Privacy Policy
Last Updated: July 29, 2026
1. Information We Collect
Aura AI collects the minimum account and product data needed to provide the service. This includes:
- Email address and profile information provided when signing in via Google OAuth, GitHub OAuth, or email and password.
- Software entitlement, Aura balance, billing status, trusted-device, and organization membership information.
- Usage records such as model selected, funding route, metered model cost, and token counts.
- Privacy-safe technical error reports when automatic reporting is enabled, and any description you choose to add to a manual problem report.
- Website analytics such as the page visited, referral or campaign source, tutorial and navigation interactions, scroll depth, active time, and general browser or device information. Aura does not put prompts, project content, provider keys, payment details, or wallet balances into website analytics.
2. How We Use Information
We use your information to:
- Authenticate access to Aura AI.
- Manage software entitlements, prepaid Aura balance, model funding, trusted devices, and organization access.
- Send transactional emails, including confirmation, welcome, billing, failed-payment, payment-recovered, balance, cancellation, cloud activity, and team invitation emails.
- Use privacy-safe technical reports for support, security, and reliability, including diagnosing errors and keeping the product reliable.
- Understand which public pages and tutorials help visitors find and use Aura. The website keeps a limited session, attribution, and engagement record in browser storage so analytics never blocks the product.
3. Project Data and AI Requests
Aura AI is local-first by default. Core project files, GDDs, chats, pages, project rules, and project memory stay on the device unless you choose a feature that requires cloud storage or processing. When you submit an AI request, Aura sends the relevant prompt and context to the selected model provider so it can answer that request.
Pro multi-device continuity is optional. When enabled, it synchronizes supported history and context through Aura's cloud services so the same Aura account can continue on trusted devices. A Cloud Loop is separately and explicitly enabled with Continue when this device is off; Aura then uploads the approved project workspace to an isolated cloud worker that processes the files needed to run the Loop and return a reviewable result.
Your source code, design docs, prompts, chats, and project context are not used to train Aura AI or shared with other customers. You explicitly choose whether a compatible request uses a personal provider key or prepaid Aura balance; Aura does not silently switch to paid balance. Model providers process request data under their applicable API terms.
4. Data Security
Authentication and application data are handled through Supabase. Payment details are handled by Stripe; Aura AI does not store raw card data. Provider API keys are encrypted at rest, scoped to the authenticated account or organization, never returned after saving, and never bundled into the desktop installer or engine plugins. Cloud workspaces and trusted-device access are account-isolated and protected by server-side authorization.
Automatic error reports are disclosed during Aura setup and can be turned off at any time in Settings. They are limited to the Aura version, operating-system version, failing Aura component, error class and code, sanitized stack-frame names, and bounded correlation details. They do not include prompts, chats, project files or snippets, GDD content, API keys, credentials, payment details, balances, or absolute file paths. Reports are encrypted in transit, stored in a private support queue, and visible only through founder-authenticated support administration. Manual reports use the same technical limits and may also include the description you type after Aura removes recognizable paths and secrets.
5. Third-Party Services
We use Supabase for authentication and database services, Stripe for payment processing, Resend for transactional email, Google Analytics for public-website traffic and engagement measurement, cloud infrastructure providers for opt-in Pro sync and Cloud Loops, and model providers for AI responses. These services process data only as needed to provide the feature you use.
6. Retention and Deletion
Local project data remains under your control. Active Pro or Studio cloud workspaces are retained while the service is active. After Pro cloud entitlement ends, the encrypted workspace becomes read-only and remains available for export or renewal for 30 days before deletion. Confirming Delete Cloud Data also schedules the encrypted workspace for deletion after a 30-day recovery window; local project files are not deleted. Resolved or dismissed support reports are normally deleted after 90 days, and all support reports are deleted after no more than 180 days. Billing records may be retained as required for legal, tax, dispute, and fraud-prevention purposes.
7. Contact Us
If you have any questions, contact us at help@aurainc.co