Privacy Policy
Effective date: August 16, 2026
This policy explains what Aura collects, why, who we share it with, and what you can do about it. It covers the Aura iPhone app and the website at downloadaura.app.
Aura is operated by Aura App LLC, 68 Harrison Ave Ste 605 #207236, Boston, MA 02111, United States ("Aura", "we", "us"). For anything in this policy, contact help@downloadaura.app.
1. The short version
- We do not sell your personal information.
- Gemini Flash receives your habit photo for verification. Aura never sees or stores the image. Photos that pass are saved to your Wall of Wins on your own phone, where only you can see them.
- Health data is read from Apple Health with your permission, stays on your device, and is never used for advertising.
- Your selections of apps, websites, and adult content to block never leave your phone. Apple's system makes it technically impossible for us to see them.
- We use analytics and advertising tools to understand how people find and use Aura. You can opt out of the advertising ones.
The rest of this document is the detail.
2. What we collect
2.1 Information you give us
Account information. If you create an Aura account, we collect your email address and an authentication identifier. If you sign in with Apple, we receive the identifier Apple gives us and, if you choose to share it, your email. If you use Apple's Hide My Email, we only ever see the relay address.
Your habits and settings. The habits you choose or create, the reward rates you set, your routines and reminder times, your streak, and your coin balance.
Support correspondence. If you email us, we keep the message and our reply.
2.2 Information collected automatically
Device and usage information. Device model, operating system version, app version, language, region, time zone, a randomly generated app instance identifier, and events describing how you use Aura (screens opened, habits completed, sessions started and ended, purchases). We use this to understand what works and to fix what doesn't.
Diagnostic information. Crash reports and performance data.
Website information. IP address, browser type, referring page, and pages viewed on downloadaura.app, along with cookies and similar technologies described in section 6.
Advertising and attribution identifiers. If you consent under Apple's App Tracking Transparency prompt, we may access your device's advertising identifier (IDFA). If you decline, we do not access it, and attribution falls back to privacy-preserving methods that do not identify you individually.
2.3 Habit verification data
This is the part of Aura that handles the most sensitive information, so it gets its own section.
Photo Proof. When you take a photo to verify a habit, the app sends the image over an encrypted connection to Google's Gemini Flash API. Gemini Flash determines whether it shows the habit you claimed and returns a pass or fail decision with a short explanation. Aura never sees or stores the photo. Google processes it under the Gemini API terms applicable to paid services, which do not permit submitted content to be used to train Google's models.
Your Wall of Wins. When a photo passes, Aura saves a copy of it on your device so you can look back at what you have done. These images are written to Aura's own private storage area on your iPhone, which other apps cannot read. They are never uploaded to us and we never see them. They are deleted when you delete the win, or when you delete the app.
One thing to be aware of: because these files live in your app's storage, they may be included in your own device backups to iCloud or a computer. Those backups are controlled by you and by Apple under Apple's terms, not by us. You can exclude Aura from iCloud Backup in iOS Settings.
Photos are also automatically screened for content that our provider's safety systems flag. Where a photo is flagged, the habit does not pass, the image is not saved to your Wall of Wins, and we do not retain or review it.
Camera Reps. Repetition counting runs entirely on your device using Apple's Vision framework. The video feed is never recorded, never transmitted, and never leaves your phone. Only the final repetition count is used.
Apple Health. With your permission, Aura reads today's steps, distance, exercise minutes, mindful minutes and active energy from Apple Health. This is read-only. Health data is processed on your device to calculate coins, and we store only the resulting coin totals, not the underlying health measurements. We never use Health data for advertising, never share it with advertising or analytics partners, and never sell it. This is both our policy and a condition of Apple's HealthKit terms.
Screen Time and blocked content. Aura blocks selected apps, websites, and adult content using Apple's Family Controls and Managed Settings frameworks. By Apple's design, those selections are represented by opaque tokens that only your device can interpret. We cannot see what you have blocked, and neither can any of our providers. Your screen time statistics are likewise processed on your device.
2.4 Purchase information
We receive confirmation that a purchase or subscription occurred, which product was bought, the price and currency, the renewal date, and its current status. We never receive your full payment card number. Payments are handled by Apple or by our web payment processor, who hold that information under their own policies.
3. Why we use it
| Purpose | Data used |
|---|---|
| Providing Aura's core features | Account, habits, settings, verification data, health data, purchases |
| Verifying that a habit was completed | Habit photos, on-device pose data, Apple Health data |
| Keeping your subscription and entitlements accurate | Account, purchase information |
| Understanding and improving the product | Device and usage information, diagnostics |
| Measuring which ads and channels bring people to Aura | Attribution identifiers, website information, purchase events |
| Sending you the reminders you asked for | Routine settings, device push token |
| Preventing fraud and abuse | Account, device information, purchase information |
| Responding to you | Support correspondence |
| Meeting legal obligations | Whatever the specific obligation requires |
Legal bases (UK and EEA users)
Where the UK GDPR or EU GDPR applies, we rely on:
- Contract for the features you signed up for, including verification, blocking and subscription management.
- Consent for advertising and attribution identifiers, non-essential cookies, push notifications, camera access and Apple Health access. You can withdraw consent at any time.
