← Aperture

Privacy Policy

Last updated: 19 September 2026

Aperture is a NetSuite developer workbench. This policy explains what the web app can see and who helps run it.

Who we are

Aperture is operated by the independent author of the application. Support: in-app Feedback (bottom-right), email wassemcs@gmail.com, or tips via Buy Me a Coffee / Instapay (tips never unlock features).

Children

We do not knowingly collect personal information from anyone under 13. Aperture accounts require you to confirm you are 13 or older when you sign up or sign in. If we learn an account belongs to someone under 13, we will delete it. Contact wassemcs@gmail.com if you believe we have collected data from a child.

Subprocessors

  • Supabase — Auth (including signup confirmation emails), database, and related cloud storage
  • Vercel — Application hosting
  • Resend — Transactional mail for recovery-email links and codes, and when paid billing is live, payment receipts and billing notices
  • PostHog (EU) — Product analytics, exception capture, optional session replay, heatmaps, and web vitals (browser → /ingest proxy), only after you accept analytics cookies

What we store when you use the cloud

  • Account identity from sign-in (email, display name, avatar, provider). Email/password accounts confirm via a time-limited link before the desk opens.
  • Tickets, activity events, inventory snapshots, log caches, fixtures, test-run ledgers
  • Key metadata (name, provider, last4, expiry / certificate dates). NetSuite OAuth private keys and client ids are encrypted at rest and are never returned to the browser after save
  • Optional Notion page ids (not the secret contents of your whole workspace)
  • Product feedback (bug / feature text, stamp version, page path) for Super Admin review

Cookies

  • Essential: sign-in session, Demo mode (aperture_demo), signed unlock cookie, onboarding marker. These are required for the desk to work.
  • Analytics (optional): PostHog, only if you choose Accept analytics on the cookie notice. That enables product events, exception capture, masked session replay, heatmaps, and performance vitals. Choose Essential only to opt out; we respect that choice on later visits (local storage and a first-party consent cookie). Sensitive fields (passwords, PEM, passcodes) are masked in replays.

What we do not do

  • Store NetSuite private keys or client ids as plaintext in the database
  • Re-display or export your PEM in the UI after you connect
  • Put full API keys, TBA tokens, or private certificates in Notion, tickets, or localStorage
  • Share credentials across Environments or clients
  • Let Demo mode read your live environments or keys
  • Train a public model on your SuiteScript unless you later opt in
  • Auto-promote to Production
  • Copy SuiteForge or replace Cursor
  • Send NetSuite passwords through Aperture (OAuth 2.0 client credentials per environment)

Retention

Account and workbench data stay while your account exists. Analytics events and replays follow PostHog’s retention on the EU project. Feedback rows are kept until reviewed and removed by Super Admin.

Delete

Use Settings → Delete my account. That runs delete_my_account() and removes your profile row and owned tickets where the schema allows.

Privacy · Terms · FAQ