Back to Aura

Privacy Policy

The short version

  • We don't run any servers for Aura. There's nothing to collect you on.
  • No accounts, no signup, no telemetry, no analytics.
  • Your API keys live in the system Keychain, on your device. We never see them.
  • Your prompts and generated media go straight from your device to the AI providers you configure — never through us.

What we collect

Nothing. Aura doesn't operate any backend, so there's no database with your name in it, no usage logs, no crash reports phoning home, no analytics SDK counting your sessions.

Concretely, that means:

  • We can't tell you how many images you've generated, because we don't know.
  • We can't recover your projects or history if you lose them — they're only ever on your device.
  • We have nothing to hand over in a data breach, because we hold no data.
  • If you email support, we have your email and whatever you tell us. That's the only "your data" we ever hold, and only if you send it to us.

Your API keys

Aura is bring-your-own-key: Kie.ai, FAL.ai, Runware, Replicate, Runway, Higgsfield, or any custom endpoint you add. Keys are stored in the system Keychain (macOS and iOS), encrypted by the OS, on your device. Aura reads a key only to attach it to a request you initiated, sent directly to the provider it belongs to. Keys never pass through any server we run, because we don't run one.

Where your prompts and media go

When you generate something, your prompt and any reference files go directly from your device to the provider you picked for that model — Kie.ai, FAL.ai, Runware, Replicate, Runway, Higgsfield, or your custom endpoint. That provider processes the request under its own privacy policy and terms, not ours. Worth reading theirs if you care about retention.

Two features route data to an LLM you've configured, specifically:

  • Enhance Prompt sends your prompt text to your configured LLM provider so it can rewrite it. If you've attached reference images or video, it also sends downscaled snapshots of those so the LLM can see what you're working with.
  • Heal sends prompt/request details to your configured LLM provider, along with a live web search against provider docs, so it can diagnose and repair a broken API call.

Both features only run against the provider you set up for them, with your key. Nothing routes through us.

Provider signup links

Signup links for providers inside Aura may carry a referral code, so the provider can tell that your signup came through Aura, and we may earn a commission when you create an account (see the Terms of Use for the details). The code identifies Aura, not you — we send the provider nothing about you, and any commission reporting we receive comes from the provider under its own terms.

Purchases

Aura is sold through the App Store: a 30-day free trial, then a one-time $49 purchase. Apple handles the transaction end to end. We never see your card number, billing address, or any other payment detail — Apple doesn't pass that along to developers, and we haven't asked for a way around that.

The website

useaura.app is a static site. No cookies, no analytics, no trackers, no forms that phone home. It's served by Vercel, which — like any host — keeps standard server logs (IP address, request time, requested page) for operating and securing the network. We don't add anything to that; it's just what a web server does by default.

Children

Aura isn't directed at children, and we don't knowingly collect information from anyone — which is easy, since we don't collect information from anyone, period.

Changes

If this policy changes, we'll update the effective date above and post the new version at this URL. We won't bury changes or backdate them.

Contact

Questions about this policy: support@useaura.app