About This Policy
Aspirenet respects your privacy. This policy explains what information we receive when you use the Aspirenet app, how we use it to provide the service, when we share it, and the choices available to you.
It applies to the Aspirenet app and the account, messaging, discovery, Collab, Link, and verification features available through it. By creating an account or using Aspirenet, you acknowledge this policy. If you do not agree with it, please do not use the app.
This policy should be read with our Terms and Conditions. The terms in this policy have the meanings given to them in the context of Aspirenet, including Creator, Brand, Collab, Link, Rank, and XP.
What Aspirenet Collects
We receive information in three ways: you provide it, the app records it when you use a feature, or a connected service returns it after you authorise a verification.
Account and Identity Information
- Email address
- Password, stored as a cryptographic hash and never in plain text
- Authentication method, including email and password, Google Sign-In, or Apple ID sign-in
- Account creation date
Profile Information
- Name and username
- Profile photo
- Biography or description, up to 150 characters
- Ambition or goal statement
- Skills and interests provided by you
- What you want to work on, up to 120 characters
- Short-term or long-term collaboration preference
- Standing, rank, and XP
- Social links, including the platform, label, and URL
Location Information
- Precise or approximate GPS coordinates, only when you explicitly enable location features
- Optional city and country information
Message Information
- Text messages you send and receive
- Voice recordings you create and send within the app
- Images, files, and other attachments shared in conversations
- Emoji reactions
- Message metadata, including timestamps, delivery status, read receipts, and sender and recipient identifiers
- References to messages you reply to
Discovery and Matching Data
- Your skills, interests, ambition, bio, collaboration preference, and project description are used as matching inputs
- Your location and experience rank may be used to sort suggestions
Collab and Task Data
- Collab group membership
- Task title, description, deadline, assigned users, subtask items, completion status, and score from 0 to 100
- Monthly task completion records and timestamps
- Approval status and approver identity
Link Data
- Link requests sent and received, including an optional request message of up to 500 characters
- Pending, accepted, or rejected Link status
- Timestamps for each status change
Push Notification Tokens
We collect the device-specific push notification token issued by Firebase Cloud Messaging.
Automatically Collected Information
- Activity streaks
- Unread message counts for each conversation
- Online or active status, maintained through Redis and not shown as a public status indicator
Google and YouTube Data
If you choose to verify a YouTube channel, Aspirenet asks for read-only access to your YouTube account through Google OAuth using the youtube.readonly scope. We access the Google access token and the channel ID, public handle, and channel title returned for the YouTube channel controlled by the signed-in Google account. We do not use this permission to upload, edit, or delete YouTube content, or to access your videos, subscriptions, comments, or private messages.
Instagram OAuth Data
If you choose to verify an Instagram account, Aspirenet requests the instagram_business_basic permission through Instagram OAuth. Instagram provides an authorization code, which our backend exchanges for an access token. We use that token to retrieve the account ID and username of the Instagram Business or Creator account that authorised the connection. We do not use the OAuth token to publish, edit, or delete Instagram content.
X OAuth Data
If you choose to verify an X account, Aspirenet requests the users.read and tweet.readpermissions through X OAuth. X provides an authorization code, which our backend exchanges for an access token. We use that token only to call X's current-user endpoint and retrieve the account ID and username that authorised the connection. Aspirenet does not retrieve your posts during the ownership-verification flow and does not use the token to publish, edit, or delete content.
How We Use It
We use the information we receive to run Aspirenet and to provide the features you choose to use.
Account and Identity Information
- Create and authenticate your account
- Verify your identity with a one-time password sent by email during registration
- Manage your session and keep you signed in
Profile Information
- Display your profile to other users
- Power discovery and matching
- Search users by name, username, skills, and bio
Location Information
- Optionally sort discovery results by proximity
- GPS coordinates are fetched at the time of use and either stored on your profile or passed to the server temporarily for sorting. We never track them in the background.
Messaging Information
- Transmit messages, voice recordings, and attachments to their intended recipients in real time
- Retain conversation history across your devices and sessions
- Display reactions, reply context, and read or delivery status
- Store shared media and files on AWS S3 so recipients can access them
- Use aggregated, non-identifiable metadata, such as delivery failure rates, to diagnose messaging reliability
Discovery and Matching Data
- A recommendation model computes similarity between your profile and other profiles using shared interests, skills, and ambitions. Results may also be sorted by proximity.
- Anthropic Claude analyses your project description to identify skills your project needs. Only your skills and project description are sent to the Claude API for this purpose.
- Your consecutive active days are recorded as an activity streak.
Collab and Task Data
- Manage collaborative projects
- Track task progress, completion rates, and scores
- Calculate XP and experience rank awarded when tasks are completed
Link Data
- Manage your professional network within Aspirenet
- People you have linked with may see more profile details than other users
Push Notification Tokens
- Deliver notifications for incoming calls, messages, and Link requests
- Remove tokens when the notification service reports that they have expired
YouTube Channel Verification
We use Google and YouTube data only to confirm that you control the YouTube channel entered in your Aspirenet profile and mark it as verified. This optional feature starts only when you choose it. We do not use Google user data for advertising, user profiling, credit decisions, or training artificial intelligence or machine-learning models.
