Back to Aurora

LEGAL  ·  UPDATED

Privacy Notice

What the app keeps on your device, what a diagnostic report contains if you send one, what this website collects when you ask for TestFlight access, and how to have it deleted.

This notice covers three things: the Aurora app, the diagnostic reports you choose to send us, and the website at auroraisyours.com. The app is built so that your conversations stay on your device. A diagnostic report leaves only when you send it, and this page says what is in one. The website collects a little, and this page lists all of it.

The short version. Your conversations are processed and stored by the iPhone that heard them. Aurora is local-first, not network-free: there is a one-time model download, an aggregate setup estimate, a free-minutes counter in your own iCloud storage, two optional features you have to switch on, an optional setup measurement you are asked about once, and a diagnostic report if you send one. That list is complete and it is below.

A diagnostic report is only ever sent because you sent it. But when you report a problem from inside a session, the one switch that attaches that session's transcript, chat, recording and screenshot starts on — so read it before you send.

This website keeps your email address if you ask for TestFlight access, and nothing else. No cookies, no tracking scripts, no IP addresses.

Contents

  1. Who we are
  2. The app: what stays on your device
  3. The app: what can leave, and why
  4. Diagnostic reports
  5. This website
  6. What we store about you, and why
  7. Deleting your data and unsubscribing
  8. Your rights
  9. Transfers outside the EU
  10. Children
  11. Changes to this notice

Who we are

The controller for the data described here is The Code Lab by Leandro Piccione, the maker of Aurora, of ul. Świeradowska 47, 02-662 Warszawa, Poland (NIP 7011105083, REGON 523096127, EU VAT PL7011105083). You can reach us at hello@auroraisyours.com.

The app: what stays on your device

Recording, transcription, speaker separation, summaries, notes and Ask Aurora run on the iPhone in front of you. Audio, transcripts and everything generated from them are stored in the app's library on that device. We do not operate a server that receives them. There is no account with us, and the app carries no usage analytics or tracking — the one measurement it can send is the setup-metrics record described below, which is refusable and contains no content.

The app: what can leave, and why

Aurora is local-first, not network-free. These are the named network paths, and there are no others. Each one is listed here with what starts it, what it carries and where it goes; the same list is kept in the site's repository as a network inventory, read out of the app source at a named commit so it can be checked line by line.

  • Model download. The speech and language models are fetched once so the device can work offline from then on. It is a real network request: no conversation content travels with it, but the host serving the models sees the request itself — your IP address, the time, and how much you fetched. Over a cellular connection, anything more than a small remainder waits until you allow it.
  • Setup time estimate. While models are being prepared, Aurora asks our own service how long preparation usually takes on a device like yours. The request carries four coarse fields — the platform, a device class, whether Low Power Mode is on, and the model generation — and no identifier. What comes back is an aggregate. A build with no estimate endpoint configured makes no request at all.
  • Free-minutes counter. Aurora records how much free recording time has been used as a single number in your own iCloud key-value storage, so that reinstalling the app does not hand out a fresh trial. It carries no audio, no transcript and nothing about what you recorded. This path is not covered by the iCloud sync setting below: it is the one path in the app that is always on.
  • Purchase or evaluation check. Verifying a purchase or evaluation entitlement, when that applies. Nothing is verified when the app launches; our purchase provider is contacted only when you open a subscription screen, buy something or restore a purchase. In a TestFlight build that screen is reachable from Settings so testers can exercise the real purchase flow.
  • Optional settings sync. Off by default. If you turn on iCloud sync, selected settings go through your own iCloud account. Audio and transcripts are not part of it.
  • Optional web research. Off by default. If you enable it in Ask Aurora, a minimized query is sent to the web search service. Audio and transcript content are not part of the query.
  • Setup metrics, if you agree. Aurora asks once, during setup, whether it may send anonymous measurements of how long model preparation took on your device. The record holds the model, the queue and run durations, the outcome and the thermal conditions — no identifier, no audio, no transcript and no generated content. Declining, or never being asked, means nothing is sent.
  • Diagnostics you send. A report leaves the device only when you choose to send one. What that report carries is governed by a single switch, and when you report a problem from inside a session that switch starts on. Diagnostic reports describes every tier, how a report is encrypted, and how long it is kept.
  • Exports you make. Anything you export or share goes to the destination you pick, and nowhere else. From that point its own privacy terms apply, not ours.

Calendar access is not in that list because it is not a network path. Aurora reads your next event on the device, through the system calendar, and sends nothing anywhere for it.

Putting the phone in airplane mode and recording is a good test, and it proves one thing precisely: capture, transcription, speaker separation and summaries work with no network at all. It does not prove that none of the paths above exists, because each of them happens at a different moment — at setup, when you allow something, or when you send something. Adding a new network path is a product decision we would have to make on purpose and write down here.

