Legal Document

Privacy Policy

We built Aurai to give people real ownership over their digital businesses. That same principle applies to your data. This policy explains exactly what we collect, why we collect it, and the rights you hold over it.

Effective: 1 June 2025 Last Updated: 1 June 2025 GDPR + CCPA Compliant
Abstract data privacy dashboard on dark monitors
SECTION 01

Who We Are

Aurai ("Aurai", "we", "our", "us") is an AI-powered software platform that generates production-ready full-stack applications and provides Agency Partner, Software Client, and Franchise Owner services. Our registered operating entity is Aurai Ltd, and our principal place of business is available on request.

This Privacy Policy applies to all personal data processed through our website at aurai.example, the Aurai platform at aurai.app, and any related services, applications, or communications we provide (collectively, the "Services").

Data Controller: For the purposes of GDPR and equivalent data protection laws, Aurai Ltd is the data controller of personal data collected through the Services. For Agency Partners who collect end-customer data through apps built on Aurai, those partners act as independent data controllers for their own customers' data.
SECTION 02

Data We Collect

We collect personal data in three ways: data you give us directly, data generated automatically by your use of the Services, and data we receive from third parties.

Data you provide directly:

  • Identity data: full name, business name, job title.
  • Contact data: email address, phone number, mailing address.
  • Account credentials: username, hashed password, security questions.
  • Financial data: billing address, partial payment card information (processed and stored by our payment processor; we never store full card numbers).
  • Agency Partner data: business sector, target client type, pitch kit preferences, proposal content.
  • Franchise application data: investment capacity, geographic preference, operating experience.
  • Software project data: app type, business requirements, feature specifications, any sample data you upload.
  • Communications: messages sent through our contact form, email correspondence, and support tickets.

Data collected automatically:

  • Usage data: pages visited, features used, time spent, click paths, and in-platform actions.
  • Device and technical data: IP address, browser type and version, operating system, screen resolution, time zone.
  • Log data: server logs including request timestamps, error reports, and performance diagnostics.
  • Cookie and tracking data: described fully in Section 6.

Data from third parties:

  • Authentication providers: if you sign in via Google or another OAuth provider, we receive your name and email address.
  • Payment processors: we receive a payment confirmation and a partial card reference from Stripe; no full card data is transmitted to us.
  • Analytics and advertising partners: aggregated or pseudonymous behavioral data, subject to those partners' own privacy policies.
SECTION 03

How We Use Your Data

We use your personal data only for clearly defined, legitimate purposes. We do not use it for automated decision-making that produces legal or similarly significant effects without human review.

Purpose Data Used Legal Basis
Create and manage your account Identity, contact, credentials Contract performance
Deliver the Aurai platform and generate apps Project data, account data Contract performance
Process payments and issue invoices Financial data, identity Contract performance, legal obligation
Provide customer support Communications, account data Legitimate interests
Send transactional emails (account notices, receipts) Contact data, account data Contract performance
Send product updates and marketing (with opt-out) Contact data Legitimate interests / consent
Analyse platform usage to improve the product Usage data, device data Legitimate interests
Detect fraud and maintain security Usage data, device data, IP address Legitimate interests, legal obligation
Comply with legal and regulatory obligations Identity, financial, communications Legal obligation
Evaluate Franchise applications Franchise application data Pre-contractual steps
SECTION 05

Sharing Your Data

We do not sell, rent, or trade your personal data. We share it only in the following circumstances, and only to the minimum extent necessary:

  • Service providers: trusted vendors who process data on our behalf under strict Data Processing Agreements. These include cloud hosting (AWS), payment processing (Stripe), transactional email (Postmark), error monitoring (Sentry), and analytics (PostHog, self-hosted).
  • Agency Partner network: if you are a Software Client introduced through an Agency Partner, your project data is shared with that partner to the extent necessary to deliver your project. The partner is an independent data controller for any data they hold.
  • Franchise infrastructure: Franchise Owner operational data is shared with our internal franchise support team and, where agreed, with regional master franchise holders.
  • Professional advisors: lawyers, accountants, and auditors who are bound by professional confidentiality obligations.
  • Legal authorities: where required by law, a court order, or regulatory authority. We will notify you of such requests unless legally prohibited from doing so.
  • Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to equivalent privacy protections. We will notify you before any such transfer takes effect.
No AI training on your data: We do not use the content of the apps you build, your project specifications, or your client data to train AI models, nor do we share this data with AI providers for training purposes. Your intellectual property stays yours.
SECTION 06

