Privacy Policy

Last updated: May 7, 2026

Aura by First24 ("Aura," "we," "us," or "our") is a personal wellness and family-memory application. This Privacy Policy explains what we collect, why, where it's stored, and what we never do. This update reflects the addition of Aura Genesis (verified family memories), Bluetooth-mediated co-presence, hardware device attestation, and Apple Watch HRV duress detection.

The short version:

1. Information We Collect

1a. Aura Safety (wellness routine, exposure context, verification)

Data TypeHow CollectedStored WhereRetention
Account info (email, name, locale, timezone)Sign-upSupabase (encrypted at rest, RLS-protected)Until account deletion
Wellness score & streak dataApp usageSupabase (encrypted)Until account deletion
Routine completion records (Golden Window)App usageSupabase (encrypted)Until account deletion
Adherence-verification photosCamera (optional)Classified on-device, then deletedNever stored — only the SHA-256 hash + classification result + EXIF timestamp/GPS persist
Adherence-verification metadataDerived from photoSupabase (encrypted)90 days (attestation TTL)
Device info (platform, OS version, app version, model)AutomaticSupabase (encrypted)Until account deletion

1b. Aura Genesis (verified family memories)

Data TypeHow CollectedStored WhereRetention
Kin Circles (family group names)You create themSupabase (encrypted, RLS to active members)Until you delete the circle
Kin Memberships (invited family member display names + relationship label)You invite themSupabase (encrypted, RLS-protected)Until membership revoked
Invitation tokensOne-shot, server-generatedSupabase (encrypted)14 days, deleted on accept/revoke
Sealed memory photos / video / audioYou capture or importPrivate Supabase Storage bucket (genesis-media); access restricted by row-level security to active members of the seal's circleUntil you (the seal's creator) delete the seal, OR until your account is deleted
Seal metadata: hash (SHA-256), capture method, timestamp, optional location label, event label, noteDerived at captureSupabase (encrypted)Same as the seal
Seal participants: which Kin were verified presentYou select OR confirmed via BLESupabase (encrypted)Same as the seal
Seal proofs: device attestation references, capture-time, BLE co-presence signaturesDerived at captureSupabase (encrypted)Same as the seal
Living Heirloom extensions: text notes, voice recordings, photos, drawings, AI-assisted summariesYou and other circle members add themText in Supabase; media in genesis-media bucketUntil the contributor soft-deletes their entry, or the seal is deleted
Time Capsule lock datesYou set themSupabase (encrypted)Same as the seal
Voice / AI consent flagsYou set in Voice Consent settingsSupabase (encrypted)Until account deletion

1c. Co-presence (Bluetooth Low Energy)

Data TypeHow CollectedStored WhereRetention
Short-lived BLE advertisement during seal captureYour phone broadcasts a random session token over BLE for up to 30 minutesBroadcast over the air; not persistedToken expires within 30 min
Witness records — confirmation that another Kin's device detected the broadcastTheir app posts a witness report when nearbySupabase (encrypted, RLS-protected)Until the seal is deleted
Optional RSSI (signal strength)Detected by witness deviceSupabase (encrypted)Until the seal is deleted

1d. Device attestation (anti-fraud)

Data TypeHow CollectedStored WhereRetention
Apple App Attest receipts (iOS) / Google Play Integrity tokens (Android)Apple / Google services attest your device's integrity at install / re-attest periodicallyVerification result + cryptographic public key in Supabase (encrypted)Until account deletion
Stable per-install device id (UUID)Generated locally on first launch; persists in app's secure storageSupabase (encrypted)Until account deletion or app reinstall
Attestation sign counterIncremented by Apple / Google on each cryptographic operationSupabase (encrypted)Used for replay-prevention; retained while device is registered

1e. Aura Watch — HRV duress detection

Data TypeHow CollectedStored WhereRetention
Heart-rate variability (HRV) patternsApple Watch sensors via HealthKitOn-watch and on-iPhone only — analyzed locallyWatch / phone storage; not transmitted
Duress alert eventsTriggered on-device when HRV pattern matches stress thresholdSupabase (encrypted) — only the event marker, not the HRV time series30 days for the alert record
Designated emergency contactsYou configure themSupabase (encrypted)Until you remove them or delete your account

1f. Subscription billing

Data TypeHow CollectedStored WhereRetention
Subscription tier (free / Genesis Plus / Genesis Legacy)RevenueCat webhook after Apple/Google Play purchaseSupabase (encrypted)Until account deletion
One-time purchase credits (e.g. Heirloom Book unlocks)RevenueCat webhookSupabase (encrypted)Until account deletion
RevenueCat purchase identifiers (product id, latest entitlement, app user id)RevenueCat webhookSupabase (encrypted)For fraud / billing reconciliation; until account deletion
Payment instrument dataNEVER collected by usApple / Google handle paymentsn/a

1g. Service operation

Data TypeHow CollectedStored WhereRetention
Audit log of sensitive operations (capsule lock/unlock, Heirloom Book export, kin invite/revoke, subscription change)Server-side, automaticSupabase (encrypted, append-only)2 years
Webhook event log (RevenueCat purchase events, deduplication)Server-side, automaticSupabase (encrypted)2 years
Crash reportsAutomatic via Sentry — scrubbed of PII; only contains user UUID + breadcrumb of routes hitSentry servers90 days
Usage analyticsAutomatic via PostHog — aggregate event counts; no message contentPostHog serversRolling 12 months

2. Verification Photos — Immediate Deletion (Aura Safety)

When you use Verified Adherence, you may optionally photograph your care product. The photo is classified on-device using machine learning and immediately deleted. We retain only an image hash (SHA-256), the classification result, a timestamp, and optional EXIF GPS coordinates. The image itself never reaches our servers.

