Last updated October 2, 2026
AQUA Privacy
AQUA Application Hub is operated by Ello Cello LLC. This page summarizes the main information the product handles and the controls reflected in the current application architecture.
Information used by the product
AQUA may process account identity needed to authenticate a user, profile information the user supplies, application questions and source material the user imports, answers and answer-version history, review and stress-test records, opportunity-fit data, and billing or subscription state when paid features are used. The system also handles ordinary request and operational metadata required to run a web application.
Application answers and answer history are sensitive user data. Users should avoid placing passwords, private API keys, authentication tokens, or unrelated secrets inside application-answer text or other fields intended for ordinary application content.
Storage, access, and credentials
Supabase is the current system of record for the application. User-scoped information is protected through authentication and row-level access controls. Bring-your-own-key provider credentials are intended to remain server-side and are encrypted when persisted. Service-role keys, webhook signing secrets, and integration encryption keys are server-side secrets and must not be exposed to frontend code.
The product preserves answer versions and review history so users can retain lineage between source material and later variants. That history is operational product data and should be handled with the same care as the current answer bank.
Providers and user choices
AQUA supports bring-your-own-key model providers. When a user enables one of those providers, selected drafting or review material may be sent to that provider under the provider's own terms and privacy practices. Billing flows may use Stripe. Hosting, authentication, database, email, and delivery infrastructure may process the information necessary to provide their respective services.
AQUA's application and scoring features are intended to help a user prepare and organize their own material. Public program records and internal fit signals should not be read as permission to disclose another user's answers or private profile data.
AQUA IDP plugin
AQUA IDP is the separate, local-folder plugin. It preserves application sources, indexes original questions, catalogs earlier answers as review candidates, stores new answer versions, and prepares Markdown drafts. It uses files, URLs, and professional context the user provides or authorizes through the host. It does not create an AQUA website account or independently sign in to private accounts.
What stays in your workspace
The plugin writes source copies, question indexes, applicant context, historical answer candidates, approved answer versions, drafts, and progress records to the folder the user chooses. The publisher does not receive this application content through the plugin's normal file workflow. The files remain until the user or their host deletes them; the plugin does not impose a remote retention period on the user's folder. The host running AQUA IDP may process the conversation, authorized URLs, and files under that host's own terms and privacy policy.
Optional beta reports
Issue details and technical tracebacks are saved in a local Beta Reports/ folder. Automatic delivery is off by default. If the user turns it on, the plugin sends a random report ID, time, plugin version, command, issue type, error class, grouping fingerprint, Python version, and operating-system name over HTTPS to the AQUA beta receiver. It does not include application questions, answers, source files, file paths, the local issue description, or traceback in that request. The Cloudflare-hosted receiver uses the request IP address for rate limiting but does not place it in the saved report record. Received report records expire after 30 days; infrastructure-level logs may have separate retention. The user can turn off future delivery with beta-reporting --disable and delete reports in their own workspace.
Your controls
Users choose which sources AQUA IDP sees and can inspect, edit, export, or delete their local workspace. Earlier submitted answers are not automatically approved for future use; a new or changed answer requires explicit approval. AQUA IDP is not designed to process payment-card data, protected health information, government identifiers, passwords, API keys, or one-time codes. Redact those before supplying an application. For help deleting local reports or a privacy request about an optional beta report, visit AQUA IDP support and include the report ID if available.
Privacy requests
For privacy, access, correction, or deletion questions, contact burnmydays@proton.me. Include the account email or other identifier necessary to locate the relevant account, but do not send passwords, private API keys, or authentication tokens. Business contact information and the mailing address are published on the Contact page.