Cookies and Tracking Technologies

We use cookies and similar technologies on our website and platform. The table below describes the categories we use.

Category Purpose Consent Required
Strictly Necessary Session management, authentication, security tokens, load balancing. The platform cannot function without these. No - exempt
Functional Remembering your preferences (language, dashboard layout, dark mode). No - legitimate interest
Analytics Aggregate usage statistics to improve the platform. Data is pseudonymised and self-hosted where possible. Yes - opt-in
Marketing Measuring ad campaign effectiveness and retargeting. Only active if you have given explicit consent. Yes - opt-in

You can manage or withdraw cookie consent at any time by clicking "Cookie Settings" in our website footer, or by adjusting your browser's cookie preferences. Withdrawing consent does not affect cookies already set before withdrawal, but no new non-essential cookies will be placed after you opt out.

We may also use pixel tags, web beacons, and local storage for functional purposes. These are governed by the same principles as cookies.

SECTION 07

Data Retention

We retain personal data only as long as necessary for the purposes set out in this policy, or as required by applicable law. Our standard retention periods are:

  • Active account data: retained for the lifetime of your account plus 30 days following closure, to allow for account reinstatement requests.
  • Financial and billing records: retained for 7 years from the date of the transaction to comply with tax and accounting regulations.
  • Generated app project files: retained while your account is active. On account deletion, project files are purged within 30 days unless you have exported them.
  • Support correspondence: retained for 3 years from the date of closure of the support ticket.
  • Marketing contact lists: retained until you unsubscribe or request deletion, with an annual suppression list review.
  • Server and security logs: retained for 90 days, after which they are automatically deleted.
  • Analytics data: retained in aggregated, non-identifiable form indefinitely; raw event data is retained for 24 months.

After the applicable retention period, data is securely deleted or irreversibly anonymised.

SECTION 08

Security

We implement technical and organisational security measures proportionate to the risk of processing your personal data. Our measures include:

  • Encryption of all data in transit using TLS 1.3 or higher.
  • Encryption of all data at rest using AES-256.
  • Role-based access control ensuring staff access only the data necessary for their role.
  • Multi-factor authentication required for all internal system access.
  • Regular penetration testing and vulnerability scanning by an independent security firm.
  • Incident response procedures with a target notification timeline of 72 hours for any notifiable breach, in accordance with GDPR requirements.
  • Annual security training for all employees and contractors with access to personal data.
Responsible disclosure: If you discover a security vulnerability in our systems, please report it to security@aurai.example before public disclosure. We will acknowledge your report within 48 hours and aim to resolve verified vulnerabilities within 30 days.
SECTION 09

Your Rights

Depending on your location, you have significant rights over your personal data. We respond to all verified rights requests within 30 days (extendable to 60 days for complex requests, with notice).

Right to Access

Request a copy of all personal data we hold about you, including the categories, sources, and purposes of processing.

Right to Rectification

Ask us to correct inaccurate data or complete incomplete data that we hold about you.

Right to Erasure

Request deletion of your personal data where there is no compelling reason for its continued processing ("right to be forgotten").

Right to Restrict

Ask us to restrict processing of your data in certain circumstances, such as while we verify a rectification request.

Right to Portability

Receive your data in a structured, machine-readable format and transfer it to another controller where technically feasible.

Right to Object

Object to processing based on legitimate interests, including direct marketing. We will cease unless we have compelling legitimate grounds that override your rights.

To exercise any of these rights, contact us at privacy@aurai.example. We will verify your identity before processing your request. There is no fee for making a request.

