Privacy Policy
What we collect, why, where it's stored, and what we never do. Last updated May 7, 2026.
- Routine-verification photos are classified on-device and immediately deleted.
- Sealed family memories (Genesis) ARE stored — encrypted, in a private vault accessible only to your verified family circle. You can delete any seal you created at any time.
- We never synthesize a family member's voice. AI-assisted features are clearly labeled.
- We never sell your data. You can delete everything from Settings → Delete Account.
Aura by First24 ("Aura," "we," "us," or "our") is a personal wellness and family-memory application. This Privacy Policy explains what we collect, why, where it's stored, and what we never do. This update reflects the addition of Aura Genesis (verified family memories), Bluetooth-mediated co-presence, hardware device attestation, and Apple Watch HRV duress detection.
1. Information We Collect
1a. Aura Safety (wellness routine, exposure context, verification)
| Data Type | How Collected | Stored Where | Retention |
|---|---|---|---|
| Account info (email, name, locale, timezone) | Sign-up | Encrypted at rest, RLS-protected | Until account deletion |
| Wellness score & streak data | App usage | Encrypted database | Until account deletion |
| Routine completion records (Golden Window) | App usage | Encrypted database | Until account deletion |
| Adherence-verification photos | Camera (optional) | Classified on-device, then deleted | Never stored — only SHA-256 hash + classification + EXIF timestamp/GPS persist |
| Adherence-verification metadata | Derived from photo | Encrypted database | 90 days (attestation TTL) |
| Device info (platform, OS, app version, model) | Automatic | Encrypted database | Until account deletion |
1b. Aura Genesis (verified family memories)
| Data Type | How Collected | Stored Where | Retention |
|---|---|---|---|
| Kin Circles (family group names) | You create them | Encrypted, RLS to active members | Until you delete the circle |
| Kin Memberships (display names + relationship label) | You invite them | Encrypted, RLS-protected | Until membership revoked |
| Invitation tokens | One-shot, server-generated | Encrypted database | 14 days, deleted on accept/revoke |
| Sealed memory photos / video / audio | You capture or import | Private storage bucket; RLS-restricted to active members | Until you delete the seal, or your account is deleted |
| Seal metadata (SHA-256 hash, method, timestamp, optional location, event, note) | Derived at capture | Encrypted database | Same as the seal |
| Seal participants (verified-present Kin) | You select OR confirmed via BLE | Encrypted database | Same as the seal |
| Seal proofs (attestation refs, capture-time, BLE co-presence sigs) | Derived at capture | Encrypted database | Same as the seal |
| Living Heirloom extensions (notes, voice, photos, drawings, AI-assisted summaries) | You and circle members add them | Text encrypted; media in private bucket | Until contributor soft-deletes, or seal is deleted |
| Time Capsule lock dates | You set them | Encrypted database | Same as the seal |
| Voice / AI consent flags | You set in Voice Consent settings | Encrypted database | Until account deletion |
1c. Co-presence (Bluetooth Low Energy)
| Data Type | How Collected | Stored Where | Retention |
|---|---|---|---|
| Short-lived BLE advertisement during seal capture | Phone broadcasts a random session token over BLE for up to 30 min | Broadcast over the air; not persisted | Token expires within 30 min |
| Witness records (another Kin's device detected the broadcast) | Their app posts a witness report when nearby | Encrypted, RLS-protected | Until the seal is deleted |
| Optional RSSI (signal strength) | Detected by witness device | Encrypted database | Until the seal is deleted |
1d. Device attestation (anti-fraud)
| Data Type | How Collected | Stored Where | Retention |
|---|---|---|---|
| Apple App Attest receipts / Google Play Integrity tokens | Apple / Google attest device integrity at install and periodically | Verification result + public key in encrypted database | Until account deletion |
| Stable per-install device id (UUID) | Generated on first launch; kept in app's secure storage | Encrypted database | Until account deletion or app reinstall |
| Attestation sign counter | Incremented by Apple / Google on each cryptographic operation | Encrypted database | Retained while device is registered (replay-prevention) |
1e. Aura Watch — HRV duress detection
| Data Type | How Collected | Stored Where | Retention |
|---|---|---|---|
| Heart-rate variability (HRV) patterns | Apple Watch sensors via HealthKit | On-watch and on-iPhone only — analyzed locally | Watch / phone storage; not transmitted |
| Duress alert events | Triggered on-device when HRV pattern matches stress threshold | Encrypted event marker only, not HRV time series | 30 days for the alert record |
| Designated emergency contacts | You configure them | Encrypted database | Until you remove them or delete your account |
1f. Subscription billing
| Data Type | How Collected | Stored Where | Retention |
|---|---|---|---|
| Subscription tier (free / Genesis Plus / Genesis Legacy) | RevenueCat webhook after Apple / Google Play purchase | Encrypted database | Until account deletion |
