AURA · PRIVACY Effective 23 June 2026

What we store,
and what we don't.

Aura is a music-discovery app that lives on your phone. There is no Aura server. Almost nothing leaves your device, and the few things that do leave do so anonymously.

Contents

  1. The short version
  2. Data that never leaves your phone
  3. Anonymous data that does leave
  4. Data sent only when you connect an account
  5. Sharing, only when you choose
  6. Crash reports
  7. How your data is stored
  8. Your rights and controls
  9. Children's privacy
  10. Changes to this policy
  11. Contact

The short version

Aura is built local-first. The app:

If you uninstall the app, every byte of your data goes with it.


Data that never leaves your phone

The following data lives only on your device and is never transmitted to any server, including ours:


Anonymous data that does leave your phone

To recommend music, Aura sends anonymous catalogue queries to the following public music databases. None of these requests include any user identifier. The third parties below cannot connect the requests to you personally.


Data sent only when you connect an account

You may optionally connect a Google account (for YouTube) and/or a Spotify account. These connections are opt-in. You can use Aura entirely without them. When you choose to connect:

YouTube / Google

If you tap "Connect to YouTube" in onboarding or in Settings → Connections, Aura uses Google's standard OAuth 2.0 flow (with PKCE) to obtain:

The scopes requested are: youtube.readonly, youtube, userinfo.email, userinfo.profile. The access and refresh tokens are stored in encrypted local storage and never leave your device except in calls to Google's own APIs.

Spotify

If you tap "Connect to Spotify," Aura uses Spotify's OAuth 2.0 flow (with PKCE) to:

You can disconnect either account at any time from Settings → Connections. Disconnecting wipes the local tokens and (for Google) issues a best-effort token revocation at Google's servers.


Sharing, only when you choose

Aura includes a Postcard feature: turning a song into a stamped, signed image you can share. When you tap Send:


Crash reports

If Aura crashes or hits an unhandled error, an anonymized crash report may be sent to Sentry (sentry.io), a third-party error-tracking service we use to fix bugs. Crash reports include:

Crash reports do not include your name, email, OAuth tokens, taste profile, marginalia notes, or any other personal data we hold on-device. Sentry retains crash data for 90 days.


How your data is stored

Everything on-device is stored in MMKV, a fast key-value store, with AES encryption. The encryption key is generated on first launch with a cryptographic random number generator and stored in the iOS Keychain / Android Keystore, which are protected by your device's secure-element hardware (Secure Enclave on iOS, StrongBox / TEE on Android).

Even with physical access to your phone, the data is unreadable without your device's unlock credentials.


Your rights and controls

From Settings → Privacy, you can at any time:

Uninstalling the app also wipes all on-device data. There's nothing else to clean up.

If you've connected Spotify, you can revoke Aura's access at any time from spotify.com/account/apps. If you've connected Google, you can revoke at myaccount.google.com → Security → Third-party apps.

EU residents (GDPR)

Aura is designed so that the developer (the data controller in EU terms) holds no user data on any server. The "right to access," "right to erasure," and "right to data portability" are exercised directly in the app via the Download / Delete buttons described above. We do not need to receive a request. Your data is already entirely in your hands.

California residents (CCPA/CPRA)

Aura does not sell or share personal information for cross-context behavioural advertising. We do not collect personal information at any Aura-owned server. The "right to know" and "right to delete" are exercised in-app.

India residents (DPDP Act)

Aura processes your personal data lawfully under your consent (given by completing onboarding and connecting any optional accounts). You can withdraw consent at any time by disconnecting accounts or deleting the app.


Children's privacy

Aura is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has connected an account through Aura, please contact us and we will assist you in revoking that account's grant.


Changes to this policy

This privacy policy may be updated to reflect changes in Aura's features or in applicable law. When we make material changes, we will update the "Effective" date at the top and surface a brief notice in-app on next launch.


Contact

If you have any questions about this privacy policy or your data, write to:

vmcniket@gmail.com

We aim to respond within 7 days.

AURA · A QUIET, GROWING PIECE · © 2026