3. Sealed Family Memories — Aura Genesis

Aura Genesis is the family-memory module. When you "seal" a memory:

Living Heirloom extensions (notes, voice memos, photos, drawings) are added by you and family members after a memory is sealed. The original (Root Memory) is cryptographically immutable. Extensions chain off it append-only and form a verifiable timeline. AI-generated content (e.g. an AI-assisted summary of your family's contributions) is always clearly labeled with an "AI" badge in the app.
Voice consent & AI rules:

4. Bluetooth Proximity (Co-Presence)

If you enable "Detect nearby Kin" during a memory capture, your phone broadcasts a short-lived random session token over Bluetooth Low Energy (typically < 30 minutes). Other Aura installations in your circle that detect the broadcast can post a witness record to confirm presence. Bluetooth is not used for tracking or location. The session token is random per capture, expires automatically, and contains no personal information. If you don't enable this feature, no BLE broadcast or scan happens.

5. Device Attestation

To prevent fraud (e.g. fake "verified device" claims), Aura uses Apple App Attest on iOS and Google Play Integrity on Android. These services let our servers cryptographically verify that requests come from a real, untampered Aura install on a real device. We store the verification result + a public key + a sign counter. App Attest and Play Integrity do not provide us with personal information about you — they tell us only whether your install passes Apple's / Google's integrity checks.

6. Watch App — HRV Duress Detection

If you install AuraWatch on Apple Watch, the app reads heart-rate variability (HRV) data from HealthKit on-device to detect distress patterns. HRV time-series data never leaves the watch / phone pair. When a duress threshold is crossed, the app may send an alert to your designated emergency contacts; only the alert event (timestamp + your user id) is logged on our servers, not the HRV data itself.

7. How We Use Your Information

We use your information to:

8. Enterprise & Insurer Programs (Aura Safety)

If you enroll in Aura through an employer or insurer wellness program:

9. What We Never Do

10. Data Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Authentication is handled through Supabase Auth with Apple Sign-In, Google Sign-In, or email magic links. Memory seals and Living Heirloom extensions are bound by HMAC-SHA256 hashes that detect tampering. Postgres row-level security ensures users can only read seals, extensions, witnesses, and entitlements they're authorized to. Webhook integrations (RevenueCat) require constant-time-compared shared secrets. Device attestation requires a real Apple App Attest receipt or Google Play Integrity verdict. The backend refuses to start in production with placeholder secrets, ensuring deploys can never silently run with predictable signing keys.

11. Your Rights

You have the right to:

12. California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at privacy@first24.io.

13. European Residents (GDPR)

If you are in the European Economic Area, our legal basis for processing is: consent (microphone, camera, Bluetooth, HealthKit access; voice / AI consent flags), contract performance (providing the Aura service, processing payments), and legitimate interest (crash reporting, fraud prevention via device attestation, audit logging). You have the right to access, rectify, erase, restrict processing, and port your data. Contact our Data Protection Officer at privacy@first24.io.

14. Children's Privacy

Aura is not directed to children under 13. Family members under 13 may be added to a Kin Circle by a parent or guardian, but the parent's account controls all data. Voice recordings of minors (e.g. a child's milestone in a Living Heirloom) are stored only at the parent's instruction and can be deleted by the parent at any time. We do not knowingly collect personal information directly from children under 13.

15. FTC Health Breach Notification

Even though Aura is a wellness tool and not a HIPAA-covered entity, we comply with the FTC Health Breach Notification Rule. In the event of a breach involving health-related data, we will notify affected users and the FTC as required by law.

16. Third-Party Services

Aura relies on these third-party services. Each is bound by its own privacy policy:

ServicePurposeData sent
SupabaseDatabase, authentication, storageAll persisted Aura data
Apple (App Store, App Attest, Sign-In, HealthKit)Auth, payments, device attestation, HRV inputAuthentication tokens, App Attest receipts, purchase events
Google (Play Store, Play Integrity, Sign-In)Auth, payments, device attestationAuthentication tokens, Play Integrity tokens, purchase events
RevenueCatSubscription management bridge between App Store / Play Store and our backendPurchase events, subscription state, your user id
SentryCrash reportingError stacks + breadcrumb of routes hit + your user id
PostHogAggregate product analyticsAnonymized event counts (e.g. "seal created"); no message content
Fly.ioBackend hostingAll API traffic (encrypted in transit)
CDC public APIsSeasonal awareness dataOutbound only; we don't send your data to CDC

17. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated through the app and by updating the "Last updated" date above. Continued use of Aura after material changes constitutes acceptance.

18. Contact Us

First24, Inc.
Burleson, Texas
Email: privacy@first24.io

Aura is a wellness, family-memory, and lifestyle tool. It does not diagnose, treat, cure, or prevent any disease.