| One-time purchase credits (e.g. Heirloom Book unlocks) | RevenueCat webhook | Encrypted database | Until account deletion |
| RevenueCat purchase identifiers | RevenueCat webhook | Encrypted database | For fraud / billing reconciliation; until account deletion |
| Payment instrument data | NEVER collected by us | Apple / Google handle payments | n/a |
1g. Service operation
| Data Type | How Collected | Stored Where | Retention |
|---|---|---|---|
| Audit log of sensitive operations (capsule lock/unlock, exports, kin invite/revoke, subscription change) | Server-side, automatic | Encrypted, append-only | 2 years |
| Webhook event log (RevenueCat, deduplication) | Server-side, automatic | Encrypted database | 2 years |
| Crash reports | Automatic via Sentry — PII-scrubbed; user UUID + route breadcrumbs | Sentry servers | 90 days |
| Usage analytics | Automatic via PostHog — aggregate event counts; no message content | PostHog servers | Rolling 12 months |
2. Verification Photos — Immediate Deletion (Aura Safety)
When you use Verified Adherence, you may optionally photograph your care product. The photo is classified on-device using machine learning and immediately deleted. We retain only an image hash (SHA-256), the classification result, a timestamp, and optional EXIF GPS coordinates. The image itself never reaches our servers.
3. Sealed Family Memories — Aura Genesis
Aura Genesis is the family-memory module. When you "seal" a memory:
- The photo, video, or audio file you capture IS uploaded to a private, RLS-protected storage bucket.
- Only verified active members of the same Kin Circle can read the file.
- Deletes propagate: deleting the seal deletes the underlying file.
- The seal is bound by an HMAC-SHA256 cryptographic hash so any tampering with the media or its participants is detectable.
- We compute SHA-256 of the original bytes; the seal's identity is bound to that hash.
Living Heirloom extensions (notes, voice memos, photos, drawings) are added by you and family members after a memory is sealed. The original (Root Memory) is cryptographically immutable. Extensions chain off it append-only and form a verifiable timeline. AI-generated content (e.g. an AI-assisted summary of your family's contributions) is always clearly labeled with an "AI" badge in the app.
Voice consent & AI rules:
- Aura NEVER synthesizes a family member's voice. There is no AI voice clone feature.
- Voice recordings in Living Heirloom extensions are real recordings only.
- The Voice Consent screen lets you control whether AI features may incorporate your contributions (off by default), whether your voice may be heard after your account is closed (memorial mode, off by default), and whether others may record your voice into shared heirlooms (on by default — you control consent at the moment of recording anyway).
4. Bluetooth Proximity (Co-Presence)
If you enable "Detect nearby Kin" during a memory capture, your phone broadcasts a short-lived random session token over Bluetooth Low Energy (typically < 30 minutes). Other Aura installations in your circle that detect the broadcast can post a witness record to confirm presence. Bluetooth is not used for tracking or location. The session token is random per capture, expires automatically, and contains no personal information. If you don't enable this feature, no BLE broadcast or scan happens.
5. Device Attestation
To prevent fraud (e.g. fake "verified device" claims), Aura uses Apple App Attest on iOS and Google Play Integrity on Android. These services let our servers cryptographically verify that requests come from a real, untampered Aura install on a real device. We store the verification result + a public key + a sign counter. App Attest and Play Integrity do not provide us with personal information about you — they tell us only whether your install passes Apple's / Google's integrity checks.
6. Watch App — HRV Duress Detection
If you install AuraWatch on Apple Watch, the app reads heart-rate variability (HRV) data from HealthKit on-device to detect distress patterns. HRV time-series data never leaves the watch / phone pair. When a duress threshold is crossed, the app may send an alert to your designated emergency contacts; only the alert event (timestamp + your user id) is logged on our servers, not the HRV data itself.
7. How We Use Your Information
- Provide and improve the Aura wellness experience (Aura Safety)
- Enable family memory creation, verification, and sharing (Aura Genesis)
- Calculate your wellness score, streaks, and household stats
- Generate signed attestations for Verified Adherence (insurer programs)
- Verify devices via App Attest / Play Integrity to prevent fraud
- Deliver seasonal awareness alerts relevant to your region (CDC data)
- Trigger emergency-contact alerts on confirmed duress detection
- Process subscription payments through Apple App Store / Google Play (RevenueCat)
- Diagnose technical issues and improve app stability (Sentry, PostHog)
- Maintain an audit trail of high-stakes operations (capsule locks, exports)
8. Enterprise & Insurer Programs (Aura Safety)
If you enroll in Aura through an employer or insurer wellness program:
- Your employer or insurer receives de-identified, aggregate analytics about their enrolled population (e.g., average streak length, average response time). Reports never identify individual users and require a minimum cohort size of 50.
