Last updated August 21, 2026

AQUA Privacy

AQUA Application Hub is operated by Ello Cello LLC. This page summarizes the main information the product handles and the controls reflected in the current application architecture.

Information used by the product

AQUA may process account identity needed to authenticate a user, profile information the user supplies, application questions and source material the user imports, answers and answer-version history, review and stress-test records, opportunity-fit data, and billing or subscription state when paid features are used. The system also handles ordinary request and operational metadata required to run a web application.

Application answers and answer history are sensitive user data. Users should avoid placing passwords, private API keys, authentication tokens, or unrelated secrets inside application-answer text or other fields intended for ordinary application content.

Storage, access, and credentials

Supabase is the current system of record for the application. User-scoped information is protected through authentication and row-level access controls. Bring-your-own-key provider credentials are intended to remain server-side and are encrypted when persisted. Service-role keys, webhook signing secrets, and integration encryption keys are server-side secrets and must not be exposed to frontend code.

The product preserves answer versions and review history so users can retain lineage between source material and later variants. That history is operational product data and should be handled with the same care as the current answer bank.

Providers and user choices

AQUA supports bring-your-own-key model providers. When a user enables one of those providers, selected drafting or review material may be sent to that provider under the provider's own terms and privacy practices. Billing flows may use Stripe. Hosting, authentication, database, email, and delivery infrastructure may process the information necessary to provide their respective services.

AQUA's application and scoring features are intended to help a user prepare and organize their own material. Public program records and internal fit signals should not be read as permission to disclose another user's answers or private profile data.

Privacy requests

For privacy, access, correction, or deletion questions, contact burnmydays@proton.me. Include the account email or other identifier necessary to locate the relevant account, but do not send passwords, private API keys, or authentication tokens. Business contact information and the mailing address are published on the Contact page.