned practices and controls separately. It is not a request for blanket consent or a claim that unfinished controls are already operating.

The service operator and controller for the activities described here is aimbud LLC, a Delaware limited liability company in the United States. Operations and shipping include Jordan. US incorporation does not mean all data is stored or accessed in the US.

Contact [email protected] about your information, our handling of it and business-contact details. This notice does not retrospectively transfer responsibility for earlier processing from a different operator.

2. The short version

  • Normal video and mouse processing happens on the external device.
  • Servers receive account and device information to check access, protect the service and deliver updates.
  • Signing in, buying and contacting support creates separate records.
  • Providers help with hosting, email, sign-in, payments and website delivery.
  • Future marketing and screenshot contributions are separate choices, not permission obtained from reading this page.
  • Users aged 13-17 need a parent or guardian to purchase and manage access for one designated young user.

Ask support to explain this notice, correct information or help with a privacy request.

3. Processing on the device

The normal aim-assist pipeline captures HDMI video, runs inference and processes mouse input locally. Routine entitlement messages do not contain gameplay video, screenshots or a stream of mouse movements. Local settings and diagnostic statistics can include frame rates and connection status.

Wi-Fi settings and credentials are stored on the device and are not part of routine entitlement messages to the API. A local reset does not delete the website account or historical server records. Remove local settings before returning or relinquishing possession of the board where possible.

A screenshot, video or log you send to support creates a separate support copy. Normal local inference alone is not a promise that no information ever leaves the board or that every possible support configuration has been independently verified.

4. Information handled by the service

Accounts and sign-in

Records include name, email, account status, sign-in and recovery information, and relevant security events. Passwords submitted to the server travel over HTTPS and are stored as password hashes rather than plaintext passwords. Google sign-in, if chosen, supplies a Google identifier, name, email and verification status; it does not request access to Gmail messages or contacts.

Account agreement

After successful email-code or Google sign-in under the displayed notice, we record the account identifier, document version, server-recorded acceptance time, sign-in method, Terms acceptance, Privacy acknowledgment and the adult declaration stated in that notice. The archived document versions and their checksums identify the text presented. Visiting a page or having an account alone does not create an acceptance record. This declaration does not independently verify someone's age or parental relationship, and the sign-in form does not identify whether the account is for adult use or parent-managed use.

Device access

The API receives processor and storage-card identifiers, a derived device fingerprint, enrollment/account linkage, authentication proofs, time and replay-prevention information, running-version and update-result information. Infrastructure sees the connecting IP address. Linked identifiers are not anonymous. They support activation, trial/membership checks, abuse prevention and updates.

Orders and payments

Records include items or periods purchased, prices, currency, payment references, membership grants and fulfillment status. Arranging delivery requires recipient and carrier-contact information. Crypto records can include asset/network, addresses, expected and received amounts, status, fees and transaction/reconciliation references. Public blockchain information may be persistent and cannot be erased by aimbud.

Support

Support receives messages, attachments and information needed to investigate a request. Avoid sending passwords, seed phrases, unnecessary identity documents or unrelated personal information. A support attachment is not automatically a training contribution.

Discord ticket support: supplement dated 9 September 2026

If you open a Discord support ticket, the bot records your Discord user ID, profile-name and avatar snapshots, ticket participants, messages, replies, reactions, attachments, timestamps and support actions. We retain versions and deleted-message content that the bot actually captured. Deleting or editing a message in Discord does not automatically remove the captured support record. Contact [email protected] for privacy requests.

Ticket archives are stored in our database and are available to authorized aimbud support staff and moderators through the protected website viewer. They are not published as public transcript links. Optional account linking associates your Discord identity with your aimbud account after a separate authenticated confirmation; it does not give a moderator general access to your orders, payment records or device settings. Support content is not used for AI model training.

Website and security

Website-delivery and hosting systems process IP addresses, browser/device information, access times and security events. The current site also uses Cloudflare performance analytics and requests Discord community content.

5. Purposes and legal grounds

Necessary information is used for accounts, device access, requested purchases, membership, delivery, service messages, support and security. Other records support complaints, consumer remedies and legal obligations.

Where the GDPR or similar rules apply, we distinguish processing necessary to perform a contract with an adult customer, legitimate interests in proportionate security and service administration, applicable legal obligations, and separate consent where required for optional purposes. Processing must meet the conditions of the applicable ground; accepting terms is not itself a legal basis for every use of a young person's information.

