Skip to content
Aura LogoAura
HomeTestimonialsPartnerCareers
Sign inSee a DemoGet started
Get started
HomeTestimonialsPartnerCareersSign inSee a Demo

On this page

  • About
  • Data Collected
  • SMS Messaging
  • Architecture
  • How We Use
  • AI Processing
  • Security
  • Your Rights
  • CCPA Categories
  • Do Not Sell
  • GPC & DNT
  • Subprocessors
  • International Transfers
  • Cookies
  • Legal Basis
  • Children's Privacy
  • Changes
  • Contact

Privacy Policy

Your privacy is important to us. Learn how we collect, use, and protect your data.

Effective: December 23, 2024 ยท Updated: July 15, 2026

About Aura

Aura A.I LLC ("Aura," "we," "us," or "our") is a sales activity tracking and coaching platform that helps sales teams analyze their meeting performance and improve outcomes through data-driven insights. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our service.

We take your privacy seriously. If you have any questions, please contact us at support@aura-app.ai.

Information We Collect

Account and Authentication Data

When you create an Aura account, we collect information through Clerk, our authentication provider:

  • Email address and identity credentials
  • Full name and optional profile information
  • Organization membership and role
  • Multi-factor authentication (MFA) settings
  • Session tokens and login history
  • Authentication method (password, SSO, OAuth)

Calendar Data (via Nylas Integration)

When you connect your calendar account (Google Calendar, Microsoft Outlook, etc.) through Nylas, Aura accesses:

Calendar Events:

  • Meeting events and metadata (title, time, participants, description)
  • Conference or meeting room information
  • Attendee lists and response status

Meeting Recordings & Transcripts (via Recall.ai):

  • Meeting recordings (audio and video) captured by a notetaker that joins the meeting
  • Meeting transcripts generated from those recordings
  • Participant information and join or leave times
  • Conference session metadata

Recording and transcription are performed by Recall.ai (Hyperdoc Inc.), which holds the captured media for a limited retention window before deleting it. Aura stores its own copy. We do not directly access Google Drive.

Booking Page Data

When you use a booking page to schedule a meeting, we collect:

  • Name, email address, and optionally phone number
  • Responses to custom prequalification questions set by the meeting organizer
  • Browser metadata (timezone, user agent) for scheduling purposes
  • Visitor session ID for cross-session identification (with consent)
  • UTM parameters and referral data for marketing attribution (with consent)

What We DON'T Collect

  • Personal emails or email content (except booking-related transactional emails)
  • Documents unrelated to meetings
  • Personal photos or files
  • Browser history or device information (except basic analytics)

SMS and Text Messaging

When you book an appointment on a business's Aura-hosted scheduling page, you may optionally opt in to receive SMS text messages about that appointment. SMS consent is collected through a separate, unchecked checkbox on the booking form. You are not required to opt in to complete your booking.

What we send

If you opt in, you may receive automated appointment-related messages from the business you booked with, such as booking confirmations, meeting reminders, and reschedule or cancellation notices. Message frequency varies and is typically up to five messages per appointment, depending on that business's notification settings. We do not send promotional or marketing SMS under this program.

Rates, opt-out, and help

Message and data rates may apply. You can opt out at any time by replying STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT. You may re-subscribe by replying START, UNSTOP, or YES. For help, reply HELP or contact support@aura-app.ai.

How we use mobile numbers

We use your mobile phone number solely to deliver appointment-related messages you requested and to record your opt-in and opt-out preferences with an audit trail. We do not sell or share mobile phone numbers with third parties or affiliates for their marketing or promotional purposes. SMS delivery is provided by Twilio, our subprocessors list describes Twilio's role, and our Terms of Service govern use of the platform.

For privacy questions about SMS, contact support@aura-app.ai.

Data Architecture and Multi-Tenant Isolation

How Your Data is Stored

All Aura user and organizational data is securely stored in Supabase, a PostgreSQL-based database platform. Aura operates as a multi-tenant platform, meaning multiple organizations use the same infrastructure while remaining completely isolated from each other.

Row Level Security (RLS)

We enforce Row Level Security (RLS) at the database level, which means:

  • Organization-Based Access: Every query is automatically filtered by organization ID, ensuring you can only access your organization's data.
  • Database-Enforced Access Control: The database itself, not application code, evaluates the isolation rules on every query.
  • Administrative Access: Background jobs, webhook handlers and administrative tooling run under a service credential that is not subject to these row-level rules. Access to that credential is restricted to authorized personnel.
  • Audit Logging: Administrative and data-modifying actions are logged and can be audited for compliance purposes.

Infrastructure Providers

  • Supabase: PostgreSQL database hosting in the US (AWS N. Virginia region)
  • Vercel: Application hosting and edge network for global access

Both providers are SOC 2 Type II certified for security and reliability.

How We Use Your Data

Primary Use Cases

  • Meeting Analysis: Analyze meeting patterns, duration, and participant engagement.
  • Sales Performance: Classify meetings as sales-related and provide performance insights.
  • Content Processing: Process transcripts to identify key topics, sentiment, and action items.
  • Activity Tracking: Create comprehensive records of sales activities for coaching.