Diagnostic reports

Recording, transcription, speaker separation and everything generated from them stay on the device, as above: none of it is sent to us as part of normal use. Aurora does keep technical diagnostics locally, so that a problem can be investigated if you decide to report it. Nothing is sent or shared until you act. When you do, Aurora sends an encrypted report to our report intake; the report flow has no other destination, and no Share, Files or Save control that would hand the package to another app. After a crash Aurora may ask once whether to send what it collected; if you decline, nothing is sent. Once you start a send, the same attempt may continue or retry in the background or after a relaunch — Aurora does not create a second report and does not widen what it includes during those retries.

One switch, and where it starts

The report form has exactly one control over content: a switch labeled "Include session details in report". With it on, the report carries the selected session's transcript, its Ask Aurora chat, its recording and a screenshot of what was on screen, on top of the technical diagnostics. With it off, the report carries the technical diagnostics only. Audio and the screenshot are not separate choices — they follow that same switch, deliberately, so that a quiet second control cannot attach something you did not expect.

When you report a problem from inside a session, that switch starts on. We would rather tell you that than describe a default the app does not have: in Aurora's own source the consent type declares the flag off, and the draft the form opens initializes it on. So the decision in front of you is not "shall I attach my transcript" but "shall I leave my transcript attached". Turning it off before you send takes one tap, and the report stays useful, because the technical diagnostics are what explain most failures. Aurora's product contract still describes reports as content-free by default; where the contract and the build disagree, this page describes the build, and we have asked for the mismatch to be closed in one direction or the other.

A report with no session attached — one you start from Settings rather than from a recording — never carries a transcript, a chat, a note or a recording, whatever that switch says. The form says so itself. What the switch can still add there is a screenshot of the screen you were looking at when you opened the form; a report that begins at a crash prompt has no screenshot at all.

What a report contains

Before you send, Aurora shows you which of three tiers the report is on:

  • Anonymized. Technical diagnostics, with the session identifiers in the structured manifest, the timeline and the recent-outcomes section replaced by a fresh per-report hash. The scrubbed log is filtered, not structurally rewritten, so short technical identifiers can survive in it: this tier reduces linkage, and we will not call it mathematically anonymous. It contains no transcript, summary, note or audio.
  • Standard. What the switch turns off. App and build details, device details, technical session state, a scrubbed diagnostic log, lifecycle and MetricKit diagnostics, an environment snapshot with recent environment history, model presence and integrity state, and recent session outcomes. Session title and tags are removed. It contains no transcript, summary, note or audio.
  • Full. What the switch turns on. Everything in Standard, plus the selected session's title, tags, transcript and summary, its Ask Aurora chat, a screenshot, and the description you type. Audio is included only in a session report, only when audio exists, and only while the switch is on. A global report never picks an arbitrary recording or transcript for you.

Scrubbing the log is a protective filter, not a promise that technical diagnostics can never contain personal information. A full report can carry highly sensitive speech and text. Read what the form tells you it is attaching, and turn the switch off unless that content is what makes the problem reproducible.

How a report travels

For a direct send, Aurora validates the plaintext package and then encrypts the complete archive on your device with the maintainer's public key, before anything is uploaded. The upload itself uses HTTPS. The public intake and its Cloudflare R2 storage hold the encrypted envelope and a limited receipt: a random attempt and ticket identifier, the time it was received, the encrypted size, the app version, and the identifier of the encryption key. The public service has a health route and authenticated write routes, and no route that reads or decrypts a report. The token the app carries limits abuse; it is not proof that a caller is a genuine Aurora installation.

The plaintext can be decrypted only with the matching private key, on a private report dashboard that is not reachable from the public internet. Cloudflare provides the encrypted storage and transport and holds no decryption key. To slow abuse, the intake may count requests per IP address for one hour; that counter expires with the hour, and the IP address is not written into the report receipt.

There is no separate export path today. The plaintext package exists on your device only as part of a delivery you started, and it is deleted when the delivery succeeds or when you discard it. If we ever add a control that hands the package to another app, this page will describe it before it ships — including the fact that a copy in another app is one we cannot recall or delete.

How long we keep it

On your device, the diagnostic stores are bounded:

  • Lifecycle events and MetricKit rows. Normally 14 days, capped at 20,000 events and 500 payloads. Rows for a crash whose consent prompt is still unanswered can be kept beyond that window.
  • Environment change history. A report carries the most recent 48 hours, and the file is capped at roughly 1 MB.
  • Diagnostic logs. A ring bounded by size, normally capped at about 16 MB. That is a size limit, not a guaranteed number of hours.
  • Unfinished deliveries. The plaintext, the encrypted copy and the receipt for a delivery in flight are deleted when it succeeds or when you discard it, and otherwise become eligible for cleanup after seven days. Cleanup runs when delivery processing runs, so seven days is when a file becomes eligible, not the moment it disappears.

On our side there is no automatic age-based deletion today. An encrypted report stays in storage until the maintainer closes it and explicitly runs the remote cleanup; the routine cleanup clears only the private dashboard's local cache. Retention is therefore manual and, until someone closes the report, potentially indefinite. We owe this page a maximum age and do not have one yet; if we ship an automatic policy, it will be written here.

What we do with a report

Reports are used to diagnose, support, secure and improve Aurora, and for nothing else. They are not used for advertising, marketing, sharing with data brokers, cross-app tracking or personalizing the product. There is no report account identifier, and we do not join reports to advertising or other identity datasets.

