Trust & Safety
Aura AI is built local-first. Your source code, design docs, chats, and project memory stay under your control, and your content is not used for training.
Your source code, design docs, prompts, and project context are not used for model training. Aura is built for commercial projects where unreleased mechanics, lore, and production plans need to stay yours.
Account, billing, update, diagnostic, and model-request traffic is encrypted in transit. Local engine communication stays on your machine.
Automatic reports are bounded to technical metadata and sanitized stack frames. They exclude prompts, projects, GDDs, keys, payment data, balances, and absolute paths, and are available only in the founder-authenticated support queue.
Authentication uses signed JWTs. User sessions are validated server-side and scoped to the authenticated account to enforce account-specific access.
We do not sell or rent your usage data, code context, or personal information to advertisers or data brokers. Service providers receive only the data needed to provide the selected feature.
Aura AI is a native background service that runs on your machine. Project context, GDDs, pages, rules, chats, and project memory are local-first and do not sync to a cloud workspace by default.
Server-side authorization, row-level security, role checks, and fail-closed gates separate account, subscription, wallet, organization, and support data. Security reports remain subject to ongoing testing and independent review.
A transparent breakdown of every data type Aura touches, where it goes, and who can access it.
Swipe sideways to compare where each data type goes and who can access it.
| Data Type | Where It Goes | Who Can See It |
|---|---|---|
| AI Prompts & Code Context | Sent as necessary request context to the model provider and funding route you selected | The selected provider processes the request; Aura does not use it for training |
| Project files, GDDs & context | Local by default. Pro sync or a Cloud Loop uses encrypted cloud storage or isolated cloud processing only after you enable it. | You and the Aura services needed to provide the cloud feature you enabled; never used for training |
| Billing and wallet data | Remote database (RLS-protected) | You only; Aura backend for software entitlement and wallet reservation/settlement |
| Email Address | Auth provider; Resend for transactional email | Aura account operations and the service providers needed for authentication and email delivery |
| Payment Information | Stripe (we never see raw card data) | Stripe only |
| Error reports | Private support storage after strict client and server allowlist checks | Founder-authenticated Aura support only; never includes prompts, project content, credentials, payment data, balances, or absolute paths |
| Website analytics | Limited public-page, referral, campaign, tutorial, navigation, and engagement events sent to Google Analytics | Aura and Google Analytics for aggregate website measurement; events exclude prompts, project content, provider keys, payment details, and wallet balances |
| Chat History | Local by default; encrypted multi-device continuity is available only when a Pro user enables cloud sync | You; Aura's cloud service handles encrypted synchronization only when enabled |
Found a security vulnerability? Please report it. We review reports as promptly as possible and will work with you to investigate and resolve confirmed issues responsibly.
security@aurainc.coWe don't run a formal bug bounty program, but we will acknowledge your contribution publicly if you'd like.
This page describes current product controls. It is not a certification or a substitute for your organization’s legal or security review.
Aura is not currently SOC 2 certified. Do not treat product architecture or internal testing as certification.
Account data export and deletion requests are handled through the published privacy process. Independent legal review remains separate from product testing.
Independent professional security, legal, and tax reviews remain explicit external follow-ups. Aura does not claim they are complete.