Privacy Policy
Last updated: September 26, 2026
Aura ("we", "our", "the app") is a personal productivity and life-planning application. We take your privacy seriously. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
- Account info — your name and email address, used to identify your account.
- Tasks & habits — titles, dates, completion status, notes you enter. Accepted friends can also see summary figures: the minutes you spent on tasks, your habit completions and your streak (you can hide them on your profile screen in Settings → Privacy & Security).
- Finance data — amounts, categories, and notes for transactions you log.
- Prayer and worship logs — which prayers you completed and when, missed-prayer (qaza) counters, dhikr counts and Quran pages read (Muslim Mode only). This kind of information can reveal your religious practice, so it is sensitive. Logging it is optional and you decide what to log. Friends you have accepted can see summary figures on your profile (for example prayers this week, Quran pages, dhikr count) and can technically read the individual prayer entries stored in your account. The switch in Settings → Privacy & Security hides these figures on your profile screen in the app only; it does not change the friends leaderboard, whose score is calculated from the same figures, and it is not a technical barrier against a friend who queries the service directly. Your missed-prayer (qaza) counters are private to your account, like the fasting data below.
- Sleep — the bedtimes and wake-up times you log.
- Quran bookmarks — verses and pages you save.
- Ramadan mode — the fasting days you mark (fasted, missed or excused), your Quran khatm progress and your suhoor and iftar reminder choices (Muslim Mode only). This data is private to your account: it is never shown to friends or in the feed.
- Fasting tracker — the days you mark as fasted (voluntary or make-up) and your fasting reminder choices (Muslim Mode only). This data is private to your account: it is never shown to friends or in the feed.
- Friends & feed — your friend list and friend requests, the posts you publish to the feed (text and photos), comments, likes and the badges you earn. Your display name, username, profile photo and language can be found by search and are visible to other signed-in users, and the participant list of a public challenge is visible to every user.
- Challenges — challenge titles and rules, your check-ins and points, and who takes part.
- Messages & files — direct messages and challenge chat, and the photos, voice notes and files you send. They are stored on our servers and deleted automatically: chat and direct messages after 180 days, feed posts after 90 days (challenge photos after 180 days). Files are opened through web links; anyone who has a link can open the file. Files uploaded by current app versions use long random names; older files and profile photos use names that are easier to guess.
- Location — when prayer times are calculated automatically, the app reads your device location (a fix accurate to roughly 100 metres) and sends the coordinates, not rounded, to prayer-time services (see section 3): muftyat.kz uses them to find the nearest city, and aladhan.com only if muftyat.kz is unavailable. Calculation methods other than the Kazakhstan one work on your device without sending anything, and if you choose a city yourself, that city's coordinates are used instead. The time tracker can keep recording your location while the screen is locked. The route line recorded by the time tracker stays on your device and is not uploaded to our servers (on an iPhone it can be included in your iCloud or computer backup). The distance, duration, activity and start time of a tracked session are saved with your tasks and synced to your account.
- Notifications — a device token so we can send you push notifications. Push notifications for direct messages never contain the message text. Push notifications for challenge chat show the beginning of the message (up to 80 characters), or the name of the file if you sent only a file, and those for challenge photos show the caption you wrote; they are kept with the notification for up to 90 days.
- App preferences — language, theme, notification settings.
- AI messages — text you send to Aura AI is forwarded to an AI provider (Groq, or Anthropic for Premium subscribers) to generate a response. We do not store conversation history on our servers.
- Bank statements — when you import a PDF statement, it is read on your device and the file itself is never uploaded. For Kaspi and Freedom Bank statements nothing leaves your phone. For other banks, the first time you use the import on a device you are asked to agree, and the agreement is remembered on that device for your account; the statement text as extracted (dates, amounts and descriptions, and any names or addresses printed on it) is then sent to Anthropic's Claude model to be read. Long account, card and personal identification numbers are replaced first. We do not store the statement text on our servers.