Deleting a report

To have a report closed and deleted, write to hello@auroraisyours.com. Include the ticket identifier Aurora shows you after a successful upload. If you no longer have it, give the approximate date and time you sent the report and the Aurora app version — but because there is no report account identifier, we may not be able to identify your report reliably without its ticket. Once the request is verified we close the ticket and delete the encrypted object and the dashboard cache under our control. Deletion cannot undo diagnostic work already done before the report was deleted, so it is worth writing to us promptly.

This website

The site sets no cookies and loads no advertising or tracking scripts. We do not build profiles of visitors, and we do not keep your IP address. The site relies on four services, each for one job:

  • Cloudflare. Hosts the site and its DNS, routes inbound mail for hello@, runs the Turnstile bot check on the access form, and provides aggregate, cookieless analytics: page counts and load times with no identifier for a person. Turnstile processes browser signals to tell people from automated traffic; it does not read what you type into the form. Cloudflare's Turnstile privacy addendum applies to that check.
  • Brevo. Stores the email address you give us and sends the TestFlight backup mail and, only after you confirm an opt-in, build notes. We do not use open or click tracking in those emails. The access form says "No newsletter unless you ask for one", and that is how it is wired: ticking the build-notes box asks Brevo to send one confirmation email, and you join the build-notes list only when you click the link in it. Leaving the box unticked sends nothing beyond the backup mail for the request you just made.
  • Better Stack. Probes our own site to tell us when it is down. The probes contain no visitor data.
  • Apple TestFlight. The access link opens Apple's TestFlight. From that tap on, Apple's terms and privacy policy apply. With a public link, Apple does not show us your name or email.

Our own counters record that a request happened and whether the email went out. They carry no email address, no IP address and no other dimension that points at a person.

Your browser remembers that you asked, so the sheet can show your link again; that stays on your device and you can clear it from the sheet.

What we store about you, and why

If you request access, we store: your email address, the time of the request, and whether you asked for build notes and when you confirmed it. We use this to send you the TestFlight link, to send build notes if you asked for them, and to remove you from the beta when you ask. Handling your request is the legal basis for the first two; your consent is the basis for build notes.

Asking for access and asking for build notes are two separate things. The address is stored so we can show and re-send your TestFlight link and remove you from the beta when you ask; build notes are sent only after you confirm them by email, and we record when that confirmation was last requested so a second tick of the box does not mail you again the same day.

Once the link is on screen, the last step of that flow offers a short optional questionnaire about testing Aurora. Every question is answered by picking from a fixed list, every question offers "Prefer not to say", and there is no free-text box anywhere in the flow. What it covers:

  • your role category — founder or operator, manager or lead, researcher, student, journalist, or other professional;
  • what you would record: meetings, interviews and research, lectures and learning, working sessions, personal voice notes;
  • the Apple hardware you would test on, as a device family, and the system version on it — never an exact model, name or serial number;
  • the language spoken in the conversations you would record;
  • how often you expect to use Aurora;
  • which transcription problem matters most to you;
  • whether you are interested in testing with assistive technology;
  • whether you would join a research session later;
  • if we ask about one, whether to write to the address you already gave us or not to contact you at all.

We ask nothing about your employer or your clients, and nothing about recordings, transcripts, notes, prompts or anything else Aurora handles on your device: the questions are about your setup, never about your conversations. Your consent is the legal basis; answering is not a condition of beta access or of build notes, and none of the three changes either of the others. The same step has a "Clear my answers" button, which empties every one of those answers immediately. We keep all of this until you ask us to delete it or the beta ends, whichever comes first. If you send a diagnostic report, what we hold for it is the encrypted report and its receipt, on the terms in Diagnostic reports.

Deleting your data and unsubscribing

Every email we send has an unsubscribe link, and using it stops that kind of email straight away. To have your address and everything attached to it removed, write to hello@auroraisyours.com from that address. We aim to finish within a month and confirm when it is done. To delete a diagnostic report, write to the same address with its ticket identifier: see Diagnostic reports for what we can and cannot remove.

Your rights

Under the GDPR you can ask for access to your data, have it corrected or erased, restrict or object to how we use it, and receive a copy in a portable form. Where we rely on consent, you can withdraw it at any time, as easily as you gave it. You can also complain to a supervisory authority: in Poland, the President of the Personal Data Protection Office, UODO; elsewhere in the EU, the authority in your own country.

Transfers outside the EU

Cloudflare and Brevo offer EU hosting, and we use it where it is offered. Where either provider handles data outside the European Economic Area, for example for support, the transfer is covered by the European Commission's standard contractual clauses in our agreements with them.

Children

The website and the beta are not directed at anyone under sixteen. If you think we hold an address from someone younger, tell us and we will remove it.

Changes to this notice

When this notice changes, we update the date at the top and keep this address stable. If a change affects what we collect or why, we tell testers by email first.

See also

  1. Terms of Use — the website and the beta.
  2. Recording & Consent — recording other people, and your responsibility to them.
  3. The boundary — the same list of what stays and what can leave, on the homepage.