Privacy Policy
Last updated September 17, 2026
This Privacy Policy explains how Aura(“Aura,” “we,” “us”) collects, uses, and protects your information. It covers both this website (auravoiceapp.com) and the Aura mobile app, where you meet Buddy - an AI companion that chats, talks with you by voice, remembers, checks in, and can help with your calendar, email, reminders, and the web.
The short version
- We collect only what we need to run Aura and make Buddy useful to you.
- We never sell your data, and we never use your Google data (Gmail or Calendar) to train AI models.
- On the website, analytics stay cookieless until you accept cookies. The voice demo streams your audio for a real-time reply and we don’t store that audio, though we do keep an anonymized text transcript of the demo chat to make Buddy better.
- Aura Keyboard processes your typing on your device. Text leaves your phone only when you tap an Aura writing action or the mic, and the keyboard asks you before the first time either one does. See Aura Keyboard.
- You can disconnect Google, revoke access, or request deletion at any time. Revoking access stops future access but does not, by itself, delete information you previously asked Aura to save.
Information we collect
On this website
- Waitlist details. If you join the waitlist, we collect the email address you submit and, optionally, which features you tell us you are most excited about, so we can tell you when Aura is available. This is stored in our own database (Firebase).
- Product analytics. We use PostHog to understand how the site is used (pages viewed, buttons clicked, the voice-demo funnel). Before you accept cookies this runs in a cookieless mode; see Cookies & analytics below.
- Voice demo.If you try the in-browser voice demo, your microphone audio is streamed in real time to our model provider (OpenAI) to generate Buddy’s spoken reply. We do not record or store this audio. We do keep a text transcriptof the conversation, along with coarse location (country, region, city) and basic device and browser info, linked only to an anonymous analytics ID and a one-way hashed version of your IP address (never your name, email, or full IP), so we can understand how people talk to Buddy and improve him. To prevent abuse we also use Cloudflare Turnstile to verify you’re human.
In the Aura app
- Account information needed to create and secure your account (handled via Firebase).
- Your conversations and memory - the messages you exchange with Buddy and the things you ask him to remember, stored to provide continuity across sessions.
- Voice interactions processed to enable real-time spoken conversations (via LiveKit).
- Reminders, check-ins, and notification preferences you set up.
- What you tell us at sign-up - the name you want Buddy to call you, the topics you want to hear about, your device language and region, and whether you are 18 or older or 13 to 17. We do not ask for your date of birth or your gender.
- Approximate location, only if you switch on weather in your morning briefing. Your device asks you at that moment, and saying no is a normal answer: Buddy then uses your region instead. When you allow it, the coordinates are rounded to about a kilometre, sent with that one briefing request, used to look up the forecast, and never stored or logged by us.
- Google data you choose to connect - see the next section.
All of it is collected directly from you, in the app, as you use it: you type it, say it, or choose it. We do not buy personal data, and we do not collect it from other companies or from your other apps. It is used to run the features you are using and to make Buddy’s replies and check-ins relevant to you. We never use it to advertise to you, and we never sell it.
Buddy is not on your phone. Answering you means sending what you share to the AI companies that run the models, listed under Sharing & third parties. The app tells you this and asks your permission before it sends anything.
Google user data & Limited Use
Connecting Google Calendar or Gmail is optional. Aura uses Google's OAuth authorization process, so you choose whether to grant access and Google shows you the permissions being requested. Aura does not receive your Google password. We request the minimum Google permissions needed for the feature you choose, in context where possible.
Google data Aura can access
- Connection information: the Google account you connect, authorization tokens, granted permissions, and technical identifiers needed to maintain and secure the connection.
- Google Calendar data: calendar and event information needed for the requested feature, such as calendar names, event titles and descriptions, dates and times, locations, availability, attendees, and related event metadata.
- Gmail data:the connected email address and the recipient, subject, message body, and delivery identifiers needed when you ask Buddy to send an email. Aura’s current Gmail integration does not read or store messages from your inbox.
How Aura uses Google data
Aura accesses Google data only to provide the Google-connected features you request or an ongoing instruction you enable. Examples include showing upcoming events, answering a question about your schedule, creating a calendar event, and drafting or sending a message on your behalf. Aura does not use Google data for generalized profiling, advertising, or unrelated product features.
AI processing and service providers
When a Google-connected request requires AI processing, Aura may send the Calendar details or email-draft content needed for that request to our AI model providers, such as Anthropic Claude, Google Gemini, or OpenAI. They process that information for Aura as service providers so Buddy can return the requested result. We do not permit them to use your Google data to create, train, or improve any AI or machine-learning model. Other infrastructure providers may securely host or process data only as needed to operate, secure, and support the feature.
