Privacy Policy

Effective date: [DATE] · Last updated: [DATE]

Auræ (“Auræ”, “the app”, “we”, “us”) is an astrology and self-reflection app made by [Yogesh Gahlot], based in [City, Province], Canada. This policy explains what the app does and does not do with your information. If anything here is unclear, email privacy@getaurae.app.

The short version

Who we are

Auræ is operated by [Yogesh Gahlot] (“the developer”). For any privacy question, request, or complaint, contact privacy@getaurae.app.

No account, no identity

Auræ works entirely on your device without an account. We do not collect your name for our records, your email, or any login. The app generates a random, anonymous device identifier (a hashed value) used only to verify your subscription and to route optional push notifications. It is not linked to your identity and we cannot use it to contact you.

Information you provide, and where it lives

When you set up your chart you may enter your name, birth date, birth time, and birth place. If you subscribe to the numerology add-on, you may enter a birth name. All of this is stored only on your device (in the app's local storage and, for sensitive recovery data, the device Keychain). We do not have a copy.

Your conversations (The Arc)

Conversations with the Oracle are stored on your device, encrypted with a key held in your device's Keychain (AES-256-GCM, this-device-only). They are never uploaded to us or synced to our servers. We cannot read them. Older sessions are pruned automatically, and you can delete them yourself at any time.

What is sent off your device

To generate a reading, the app sends a request to our secure relay server (hosted on Cloudflare) which forwards it to our AI provider, Anthropic (the Claude API). A request contains only:

Requests are sent over encrypted connections (TLS). We do not store the content of these requests on our servers. Anthropic processes the request to produce a response and, per their terms, does not use API content to train their models. See Anthropic's privacy terms.

Each request also carries a device-integrity token (Apple App Attest) and your subscription receipt, used solely to confirm the request comes from a genuine copy of the app and that your subscription is valid. These do not identify you.

Location

If you grant permission, the app uses your current location while you are using the app (never in the background) to name your current city for context in readings. Your location is used on your device only and is not transmitted to us or to any third party. You can decline or revoke this permission in iOS Settings.

Notifications

Notifications are private by default: they are generated and scheduled entirely on your device, with no server involvement.

You may optionally switch to Connected delivery. In that mode only, we register your device's push token with our server and briefly store the text of your daily reading (for up to about 48 hours) so it can be delivered via Apple's Push Notification service. This text contains no name, birth data, or identifiers. Switching back to Private mode removes your token and stored content from our server.

Subscriptions and purchases

Purchases are handled entirely by Apple through the App Store. We never see your payment details. We receive only Apple's signed receipt confirming which subscription you hold, used to unlock features.

Recovery backup (optional)

If you reset your profile, some non-identifying data (such as your streak and chart signs — never your name) may be kept for a 30-day grace period so you can restore it, then deleted. Recovery data on your device may be included in your normal iCloud device backup, which is controlled and encrypted by Apple under your iCloud account, not by us.

Third parties

We use no analytics, advertising, tracking, or crash-reporting services of any kind. The only external parties that ever receive data are:

Data retention

Your choices and rights

Because your data lives on your device, you are in control of it:

Depending on where you live (including under Canada's PIPEDA, the EU/UK GDPR, and California's CCPA/CPRA), you may have rights to access, correct, or delete personal information, and to lodge a complaint with a regulator. Since we hold essentially no personal data on our servers, most of these rights are exercised directly on your device; for anything else, email privacy@getaurae.app and we will respond within the time your law requires. We do not sell or share personal information, and we do not use it for advertising.

Children

Auræ is not directed to children. You must be at least [13 / 16] years old to use the app. We do not knowingly collect information from children under that age.

International use

The app is operated from Canada and uses service providers (Anthropic, Cloudflare, Apple) that may process data in the United States and other countries. Where required, these transfers rely on appropriate safeguards.

Changes to this policy

If we change this policy we will update the date above and, for significant changes, note it in the app. Continued use after a change means you accept the updated policy.

Contact

Questions or requests: privacy@getaurae.app
Developer: [Yogesh Gahlot], [City, Province], Canada.