- Legitimate interests for product analytics, security, fraud prevention and service improvement, where we have assessed that these do not override your rights.
- Legal obligation where we are required to keep records, for example for tax.
Apple Health data is special category data. We process it only with your explicit consent, given through Apple's Health permission prompt, and you can revoke it in the Health app at any time.
4. Who we share it with
We do not sell your personal information, and we do not share it for cross-context behavioural advertising except as described under "Advertising" below, which you can opt out of.
We use the following providers. Each processes data only on our instructions, except where noted that they act as an independent controller.
Infrastructure
Supabase (supabase.com) hosts our database, authentication and serverless functions. Data is stored in us-west-2 (Oregon).
Google (Gemini Flash API) (policies.google.com/privacy) performs habit photo verification. Gemini Flash receives the photo for analysis; Aura never sees or stores it. Google processes it under the Gemini API terms applicable to paid services, which do not permit submitted content to be used to train Google's models.
Payments, subscriptions and paywalls
Apple (apple.com/legal/privacy) processes in-app purchases and subscriptions. Apple acts as an independent controller for payment data.
Paddle (paddle.com/legal/privacy) is the merchant of record for purchases made on our website. Paddle handles payment details, tax and invoicing, and acts as an independent controller for those.
RevenueCat (revenuecat.com/privacy) manages subscription state and entitlements across platforms.
Superwall (superwall.com/privacy) delivers and tests our paywalls.
Web2Wave (web2wave.com) runs our web onboarding and subscription funnel and links a web signup to your app account.
Analytics and attribution
PostHog (posthog.com/privacy) provides product analytics. We use it to understand feature usage, not to profile you individually.
AppsFlyer (appsflyer.com/legal/services-privacy-policy) provides install attribution and marketing measurement.
Advertising
Meta (facebook.com/privacy/policy) receives events from the Meta Pixel on our website and from our app when you have consented, so we can measure and improve our advertising. Meta may act as an independent controller for some of this. You can control this through the cookie banner on our site, through Apple's App Tracking Transparency prompt in the app, and through your Meta ad preferences.
Other
We may also disclose information where we are legally required to, where necessary to investigate fraud or protect someone's safety, or to a buyer in connection with a merger or acquisition. If ownership of Aura changes, we will tell you before your information becomes subject to a different policy.
5. International transfers
Our providers operate in the United States and elsewhere. Where we transfer personal data out of the UK or EEA, we rely on the UK International Data Transfer Addendum, the European Commission's Standard Contractual Clauses, or an adequacy decision, together with additional safeguards where appropriate. You can ask us for details of the mechanism used for a particular provider.
6. Cookies and similar technologies
On downloadaura.app we use:
- Strictly necessary cookies, which keep the site working and cannot be turned off.
- Analytics cookies (PostHog), which tell us how the site is used.
- Advertising cookies (Meta Pixel), which measure the performance of our ads.
Non-essential cookies are set only after you agree through our cookie banner, and you can change your choice at any time from the link in the site footer.
In the app, Apple's App Tracking Transparency prompt controls whether we can access your advertising identifier. Declining does not reduce any Aura feature.
7. How long we keep it
| Data | Retention |
|---|---|
| Habit photos (Aura) | Never received or stored. |
| Habit photos (your device) | Kept in your Wall of Wins until you delete the win or the app. Never uploaded. |
| Camera Reps video | Never leaves your device and is never recorded. |
| Apple Health measurements | Not retained. Processed on device; only coin totals are kept. |
| Blocked apps, websites, and adult-content selections | Never leave your device. |
| Account and habit data | For as long as your account is active, then deleted within 90 days of your deletion request. |
| Analytics events | 24 months. |
| Attribution and advertising events | 12 months. |
| Purchase and subscription records | 7 years, as required for tax and accounting. |
| Support correspondence | 24 months after the conversation ends. |
Data stored only on your device is removed when you delete the app.
8. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw consent. Exercising these rights is free and will not result in worse service.
To delete your account and data, use Settings in the app or email help@downloadaura.app. We will confirm within 30 days.
California residents. You have the rights to know, delete, correct, and to opt out of sale or sharing. We do not sell personal information. We do share limited advertising identifiers and event data with Meta for advertising measurement, which California law may treat as "sharing"; you can opt out via our cookie banner and by declining the App Tracking Transparency prompt. We will not discriminate against you for exercising any right. You may use an authorised agent.
UK and EEA residents. You may complain to your local supervisory authority, and in the UK to the Information Commissioner's Office at ico.org.uk.
9. Security
We use encryption in transit (TLS) for all network traffic, encryption at rest for stored data, access controls limiting who on our side can reach production systems, and we keep sensitive health measurements and blocking selections on your device, while Aura never receives your habit photos. No system is perfectly secure, and we cannot guarantee absolute security.
10. Children
Aura is not intended for children under 13, and we do not knowingly collect data from them. In the UK and EEA the minimum age is 16 unless your country sets a lower age, in which case that age applies. If you believe a child has provided us with personal information, email us and we will delete it.
11. Changes
If we make a material change we will update the date at the top, and tell you in the app or by email before it takes effect. Continuing to use Aura after a change means you accept it.
12. Contact
Aura App LLC 68 Harrison Ave Ste 605 #207236, Boston, MA 02111, United States help@downloadaura.app

