Skip to content
Back to Aura

Mobile app privacy

Aura app privacy policy.

This policy describes the Aura iOS and Android applications operated by ParathoughtLabs LLC. It identifies the data categories Aura processes, why they are used, who receives them, how long they are retained, and the controls available to users.

Effective August 10, 2026

Current service boundary

Aura is an adult-only service. Aura has no paid subscription, premium feature tier, or advertising product. Paid event tickets and organizer payouts are disabled in the current pre-alpha service. Aura does not sell personal data or share it for cross-context behavioral advertising.

Ticket payments and the free app

Every Aura app feature is available without a consumer subscription. Aura does not serve third-party advertising. The intended revenue source is a disclosed platform fee on paid event tickets, similar to other event-ticket marketplaces.

If ticket commerce is enabled after its separate release review, Aura will use Stripe-hosted Checkout for buyers and Stripe Connect for organizer payouts. Stripe may process transaction identifiers, payment status, fraud and security signals, and the payment information described in its notice. Aura will not store card numbers or security codes in its mobile apps.

Data Aura is designed to process

  • Account and profile: name, age confirmation, email or provider identifier, photo, biography, interests, education, work, social links, settings, verification state, friends, blocks, and free profile follows.
  • Optional mutual contact matching: after a user chooses Find friends from contacts and grants the operating-system permission, Aura normalizes email addresses and phone numbers on the device and sends only bounded one-way hashes to the authenticated AWS service. Contact names and raw address-book values are not uploaded. Aura reveals a match only when both members' recent address-book snapshots contain one another, applies an account-level request limit, expires stale snapshots, and keeps a separate default-off choice for whether the user's verified account email or phone can participate in matching.
  • Events and user content: event details, invitations, attendance, groups, messages, reactions, polls, reviews, reports, photos, videos, memories, and selected audiences.
  • Location: a selected city and, only after a separate runtime choice, precise or approximate device or live location for nearby discovery, maps, and permissioned sharing.
  • Device and operations: app version, device and operating-system information, IP address, security events, crash and performance diagnostics, notification token, and service logs needed to protect and operate Aura.
  • Safety and support: reports, blocked identifiers, moderation decisions, appeals, support correspondence, and evidence required to investigate abuse.

Do not place passwords, government identifiers, medical records, card numbers, or other unnecessary sensitive data in messages or events.

Purposes and sharing

Aura uses data to authenticate users; provide discovery, messaging, events, maps, planning, profile follows, and memories; apply privacy audiences; prevent fraud and abuse; provide support; comply with law; and maintain service reliability. Aura does not sell personal data or use it for cross-context behavioral advertising.

Data may be shared with the people and audiences a user selects, event or group participants, and contracted infrastructure, identity, map, media, email, support, moderation, security, and app-store providers only as necessary for their services. Current provider categories include Amazon Web Services and Amazon Cognito, Apple and Google platform services, map providers selected by the operating system, Vercel, Resend, and the social sign-in provider a user chooses. Stripe is a conditional provider only if the separately reviewed ticket-payment feature is enabled. Provider access is limited by contract and configuration to the service being performed.

Control, retention, and deletion

Users can control profile, friends, event-history, attendee, and live-location audiences; stop live sharing; block people; and report profiles, events, or conversations. Runtime permissions can be denied or revoked in iOS or Android settings without losing unrelated features. Public events can allow reviews; private events do not publish reviews.

  • Account data and user content remain while the account or content is active and are erased after verified account or content deletion, subject to a documented legal or safety hold.
  • Notifications expire after 90 days. Verification evidence is deleted after the review decision; Aura does not create biometric templates. A limited verification decision record expires after 365 days.
  • Reports, moderation decisions, and appeals are retained for up to 730 days unless a shorter period is appropriate or a documented legal or safety hold applies.
  • Production application and security logs are retained for up to 365 days and test logs for 30 days. Logs must not contain message bodies, precise location, credentials, access tokens, or verification evidence.
  • DynamoDB recovery points use the provider’s rolling window of no more than 35 days. Deleted or replaced media versions expire within 90 days in production and 30 days in test.

Users can initiate account and associated-data deletion in Profile or at the public account deletion page. See Privacy Choices for access, correction, portability, consent withdrawal, limitation, and appeal requests.

Before financial processing is enabled, ParathoughtLabs will publish a reviewed field-level retention schedule. Applicable tax, fraud, dispute, or regulatory records may need to be retained after account deletion; any such exception will be limited, access-controlled, and explained before processing begins.

Location, verification, and sensitive information

Aura offers manual city selection when device location is unavailable. Precise or live location is optional, requires a separate permission and feature choice, is limited to the selected audience, and can be stopped at any time. Aura does not request background-location permission.

Verification evidence is available only to authorized reviewers and is deleted when the review is decided. Aura does not create face geometry or biometric templates. Fitness and wellness interests are used as discovery preferences; Aura does not infer a diagnosis, sell consumer health data, or integrate health records.

Security, age, and contact

Aura uses HTTPS-only transport, least-privilege access, protected release signing, server-side authorization, and encrypted provider storage as production requirements. No system can guarantee absolute security. Aura is for adults age 18 and older, does not offer child profiles, and follows its child safety standards.

For access, correction, deletion, portability, consent withdrawal, limitation, appeal, or privacy questions, use Privacy Choices or contact support@parathoughtlabs.com. Identity verification may be required. Applicable users may also complain to their privacy regulator.

© 2026 ParathoughtLabs. Account deletion Privacy choices Terms Privacy contact