Privacy
Last updated 31 July 2026 · Aura is a personal project in active development.
Aura's rule is the same as its design principle: nothing happens to your data without your say-so, and we'd rather tell you plainly than impress you vaguely.
What Aura stores
- Your account — email, name, and a hashed password (we never store the password itself; Google sign-in shares your name and email, never your Google password).
- Your stuff — events, tasks, calendars and notes, stored in Aura's database (hosted on Convex) so every device you sign into sees the same day.
- Photos and attachments — kept in your browser's own storage, on the device that added them. They are not uploaded.
- AI keys — if you add one, it is encrypted (AES-256-GCM) before it is stored, and is only ever decrypted server-side to make your own requests. No client can read it back.
What Aura sends to AI providers
Only if you turn the assistant on, and only to the provider you chose (Claude, ChatGPT, Gemini or Groq): your message, and a compact snapshot of your tasks, events and notes so it can answer usefully. That provider processes it under its own terms and bills your key directly. With the assistant off, nothing leaves except sync itself.
What Aura doesn't do
- No analytics, no trackers, no ads, no cookies beyond the session that keeps you signed in.
- No selling, sharing or mining of your data. There is no business model attached to it.
- No reading your calendar to build a profile of you. It's yours.
Deleting everything
Setup → Account → Delete account. It wipes your account and every event, task, calendar and note from the database immediately and permanently. No retention, no "30-day grace", no export nag.
Contact
Questions: gokingcool9321@gmail.com