Instagram and X Account Verification
We use Instagram and X OAuth data only to confirm account ownership, prevent one social account from being claimed by multiple Aspirenet users, and mark the account as verified. These connections are optional and begin only when you choose to verify an account. We do not use this OAuth data for advertising, credit decisions, or training artificial intelligence or machine-learning models. Public follower counts and public content used for creator features come from public sources and do not rely on stored Instagram or X OAuth tokens.
Services That Process Data
Some parts of Aspirenet rely on service providers. We give them only the information needed for the task they perform for us, and we do not sell your personal information.
- Google and YouTube. During YouTube verification, our backend validates the Google access token with Google's token-information service and uses the YouTube Data API to retrieve the signed-in user's channel ID, public handle, and channel title. Google processes these requests under its own privacy policy.
- Instagram and Meta. Instagram receives the authorization request. Our backend exchanges the returned code for an access token, then uses the Instagram Graph API to retrieve the account ID and username.
- X. X receives the authorization request. Our backend exchanges the returned code for an access token, then uses X's API to retrieve the account ID and username.
- Infrastructure providers. AWS, MongoDB, Redis, Firebase Cloud Messaging, and other providers may process information to host the app, store files, maintain presence and notification features, or operate the account. They may not use your information for their own advertising or unrelated purposes.
- Anthropic Claude. When Aspirenet identifies skills a project may need, we send only the project description and the skills associated with that project to Claude for that task.
- Other Aspirenet users. Information that you make part of your profile, such as your username, social link, channel title, or verified status, may be visible to other users. OAuth authorization codes and access tokens are not shown.
We do not sell Google, Instagram, or X OAuth data or provide it to an organisation for its own unrelated use. We may disclose information if the law requires it or when disclosure is needed to protect users or Aspirenet's security.
Aspirenet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Permissions and Location
Aspirenet may ask for access to your camera, microphone, photo library, and location services. The app uses each permission only when you use a feature that needs it. You can allow, refuse, or later change these permissions through your device settings.
Location features are optional. When you use them, Aspirenet may request precise or approximate GPS coordinates to sort discovery results by proximity. We fetch location at the time of use and do not track your location in the background.
How We Protect It
We use technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, or destruction.
Your data travels over TLS encryption and is stored on secure servers. Audio messages, images, and other attachments are stored on encrypted AWS S3 infrastructure with access controls that restrict retrieval to authorised parties.
No internet transmission or electronic storage method is completely secure, so we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for activity under your account.
If we learn of a data breach that affects your personal information, we will notify you as required by applicable law.
Your Choices and Rights
Depending on where you live, you may have the following rights over your personal information:
- Access. Request a copy of the personal data we hold about you.
- Correction. Ask us to correct inaccurate or incomplete information.
- Deletion. Ask us to delete your account and associated personal data.
- Portability. Ask us to provide your data in a structured, machine-readable format.
- Objection or restriction. Object to or ask us to restrict certain kinds of processing.
- Withdraw consent. Where processing depends on consent, withdraw it at any time without affecting earlier lawful processing.
To exercise these rights, email aspirenetcontact@gmail.com. We will respond within 30 days and may need to verify your identity first.
If you are in the European Economic Area, you may also lodge a complaint with your local data protection authority.
Children and Safety
Aspirenet is not intended for anyone under 18, and we do not knowingly collect personal information from children.
If you are a parent or guardian and believe your child gave us personal information without your consent, email aspirenetcontact@gmail.com or contact support. After verification, we will delete the information from our systems.
If we discover that we collected personal information from someone under the applicable minimum age, we will take immediate steps to delete it.
Deletion and Retention
You can delete your account through the Settings menu in the Aspirenet app. Account deletion permanently removes your profile, Links, and message history. We remove profile data and messages from our active databases within 30 days, except where the law requires us to keep them.
The Google access token used for YouTube verification is used only during the verification request and is not stored. We retain the verified channel ID, handle or title, platform, and verification status while your Aspirenet account is active. Instagram and X authorization codes and access tokens are also used only during verification and are not stored. We retain the verified account ID, username, platform, and verification status while your account is active. We delete these records when we delete your account, subject to any retention required by law.
Why We Process Data
Under laws including the GDPR and CCPA, we process information when you consent to a feature, when it is needed to provide Aspirenet, or when we have a legitimate interest in keeping the app secure and reliable. For example, location features rely on your permission, message delivery relies on providing the service, and reliability work relies on our legitimate interest in operating Aspirenet.
Where Data Is Processed
Our AWS and MongoDB servers are in the Asia Pacific Mumbai region. Your information may be transferred to and processed in India. By using Aspirenet, you acknowledge this transfer.
Policy Updates
We may revise this policy when our practices, legal requirements, or Aspirenet features change. We will update the date at the top of this page.
If a change materially affects how we use your information, we will provide a more prominent notice, such as an in-app notification or an email to the address linked to your account, before the change takes effect.
If you continue to use Aspirenet after the revised policy takes effect, the updated policy will apply to your use of the app. If you do not agree, stop using Aspirenet and request account deletion.
Contact Aspirenet
Questions about this policy, your information, or a rights request can be sent to aspirenetcontact@gmail.com. You can also contact support.