AURA

Privacy Policy

Effective date: 2 July 2026

1. About this Policy

This Privacy Policy describes how the AURA iOS application ("AURA", "we", "us", "the app") handles information when you use it. By installing or using AURA you agree to the processing described below.

2. Who we are

3. Information we process

3.1 Information stored on your device

AURA stores the following information locally on your device using Apple's UserDefaults storage in JSON form:

This data does not leave your device unless you explicitly export or share it.

3.2 Health and fitness data (HealthKit)

If, and only if, you grant HealthKit permission, AURA may:

You can revoke HealthKit access at any time in iOS Settings → Apple Health → Apps. We do not transmit your health data to any server. All health data is processed only on your device.

3.3 Subscription information

If you purchase an AURA+ subscription, Apple's App Store handles payment. We receive only the receipt and entitlement state from Apple, processed on-device by StoreKit. We do not see your payment method, billing address, or full Apple ID.

If you redeem a partner offer code (a promotional code shared by one of our partners), the app sends our server a single anonymous signal containing only the offer's code and a random event identifier — no information about you, your device, or your subscription. We store it as a daily counter so the partner can see how many people redeemed their code.

3.4 Notifications

If you grant permission, AURA schedules local notifications on your device to remind you of practice. We do not send push notifications from a server.

3.5 AI features

AURA includes an in-app assistant. As of this version the assistant operates entirely on your device with pre-defined response patterns. We do not transmit your messages to any server. If we later introduce a cloud-based AI model, this Policy will be updated and your consent requested before any data is sent.

3.6 Analytics

AURA uses TelemetryDeck to collect anonymous, aggregated product-analytics events — for example: app opens, which features and practices are used, and subscription lifecycle events (such as a trial or purchase starting). This data is not linked to your identity and is not used to track you across other apps or websites. It contains no journal content, no health data, and no message content. You can review TelemetryDeck's privacy information at telemetrydeck.com/privacy.

3.7 Advertising

Versions of AURA up to and including 2.0 contain no advertising SDK at all. From version 2.0.1 the app includes the Google AdMob SDK so that people who do not subscribe can unlock the full app for a while by choosing to watch a short rewarded video.

Advertising in AURA is opt-in by design: a video is only ever shown after you deliberately choose it on the unlock screen. Ads never interrupt a practice, never play during breathing, meditation or ambient sound, never appear after a session, never autoplay, and there are no banners or interstitials anywhere in the app. AURA+ subscribers see no advertising at all.

Ads are requested as non-personalized. We do not ask for permission to track you, we do not use the advertising identifier (IDFA) for personalization, and we do not combine your data with third-party data to target you. To serve, measure and protect these ads from fraud, Google may process technical data such as your IP address (which can indicate an approximate region), device identifiers, information about which ads were shown, crash and performance data, and basic interaction events. This is described by Google in its Mobile Ads SDK data disclosure and governed by Google's Privacy Policy.

If we ever move to personalized advertising, iOS will ask for your permission first through the system tracking prompt, and this Policy will be updated before that happens. Declining changes nothing about how AURA works for you.

The rewarded unlock can be switched off remotely by us. When it is off — as it is at the time of writing — no advertising code runs in the app at all.

4. Your rights

You can at any time:

Because all data is local, deletion is immediate and irreversible.

If you reside in the European Economic Area, the United Kingdom, California, or another jurisdiction with similar laws, the equivalent rights of access, rectification, erasure, restriction, portability and objection are exercised through these in-app controls.

5. Data retention

We retain data only as long as it exists on your device. Deleting the app removes all locally stored data.

6. Children's privacy

AURA is not directed at children under 13 (or under the minimum age in your jurisdiction). We do not knowingly process data from children under that age. If you believe a child has used the app, please contact us so we can address it.

7. Third-party services

AURA relies on Apple's platform services:

Apple processes these interactions according to Apple's own Privacy Policy. AURA also uses TelemetryDeck for the anonymous analytics described in section 3.6.

Optional practice content downloaded from inside the app, this website and our partner pages are delivered via Cloudflare (CDN and hosting). Cloudflare may process technical connection data (such as IP addresses) to serve and protect these resources, per Cloudflare's Privacy Policy. If you submit a web form on our sites (for example, a partner application with your name, e-mail and channel), we store that information only to review the request and reply to you.

8. Security

Data stored by AURA is protected by iOS's standard sandbox isolation and Data Protection. We recommend you protect your device with a passcode and Face ID or Touch ID.

9. International users

AURA is offered worldwide. Because data does not leave your device, no international data transfer occurs.

10. Changes to this Policy

We may update this Privacy Policy. Material changes will be reflected in an updated effective date and announced inside the app on next launch.

11. Contact

Questions, requests, or complaints: picirigavasile@icloud.com.