Where consent is required, it must be separate and valid. Withdrawal stops the relevant future consent-based processing without making earlier lawful processing unlawful. Optional processing must not be presented as necessary for unrelated purchased features. Acknowledging this notice does not authorize a new use of data.

6. Providers and recipients

The following provider roles have been identified. The final inventory of legal entities, account-specific settings, regions, agreements and onward recipients is still being verified.

Provider or recipientInformation and purpose
Hosting infrastructureWebsite, API, database and operational security. Provider/region details remain to be finalized.
CloudflareWebsite delivery, protection and performance analytics; network and browser-performance information.
ResendEmail address and transactional message content, including verification, recovery and service messages.
DeBounceThe current signup check sends the submitted email address to screen disposable addresses.
Have I Been PwnedPassword-breach checking sends the first five hexadecimal characters of a password-hash value, not the password or full hash.
Google sign-inAuthentication exchange when you choose Google.
NOWPaymentsOrder/payment reference, price/currency, payment instructions, callbacks and status verification.
DiscordBrowser requests for community data and images expose network information before a link is necessarily clicked.
Google WorkspaceSupport email, sender/contact information, correspondence and attachments.
DiscordOptional community support channels, Discord profiles, ticket messages and attachments. Discord also processes information under its own privacy policy.
Jordan fulfillment and Jordan PostPlanned sharing of necessary recipient, order, delivery and customs information with fulfillment and postal partners. Exact entities and fields remain under review.

The inspected NOWPayments payment-creation request does not send the account name or email. The processor or exchange may independently request information for its own security/legal checks. Binance may receive merchant settlement funds; it is not an aimbud account-login integration.

Necessary and lawful disclosures may also be made to advisers or authorities for legal obligations, rights or disputes. A business reorganization requires its own lawful handling and notice; an affiliate is not automatically entitled to all customer data.

7. Staff and moderator access

The approved access policy gives support and shipping staff only information needed for their jobs. Designated support staff and moderators can read private Discord tickets and their archives. This does not grant access to private order, address, payment or device-setting administration. Avoid including unnecessary sensitive information in a ticket. Refund approval is reserved to the owner at launch.

These are approved requirements, not a claim that a complete role-based permission system has already been deployed. Detailed permissions, individual staff access and operating controls still require verification. Community moderation must not be treated as authorization for customer-database access.

8. Cookies, browser storage and external content

Necessary cookies support sessions, request protection and short-lived Google sign-in state. Blocking them can prevent sign-in or protected actions. The browser also stores a return destination and timestamp so sign-in can return to the requested page. Its current validity check is 30 minutes; that is not automatic deletion from browser storage. You can clear site storage in the browser.

Cloudflare performance analytics involve information processing even when cookieless. The current community component may request Discord data and images before you follow an external link. External providers' own notices also apply to their independent services.

Account-specific tracking behavior, regional consent requirements and handling of Do Not Track or Global Privacy Control are still being reviewed. We do not currently claim an implemented signal-response or optional-tracking control. A Privacy acknowledgment does not substitute for any separate consent or opt-out required by law.

9. Promotions and screenshot contributions

Promotional email

Our policy requires separate, initially unticked opt-in, with unsubscribe in each promotional email. Marketing provider, consent records and suppression controls are still being finalized. Account creation, Terms acceptance and Privacy acknowledgment do not subscribe an account. Necessary security, purchase and service messages are different from promotions.

Any marketing to eligible teens needs age-appropriate safeguards and parental authorization where required; a guardian's purchase is not marketing consent. No under-13 marketing is intended.

Future model-development contributions

The screenshot-contribution program is not enabled by this release. The initial approved scope is adults only, off by default, with separate opt-in and no contribution capture while someone under 18 uses the board. Its purpose is solely developing and evaluating aimbud models, not advertising or selling/licensing screenshots to other companies for their own use.

A gameplay classifier can make mistakes. Gameplay can itself contain chat, usernames, notifications, webcam overlays or other private details. No promise is made that a classifier removes all personal information. A separate launch notice must explain the sampling, local filtering, recipients, retention, pause/stop controls, deletion and treatment of trained models. Benefits have not been decided or promised.

Support attachments are not automatically enrolled. Any future opt-out must address new capture and queued uploads, and relevant rights must address identifiable retained samples and copies. Acknowledging this notice neither grants indefinite reuse nor promises instant removal from every already trained model.

