LEGAL • PRIVACY

Privacy Policy

How AESIR handles your data across all programs.

Last updated: 16 July 2026 · Effective immediately

Plain-English Summary

AESIR builds defense and commercial technology. Different products handle different kinds of data; the per-product sections below describe what each one collects. The basics across everything we do:

  • We only collect data we need to deliver the product you're using.
  • We do not sell your data. Ever.
  • We do not share data between products without your consent.
  • You can request access, correction, or deletion of your data at any time.
  • If a third-party service is involved (an AI provider, Apify, Hunter, etc.) we identify it in the relevant product section.

HEIMDALL operates on a separate domain (heimdall.projectaesir.com), including OAuth connections to third-party platforms (TikTok, Instagram, YouTube, LinkedIn, X). Its data practices are covered in full in the HEIMDALL section below — what it holds about operators versus leads, OAuth scopes and token storage, and every third party it calls.

Who We Are

AESIR is a defense technology and commercial AI company founded by Gage Ludwig. Our products serve special operations forces, defense contractors, and commercial operators. Contact: [email protected].

This policy covers projectaesir.com and all subdomains (heimdall.projectaesir.com, etc.) and all products listed below, unless an individual product publishes a more specific policy at its own URL.

General Data Practices

What we typically collect

  • Account data — email, name, hashed password, organization name (where applicable).
  • Usage data — what features you use, error logs, request timestamps. Used for debugging and improving the product.
  • Communications — when you email us or fill in a contact form, we keep the message so we can reply.
  • Technical & security data — IP address, request timestamps, and an audit trail of security-relevant actions (logins, data changes, and safety flags). Kept to secure the platform, prevent abuse, and debug issues.

What we never do

  • Sell or rent your personal data to anyone.
  • Use your data to train AI models for other customers.
  • Track you across the web with advertising cookies (see Cookies below).

Where data lives

All AESIR data is stored on infrastructure we directly control (on-premise servers in the United States). Some operations call third-party APIs (listed per product); those calls send only the minimum data required. Where a feature sends your input to a third-party AI provider (Anthropic's Claude API), that data is processed under the provider's commercial API terms, which prohibit the provider from using your data to train its models and impose only a short abuse-monitoring retention window.

By Product

Each AESIR product handles data differently because each does different work. Sections below describe what each product collects, why, and from whom.

HEIMDALL — AI-Driven Market Intelligence & Revenue Engine

Surface: heimdall.projectaesir.com

HEIMDALL helps operators discover, evaluate, and reach out to ecommerce brands. It collects two distinct categories of data:

About operators (people who use HEIMDALL):

  • Email, hashed password, organization name, role, brand profile (services / value prop / tone — for AI personalization).
  • Optional connected social handles for any of: Instagram, TikTok, YouTube, LinkedIn, X. We use these to fetch public bio / followers / recent post themes so the AI can personalize outbound emails in the operator's voice.
  • Optional OAuth access tokens for connected platforms. Tokens are AES-GCM encrypted at rest; they are read-only and used solely to fetch public profile metadata.
  • Optional SMTP/IMAP credentials for sending outreach and parsing replies. Also AES-GCM encrypted at rest.

About leads (the brands operators research):

  • Public business data: domain, brand name, product category, price range, social handles, follower counts, public emails / phone numbers scraped from the brand's own website or returned by Hunter / Apollo.
  • AI-generated analysis (brand reports, fit scores, outreach drafts).
  • Decision-maker contact information where publicly listed.

Third parties HEIMDALL uses:

  • AI inference provider — AI brand analysis, outreach drafting, intent classification.
  • Apify — Instagram / TikTok / YouTube / LinkedIn / X / Etsy / Amazon scraping.
  • Hunter.io — email discovery + verification.
  • Apollo.io — optional, on-demand decision-maker phone reveal.
  • Meta, TikTok, Google, LinkedIn, X — only when an operator actively connects their own social profile via OAuth.
  • Cloudflare — DNS + tunnel for the heimdall.projectaesir.com domain.
  • Plausible — privacy-friendly analytics for the marketing site only (no cookies, no cross-site tracking).