Storage and retention of Google data
We retain Google authorization tokens and connection metadata while your account remains connected so Aura can perform the features you enable. While Google Calendar is enabled, Aura caches event data in its database so it can keep your schedule synchronized and answer calendar requests. Aura deletes that Calendar cache when you disable or disconnect the Calendar integration. The current Gmail integration does not retrieve or cache inbox messages.
If you intentionally ask Buddy to save Calendar information or an email draft in a conversation, memory, reminder, or other Aura feature, that saved or derived content becomes part of your Aura data and is retained under the rules for that feature until you delete it or your account. We delete or anonymize Google data and derived data when it is no longer needed for the disclosed feature, subject to limited security, legal, and backup requirements.
Aura’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google data only to provide or improve the prominent, user-facing Google-connected features you request.
- We do not use your Google data to train, fine-tune, or develop any AI or machine-learning models.
- We do not sell your Google data or use it for advertising.
- We transfer Google data only to service providers as needed to provide the requested feature and with your consent, for security, to comply with law, or as part of a merger or sale after obtaining any consent required by Google policy and applicable law.
- Humans don’t read your Google data except with your explicit consent, for security/abuse purposes, or where required by law.
You can review or revoke Aura’s access to your Google account at any time from myaccount.google.com/permissions. Revocation prevents new access after Google notifies Aura or the authorization stops working. It does not automatically erase Aura conversations, memories, reminders, drafts, or other content you previously asked Aura to create from Google data. To delete those items and the associated connection data, use Aura’s available deletion controls or contact us using the address below.
How we use your information
- To provide, maintain, and improve Aura and Buddy.
- To enable features you ask for - conversations, memory, voice, reminders, and calendar/email help.
- To send you product and waitlist updates (you can opt out anytime).
- To keep Aura secure and prevent abuse.
- To understand usage in aggregate so we can improve the product.
AI processing
Buddy is powered by large language models, including Anthropic Claude and Google Gemini (and OpenAI for the website voice demo). To generate a response, relevant parts of your request may be sent to these providers and processed for Aura under applicable agreements. As explained in the Google user data section, this can include relevant Calendar details or email-draft content when needed to complete your request. Your content is not used to train our models, and your Google data is never used to create, train, or improve any AI or machine-learning model.
Buddy is an AI companion, not a person, and not a substitute for professional medical, legal, financial, or mental-health advice. If you are in crisis or thinking about harming yourself, please contact your local emergency services or a crisis line such as 988 (Suicide & Crisis Lifeline, US) right away.
Sharing & third parties
We do not sell your personal information. We share data only with service providers that help us run Aura, each handling data under their own terms:
- Google APIs - the Calendar and Gmail connections you authorize.
- Anthropic, Google Gemini, OpenAI - AI model providers. They receive the messages and files you send Buddy, the transcript of what you say, your name, and the profile Buddy builds, and use them only to produce the reply you asked for. Calendar details or email-draft content are shared with an AI provider only when needed for the Google-connected feature you request; Google data is not used to create, train, or improve AI models.
- Deepgram- speech-to-text. Receives your microphone audio while a voice conversation or voice typing is running, and the names in your personal vocabulary so it recognizes them. We opt out of Deepgram’s model-improvement program, so your audio is not used to train their models.
- Cartesia- text-to-speech. Receives the text of Buddy’s reply in order to speak it.
- ai-coustics - removes background noise from your microphone audio during a voice conversation.
- Groq - formats text you dictate, and receives that text with the app and field you are typing into.
- Brave Search, Brave News, newsdata.io, Google News - news and web lookups. They receive the search terms or topics involved, not your conversations.
- Open-Meteo - the forecast in your morning briefing. It receives the rounded coordinates described above, or your region when you have not granted location, and nothing else about you.
- Firebase - accounts, app data, website waitlist signups, and stored website voice-demo transcripts.
- LiveKit - carries the real-time voice call in the app, and routes one of the voice model connections.
- PostHog - product analytics.
- Cloudflare - bot/abuse protection for the voice demo.
- Vercel - website hosting.
Every provider above is bound by a written agreement to protect your data to a standard at least equivalent to this policy: to process it only on our instructions and only to deliver the feature you asked for, not to sell or share it, and not to use your content to train or improve their own models.
Before anything is sent to an AI provider, the app tells you what is sent and names who receives it, and asks you to agree. You can review that disclosure, and withdraw your agreement, at any time in the app under Settings → Legal → AI processing.
We may also disclose information if required by law, or to protect the rights, safety, and security of our users and Aura.
