Privacy Policy
This Privacy Policy explains how Aureo collects, uses, and protects your information when you use the Aureo app and services.
Who We Are
Aureo is operated by a company currently being formed. We will update this policy with the legal entity and address before broad release.
Age Requirement
Aureo is intended for users aged 16 and over.
Data We Store
- Account data managed by Supabase Authentication (user ID and auth metadata such as provider-linked identifiers).
- Profile data: display name, birthday, and an optional profile photo stored privately in Supabase Storage.
- Settings data: currency, monthly budget, first weekday, notification preference, liquidity threshold, and monthly closing day.
- Financial planning data: assets, incomes, expenses, goals, and monthly records (including notes, overrides, and monthly snapshots used for forecasting).
- In-app notification data: notification type, title, message, actions, and consumed timestamp.
- Analytics linkage data: hashed anonymous ID linked to your account for export/deletion requests.
- Analytics event data: event name, hashed anonymous ID, timestamp, platform, app version, locale, and limited event metadata (screen, flow, step, duration_ms, success, feature, count).
- Production crash diagnostics: app version and build, locale, a pseudonymous diagnostics identifier, and limited technical breadcrumbs such as screen, action category, endpoint family, status class, and error category.
How We Use Data
- Provide core app features, including budgeting, goal tracking, projections, and monthly summaries.
- Compute derived insights and forecast metrics from the financial data you provide.
- Deliver and manage in-app notifications.
- Measure product usage in aggregate through pseudonymized analytics.
- Operate, secure, and maintain the service.
- Diagnose and fix production crashes and unexpected technical failures.
- Support data rights requests, including data export and account/data deletion.
Authentication
User authentication is handled through Supabase Authentication with Bearer tokens.
Analytics and Pseudonymization
Analytics uses client-provided anonymous IDs that are hashed server-side before storage. Raw anonymous IDs are not stored by the backend. Analytics payload metadata is filtered to a limited allowlist.
Crash Diagnostics
In production release builds, Aureo uses Google Firebase Crashlytics to collect crash reports automatically and to record selected unexpected technical failures. We do not send financial amounts, financial records, authentication tokens, email addresses, request or response bodies, feedback text, or raw backend error messages to Crashlytics. Normal connectivity, validation, authentication-expiry, and expected service errors are not recorded as Crashlytics non-fatal events.
Data Processing and Residency
Data is processed in the European Union. Our core infrastructure runs in Ireland (EU West) for both database (Supabase) and backend (Vercel).
Processors
- Supabase (authentication, database, storage) - EU West (Ireland).
- Vercel (backend hosting) - EU West (Ireland).
- Google Firebase Crashlytics (production crash diagnostics).
Data Retention
We retain your data while your account is active, or as needed to provide the service and comply with legal obligations. You can request full account/data deletion from the app. Analytics and notification records may also be subject to additional retention cleanup rules configured by the service.
Your Rights
You can access or export your data, and delete your account and data, directly from the app.