Account privacy.
Updated October 3, 2026
This page explains the data used by Aster’s website signup, sign-in and download area. A free account does not start a paid subscription.
What the account service uses
- Your email address to send requested account verification or recovery links and identify your account. Your password is sent securely to the authentication provider for verification.
- Account creation and verification times, plus temporary sign-in proofs and sessions.
- Keyed hashes of IP addresses and email addresses for request limits and account lookup. The application’s rate-limit records do not store raw IP addresses.
Email addresses and pending email content are encrypted in the account store. Sign-in links expire after 10 minutes and work once. Session cookies are secure, HttpOnly and host-only, and expire after 8 hours, or 30 days if you choose to stay signed in. The owner dashboard requires a password sign-in within the last 15 minutes. Password changes revoke older Aster sessions. Signing out revokes the current session.
Why and where this is processed
The service uses this information to verify email ownership, open your account, authorize downloads and limit abuse. Cloudflare hosts the website and account service; Resend delivers account emails. Supabase manages password verification. Aster does not store plaintext passwords. These providers process request and delivery information as part of operating their services.
This signup form is not a marketing subscription. It does not ask for payment-card details. The website account/download flow does not upload your controller inputs, saved profiles or macros.
Membership, payments and activation
If you choose a membership, Stripe Managed Payments processes checkout through Link. Payment-card details go to the payment provider, not the Aster account store. Aster records checkout and subscription references, payment status and paid-through dates so it can verify access.
Activation uses an installation identifier and public verification key to bind access to one computer. Aster stores that binding, issued-permit expiry times, transfer requests, complimentary grants and access-change history. Activation codes and pending service-email content are encrypted in storage. Your private device key stays on your computer. Service emails link back to your signed-in account; they do not include your activation code.
Account or access changes do not themselves cancel billing. Use the management link in your Link receipt to manage a subscription or contact support. Payment providers retain transaction records under their own requirements.
Website measurements and daily reports
Cloudflare Web Analytics measures visits and page views on the public homepage to help us understand website activity. Cloudflare processes these browser measurements using the configured analytics settings. Some visits are not measured, including visitors excluded by the regional setting or whose browser blocks the measurement script.
Private daily reports combine website measurements with account-signup totals and membership and payment totals when available. Daily reports use aggregate counts and do not include customer email addresses. A visit is not a uniquely identified person, and website visits are not linked to an individual account in these reports.
Retention and your choices
Expired sign-in proofs are removed by the service’s cleanup process. Verified account records remain until removed. Provider delivery and operational records are subject to their own retention practices.
To request a copy, correction or removal of your account information, email support@astergg.com from your account email. We may need to verify ownership before making a change. Do not include your sign-in link, password or payment details.