Privacy Policy
Effective date: September 13, 2026
This policy explains what Aura collects, why we use it, who helps us process it, and how you can delete your account. It covers the Aura iPhone app and the website at downloadaura.app.
Aura is operated by Aura App LLC, 68 Harrison Ave Ste 605 #207236, Boston, MA 02111, United States ("Aura", "we", "us"). For anything in this policy, contact help@downloadaura.app.
1. The Short Version
- We do not sell your personal information.
- We do not track you across apps or websites for advertising.
- Account data is used to run your account and sync your Aura progress.
- After you explicitly allow AI photo verification, verification photos are transmitted through Aura's verification service to Google Gemini, or to OpenAI if Gemini is unavailable, to check a habit. Aura does not store those photos for verification.
- After a Photo Proof pass, Aura attempts to save the photo to your Wall of Wins on your device. When you are signed in, Aura also attempts to sync it to private, owner-scoped Supabase Storage without public URLs.
- Screen Time selections use Apple's Family Controls. The app and website tokens are opaque, and readable app or site names do not leave your device.
- Support messages, plus your account name and email, go to Crisp so we can reply to you. Aura also posts an internal Slack notification for support visibility.
- Crash and error diagnostics are handled anonymously through Sentry so we can find and fix bugs.
- Product analytics are optional. Aura sends product interaction and device/OS information to PostHog only after you opt in through Settings, using a random identifier that is not attached to your Aura account. Session replay is disabled, so Aura does not send screen recordings to PostHog.
2. What We Collect
2.1 Account Information
When you create or use an Aura account, we collect your email address, account identifier, and name if your sign-in provider gives it to us. You can sign in with Apple, Google, or email and password.
Google Sign-In. Aura requests the authentication tokens, name, and email needed to create or access your account, with no additional Google permissions. Google’s sign-in software declares that it may also collect information linked to your identity, including user and device identifiers, usage data, a phone number, other data types, and coarse location, for app functionality and analytics. Google declares that this data is not used for tracking. Google also explains that it may use an IP address to estimate general location for fraud prevention. Aura’s sign-in code does not request precise location.
2.2 Habit, Progress, and App Settings
Aura stores the habits you set up, routine and reminder settings, streak and progress data, coin history, and related app settings needed to make the product work across sessions and devices.
2.3 Verification Photos
When you use Photo Proof, Aura first asks for your explicit permission to share the image for AI verification. If you allow it, the app sends the photo over an encrypted connection to Aura's verification service. The service sends it to Google Gemini first. If Gemini is unavailable, Aura may use OpenAI gpt-5-mini as a fallback. The provider returns a pass/fail result and a short explanation.
Aura does not keep the verification copy in its own database or file storage. Google and OpenAI may retain verification inputs and outputs under their API terms for safety, abuse prevention, security, and legal obligations. Google's paid Gemini API does not use submitted prompts, images, or responses to improve its products, but Google logs prompts and responses for a limited period. If developer logging is enabled for Aura's Gemini project, developer logs may be retained for 7, 14, 28, or 55 days. OpenAI does not use API data to train its models by default, but standard Chat Completions requests may be retained for up to 30 days for abuse monitoring unless approved data controls apply. An image flagged for potential child sexual abuse material may be retained by OpenAI for manual review even when Zero Data Retention or Modified Abuse Monitoring is enabled.
2.4 Wall-of-Wins Photos and Avatar
After a Photo Proof habit passes, Aura automatically attempts to save the photo to your Wall of Wins on your device. When you are signed in, Aura also attempts to upload that copy to a private, owner-scoped Supabase Storage bucket called user-media so it can sync with your account. A failed local write or upload can prevent the corresponding copy from being saved. Your avatar may also be stored in the same private bucket. These images are not public and are not used for advertising, model training, or marketing.
2.5 Camera Reps
For supported exercises, Aura uses the camera feed on your device to count repetitions. The video feed is not recorded or sent to Aura's servers. Aura keeps completed exercise results, including repetition counts, as progress data and syncs those results with your account when you are signed in.
