Privacy & Cookie Policy
Last updated: 28 August 2026
This Policy explains how Aurora SS Group ("we", "us", "our") handles personal data in connection with the Ionika project website at ionika.cc (this "Site"), and what rights you have. Aurora SS Group is the controller of the personal data described here. For any privacy question or request, contact us at ionikasupport@gmail.com.
1. Scope — and what this Policy does not cover
This Site is an informational page about the Ionika ecosystem. It has no accounts, no sign-in, no forms, no comments, and no payments: you cannot submit personal data through it.
This Policy covers only this Site. Our products have their own privacy policies, which apply once you follow a link to them — in particular Ionex (ionex.ionika.cc), IO Aura (ioaura.ionika.cc) and IONI (ioni.ionika.cc). Third-party platforms we link to (Google Play, X, Instagram, Discord, Telegram, Reddit, Steam) are controlled by their own operators and governed by their own policies; opening one of those links tells that platform you came from this Site.
2. What data we process
- Server log data — when your browser requests a page or asset, our web server and the load balancer in front of it record the request: your IP address, date and time, the requested URL, HTTP status and response size, referring URL, and your browser's user-agent string. This is unavoidable technical data that every web server receives; we use it only to deliver the Site and to keep it secure.
- Your cookie-consent choice — if you use the consent banner, we store your choice in your browser's localStorage (key cookie-consent: the choice, a version number and a timestamp). It stays on your device, is not a cookie, and is never transmitted to us.
We do not collect your name, email address, phone number, postal address, date of birth, or payment details through this Site, and we do not build profiles of visitors.
3. Cookies and similar technologies
This Site sets no cookies at all — no strictly necessary cookies, no analytics cookies, no advertising or tracking cookies — and it loads no third-party content: web fonts are served from our own server, and there are no embedded videos, maps, social widgets, pixels, or tag managers. No data about you is therefore shared with any third party as you browse this Site.
The only information stored on your device is the consent record described in §2, kept in localStorage for 180 days, after which the banner asks again. That record is what makes your choice persist; storing it is itself strictly necessary to honour that choice.
What your consent covers. Because nothing non-essential runs today, the banner records your position on optional analytics that we may introduce in the future. If we do add analytics, it will run only for visitors whose stored choice is "accept", and we will update this Policy first. If you reject, no optional technology will be loaded.
Changing or withdrawing your choice is as easy as giving it: click “Cookie settings” in the footer of any page (or run window.ionikaOpenCookieSettings() in your browser console) and pick again. You can also clear the Site's local storage in your browser settings, which resets the choice entirely. Withdrawing consent does not affect the lawfulness of any processing carried out before you withdrew it.
4. Why we process it, and our legal bases (GDPR Art. 6)
| Purpose | Data | Legal basis |
|---|---|---|
| Delivering the Site to your browser | Server log data | Legitimate interests (Art. 6(1)(f)) — operating a website you asked to load |
| Security, integrity, and abuse/DDoS prevention | Server log data | Legitimate interests (Art. 6(1)(f)) — protecting the Site and its visitors |
| Recording and honouring your cookie choice | Consent record in local storage | Strictly necessary for a service you requested; Art. 6(1)(c)/(f) |
| Optional analytics (none today; only if introduced) | Usage data | Your consent (Art. 6(1)(a)) — withdrawable at any time |
| Complying with legal obligations and lawful requests | Server log data | Legal obligation (Art. 6(1)(c)) |
5. Who we share data with
We do not sell or rent personal data, and we do not "sell" or "share" it as those terms are defined under California law (including for cross-context behavioural advertising). We do not disclose your data for any third party's own purposes.
Server log data is processed on our behalf by our hosting and infrastructure providers (our server host and the Google Cloud load balancer that terminates TLS and routes traffic to the Site), acting as processors under contract and on our instructions. We may also disclose data where necessary to comply with law, to enforce our terms, or to protect the rights, property, safety, or security of Aurora SS Group, our users, or the public. If we are involved in a merger, acquisition, or asset sale, data may be transferred subject to this Policy.
6. International transfers
Our infrastructure providers may process data in countries outside your own, including outside the European Economic Area (for example in the United States). Where required, such transfers rely on appropriate safeguards — in particular the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework — together with supplementary technical measures such as encryption in transit.
7. How long we keep data
- Server logs — retained for around 90 days for security and troubleshooting, then deleted or anonymised. Aggregated, non-identifying statistics may be kept longer.
- Your consent record — kept in your browser for 180 days (or until you clear it); we hold no copy.
8. How we protect data
The Site is served over HTTPS with TLS encryption end to end, including between the load balancer and the origin server. The origin accepts only requests coming through the load balancer, runs as an isolated container with a read-only static payload, and sends hardening headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy: no-referrer). Access to infrastructure is limited to authorised personnel. No system can be guaranteed 100% secure, but we work continuously to protect data we handle.
9. Your rights
Depending on where you live, you may have some or all of the rights below. Note that, because we hold only server logs and no account data, we usually cannot identify you from the data we hold — to act on a request about log data we may need information such as the IP address and time window concerned, and where we genuinely cannot identify you we may be unable to comply (GDPR Art. 11).
- EEA / UK (GDPR, UK GDPR): access your data; have it corrected; have it erased; restrict processing; object to processing based on our legitimate interests; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with your local data-protection supervisory authority.
- United States (California CCPA/CPRA and other state privacy laws — e.g. Virginia, Colorado, Connecticut, Utah, Texas): the right to know and access the personal information we hold about you, to delete it, to correct it, to data portability, to opt out of the "sale" or "sharing" of personal information and of targeted advertising and profiling (we do none of these), to limit the use of sensitive personal information (we collect none), and not to be discriminated against for exercising your rights. Where available, you may appeal a decision on your request; you may also use an authorized agent.
To exercise any right, email ionikasupport@gmail.com. We respond within the time limits required by law — one month under the GDPR, 45 days under the CCPA, each extendable where the law permits. Requests are free unless manifestly unfounded or excessive.
We honour browser opt-out preference signals such as the Global Privacy Control (GPC). Because we do not sell or share personal information and run no advertising or tracking, such a signal does not change how we process your data.
10. Children
The Ionika products are intended for adults (18 or older) and this Site is not directed to children. We do not knowingly collect personal data from anyone under 18 through the Site; if we learn that we have, we will delete it. This Site does not knowingly sell or share the personal information of consumers under 16 (we do not do so for anyone).
11. Do Not Track
We do not track visitors across websites, so there is nothing for a "Do Not Track" browser signal to switch off; we do not respond to it separately.
12. Changes to this Policy
We may update this Policy from time to time — for example if we introduce analytics or new features. The "Last updated" date above shows when it last changed, and we will take reasonable steps to highlight material changes. Where a change requires your consent, we will ask for it before the change takes effect.
13. Contact
Aurora SS Group — operator of the Ionika project.
Privacy questions and data requests: ionikasupport@gmail.com.
If you are in the EEA or UK, you may also contact your local data-protection supervisory authority.
nika