Privacy Policy

Last updated: 2026-07-26

This Privacy Policy explains how Aureo collects, uses, and protects your information when you use the Aureo app and services.

Who We Are

Aureo is operated by a company currently being formed. We will update this policy with the legal entity and address before broad release.

Age Requirement

Aureo is intended for users aged 16 and over.

Data We Store

How We Use Data

Authentication

User authentication is handled through Supabase Authentication with Bearer tokens.

Analytics and Pseudonymization

Analytics uses client-provided anonymous IDs that are hashed server-side before storage. Raw anonymous IDs are not stored by the backend. Analytics payload metadata is filtered to a limited allowlist.

Crash Diagnostics

In production release builds, Aureo uses Google Firebase Crashlytics to collect crash reports automatically and to record selected unexpected technical failures. We do not send financial amounts, financial records, authentication tokens, email addresses, request or response bodies, feedback text, or raw backend error messages to Crashlytics. Normal connectivity, validation, authentication-expiry, and expected service errors are not recorded as Crashlytics non-fatal events.

Data Processing and Residency

Data is processed in the European Union. Our core infrastructure runs in Ireland (EU West) for both database (Supabase) and backend (Vercel).

Processors

Data Retention

We retain your data while your account is active, or as needed to provide the service and comply with legal obligations. You can request full account/data deletion from the app. Analytics and notification records may also be subject to additional retention cleanup rules configured by the service.

Your Rights

You can access or export your data, and delete your account and data, directly from the app.