2.6 Apple Health
With your permission, Aura reads selected Apple Health data, such as steps, distance, exercise minutes, mindful minutes, and active energy. This is read-only. Health measurements are processed on your device to calculate Aura coins. Aura keeps daily claimed totals on your device to avoid awarding the same activity twice. Signed-in progress sync includes earned coins and the number of Health reward collections, rather than the underlying HealthKit samples. We do not use Health data for advertising, do not sell it, and do not share it with advertising partners.
2.7 Screen Time, App, and Website Blocking
Aura uses Apple's Family Controls, DeviceActivity, and Managed Settings frameworks to let you select apps, websites, and categories to block. Apple represents those selections as opaque tokens. Aura's Screen Time report processes activity information on your device to display your usage. Your selections, app and website activity, and Screen Time reports are not sent to Aura's servers.
2.8 Support Messages
If you contact support, we process your messages, any photos or voice notes you choose to attach, and your account name and email so we can respond. Support conversations and attachments are handled through Crisp. Aura may also send an internal Slack notification that a support request arrived.
2.9 Subscription and Billing Information
Aura receives subscription status, product identifier, renewal or expiration status, and related entitlement information. App Store subscriptions are handled through Apple and RevenueCat. Website subscriptions are handled through web2wave and Paddle. Superwall presents the paywall experience in the app.
We do not receive your full payment card number.
2.10 Transactional Email
Aura uses Resend to send transactional email, such as account or support-related messages.
2.11 Device Identifier
Aura may use an anonymous device identifier for app functionality, diagnostics, fraud prevention, and keeping the app working. It is not used for tracking.
2.12 Crash and Error Diagnostics
Crash and error diagnostics (Sentry). We use Sentry (Functional Software, Inc.) to detect crashes and errors so we can fix bugs. Sentry receives anonymous diagnostic data, such as crash reports, error details, and device/OS information. We do not link this to your account or identity, and we do not send your IP address or personal information to Sentry.
2.13 Optional Product Analytics
Optional product analytics (PostHog). If you opt in through Aura's Settings, we use PostHog (PostHog, Inc.) to understand how the app is used and improve the experience. PostHog receives product interaction events and device/OS information under a random identifier that Aura does not attach to your name, email, or account. Session replay is disabled in the release app, so Aura does not send screen recordings to PostHog. You can revoke consent in Settings at any time; this stops future analytics capture. We do not use PostHog to track you across other apps.
3. Why We Use Data
| Purpose | Data Used |
|---|---|
| Create and maintain your account | Email, name, authentication identifiers |
| Run Aura's core features | Habits, settings, progress, subscription status |
| Verify habit completion | Verification photos, on-device camera reps, Apple Health data |
| Sync your private media | Wall-of-Wins photos and avatar |
| Block selected content | Opaque Screen Time tokens stored on device and in the app group |
| Manage subscriptions | Account identifiers and purchase status |
| Provide support | Support messages, account name, account email |
| Send transactional email | Email address and message content |
| Fix crashes and errors | Anonymous crash reports, error details, and device/OS information |
| Improve the product experience | Optional product interaction events and device/OS information after you opt in |
| Protect the service | Account, device, diagnostic, and purchase signals |
| Meet legal obligations | Records needed for tax, accounting, compliance, or legal requests |
Legal Bases for UK and EEA Users
Where the UK GDPR or EU GDPR applies, we rely on:
- Contract to provide Aura features, account access, subscriptions, support, and deletion.
- Consent for AI photo verification, optional product analytics, camera access, Apple Health access, notifications, and other permissions you grant through iOS or Aura's Settings.
- Legitimate interests for security, fraud prevention, diagnostics, service improvement, and support operations.
- Legal obligation where we must keep or disclose records for tax, accounting, legal, or regulatory reasons.
