Privacy Policy

Last update: October 3, 2026

Your privacy is the cornerstone of AURA. This policy describes in a transparent and detailed manner, in accordance with the General Data Protection Regulation (GDPR - Regulation EU 2016/679), what personal data we collect, how it is processed through our Artificial Intelligence modules, how it integrates with wearable devices, and how you can exercise full control over it.

1. Data Controller and Principles

Personal data processing is managed by the AURA Team. We operate according to the principles of data minimization, purpose limitation, transparency and "privacy by design". All sensitive data related to your wellbeing is protected and encrypted in transit and at rest.

2. Personal Data Collected

We collect and process the following categories of data: (a) Basic identifying data: email, display name, avatar. (b) Wellbeing and lifestyle data: tracked habits, daily mood records, text notes and journal audio recordings (audioUrl). (c) Physical parameters: sex, age, height, weight (used to compute BMI and calibrate training/nutrition plans). (d) Wearable device data: step count, heart rate and physical activity imported via Google Fit, Health Connect or Apple Health. (e) Financial and transaction data: subscription or in-app purchase transaction details processed through Stripe. (f) Location data: geographic coordinates approximated to ~1km for the Aura World feature, only with the user explicit consent.

3. Processing through Artificial Intelligence (AI)

AURA uses advanced artificial intelligence models (specifically AURA AI) to deliver Motivational Coaching, Journal Emotional Analysis, Dr. Diet and Personalized Nutrition. Journal notes and your nutrition goal data are sent to the AI API to generate feedback, but are not stored to train commercial models. No personal data is sold to third parties or used for advertising profiling.

4. Legal Basis for Processing

We process your data solely on the basis of your explicit consent (art. 6(1)(a) GDPR), given when the application starts and when individual features are enabled (such as wearable sync or location sharing), or for the performance of the service contract (art. 6(1)(b) GDPR) for Premium subscription purchases and in-app transactions.

5. Data Security and Cloud Storage

We use the secure Google Firebase cloud services (Firestore and Realtime Database) hosted on servers inside the European Union. All data is stored securely with restrictive security rules to prevent unauthorized access. Your sensitive data such as journal notes and audio files is transmitted over secure encrypted channels (HTTPS).

6. Data Subject Rights (GDPR)

In accordance with articles 15-22 of the GDPR, you have the right at any time to: (a) Access your personal data stored on our servers. (b) Request rectification of inaccurate data. (c) Request data portability by exporting it in standard JSON format directly from the application settings page. (d) Request permanent deletion ("Right to be forgotten") of all your personal data and your account through the "Delete Account" button in the app settings, which immediately removes every record from the Firebase databases.

7. Third-Party Advertising

AURA may display advertising served by third-party advertising networks to users on the Free plan. These networks may use cookies or similar technologies to deliver and measure ads. Premium plan users are never served advertising.

8. AURA Coach (Android app and useaura.it/coach)

AURA Coach uses the same AURA account. Coaches enter data about their athletes, often minors: a nickname, birth year, shirt number, roles, height and reach, attendance, injury return date, test results and short notes. Body weight and athlete photos are never requested. This data is used only to plan practices and matches: it is visible to the coach and the staff they invite, and to club directors for the teams their licence covers. Practices, plans and nutrition reports are generated by AURA AI: the nickname and the data needed are sent to the AI service only to produce the response and are not used to train models. Purchases in the Android app go through Google Play Billing and are verified by RevenueCat, which acts on our behalf and receives your user ID and the purchase details; we never see card data. The device token is used only for push notifications. Drills shared with everyone show the author's name and are moderated; anyone can report them or hide an author. Coaches must be entitled to enter their athletes' data (for example as club staff or with parental consent). Deleting the account deletes teams, rosters and all Coach data: see useaura.it/account-delete.

For any questions or to exercise your legal rights, please contact our Data Protection Officer (DPO) through the form at useaura.it/contact

AURA โ€ข https://useaura.it