The short version

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. There are no advertising trackers in the app.

Health and fitness data stays out of marketing entirely. Journal entries are encrypted on your device and are never used to train models.

You can export or delete everything from Settings, and unsubscribe from any message we send. Mobile numbers given for text messages are never shared for others' marketing.

1. Who is responsible

Aura Corp, 30 N Gould St, Sheridan, WY 82801, United States, is the controller of the personal information described here. For privacy questions write to privacy@auraapp.com.

2. What we collect

Account information. Your name or chosen display name, email address, password hash, and — if you sign in with Apple or Google — the identifier and email that service returns.

Birth data. Your date of birth, time of birth and place of birth, and the same details for any chart you save for another person. This is what makes a natal chart possible; without it Aura can only give you a generic reading. Where the law treats a date of birth as sensitive, we handle it accordingly. Only give us another person's birth details if you have their permission.

Health and wellness data. If you switch it on, Aura reads and writes mindful minutes, yoga and workout sessions, heart rate and sleep through Apple HealthKit or Google Fit, and records the classes you complete, session lengths, streaks and any mood, energy or sleep values you log. HealthKit and Fit data is used only to show you your own progress and to write your practice back to those apps. It is never used for advertising or marketing, never sold, and never shared with third parties for their own purposes. You can revoke the permission in your device settings at any time.

Journal and reflection content. Written entries, voice notes and their on-device transcriptions, tarot pulls and saved readings. Entries are encrypted on your device and, when you enable sync, encrypted in transit and at rest. We do not read them, use them to train models, or use them for marketing.

Location data. To place a birth chart we need a birth city, which you type in — that is a place name, not a live location. Separately, and only if you grant the permission, we use your approximate current location to set your time zone, show local sunrise, sunset and moon times, and calculate transits correctly. We do not collect continuous background location, and we do not use location for advertising. Refusing the permission means you enter a city manually instead.

Payment information. Purchases made in the App Store or Google Play are processed by Apple or Google; we receive a transaction identifier, plan, currency, country and renewal status, not your card number. Where we bill directly, our payment processor handles the card and we retain only the last four digits, the brand and the billing country.

Mobile number and message data. If you join Aura Daily we collect your mobile number, your carrier, the record and timestamp of your consent, the messages we send you, and delivery, click and opt-out events. See section 6.

Device and usage data. Device model, operating system version, app version, language, region, crash reports, an app-generated identifier, and events describing how the app is used — screens opened, classes started and finished, filters used, features tried. We use these to fix bugs and decide what to build.

Support correspondence. What you write to us, and what we reply.

3. Why we collect it

To provide the Service and the features you ask for: calculating charts and transits, delivering your reading, playing classes, keeping your journal, syncing across your devices. To create and secure your account and prevent fraud and abuse. To process subscriptions and handle refunds. To send the messages and notifications you have chosen. To answer support requests. To understand which features are used and improve them. To keep records we are required to keep, and to comply with legal obligations and defend legal claims.

Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract for account, subscription and core app functions; your explicit consent for sensitive data including health data and birth data, for location access, and for marketing messages; our legitimate interests in securing the Service, preventing abuse and improving the product; and compliance with legal obligations. You may withdraw consent at any time, which does not affect processing that already took place.

4. What we do not do

We do not sell personal information, and we have not sold it in the past twelve months. We do not share personal information for cross-context behavioural advertising or targeted advertising. We do not run third-party advertising in the app. We do not use health data, journal content, birth data or mobile numbers for advertising or profiling. We do not use your content to train machine learning models. We do not knowingly collect information from children under 13, and if we learn we have, we delete it.

5. Analytics and third parties

We use a small set of service providers, each bound by contract to use data only on our instructions: cloud hosting and storage, crash reporting, product analytics, our email provider, our text message aggregator, our payment processor, and Apple and Google for distribution and in-app purchase. Analytics is limited to product measurement — we do not permit our analytics or attribution providers to use your data for their own advertising purposes, and we do not embed advertising SDKs. On the website we use only cookies necessary for the site to function plus first-party analytics; where consent is required, a banner asks for it before any non-essential cookie is set. Aura may also share information where we are legally required to, to protect someone's safety, or in connection with a merger or acquisition — in which case we will tell you before your information becomes subject to a different policy.

6. Text messages

Aura Daily is opt-in only. We collect your mobile number, the consent record, message and delivery logs, and opt-out requests, and we use them solely to run the program, to honour your opt-out, and to keep the compliance records the law requires. Mobile opt-in data and consent are never shared or sold to third parties for their own marketing purposes. Our text message aggregator and the mobile carriers process messages on our behalf in order to deliver them. Reply STOP to end the program at any time. Full details are in the SMS Mobile Terms.

7. How long we keep it

Account, chart and journal data is kept while your account is open. When you delete your account we remove it from live systems within 30 days and from backups within 90 days. Analytics events are retained in identifiable form for 14 months and aggregated after that. Support correspondence is kept for 24 months. Consent records for text messages and transaction records are kept for as long as the applicable statute of limitations requires, typically four to six years, because we may need them to prove compliance.

8. Security

Data is encrypted in transit with TLS and at rest. Journal entries are additionally encrypted on the device and can be locked behind Face ID, Touch ID or a passcode. Access to production systems is limited to staff who need it, logged, and protected by multi-factor authentication. No system is perfectly secure; if a breach affects your information we will notify you and the relevant regulators as the law requires.

9. International transfers

We are based in the United States and our providers may process data there and elsewhere. Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, and we carry out transfer risk assessments. A copy of the relevant safeguards is available on request.

10. Your choices in the app

In Settings you can edit or remove your birth details and any saved chart, turn health sync and location access on or off, choose exactly which notifications you receive, leave the text message program, export your data as a file, and delete your account outright. Device-level permissions for health, location and notifications can be revoked in iOS or Android settings at any time.

11. Your rights

Everyone. You may ask us for a copy of your information, ask us to correct or delete it, or ask us to stop sending you marketing. Write to privacy@auraapp.com and we will respond within 30 days. We will not treat you differently for exercising a right.

California (CCPA/CPRA). You have the right to know what we collect and why, to access a copy, to delete, to correct, to opt out of sale or sharing — we do neither — and to limit the use of sensitive personal information. We collect the categories listed in section 2, which include identifiers, commercial information, internet activity, geolocation, and the sensitive categories of health data and precise location where you grant it. An authorised agent may act for you with written proof. Submit a request at privacy@auraapp.com or by post to the address in section 1.

European Economic Area, United Kingdom and Switzerland (GDPR). You have the rights of access, rectification, erasure, restriction, portability and objection, the right not to be subject to solely automated decisions with legal effect — we make none — and the right to withdraw consent. You may complain to your national data protection authority; in the UK, the Information Commissioner's Office.

Other US states. Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have equivalent rights of access, correction, deletion, portability and opt-out, including the right to appeal a refusal. To appeal, reply to our decision and we will review it within 45 days.

12. Children

Aura is intended for users aged 16 and over, and subscriptions and text messages are for users 18 and over. We do not knowingly collect personal information from children under 13. Parents who believe a child has given us information should write to privacy@auraapp.com and we will delete it.

13. Changes to this policy

We will post any change here and update the date at the top. If a change is material — a new purpose, a new category of data, a new kind of sharing — we will tell you in the app or by email before it takes effect and, where the law requires it, ask for your consent.

14. Contact

Aura Corp, 30 N Gould St, Sheridan, WY 82801, United States.
Privacy: privacy@auraapp.com
Support: support@auraapp.com