4. Third-Party Processors
We use the providers below to operate Aura. Some act only on our instructions; some, such as Apple and Paddle for payments, may act as independent controllers for their parts of the transaction.
| Provider | What They Handle |
|---|---|
| Supabase | Authentication, database, private media storage, and serverless functions |
| Google Sign-In, including the software-declared linked identifiers, usage data, phone number, other data types, and coarse location described above; Gemini habit-photo verification | |
| OpenAI | Fallback habit-photo verification if Gemini is unavailable |
| RevenueCat | App Store subscription status and entitlement management |
| Superwall | In-app paywall presentation |
| web2wave | Web onboarding and web subscription status |
| Paddle | Website subscription checkout, payment, tax, and invoicing |
| Crisp | Customer support chat and support conversation management |
| Resend | Transactional email |
| Sentry | Anonymous crash and error diagnostics |
| PostHog | Optional product analytics after you opt in; session replay is disabled |
We may also disclose information if required by law, to investigate fraud or abuse, to protect someone's safety, or as part of a merger, acquisition, financing, or sale of assets.
5. Cookies and Website Data
The website may use strictly necessary cookies and hosting logs needed to serve pages, secure the site, and troubleshoot issues. Aura does not use website cookies or app identifiers for cross-app tracking or advertising.
6. Retention
| Data | Retention |
|---|---|
| Verification photos | Not kept in Aura's database or file storage for verification. Provider safety, abuse-prevention, security, legal, and optional developer logs may retain inputs or outputs: Google for a limited period, with developer logs up to 55 days if enabled; OpenAI Chat Completions for up to 30 days unless approved data controls apply, with a separate flagged-image safety-review exception. |
| Wall-of-Wins photos and avatar | Local copies remain until you delete the win or remove local app data. Signed-in sync copies are intended to be removed when you delete the win or your account; contact support if deletion reports an error or you want confirmation. |
| Camera Reps video feed | Not recorded and not sent to Aura |
| Apple Health measurements | Underlying HealthKit samples are processed on device. Daily claimed totals are saved locally to prevent duplicate rewards; earned coins and Health reward collection counts are retained with account progress. |
| Screen Time app and website selections | Opaque tokens stay on device and in the app group |
| Account, habits, settings, and progress | Kept while your account is active |
| Purchase and subscription records | Kept as needed for subscriptions, tax, accounting, and legal compliance |
| Support messages | Kept as needed to respond and maintain support history |
| Crash and error diagnostics | Kept as needed to detect, diagnose, and fix bugs |
| Optional product analytics | Opting out stops future capture. Analytics collected while you were opted in may remain under Aura's PostHog project retention settings; contact support to request deletion. No session recordings are collected. |
7. Account Deletion
You can request account deletion in the app by going to Profile -> Settings -> Delete account. The deletion flow is intended to remove your Aura account, app data tied to the account, and stored media such as Wall-of-Wins photos and avatar from Aura's servers. If the flow reports an error, or if you want help confirming deletion, email help@downloadaura.app from the address on your account.
We may keep records that are required for tax, accounting, fraud prevention, dispute resolution, or other legal obligations. Records held by Apple, Paddle, or another independent provider are governed by that provider's terms and deletion process.
Deleting your Aura account does not automatically cancel an active App Store, Paddle, or web subscription. Cancel subscriptions separately through Apple, the web receipt link, or Aura support.
8. Your Rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or receive a copy of your personal information, and to object to or withdraw consent for certain processing.
To make a request, email help@downloadaura.app from the email address on your Aura account.
California residents. We do not sell personal information and do not use personal information for cross-context behavioral advertising. You may have rights to know, access, correct, delete, and limit certain uses of your information. We will not discriminate against you for exercising your rights.
UK and EEA residents. You may contact your local data protection authority. In the UK, you can contact the Information Commissioner's Office at ico.org.uk.
9. Security
Aura uses encryption in transit, private owner-scoped storage for user media, Supabase row-level security, and restricted production access. No system is perfectly secure, but we design Aura to keep sensitive data either on device, transient during verification, or in private account-scoped storage.
10. Children
Aura is not intended for children under 13. If you are in the UK or EEA, you must be at least 16 unless your country sets a lower digital consent age. If you believe a child has provided us personal information, email us and we will take appropriate steps to delete it.
11. Changes
If we make material changes, we will update the effective date and may notify you in the app, by email, or on the website.
12. Contact
Aura App LLC 68 Harrison Ave Ste 605 #207236, Boston, MA 02111, United States help@downloadaura.app

