Privacy Policy

Last updated: May 24, 2026

What this policy covers

This policy explains what data Aksara collects, why, and who we share it with. Aksara is operated by Echoforge, a Delaware company. If you have questions, email fabio@echoforge.to.

Data we collect

We collect only what we need to run the service.

  • Account data. When you sign up, we store your email address, display name, and avatar. If you sign in with GitHub or Google, we receive what those services share (see OAuth sections below).
  • Profile content. Everything you add to your Aksara profile: bio, links, projects, images, and other content. Your profile is public by default at aksara.so/username.
  • GitHub import data. If you use the GitHub import feature, we fetch your public repository list temporarily to let you select projects. We do not store your full repo list after the import is complete.
  • Billing data. If you subscribe to Aksara Pro, Stripe collects your name, email, card details, and billing address. We store only what Stripe returns after a successful payment: your Stripe customer ID, subscription status, and the last 4 digits of your card for display purposes.
  • Usage data. We log product events (page views, profile edits, project saves, sign-ins, sign-outs, feature usage) via PostHog to understand how the product is used and where to improve it.
  • Technical data. Vercel, our hosting provider, logs standard request data: IP address, user-agent, referrer, and response codes. We do not process this data ourselves.

Third-party services

We use the following services to run Aksara. Each one receives only the data they need for their specific role.

Supabase

Our database, authentication, and file storage provider. Supabase hosts all user data including account information, profile content, and uploaded images. Supabase is GDPR-compliant and SOC 2 Type 2 certified. Their privacy policy is at supabase.com/privacy.

PostHog

We use PostHog for product analytics. PostHog receives your user ID (pseudonymous), the events you trigger (such as pageviews, profile edits, project saves, feature interactions, and sign-outs), and basic browser/device metadata. PostHog does not receive your password or payment details.

PostHog sets a session cookie to identify your browsing session. If you prefer not to be tracked, you can opt out at any time from your account settings. Their privacy policy is at posthog.com/privacy.

Stripe

We use Stripe to handle payments. When you enter payment information, it goes directly to Stripe. We never see or store your full card number. Stripe receives your name, email address, card details, and billing address. Their privacy policy governs payment data: stripe.com/privacy.

GitHub OAuth

If you sign in with GitHub, GitHub shares your name, email address, and avatar with us. If you use the GitHub import feature, we also request read access to your public repository list. We store only the profile fields needed for your Aksara account. We do not store your GitHub access token beyond the current session.

Google OAuth

If you sign in with Google, Google shares your name, email address, and avatar with us. We store only the profile fields needed for your Aksara account. We do not request access to Gmail, Google Drive, or any other Google service.

Vercel

Aksara is hosted on Vercel. Vercel logs basic request data including IP address, user-agent, referrer, and HTTP response codes. This data is retained per Vercel's policy at vercel.com/legal/privacy-policy. We do not process Vercel's request logs ourselves.

Cookies and tracking

We use two types of cookies:

  • Supabase auth cookies. When you sign in, Supabase sets an httpOnly session cookie to keep you logged in. This cookie is required for the service to work. It contains no personally identifiable information directly; it references your session on Supabase's servers.
  • PostHog session cookie. PostHog sets a cookie to identify your browsing session for analytics. This is not required for core functionality. You can opt out from your account settings.

We do not use advertising cookies. We do not use third-party tracking pixels.

Your rights and controls

  • Access your data. Your public profile is visible at aksara.so/username. Your account details are accessible from your account settings page.
  • Export your data. You can export your profile data from your account page at any time.
  • Delete your account. Go to your account page and select "Delete account." This permanently deletes your profile, content, and account data from our systems. Stripe retains billing records as required by law. PostHog retains anonymized event data per their retention policy.
  • Opt out of analytics. You can disable PostHog tracking from your account settings.
  • Correct your data. You can edit your profile and account details directly from your account settings.

If you need help with any of these, email fabio@echoforge.to and we will respond within 5 business days.

Data retention

  • Account and profile data is retained until you delete your account.
  • Analytics events are retained for 90 days by default per PostHog's standard plan settings.
  • Payment records are retained by Stripe and may also be retained by us as required by applicable tax and financial regulations, typically for 7 years.
  • Vercel request logs are retained per Vercel's policy, which we do not control.

Data sales and marketing

We do not sell your personal data. We do not share your data with advertising networks. We do not use your data to serve targeted ads.

Children

Aksara is not directed at children under 13. If you believe a child under 13 has created an account, contact us at fabio@echoforge.to and we will delete the account.

Changes to this policy

If we make material changes to this policy, we will notify you by email at least 30 days before the changes take effect. The latest version will always be at aksara.so/privacy. The "Last updated" date at the top tells you when this version was published.

Contact

Questions about this policy: fabio@echoforge.to