- Purchases — if you subscribe to Aura Premium, the purchase is processed by Apple or Google; we receive your subscription status, never your payment details.
- Crash reports — error logs with a device identifier, device model and OS version, to help us fix bugs (via Firebase Crashlytics). They are collected automatically in release builds and cannot be switched off in the app.
- Usage analytics — which screens and features are used, without the content you enter (via Firebase Analytics). You can switch this off in Settings → Privacy & Security.
2. How We Use Your Data
- To sync your data across your devices.
- To send you reminders and notifications you configure.
- To let you connect with friends, message them, post to the feed and take part in challenges.
- To review reported content and keep the community safe.
- To power the AI assistant with context from your message.
- To turn a bank statement you import into transactions you can review and save.
- To improve app stability via crash reports.
We never sell your personal data to third parties.
3. Third-Party Services
- Supabase — cloud database, file storage and authentication. The primary database and file storage are hosted on AWS in the Mumbai (India) region; some parts of the service, such as serverless functions and file caches, can run in other regions. Privacy policy →
- Firebase (Google) — crash reporting, usage analytics and push notifications. Privacy policy →
- Prayer-time services (muftyat.kz, aladhan.com) — receive the coordinates of your device location (or of the city you choose) to return prayer times for it.
- OpenStreetMap — provides the map tiles for the time tracker; it sees the map area you view and your IP address. Privacy policy →
- Quran text and audio providers (api.quran.com, alquran.cloud, everyayah.com, islamic.network) — deliver the Quran text, translations and recitations you open; they see your IP address and which surah or verse you request.
- Groq — AI inference for the Aura AI assistant. Messages sent to Groq are subject to their privacy policy →
- Anthropic — AI inference (Claude) for the Aura AI assistant on Premium and for reading bank statements in formats the app cannot read on-device. Data sent through Anthropic's API is not used to train their models. Privacy policy →
- RevenueCat — subscription status for Aura Premium, linked to your account ID. Privacy policy →
4. Data Storage & Security
Your data is stored locally on your device (SQLite) and synced to Supabase cloud storage. We use HTTPS for all network communication, and our cloud provider encrypts stored data at rest. Passwords are never stored in readable form — authentication is handled by Supabase Auth.
Aura does not use end-to-end encryption. The developer of Aura can technically access data stored on our servers, including messages, and does so only to run the service, fix problems and review reports of abuse.
Our cloud provider and the other service providers listed above process data in several countries, including outside Kazakhstan and the European Union (for example India and the United States).
5. Your Rights
- Access and copies — your data is visible in the app at all times. To request a copy of your data, email us at the address below.
- Delete — in Settings → Privacy & Security, Delete All Data removes your tasks, habits, finance entries, prayer and worship logs and notes (deleted items are kept for up to 30 days before they are purged). Delete All Data does not remove your account, your friends, your feed posts or your challenge participation, and the summary figures shown to friends are refreshed the next time you open Friends. Delete account permanently removes your account, posts, messages, photos, check-ins and profile. A challenge or project you created that other people have joined is handed over to another member (its title and rules stay); if you are its only member it is deleted. Data already sent to Firebase (analytics and crash reports) is kept by Google under its own retention rules.
- Opt out of analytics — toggle off in Settings → Privacy & Security.
- Block and report — you can block another user and report messages or posts; reported content is reviewed by the developer.
- Retention — chat and direct messages are deleted after 180 days, feed posts after 90 days, friend, feed and challenge notifications after at most 90 days, and items you delete are purged from our database generally within 30 days. When you delete your account, the personal data tied to it is removed from our database and file storage; copies may remain in our provider's rolling backups for a short period.
6. Children
Aura is not directed to children under 13. We do not knowingly collect data from children.
7. Changes
We may update this policy. Significant changes will be notified in the app. Continued use after changes means you accept the updated policy.
8. Contact