1. Overview
AURA.AI provides AI-powered facial analysis, attractiveness scoring, aura reading, and related identity services ("Services"). To deliver these Services, we process certain personal data including images you upload. We are committed to protecting your data in accordance with applicable laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), India's Digital Personal Data Protection Act (DPDPA) 2023, and other relevant regulations.
2. Information We Collect
2.1 Information You Provide
- Photos & Images: Facial photographs you upload for analysis. These are processed by our AI models and deleted from our servers within 24 hours of analysis completion unless you explicitly save a result.
- Account Information: When you sign in via Google OAuth, we receive your name, email address, and profile picture from Google.
- User Content: Any feedback, messages, or content you voluntarily submit to us.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, click interactions, and session duration.
- Device & Technical Data: IP address, browser type and version, operating system, device identifiers, screen resolution, and referring URLs.
- Cookies & Tracking Technologies: We use cookies, web beacons, and similar technologies for session management, analytics, and advertising. See Section 4 for full details.
2.3 Information from Third Parties
- Google Sign-In: Name, email, and Google profile information if you authenticate via Google.
- Analytics Providers: Aggregated behavioral data from Vercel Analytics.
- Advertising Partners: Interest and demographic data from Google AdSense to serve relevant ads.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To process your uploaded images and generate AI-powered analysis reports.
- Account Management: To authenticate your identity, maintain your session, and manage your account.
- Service Improvement: To understand how users interact with our platform, fix bugs, and develop new features. We use only anonymized or aggregated data for this purpose.
- Communications: To send service-related notifications, updates, or respond to your inquiries. We do not send unsolicited marketing emails without your consent.
- Advertising: To display personalized advertisements through Google AdSense based on your usage behavior and interests.
- Legal Compliance: To comply with applicable laws, regulations, legal proceedings, or enforceable governmental requests.
- Safety & Security: To detect and prevent fraud, abuse, and violations of our Terms of Service.
⚠️ Important Notice on Biometric Data
Facial images constitute biometric data under GDPR, CCPA, and Illinois BIPA. We process your images solely for the purpose of generating your analysis report and do not use them to train AI models, sell them, or share them with third parties for their own use. Images are automatically deleted from our servers within 24 hours.
4. Advertising & Cookies
4.1 Google AdSense
We use Google AdSense to display advertisements on our site. Google and its partners may use cookies to serve ads based on your prior visits to our website and other websites across the internet. Google's use of advertising cookies enables it and its partners to serve ads based on your visit to our site and/or other sites on the internet.
You may opt out of personalized advertising by visiting Google Ads Settings or by visiting aboutads.info.
4.2 Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, session management | Session |
| Analytics | Usage analytics via Vercel Analytics | Up to 2 years |
| Advertising | Personalized ads via Google AdSense | Up to 2 years |
| Preferences | Saving user settings and preferences | 1 year |
4.3 Managing Cookies
You can control cookies through your browser settings. Disabling cookies may affect the functionality of our Services. For more information, visit allaboutcookies.org.
5. Data Sharing & Disclosure
We do not sell your personal information. We share your information only in the following circumstances:
- Service Providers: We share data with trusted third-party service providers (e.g., OpenAI for AI processing, Google Cloud, Vercel) who assist us in operating our Services. These providers are contractually obligated to protect your data and use it only for specified purposes.
- Advertising Partners: Google AdSense receives usage and cookie data to deliver targeted advertising, as described in Section 4.
- Legal Requirements: We may disclose your information if required by law, court order, or government authority, or to protect the rights, property, or safety of AURA.AI, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
- With Your Consent: We may share your data for any other purpose with your explicit consent.
6. Data Retention
- Uploaded Photos: Automatically deleted from our servers within 24 hours of analysis, unless you explicitly save the result to your profile.
- Analysis Results: Retained for as long as your account is active or as needed to provide services to you. You may delete saved results at any time from your profile.
- Account Data: Retained until you delete your account. Upon deletion, your personal data will be permanently removed within 30 days.
- Analytics Data: Aggregated and anonymized usage data may be retained indefinitely for business analytics purposes.
- Legal Holds: We may retain certain data longer if required by applicable law.
7. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Restriction
Request that we restrict processing of your data.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or direct marketing.
CCPA Rights (California)
Know, delete, opt-out of sale, and non-discrimination rights under CCPA.
Withdraw Consent
Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at privacy@auramaxing.tech. We will respond to your request within 30 days. We may need to verify your identity before processing your request.
CCPA Notice: We do not sell personal information as defined by the CCPA. California residents may submit requests at the contact information below.
8. Children's Privacy
Our Services are not directed to individuals under the age of 13 years old (or 16 years in the EEA/UK). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@auramaxing.tech. We will promptly delete such information from our records.
9. Data Security
We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, loss, destruction, or alteration. These measures include:
- End-to-end encryption (TLS/HTTPS) for all data transmitted to and from our servers
- Encrypted storage for sensitive personal data
- Strict access controls limiting data access to authorized personnel only
- Regular security audits and vulnerability assessments
- Automatic deletion of uploaded images within 24 hours
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page. For significant changes, we will notify you via email (if you have an account) or by displaying a prominent notice on our website. We encourage you to review this Privacy Policy regularly. Your continued use of our Services after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Team:
AURA.AI — Privacy Team
Email: privacy@auramaxing.tech
Website: https://www.auramaxing.tech
Response Time: Within 30 business days
If you are in the EEA and believe we have not handled your data appropriately, you have the right to lodge a complaint with your local Data Protection Authority (DPA).