Privacy Policy
We built Aurai to give people real ownership over their digital businesses. That same principle applies to your data. This policy explains exactly what we collect, why we collect it, and the rights you hold over it.
Who We Are
Aurai ("Aurai", "we", "our", "us") is an AI-powered software platform that generates production-ready full-stack applications and provides Agency Partner, Software Client, and Franchise Owner services. Our registered operating entity is Aurai Ltd, and our principal place of business is available on request.
This Privacy Policy applies to all personal data processed through our website at aurai.example, the Aurai platform at aurai.app, and any related services, applications, or communications we provide (collectively, the "Services").
Data We Collect
We collect personal data in three ways: data you give us directly, data generated automatically by your use of the Services, and data we receive from third parties.
Data you provide directly:
- Identity data: full name, business name, job title.
- Contact data: email address, phone number, mailing address.
- Account credentials: username, hashed password, security questions.
- Financial data: billing address, partial payment card information (processed and stored by our payment processor; we never store full card numbers).
- Agency Partner data: business sector, target client type, pitch kit preferences, proposal content.
- Franchise application data: investment capacity, geographic preference, operating experience.
- Software project data: app type, business requirements, feature specifications, any sample data you upload.
- Communications: messages sent through our contact form, email correspondence, and support tickets.
Data collected automatically:
- Usage data: pages visited, features used, time spent, click paths, and in-platform actions.
- Device and technical data: IP address, browser type and version, operating system, screen resolution, time zone.
- Log data: server logs including request timestamps, error reports, and performance diagnostics.
- Cookie and tracking data: described fully in Section 6.
Data from third parties:
- Authentication providers: if you sign in via Google or another OAuth provider, we receive your name and email address.
- Payment processors: we receive a payment confirmation and a partial card reference from Stripe; no full card data is transmitted to us.
- Analytics and advertising partners: aggregated or pseudonymous behavioral data, subject to those partners' own privacy policies.
How We Use Your Data
We use your personal data only for clearly defined, legitimate purposes. We do not use it for automated decision-making that produces legal or similarly significant effects without human review.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Create and manage your account | Identity, contact, credentials | Contract performance |
| Deliver the Aurai platform and generate apps | Project data, account data | Contract performance |
| Process payments and issue invoices | Financial data, identity | Contract performance, legal obligation |
| Provide customer support | Communications, account data | Legitimate interests |
| Send transactional emails (account notices, receipts) | Contact data, account data | Contract performance |
| Send product updates and marketing (with opt-out) | Contact data | Legitimate interests / consent |
| Analyse platform usage to improve the product | Usage data, device data | Legitimate interests |
| Detect fraud and maintain security | Usage data, device data, IP address | Legitimate interests, legal obligation |
| Comply with legal and regulatory obligations | Identity, financial, communications | Legal obligation |
| Evaluate Franchise applications | Franchise application data | Pre-contractual steps |
Legal Bases for Processing
Where GDPR or equivalent legislation applies, we rely on one or more of the following legal bases for each processing activity:
- Contract performance: processing is necessary to deliver the services you have agreed to, including generating your apps, managing your Agency Partner account, and processing payments.
- Legal obligation: processing required to comply with applicable laws, including tax record keeping, fraud prevention, and responding to lawful government requests.
- Legitimate interests: processing that serves our genuine business interests without overriding your rights, such as platform analytics, security monitoring, and direct marketing to existing customers. You may object to processing on this basis at any time.
- Consent: for non-essential cookies and certain marketing communications where required by law. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Vital interests: in rare emergency situations where processing is necessary to protect life.
Sharing Your Data
We do not sell, rent, or trade your personal data. We share it only in the following circumstances, and only to the minimum extent necessary:
- Service providers: trusted vendors who process data on our behalf under strict Data Processing Agreements. These include cloud hosting (AWS), payment processing (Stripe), transactional email (Postmark), error monitoring (Sentry), and analytics (PostHog, self-hosted).
- Agency Partner network: if you are a Software Client introduced through an Agency Partner, your project data is shared with that partner to the extent necessary to deliver your project. The partner is an independent data controller for any data they hold.
- Franchise infrastructure: Franchise Owner operational data is shared with our internal franchise support team and, where agreed, with regional master franchise holders.
- Professional advisors: lawyers, accountants, and auditors who are bound by professional confidentiality obligations.
- Legal authorities: where required by law, a court order, or regulatory authority. We will notify you of such requests unless legally prohibited from doing so.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to equivalent privacy protections. We will notify you before any such transfer takes effect.
