Privacy Policy

Last Updated: February 20, 2026


Our Commitment

At AURA, we believe that meaningful connections start with trust. This Privacy Policy explains how we collect, use, protect, and share your information when you use the AURA mobile application and related services. We are committed to being transparent about our data practices and giving you control over your personal information.

01

Information We Collect

Information You Provide Directly

Information Collected Automatically

Information from Third Parties

02

How We Use Your Information

We use the information we collect for the following purposes:

Purpose Data Used
Account creation & authentication Account info, sign-in provider data
AI personality analysis & matching Conversation data, usage patterns, preferences
Delivering matches & Chemistry Scores Personality DNA, location, preferences
Blur Reveal & mission features Interaction data, photos, match progress
Chat, Confession Wall & Whisper Messages, user-generated content
Push notifications & alerts Device tokens, preferences, match events
Safety & content moderation Messages, photos, reports, usage patterns
Product improvement & analytics Usage data, device info, crash reports
Payment processing Purchase history, subscription status
Legal compliance & fraud prevention Account info, log data, device info
03

AI & Personality Analysis

Important — Third-Party AI Processing

AURA uses OpenAI, a third-party AI service provider, to analyze your personality and generate compatibility matches. Before any of your data is sent to OpenAI, you will be asked for your explicit consent through a dedicated consent screen within the app. You may decline and choose not to proceed.

What Data Is Sent to OpenAI

When you consent to AI processing, the following data is sent to OpenAI's servers:

What Data Is Never Sent to OpenAI

The following personal information is never shared with OpenAI or any third-party AI provider:

How Your Data Is Processed

OpenAI's Data Handling

Data Retention by OpenAI
  • We use the OpenAI API with zero data retention — OpenAI does not store your data after processing.
  • OpenAI does not use your data to train or improve their models.
  • All communication between AURA and OpenAI occurs over encrypted HTTPS connections through our secure servers.
  • For more information, see OpenAI's API Data Usage Policy.

Your Consent & Control

AI Data Processing Principles

Content Moderation

AI-powered systems automatically scan user-generated content (messages, photos, confessions) to detect and filter explicit, harmful, or harassing content. This processing is essential to maintain a safe environment for all users.

04

How We Share Your Information

We do not sell your personal information. We share data only in the following limited circumstances:

With Other Users

With Service Providers

For Legal Reasons

We may disclose information if required by law, subpoena, or legal process, or if we believe in good faith that disclosure is necessary to protect the safety of any person, prevent fraud, or respond to a government request.

Business Transfers

In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction. We will notify you via in-app notice or email before your information becomes subject to a different privacy policy.

05

Data Retention

We retain your information only for as long as necessary to provide our services and fulfill the purposes described in this policy.

Data Type Retention Period
Account & profile data Until account deletion
AI conversation data Processed into embeddings, then deleted within 90 days
Personality DNA vectors Until account deletion
Chat messages Until account deletion by either participant
Confession Wall posts Until deleted by user or account deletion
Photos Until removed by user or account deletion
Location data Approximate location cached for 24 hours only
Usage & analytics data Aggregated data retained up to 24 months
Safety & moderation records Up to 3 years for abuse prevention

When you delete your account, we begin the deletion process within 30 days. Some data may be retained in encrypted backups for up to 90 days before complete removal. Data required for legal obligations or dispute resolution may be retained longer as permitted by law.

06

Data Security

We implement industry-standard security measures to protect your personal information:

While we strive to protect your information, no method of electronic transmission or storage is 100% secure. If you discover a security vulnerability, please contact us immediately at support@appflows.co.

07

Your Rights & Choices

You have the following rights regarding your personal data:

Your Controls
  • Access: Request a copy of the personal data we hold about you.
  • Correction: Update or correct inaccurate information in your profile at any time.
  • Deletion: Delete your account and associated data through Settings > Account > Delete Account, or by contacting us.
  • Data Portability: Request your data in a structured, machine-readable format.
  • Withdraw Consent: Revoke consent for optional processing (e.g., location services, notifications) at any time.
  • Restrict Processing: Request that we limit how we use your data in certain circumstances.
  • Object: Object to processing based on legitimate interests, including AI-based profiling.

Managing Permissions

Account Deletion

You may delete your account at any time from Settings within the app. Upon deletion:

To exercise any of these rights, contact us at support@appflows.co. We will respond within 30 days.

08

Cookies & Tracking Technologies

AURA is a native mobile application and does not use browser cookies. However, we use the following technologies:

On iOS, you will be prompted via the App Tracking Transparency dialog before any cross-app tracking occurs. You may change your preference at any time in your device settings.

09

Third-Party Services

We integrate with the following categories of third-party services:

Service Category Purpose Data Shared
Cloud Infrastructure Hosting, storage, database All data (encrypted)
AI Processing (OpenAI) Personality analysis, moderation Conversation text only (no name, photos, or contact info). Requires explicit user consent. Zero data retention by OpenAI.
Authentication Sign-in services Auth tokens, email
Analytics Usage insights Anonymized usage data
Notifications Push delivery Device tokens, message content
Payment Processing Subscriptions & purchases Handled by App Store / Play Store

All third-party providers are bound by data processing agreements and are required to handle your data in accordance with this policy and applicable law. We do not allow third-party providers to use your data for their own purposes.

10

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer data internationally, we implement appropriate safeguards:

11

Children's Privacy

AURA is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected data from a user under 18, we will delete that information immediately. If you believe a minor has provided us with personal data, please contact us at support@appflows.co.

12

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:

Categories of Information Collected

Identifiers Photos Geolocation Usage Data Inferences Sensitive PI

To submit a request, email support@appflows.co or use the in-app privacy request form. We will verify your identity before processing your request and respond within 45 days.

13

European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply:

Legal Bases for Processing

Processing Activity Legal Basis
Account creation & service delivery Performance of contract
AI personality analysis & matching Consent
Safety & content moderation Legitimate interest
Analytics & product improvement Legitimate interest
Marketing communications Consent
Legal compliance Legal obligation
Location-based features Consent

Additional Rights

14

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes:

We encourage you to review this policy periodically. Your continued use of AURA after changes are posted constitutes your acceptance of the updated policy.

15

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us:

Email
support@appflows.co

Mailing Address
APPFLOWS TEKNOLOJİ ANONİM ŞİRKETİ
Pınarbaşı Mah. Hürriyet Cad. Akdeniz Üniversitesi Uluğbey AR-GE 2 No: 3 A İç Kapı No: B33
Konyaaltı/Antalya 07070 Turkey

We aim to respond to all privacy-related inquiries within 30 days.