Cookies & analytics
On the website we use PostHog for analytics. Until you accept cookies, PostHog runs in a cookieless mode that measures anonymous, in-session activity without storing a tracking cookie on your device. If you accept, we store a cookie so we can recognize return visits and measure conversions more accurately. If you decline, analytics capture is turned off. You can change your mind by clearing your browser storage for this site, which brings the choice back.
Aura Keyboard
Aura Keyboard is an optional Android keyboard. When you enable it, Android warns you that a keyboard can read what you type. Here is exactly what we do with that.
Your typing stays on your phone. Keystrokes, autocorrect, and word suggestions are processed entirely on your device. We do not receive, store, or transmit what you type.
What the keyboard learns, it keeps locally. Words, phrases, and corrections it picks up are stored encrypted on your device under a key held in the Android Keystore. That data is excluded from Google cloud backup and from device-to-device transfer. It is never uploaded to us, and we cannot read it.
Text is sent only when you explicitly ask for it. Three features send data, and each asks your permission before the first time it does:
- Aura writing actionssend the text in the field you are typing in, up to 2,000 characters, to our servers so Buddy can draft or rewrite it. “Reply as me” sends the message you copied instead. If what you copied looks like a one-time code or a password, it is not sent.
- Talking to Buddy streams your microphone audio to our servers while the mic is on, along with the text in the field so Buddy knows what you are working on.
- Voice typing (Dictate in the keyboard, or the mic in the Aura chat box) streams your microphone audio to our speech provider, Deepgram, while you dictate, to turn it into text. When personalization is allowed, names from your Aura vocabulary may be sent with it to improve recognition. Nothing from the field around your cursor is sent. If you tap Clean up, the transcript is sent to our servers to fix punctuation. Aura does not save the audio or the transcript.
If you decline any of them, the keyboard keeps working normally for everything else. You can turn any of them back on, or off again, in Aura Keyboard settings at any time.
Private fields are excluded. In password, PIN, one-time-code, numeric, phone, email, and web address fields, the writing features are unavailable and no field text is ever sent, even if you start a voice session from one.
Processing. Text and audio you explicitly send are processed by us and by our model and speech providers to produce a reply. They are not used to train models.
Deleting it.“Clear learned words and personalization” in Aura Keyboard settings removes everything the keyboard has learned on that device, including any saved vocabulary hints and your recently used emoji. The keyboard confirms only after it has verified each one is gone. If you sign in with a different Aura account on the same device, the previous account’s learned data is cleared automatically.
Diagnostics. The optional developer diagnostics screen in keyboard settings shows status values and counters only. It never displays, stores, or transmits anything you typed.
Data retention
We keep your information for as long as your account is active or as needed to provide Aura. The Google user data section above explains the more specific rules for Google authorization tokens, temporary processing, saved or derived content, and the Google Calendar cache. You can ask us to delete your data at any time (see Your rights), and we delete or anonymize data we no longer need.
Anonymous website voice-demo transcripts are retained to help us improve Buddy. Because they hold no name, email, or account link, they aren’t tied to your identity.
Your rights & choices
- Delete your account, in the app.Settings → Manage account → Delete account removes your stored files, your database records and your sign-in record. It is immediate and needs no email to us. You can also email us to access or correct your data.
- Withdraw AI processing consentat Settings → Legal → AI processing.
- Revoke Google access anytime at myaccount.google.com/permissions. Revocation stops future access; separately delete any Google-derived content you previously asked Aura to save.
- Opt out of emails using the unsubscribe link in any message.
- Depending on where you live (e.g. the EEA/UK under GDPR, or California under the CCPA/CPRA), you may have additional rights to access, portability, correction, deletion, and to object to certain processing. Contact us to exercise them.
Children’s privacy
Aura is not directed to children under 13 (or the minimum age in your country), and we don’t knowingly collect their data. At sign-up we ask only whether you are 18 or older, or 13 to 17. We do not ask for or store your date of birth. If you tell us you are 13 to 17, Aura never builds a profile from your conversations and Buddy keeps additional conversational restrictions. Companion AI may not be suitable for some minors; if you believe a child has provided us information, contact us and we’ll delete it.
Security
We use reasonable technical and organizational measures to protect your information. No method of transmission or storage is perfectly secure, but we work to safeguard your data and limit access to it.
International users
Aura is operated from the United States, and your information may be processed in the US and other countries where our providers operate. By using Aura you consent to this processing.
Changes to this policy
We may update this policy as Aura evolves. We’ll revise the “Last updated” date above and, for material changes, give notice through the app or website.
Contact
Questions, requests, or deletion: hello@auravoiceapp.com.