OAuth access tokens are read-only, AES-GCM encrypted at rest, and used solely to fetch public profile metadata; you can disconnect any platform at any time from HEIMDALL's settings. To request access to, correction of, or deletion of data HEIMDALL holds about you, see Your Rights below or email [email protected].

BIFROST — Closed-Loop Rebreather

BIFROST is hardware (combat diving life-support). The product itself does not collect personal data. Customer interactions — sales inquiries, defense-contracting communications — fall under the General Data Practices above.

SINDRI — Autonomous Bug Bounty System

SINDRI is an internal AESIR system that operates on authorized external attack surfaces in scope of bug-bounty programs we participate in. It does not handle data of website visitors or third-party customers. When SINDRI submits a finding to a bug bounty platform, that platform's privacy policy governs the submission.

MIMIR — Self-Hosted Autonomous AI

MIMIR is deployed either fully local (no data leaves your infrastructure) or cloud-hosted by us. In the cloud-hosted configuration, prompts and responses are stored only for the duration needed to deliver the response unless you explicitly opt in to retention for fine-tuning. MIMIR is not used to train models on customer data without explicit, contract-level opt-in.

LIMITING FACTOR — Adaptive Training Platform

Surface: app.projectaesir.com

LIMITING FACTOR is an adaptive training platform used both by active-duty service members preparing for selection pipelines (BUD/S, SFAS, MARSOC, RASP, PJ/CCT, Delta, etc.) and by individual civilian athletes training toward their own goals. It collects training logs and program-adherence data; a PAR-Q health screening and the resulting medical-clearance flag; injuries, pain, and physical limitations you report; readiness and biometric inputs you choose to enter (sleep, soreness, energy, stress, HRV, body weight, RPE) and any free-text notes; and nutrition entries (including coach-assigned nutrition plans). For athletes managed by a military unit, the account may also hold unit-relevant profile fields such as rank/unit, blood type, medical notes, and an emergency contact.

Some of this is health-related, sensitive information. LIMITING FACTOR is a fitness product, not a healthcare provider, and is not a HIPAA-covered entity; we treat this data as sensitive and use it only to render your own dashboard, guide your training, and — where you consent — allow your coach or unit to view it. No data is shared outside your team account (or, for solo athletes, with anyone) without your explicit consent, except as described in "AI coaching" below.

AI coaching:

The individual and team AI coach features send the information you enter — your goal and goal notes, any injuries, pain, or PAR-Q medical-screening flags you declare, your daily readiness check-ins (sleep, soreness, energy, and any free-text note), your body-weight entries, and the messages you send the coach — to our AI inference provider, Anthropic (the Claude API), which generates your training session and coaching replies. Under Anthropic's commercial API terms this data is not used to train Anthropic's models and is retained only briefly for abuse monitoring. If no AI provider is configured, the coach falls back to a deterministic plan and your data stays on infrastructure we control.

Automated safety monitoring:

To keep athletes safe, free text you enter into the coach chat, daily readiness check-in, and mid-workout adjustments is automatically screened for signs of a medical emergency, a self-harm or suicide crisis, or disordered eating. If a message trips this screen, we show you crisis resources and flag it for human review instead of generating an AI coaching reply, and — if you train with a military unit — send an alert to your team's Head Coach. We record that a flag occurred (its severity and category), but we do not store your original free-text wording in the general security audit log.

Mobile number & text messages (SMS): (see our SMS Program page)

  • Your mobile number is used as your login identifier and to deliver a login code when you request one (transactional).
  • If you opt in, we send recurring training reminders by SMS. Opting in via the in-app reminders toggle, the SMS consent box at signup, or by texting START is your express consent to receive automated texts. Message frequency varies; message & data rates may apply.
  • You can opt out any time by replying STOP to a message, or from your account settings. Reply HELP for help, or START to opt back in.
  • If a coach or team lead enters your number to send you an access code, they must first confirm you agreed to receive it; we record that attestation as proof of consent.
  • Consent to receive SMS is not a condition of purchase.
  • We do not sell or share your mobile number or SMS consent with third parties, and mobile opt-in data is never shared for third-party marketing. SMS is delivered via our messaging provider (Twilio) solely to send you these messages.