California Residents (CCPA): In addition to the rights above, California residents have the right to know the categories of personal information collected, the right to opt out of the sale of personal information (we do not sell personal information), and the right to non-discrimination for exercising their privacy rights. To submit a verifiable consumer request, contact privacy@aurai.example.
SECTION 10

Children's Privacy

The Aurai Services are intended for use by adults aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has submitted personal data to us, please contact us immediately at privacy@aurai.example and we will take prompt steps to delete it.

SECTION 11

International Data Transfers

Aurai operates globally, and your personal data may be transferred to and processed in countries outside your country of residence, including countries outside the European Economic Area (EEA) that may not offer the same level of data protection.

When we transfer personal data from the EEA, UK, or Switzerland to countries that have not received an adequacy decision from the European Commission, we rely on one or more of the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our Data Processing Agreements with service providers.
  • The EU-US Data Privacy Framework, where applicable to our US-based service providers.
  • UK International Data Transfer Agreements (IDTAs), where UK GDPR applies.

You may request a copy of the safeguards we rely on by contacting privacy@aurai.example.

SECTION 12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Send an email notification to all registered account holders at least 14 days before the changes take effect.
  • Display a prominent notice on the Aurai platform on your next login after the update.

We encourage you to review this policy periodically. Continued use of the Services after the effective date of an update constitutes acceptance of the revised policy. If you do not agree with material changes, you may close your account before they take effect.

SECTION 13

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through one of the following channels. We aim to respond within 5 business days.

Aurai Privacy Team

Our dedicated privacy team handles all data subject requests, disclosures, and regulatory enquiries. For general support, please use the contact page.

Data Controller: Aurai Ltd, available on written request

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority. In the UK this is the Information Commissioner's Office (ICO). In the EU, contact your national supervisory authority.

Privacy FAQ

Quick Answers to Common Questions

Everything you need to know about how Aurai handles your data.

What personal data does Aurai collect?
Aurai collects information you provide directly, such as your name, email address, phone number, and business details when you register as an Agency Partner, submit a software project request, or apply for Franchise Ownership. We also collect usage data, device information, and cookies automatically when you interact with the platform.
Does Aurai sell my personal data?
No. Aurai does not sell, rent, or trade your personal data to third parties. We share data only with trusted service providers who help us operate the platform, and only under strict confidentiality obligations.
How long does Aurai retain my data?
We retain your personal data for as long as your account is active or as needed to provide services. You may request deletion of your account and associated data at any time by contacting us at privacy@aurai.example. Financial records are retained for 7 years as required by law.
What are my rights under GDPR or CCPA?
Depending on your jurisdiction, you have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing. California residents have additional rights under CCPA including the right to know and the right to opt out of sale (which we do not engage in). Contact privacy@aurai.example to exercise any right.
How does Aurai use cookies?
We use strictly necessary cookies to operate the platform, functional cookies to remember your preferences, analytics cookies to understand usage patterns, and marketing cookies only if you have given explicit consent. You can manage your cookie preferences at any time through your browser settings or our consent tool.
Is my app data used to train AI models?
No. We do not use the content of the apps you build, your project specifications, or your client data to train AI models, nor do we share this data with AI providers for training purposes. Your intellectual property stays entirely yours.
How do I delete my account and all my data?
You can request account deletion by emailing privacy@aurai.example with the subject line "Account Deletion Request". We will verify your identity and complete deletion within 30 days, with the exception of data we are legally required to retain (such as financial records for 7 years).
Choose Your Path

Ready to Build, Sell, and Own Your Software Business?

Choose your path. Start as an Agency Partner, send us a project as a Software Client, or apply for Franchise Ownership. All three doors open here.

Agency Partners: Build a home-based digital agency from day one
Software Clients: Get your custom app built fast and affordably
Franchise Owners: Secure a territory and recurring revenue operation

Become an Agency Partner Now

Tell us about yourself and we will get you started with your Agency Partner account and all 17 tools.

No credit card required. Your information is private and secure.