Privacy Policy

Last updated: 2026-09-16

This Privacy Policy explains how Aureo collects, uses, and protects your information when you use the Aureo app and services.

Who We Are

Aureo is operated by a company currently being formed. We will update this policy with the legal entity and address before broad release.

Age Requirement

Aureo is intended for users aged 16 and over.

Data We Store

How We Use Data

Authentication

User authentication is handled through Supabase Authentication with Bearer tokens.

Analytics and Pseudonymization

Product analytics is enabled by default and can be disabled at any time under Privacy & Security in the app. Before sign-in, analytics is associated with a rotating installation identifier that is hashed by our backend. After sign-in, accepted product events are associated with the authenticated account by the backend. Only the current verified installation's unowned events from the previous 24 hours may be claimed by that account. Unclaimed guest events are not attributed to an account or included in an account export.

Apple App Attest is used on supported production devices to verify analytics requests. If verification is unavailable or fails, analytics is disabled rather than sent through a less secure fallback. Turning analytics off immediately stops collection, removes queued events and local analytics identifiers, and requests deletion of account-owned and current-installation analytics. Turning it back on starts with a new identifier and does not restore deleted data.

Crash Diagnostics

In production release builds, Aureo uses Google Firebase Crashlytics to collect crash reports automatically and to record selected unexpected technical failures. We do not send financial amounts, financial records, authentication tokens, email addresses, request or response bodies, feedback text, or raw backend error messages to Crashlytics. Normal connectivity, validation, authentication-expiry, and expected service errors are not recorded as Crashlytics non-fatal events.

Data Processing and Residency

Data is processed in the European Union. Our core infrastructure runs in Ireland (EU West) for both database (Supabase) and backend (Vercel).

Processors

Data Retention

We retain your data while your account is active, or as needed to provide the service and comply with legal obligations. You can request full account/data deletion from the app. Accepted product analytics events are retained for no more than 90 days and are deleted sooner after analytics opt-out or account deletion as described above. Notification records are managed separately and may be subject to their own retention rules.

Your Rights

You can access or export your data, and delete your account and data, directly from the app.