Other commercial uses

The approved business policy prohibits selling or providing customer information for another company's advertising or independent commercial use. Necessary service/fulfillment processing and legal disclosures are separate. Provider arrangements still need verification against that policy; it is not a claim that no information is ever disclosed to anyone.

10. International processing

Operations include access from Jordan, planned Jordan fulfillment, and providers that may process information in multiple countries. US incorporation does not imply US-only storage or access.

Specific hosting, backup and support-access locations, recipient roles and any required transfer mechanisms are still being verified. We do not represent that unverified contractual safeguards, certifications or appointments already exist. Contact support about international handling; acceptance of terms is not blanket consent to every transfer.

11. Retention

Retention depends on the purpose, service relationship, recordkeeping obligations, disputes and justified security needs. One duration is not suitable for every kind of record.

The following limits are approved operating targets. Enforcement across live systems, email providers and backups is not yet verified; they must not be read as a claim that every existing copy is already deleted on these schedules.

  • Ordinary support messages: 12 months after case closure.
  • Support attachments: 30 days after case closure.
  • Routine website logs: 30 days.
  • Security logs: 180 days.
  • Backups: a rolling 30-day lifecycle.

For Discord tickets specifically, captured message text and edit/deletion history are retained for 12 months after closure; images, avatar snapshots and logs for one year; and supported short video clips for 30 days. Expired files are removed while a filename or expiry marker may remain until the transcript expires. Limited, documented retention may apply to a specific unresolved dispute or legal obligation, subject to applicable requirements. Privacy requests also cover relevant archive copies and search records. Backup copies age out under the backup lifecycle rather than disappearing immediately.

The inspected service schedules cleanup of expired or used login/recovery records, expired sessions and older audit events. Schedule eligibility is different from proof of completed deletion. Financial records require a separately confirmed accounting schedule; there is no asserted universal seven-year rule.

Closing an account or resetting a board does not necessarily erase records required for accounting, agreement evidence, remedies or a dispute. Agreement evidence is retained while needed to establish the applicable service or purchase terms and handle legal claims, subject to applicable retention and deletion requirements. Any retained information should be limited to its justified purpose. Public blockchain records cannot be erased by aimbud. Backup treatment and all other category-specific periods remain part of the retention review.

12. Requests and choices

Contact [email protected] about access, correction, deletion, a copy of your information or other applicable rights. Identify the relevant account/request without sending excessive documents. Proportionate verification may be needed before disclosure or changes.

Depending on the law, rights can also include objection, restriction, portability, consent withdrawal, specified opt-outs, appeal and complaints to a supervisory authority. Support will explain any lawful refusal and available review route. Acknowledging this notice does not waive these rights.

The approved human support-response target is two Sunday-Thursday business days. That is not a promise that a privacy request will be fully resolved in two days or a substitute for its applicable legal deadline. Operational request handling is still being finalized.

13. Younger users

The intended minimum use age is 13, with a parent/guardian purchasing and managing the account for one designated user aged 13-17. A parent should review this information with the young user. Contact support if you believe an under-13 account or other use contrary to the age policy exists.

The sign-in notice requires the person managing the account to declare that they are at least 18 and legally able to manage it. This is self-declaration, not independent age or guardian verification. An age statement alone does not prove that no under-13 information is ever received. Local requirements for consent can differ, and an adult purchase does not authorize every use of a teenager's data. Future screenshot contributions remain restricted to adult use and require a separate eligibility check and opt-in.

14. Security, checks and support

The inspected system uses encrypted transport, password hashing, authenticated device communication and signed updates. No system is perfectly secure. Those measures do not replace incident handling or required notifications.

Automated checks screen signups, validate access and payments and flag issues. A failed check can delay or prevent an action. Contact support to explain a suspected mistake and request human review.

The intended support model is help with specifically authorized aimbud settings, not remote desktop or shell access. Final device-image access and settings-assistance controls are still being verified; we do not make an absolute no-remote-access guarantee.

15. Changes and contact

This version was published on 7 September 2026. Material changes will be identified with a new version and notice where required. Archived versions remain available. A new purpose requiring permission is not authorized simply by editing this page or obtaining acknowledgment of it.

For questions and requests, contact [email protected].

Back to topContact support
© 2026 aimbud LLCVersion 2026-09-07.2