Legal · Privacy

Privacy Policy

Aura is built local-first. Your code lives on your machine, not ours. This policy explains the limited data we do handle when you sign in, sync, or pay: in plain language, without the boilerplate.

Effective July 24, 2026

This Privacy Policy describes how the Aura product handles your information. The Aura product means the website at auravcs.com, the Aura desktop app, the Aura CLI, the Aura mobile app, and Aura Cloud (collectively, “Aura”, “we”, “us”). Aura is operated by Naridon, Inc. The Aura iOS app is distributed on the Apple App Store by Aikolumi Software Pvt.

The short version

  • Local-first by default. The engine, CLI, and desktop app run against a local daemon. Your source code, diffs, and semantic history stay on your machine and are never uploaded for analysis.
  • Cloud only when you choose it. Data leaves your machine only when you sign in and use a feature that needs the cloud: sync, team collaboration, live-sync, chat history across devices, or the mobile app.
  • No ad tracking, no data sale. We do not run advertising trackers, we do not track you across other apps or websites, and we never sell your data.
  • Analytics are opt-in. Product analytics are off until you consent, and are collected without advertising identifiers.

Information we collect

Account and identity

You sign in to Aura Cloud with GitHub. When you do, we receive your GitHub username, the email address associated with that account, your avatar, and a stable account identifier. We use this to identify you across your devices and teammates, and to attribute changes and messages to you rather than to “an agent”.

Content you sync to Aura Cloud

When you are signed in and use sync or collaboration, we store the Aura ledger for your project: the signed intent log, semantic (AST-level) change metadata, provenance records, sessions, tasks, notes/Pages, and chat messages you send to the assistant. If you explicitly use live-sync or team collaboration, the specific function bodies or code snippets you push are synced so teammates can pull them; this is the one path where code content leaves your machine, and only for the symbols you share.

Payment information

Paid plans are handled by Stripe. Stripe processes your card details directly. We never see or store your full card number. We retain only what we need to manage your subscription (plan, status, and a billing identifier).

Product analytics (opt-in)

If you consent, the desktop app sends anonymous product-usage events (for example, which surfaces are used) to our analytics provider, PostHog, hosted in the EU. Events are keyed to a random device identifier, not to advertising IDs, and you can decline: analytics stay off until you opt in.

Mobile app

  • Camera: used only to scan a QR code when pairing the app to your cloud. Camera frames are processed on-device to read the code and are not stored or transmitted.
  • Push notifications: if you enable them, we store a push token (from Apple / Expo) so we can notify you when an agent needs you or a session updates. No notification content is used for tracking.
  • Settings: your selected project and cloud address are stored on the device (Keychain-backed) so the app remembers where to connect.

Technical and log data

When your client talks to Aura Cloud, our servers process standard request data (IP address, timestamps, and basic device/app version) to route traffic, keep the service secure, and debug problems. We do not build advertising profiles from it.

What we do not do

  • We do not sell or rent your personal data.
  • We do not run third-party advertising networks or ad trackers.
  • We do not track you across other companies’ apps or websites.
  • We do not upload your source code for analysis in the default, local-first flow.

How we use information

  • To provide the product: authenticate you, sync your work, and power collaboration.
  • To run the assistant and agents you invoke, and to attribute their work.
  • To operate billing for paid plans.
  • To keep the service secure and reliable, and to fix bugs.
  • With your consent, to understand product usage in aggregate and improve Aura.

Service providers

We share data only with the providers that make Aura work, and only as needed:

  • GitHub: sign-in / identity.
  • Stripe: payment processing for paid plans.
  • PostHog (EU): opt-in, anonymized product analytics.
  • Apple / Expo: mobile push-notification delivery.
  • Our cloud hosting provider: running Aura Cloud infrastructure.

Each provider handles data under its own terms and only for the purpose above.

If you self-host

Aura’s engine and CLI are open source, and you can run Aura Cloud on your own infrastructure (the aura:// substrate). When you self-host, your synced data lives on servers you control, and this policy’s cloud sections apply to your deployment, not ours.

Data retention

We keep account and synced data for as long as your account is active. When you delete your account or ask us to remove your data, we delete it from our production systems within a reasonable period, except where we must retain limited records for legal, security, or billing reasons.

Your rights and choices

  • Access & export: request a copy of the data we hold about you.
  • Correction: ask us to fix inaccurate account data.
  • Deletion: ask us to delete your account and associated data.
  • Analytics: decline or withdraw analytics consent at any time.

Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. To exercise any of these, email us at mo@auravcs.com.

Security

Traffic between your clients and Aura Cloud is encrypted in transit (HTTPS/TLS). Signed intent and provenance records are cryptographically verifiable. No system is perfectly secure, but we design Aura so that the default path keeps your code on your own machine.

International data transfers

Aura is available globally, and our providers may process data in regions including the United States and the European Union. Where required, we rely on appropriate safeguards for cross-border transfers.

Children’s privacy

Aura is a developer tool intended for adults and is not directed to children. We do not knowingly collect personal information from children under 13 (or the minimum age in your jurisdiction).

Changes to this policy

We may update this policy as the product evolves. When we make material changes, we will update the effective date above and, where appropriate, notify you in the app.

Contact

Questions about privacy, or a data request? Email mo@auravcs.com. We read every message.