Privacy Policy

Last Updated: July 29, 2026

1. Information We Collect

Aura AI collects the minimum account and product data needed to provide the service. This includes:

2. How We Use Information

We use your information to:

3. Project Data and AI Requests

Aura AI is local-first by default. Core project files, GDDs, chats, pages, project rules, and project memory stay on the device unless you choose a feature that requires cloud storage or processing. When you submit an AI request, Aura sends the relevant prompt and context to the selected model provider so it can answer that request.

Pro multi-device continuity is optional. When enabled, it synchronizes supported history and context through Aura's cloud services so the same Aura account can continue on trusted devices. A Cloud Loop is separately and explicitly enabled with Continue when this device is off; Aura then uploads the approved project workspace to an isolated cloud worker that processes the files needed to run the Loop and return a reviewable result.

Your source code, design docs, prompts, chats, and project context are not used to train Aura AI or shared with other customers. You explicitly choose whether a compatible request uses a personal provider key or prepaid Aura balance; Aura does not silently switch to paid balance. Model providers process request data under their applicable API terms.

4. Data Security

Authentication and application data are handled through Supabase. Payment details are handled by Stripe; Aura AI does not store raw card data. Provider API keys are encrypted at rest, scoped to the authenticated account or organization, never returned after saving, and never bundled into the desktop installer or engine plugins. Cloud workspaces and trusted-device access are account-isolated and protected by server-side authorization.

Automatic error reports are disclosed during Aura setup and can be turned off at any time in Settings. They are limited to the Aura version, operating-system version, failing Aura component, error class and code, sanitized stack-frame names, and bounded correlation details. They do not include prompts, chats, project files or snippets, GDD content, API keys, credentials, payment details, balances, or absolute file paths. Reports are encrypted in transit, stored in a private support queue, and visible only through founder-authenticated support administration. Manual reports use the same technical limits and may also include the description you type after Aura removes recognizable paths and secrets.

5. Third-Party Services

We use Supabase for authentication and database services, Stripe for payment processing, Resend for transactional email, Google Analytics for public-website traffic and engagement measurement, cloud infrastructure providers for opt-in Pro sync and Cloud Loops, and model providers for AI responses. These services process data only as needed to provide the feature you use.

6. Retention and Deletion

Local project data remains under your control. Active Pro or Studio cloud workspaces are retained while the service is active. After Pro cloud entitlement ends, the encrypted workspace becomes read-only and remains available for export or renewal for 30 days before deletion. Confirming Delete Cloud Data also schedules the encrypted workspace for deletion after a 30-day recovery window; local project files are not deleted. Resolved or dismissed support reports are normally deleted after 90 days, and all support reports are deleted after no more than 180 days. Billing records may be retained as required for legal, tax, dispute, and fraud-prevention purposes.

7. Contact Us

If you have any questions, contact us at help@aurainc.co