- If your plan offers co-pay incentives through Verified Adherence, your insurer may query individual attestation records by attestation id. The query returns only: verification status, response time, adherence score, and incentive eligibility. It does NOT return photos, audio, or any health information beyond what is covered by the Business Associate Agreement (BAA) between First24 and the insurer.
- Aura Genesis (family memories) is never exposed to enterprise or insurer queries — that data is strictly personal.
9. What We Never Do
- We never sell your personal data.
- We never store Verified Adherence photos.
- We never synthesize a family member's voice or face.
- We never use sealed family memories or extensions for AI training, advertising, or any purpose other than serving them back to your circle.
- We never share individual health data with employers or insurers without your explicit consent and a BAA in place.
- We never use your data for advertising. Aura does not run ads.
- We never expose HRV time-series data to our servers; only the duress event marker.
10. Data Security
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Authentication is handled through Apple Sign-In, Google Sign-In, or email magic links. Memory seals and Living Heirloom extensions are bound by HMAC-SHA256 hashes that detect tampering. Postgres row-level security ensures users can only read seals, extensions, witnesses, and entitlements they're authorized to. Webhook integrations (RevenueCat) require constant-time-compared shared secrets. Device attestation requires a real Apple App Attest receipt or Google Play Integrity verdict. The backend refuses to start in production with placeholder secrets, ensuring deploys can never silently run with predictable signing keys.
11. Your Rights
- Access your data — Settings → Export Data (returns JSON of all your records: account, kin circles you own or belong to, seals you created, extensions you authored, wellness data, subscription history)
- Delete your data — Settings → Delete Account (processed within 30 days)
- Soft-delete a single contribution — extensions you authored can be hidden via the Heirloom timeline
- Revoke Kin memberships you own (removes the member's access to the circle's seals)
- Set Voice / AI consent — Settings → Voice & AI Consent
- Opt out of analytics — Settings → Privacy
- Withdraw consent for microphone, camera, Bluetooth, location, or HealthKit — revoke in your device Settings at any time
12. California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at privacy@first24.io.
13. European Residents (GDPR)
If you are in the European Economic Area, our legal basis for processing is: consent (microphone, camera, Bluetooth, HealthKit access; voice / AI consent flags), contract performance (providing the Aura service, processing payments), and legitimate interest (crash reporting, fraud prevention via device attestation, audit logging). You have the right to access, rectify, erase, restrict processing, and port your data. Contact our Data Protection Officer at privacy@first24.io.
14. Children's Privacy
Aura is not directed to children under 13. Family members under 13 may be added to a Kin Circle by a parent or guardian, but the parent's account controls all data. Voice recordings of minors (e.g. a child's milestone in a Living Heirloom) are stored only at the parent's instruction and can be deleted by the parent at any time. We do not knowingly collect personal information directly from children under 13.
15. FTC Health Breach Notification
Even though Aura is a wellness tool and not a HIPAA-covered entity, we comply with the FTC Health Breach Notification Rule. In the event of a breach involving health-related data, we will notify affected users and the FTC as required by law.
16. Third-Party Services
Aura relies on these third-party services. Each is bound by its own privacy policy:
| Service | Purpose | Data sent | |
|---|---|---|---|
| Supabase | Database, authentication, storage | All persisted Aura data | |
| Apple (App Store, App Attest, Sign-In, HealthKit) | Auth, payments, device attestation, HRV input | Auth tokens, App Attest receipts, purchase events | |
| Google (Play Store, Play Integrity, Sign-In) | Auth, payments, device attestation | Auth tokens, Play Integrity tokens, purchase events | |
| RevenueCat | Subscription bridge between App Store / Play Store and our backend | Purchase events, subscription state, your user id | |
| Sentry | Crash reporting | Error stacks + route breadcrumbs + your user id | |
| PostHog | Aggregate product analytics | Anonymized event counts (e.g. "seal created"); no message content | |
| Fly.io | Backend hosting | All API traffic (encrypted in transit) | |
| CDC public APIs | Seasonal awareness data | Outbound only; we don't send your data to CDC |
17. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated through the app and by updating the "Last updated" date above. Continued use of Aura after material changes constitutes acceptance.
18. Contact Us
First24, Inc.
Burleson, Texas
Email: privacy@first24.io