Data Retention
We retain personal data only as long as necessary for the purposes set out in this policy, or as required by applicable law. Our standard retention periods are:
- Active account data: retained for the lifetime of your account plus 30 days following closure, to allow for account reinstatement requests.
- Financial and billing records: retained for 7 years from the date of the transaction to comply with tax and accounting regulations.
- Generated app project files: retained while your account is active. On account deletion, project files are purged within 30 days unless you have exported them.
- Support correspondence: retained for 3 years from the date of closure of the support ticket.
- Marketing contact lists: retained until you unsubscribe or request deletion, with an annual suppression list review.
- Server and security logs: retained for 90 days, after which they are automatically deleted.
- Analytics data: retained in aggregated, non-identifiable form indefinitely; raw event data is retained for 24 months.
After the applicable retention period, data is securely deleted or irreversibly anonymised.
Security
We implement technical and organisational security measures proportionate to the risk of processing your personal data. Our measures include:
- Encryption of all data in transit using TLS 1.3 or higher.
- Encryption of all data at rest using AES-256.
- Role-based access control ensuring staff access only the data necessary for their role.
- Multi-factor authentication required for all internal system access.
- Regular penetration testing and vulnerability scanning by an independent security firm.
- Incident response procedures with a target notification timeline of 72 hours for any notifiable breach, in accordance with GDPR requirements.
- Annual security training for all employees and contractors with access to personal data.
Your Rights
Depending on your location, you have significant rights over your personal data. We respond to all verified rights requests within 30 days (extendable to 60 days for complex requests, with notice).
Right to Access
Request a copy of all personal data we hold about you, including the categories, sources, and purposes of processing.
Right to Rectification
Ask us to correct inaccurate data or complete incomplete data that we hold about you.
Right to Erasure
Request deletion of your personal data where there is no compelling reason for its continued processing ("right to be forgotten").
Right to Restrict
Ask us to restrict processing of your data in certain circumstances, such as while we verify a rectification request.
Right to Portability
Receive your data in a structured, machine-readable format and transfer it to another controller where technically feasible.
Right to Object
Object to processing based on legitimate interests, including direct marketing. We will cease unless we have compelling legitimate grounds that override your rights.
To exercise any of these rights, contact us at privacy@aurai.example. We will verify your identity before processing your request. There is no fee for making a request.
Children's Privacy
The Aurai Services are intended for use by adults aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has submitted personal data to us, please contact us immediately at privacy@aurai.example and we will take prompt steps to delete it.
International Data Transfers
Aurai operates globally, and your personal data may be transferred to and processed in countries outside your country of residence, including countries outside the European Economic Area (EEA) that may not offer the same level of data protection.
When we transfer personal data from the EEA, UK, or Switzerland to countries that have not received an adequacy decision from the European Commission, we rely on one or more of the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our Data Processing Agreements with service providers.
- The EU-US Data Privacy Framework, where applicable to our US-based service providers.
- UK International Data Transfer Agreements (IDTAs), where UK GDPR applies.
You may request a copy of the safeguards we rely on by contacting privacy@aurai.example.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Send an email notification to all registered account holders at least 14 days before the changes take effect.
- Display a prominent notice on the Aurai platform on your next login after the update.
We encourage you to review this policy periodically. Continued use of the Services after the effective date of an update constitutes acceptance of the revised policy. If you do not agree with material changes, you may close your account before they take effect.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through one of the following channels. We aim to respond within 5 business days.
Aurai Privacy Team
Our dedicated privacy team handles all data subject requests, disclosures, and regulatory enquiries. For general support, please use the contact page.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority. In the UK this is the Information Commissioner's Office (ICO). In the EU, contact your national supervisory authority.
Quick Answers to Common Questions
Everything you need to know about how Aurai handles your data.
What personal data does Aurai collect?
Does Aurai sell my personal data?
How long does Aurai retain my data?
What are my rights under GDPR or CCPA?
How does Aurai use cookies?
Is my app data used to train AI models?
How do I delete my account and all my data?
Ready to Build, Sell, and Own Your Software Business?
Choose your path. Start as an Agency Partner, send us a project as a Software Client, or apply for Franchise Ownership. All three doors open here.
Become an Agency Partner Now
Tell us about yourself and we will get you started with your Agency Partner account and all 17 tools.
No credit card required. Your information is private and secure.