← Back to Aura

Privacy Policy

Effective date: [MONTH DAY, YEAR]

1. Who we are

Aura is operated by [LEGAL COMPANY NAME] ("Aura", "we", "us"). This policy explains what personal information we collect, how we use it, and the choices you have. By creating an account you agree to this policy. Questions any time: [privacy@yourdomain.com].

2. What we collect

Account information: your name, email address, and password (stored in hashed form). Birth details: your birth date, time, and place, which we use to compute your astrological chart. Journal entries: the text you write, your selected mood, and tags. Wellness logs: sleep, hydration, and mindfulness values you record. Auro conversations: the messages you exchange with our AI companion. Technical data: basic device and usage information needed to run and secure the service. We practice data minimization: we do not collect information we do not need to provide Aura.

3. How we use your information

We use your information to: (a) create and display your astrological chart and daily readings; (b) personalize journal prompts and wellness suggestions; (c) provide the Auro AI companion, which references your chart, recent journal entries, and wellness logs to respond to you; (d) maintain, secure, and improve the service; and (e) communicate with you about your account. We do not sell your personal information, and we do not show you advertising based on it.

4. AI processing and model training

AI processing. When you chat with Auro, your message — together with a summary of your chart and excerpts of your recent journal entries and wellness logs — is sent to our AI service provider (currently Google's Gemini API) to generate a response. We use API terms under which the provider does not use this content to train its own models.

Model training and service improvement. With your consent, we may use your data — including journal entries and Auro conversations — in de-identified form to improve Aura and to train or fine-tune the AI models that power it. "De-identified" means we remove your name, email, and other direct identifiers first. You can opt out at any time in Settings → Privacy or by emailing [privacy@yourdomain.com], and opting out does not affect your use of Aura. We will never use your identifiable journal content for training without your explicit consent.

5. Sensitive information

Journal entries and mood data can reveal information about your emotional wellbeing. We treat all such content as sensitive: it is protected by per-account access controls (row-level security), encrypted in transit and at rest, never shared with other users, and accessible to our staff only when strictly necessary to operate the service or when you ask us for help.

6. Who we share data with

We share personal information only with the service providers required to run Aura: Supabase (database and authentication), Vercel (hosting), and Google (AI responses, as described in Section 4). Each processes your data under contractual data-protection obligations. We may also disclose information if required by law, or as part of a merger or acquisition (in which case this policy continues to apply to your data). We never sell personal information.

7. Data retention and deletion

We keep your information while your account is active. You can delete individual journal entries and conversations at any time, and you can request full account deletion at [privacy@yourdomain.com] (self-serve deletion is coming to Settings). Upon account deletion we erase your personal information within 30 days, except records we are legally required to keep.

8. Security

We protect your data with encryption in transit (TLS) and at rest, per-user database isolation (row-level security), hashed passwords, and least-privilege access for our systems. No service can guarantee absolute security; if a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law.

9. Your rights and choices

Wherever you live, you may: access a copy of your personal information; correct inaccurate information; delete your data; withdraw any consent you have given (including for model training, per Section 4) without penalty; and export your journal entries. Contact [privacy@yourdomain.com] to exercise any right — we respond within 30 days (or sooner where local law requires). Additional region-specific rights appear in Section 12.

10. Children

Aura is not directed to children. Minimum ages: India — 18 (or verifiable parental consent as permitted by the DPDP Act); United States — 13 (per COPPA); United Arab Emirates — 18; Canada — 16; everywhere else — 18 by default. We do not knowingly collect personal information from anyone below the applicable age, and we do not use children's data for tracking, advertising, or model training. If you believe a child has created an account, contact [privacy@yourdomain.com] and we will delete it.

11. For reflection and entertainment only

Aura's astrological readings, charts, prompts, and Auro's responses are provided for reflection, self-exploration, and entertainment purposes only. They are not medical, psychological, legal, or financial advice, and they are not predictions of future events. Do not rely on Aura to make health, safety, legal, or financial decisions — always consult a qualified professional. If you are in crisis or concerned about your mental health, contact a healthcare provider or local emergency services. To the maximum extent permitted by law, [LEGAL COMPANY NAME] disclaims liability for decisions made in reliance on content in the app. (This disclaimer also appears in our Terms of Service, which govern your use of Aura.)

12. Region-specific privacy notices

Aura serves people worldwide. The notices below cover our primary markets; if your country isn't listed, the Global baseline notice applies to you and gives you the same core protections.

United States (state privacy laws, incl. California CCPA/CPRA): we do not sell your personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. Journal and mood content is treated as sensitive personal information and used only with your consent for the purposes in this policy. You have the rights to know, access, correct, delete, and port your data, and to not be discriminated against for exercising them. Authorized agents may submit requests to [privacy@yourdomain.com].

Canada (PIPEDA): we rely on your consent to collect and use your information as described here; you may withdraw it at any time and may complain to the Office of the Privacy Commissioner of Canada.

India (Digital Personal Data Protection Act, 2023): [LEGAL COMPANY NAME] acts as the Data Fiduciary for your personal data. We process it only with your consent for the purposes stated here, and you may withdraw consent, access, correct, and erase your data, and nominate another person to exercise your rights. Grievances: our Grievance Officer, [NAME], can be reached at[privacy@yourdomain.com] and will acknowledge complaints within the timelines prescribed by law; if unresolved, you may approach the Data Protection Board of India.

United Arab Emirates (Federal Decree-Law No. 45 of 2021, PDPL): we process your personal data on the basis of your consent, and journal and mood content is treated as sensitive personal data requiring your explicit consent. You may access, correct, restrict, object to, and request erasure of your data, and withdraw consent at any time. Complaints may be directed to us first and, if unresolved, to the UAE Data Office. If you access Aura from a free zone such as the DIFC or ADGM, an additional local data protection law may also apply to you.

Global baseline: wherever else you are, we apply the same core protections described in this policy — consent-based processing, the rights in Section 9, and the safeguards in Section 5 — regardless of local law.

13. International data transfers

Your information is processed by providers that may store it outside your country, including in the United States. Where required, we protect these transfers with recognized safeguards, such as Standard Contractual Clauses and equivalent mechanisms recognized under India's DPDP Act and the UAE's PDPL. Details of the safeguards for any specific transfer are available on request at [privacy@yourdomain.com].

14. Changes to this policy

If we materially change this policy — especially anything about how journal or conversation data is used — we will notify you in the app or by email before the change takes effect, and where required we will ask for your consent again.

15. Contact

[LEGAL COMPANY NAME] · [privacy@yourdomain.com] · [MAILING ADDRESS]. We respond to privacy requests within 30 days.

© 2026 [LEGAL COMPANY NAME]. See also our Terms of Service.