Third Parties

We use the following third-party services across AESIR products. Each link goes to that provider's privacy policy.

  • Anthropic (Claude API) — AI inference for analysis, drafting, and classification, and Limiting Factor coach session generation, briefings, chat, and safety screening; processed under Anthropic's commercial API terms (no training on your data).
  • Apify — public-data scraping.
  • Hunter.io — email discovery.
  • Apollo.io — optional contact enrichment.
  • Cloudflare — DNS, CDN, tunnel.
  • Twilio — SMS delivery for Limiting Factor login codes & reminders.
  • Plausible — privacy-respecting analytics (no cookies, no personal data).
  • Operator-initiated OAuth providers (Meta/Instagram, TikTok, Google/YouTube, LinkedIn, X). Each provider's policy applies when an operator chooses to connect.

Cookies & Analytics

We use session cookies only — the cookie needed to keep you logged in after authentication. No advertising cookies, no cross-site trackers, no fingerprinting.

Analytics on the marketing site (projectaesir.com) is handled by Plausible, which does not use cookies and does not collect personally identifying information.

Data Retention

  • Account data — retained for the lifetime of your account, plus 90 days after deletion request to allow recovery in case of mistake.
  • Operational logs — 90 days, then aggregated or deleted.
  • HEIMDALL lead/brand data — retained until the operator deletes the lead or closes the tenant.
  • OAuth tokens — retained until the operator disconnects the platform, the token expires, or the operator deletes their account.
  • LIMITING FACTOR athlete data — retained until the athlete deletes their account. Individual (non-unit) athletes can trigger this deletion themselves from their account settings, immediately and irreversibly.

Data Breach Notification

If we discover a breach of security that compromises your personal information, we will notify affected users and any regulator or authority required by applicable law without undue delay after confirming the incident, describing what happened, what data was involved, and the steps we are taking.

Your Rights

Regardless of where you live, AESIR honors these rights for everyone whose data we hold:

  • Access — request a copy of the data we hold about you.
  • Correction — ask us to fix anything inaccurate.
  • Deletion — ask us to delete your data. We will, unless a legal hold requires retention. If you signed up for Limiting Factor as an individual (an account not managed by a unit), you can also delete your account and all associated data immediately from your account settings — no email needed; unit-managed athletes are removed by their unit lead.
  • Export — request your data in a machine-readable format. Limiting Factor individual athletes can download all their data as JSON from account settings.
  • Withdraw consent — disconnect any OAuth integration, revoke SMTP credentials, or stop SMS (reply STOP to any text, or turn off reminders in your account settings), at any time from the app's settings.

California residents (CCPA/CPRA): you also have the right to know what personal information we collect, to delete it, to correct it, to opt out of any sale or sharing (note: we do not sell or share personal information), to limit our use of sensitive personal information, and not to be discriminated against for exercising these rights.

EEA/UK residents (GDPR/UK GDPR), where it applies to you: our legal bases for processing are performance of our contract with you, your consent (for example, SMS reminders and processing of sensitive health-related data), and our legitimate interests. You may withdraw consent at any time and have the right to lodge a complaint with your local data-protection supervisory authority.

To exercise any of these rights, email [email protected] with the subject "Privacy request". We respond within 30 days; usually within 72 hours.

Children

AESIR products are not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe we have done so, contact us and we will delete it.

LIMITING FACTOR collects fitness and health-related information and can send automated text messages. If you are 13–17, you may use LIMITING FACTOR only with the involvement and consent of a parent or legal guardian, who must agree to these terms and to any SMS enrollment on your behalf. We do not knowingly enroll anyone under 18 in recurring SMS reminders without such consent.

Changes to This Policy

Material changes will be announced via email to active operators and prominent notice on our site at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Contact

AESIR
Email: [email protected]
Privacy requests: [email protected]