Data Processing

  • Automated Analysis: AI-powered analysis of transcripts for sales insights.
  • Classification: Automatic categorization of meetings (sales calls, demos, follow-ups).
  • Reporting: Generate performance dashboards and coaching recommendations.
  • Storage: Securely store your meeting recordings, transcripts, AI-generated insights, and metadata in your organization's isolated, encrypted workspace.

Artificial Intelligence Processing

Aura uses AI to analyze meeting transcripts and generate sales insights. We believe in transparency about how AI processes your data.

AI Providers

Meeting transcripts are processed by the following AI providers:

  • Anthropic (Claude): Transcript analysis and insight generation
  • OpenAI (GPT-4): Transcript analysis and insight generation
  • Google (Gemini): Transcript analysis and insight generation

How AI Processes Your Data

  • In-Memory Processing: Transcripts are sent to AI providers via API and processed in-memory. They are not permanently stored by the AI providers.
  • No Model Training: AI providers do not use data sent via their APIs to train their models (per their enterprise API terms).
  • Output Storage: AI-generated insights (summaries, action items, coaching recommendations) are stored in your organization's Aura database.
  • Routing: Model requests are routed through Vercel AI Gateway, which acts as the intermediary between Aura and the model providers named above.

What AI Analyzes

  • Meeting transcripts (text only, not audio or video)
  • Conversation topics and sentiment
  • Action items and follow-up recommendations
  • Sales performance patterns

AI-generated insights are recommendations only. Aura makes no warranties regarding AI accuracy. You are responsible for reviewing all AI-generated content before using it for business decisions.

Data Security and Storage

Security Measures

  • Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Access Control: Role-based access. Multi-factor authentication is available and recommended.
  • Infrastructure: Hosted on SOC 2 compliant cloud providers (Vercel, Supabase).
  • Monitoring: 24/7 security monitoring and automated threat detection.
  • Security Headers: Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and Permissions-Policy headers protect against XSS, downgrade attacks, and unauthorized browser API access.
  • PII Redaction: Personal data (emails, phone numbers, names) is automatically redacted from error tracking and application logs.

Data Retention

  • Recording Provider: Recall.ai holds the captured audio and video for a limited window configured by Aura, then deletes it.
  • Aura's Copy: Recordings, transcripts, AI-generated insights, lead records, visitor session records and communications are stored in your organization's workspace and retained until deleted on request. We do not currently operate automated retention or deletion schedules for these records.
  • Deletion Requests: Contact support@aura-app.ai to request deletion of specific records or of an organization's data. Requests are handled by our team rather than through a self-serve control.
  • Analytics Data: Aggregated insights retained for historical reporting.

Your Rights and Controls

Universal Rights

Regardless of your location, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate information.
  • Deletion: Request deletion of your data (subject to legal retention requirements).
  • Portability: Request your data in a portable, machine-readable format.
  • Object: Object to certain types of data processing.

GDPR Rights (European Economic Area)

If you are located in the EEA, UK, or Switzerland, GDPR grants you additional rights including the right to restrict processing and the right to lodge a complaint with your data protection authority.

Geo-Based Consent: We automatically detect visitors from EU/EEA countries using server-side geolocation. Visitors from these regions are shown a GDPR consent checkbox on booking forms and a cookie consent banner before any non-essential tracking is activated. No tracking scripts load until consent is explicitly given (zero-load consent policy).

CCPA/CPRA Rights (California Residents)

If you are a California resident, the CCPA grants you the right to:

  • Know what personal information is collected, used, and shared.
  • Request deletion of personal information collected from you.
  • Opt-out of the sale or sharing of personal information.
  • Receive equal service and pricing even if you exercise your rights.
  • Correct inaccurate personal information.

We do not sell your personal information.

Exercising Your Rights

To exercise your rights, email us at support@aura-app.ai with your request, including sufficient detail to identify your account. We will respond within 30 to 45 days.

CCPA Categories of Personal Information

In the last 12 months, Aura has collected the following categories of personal information for California residents. Aura does not sell personal information.

CategoryExamplesCollectedSold or SharedSourceRetention
IdentifiersEmail, name, IP addressYesNoDirect from userUntil deleted on request
Commercial informationBooking history, billing recordsYesNoService usageUntil deleted on request
Internet activityPage views, UTM parametersYes (with consent)NoTracking pixelsUntil deleted on request
InferencesLead scoring, qualification statusYesNoDerived from usageService duration
GeolocationCity, region, country, and approximate latitude and longitude (IP-derived)YesNoVercel edgeUntil deleted on request

Do Not Sell or Share My Personal Information

Under the California Consumer Privacy Act (CCPA) and similar US state privacy laws, you have the right to opt out of the "sale" or "sharing" of your personal information for targeted advertising purposes.

Aura uses tracking technologies (Meta Pixel, HYROS) on public pages that may constitute "sharing" of personal information under these laws. To opt out:

  • Enable Global Privacy Control (GPC) in your browser settings or install a browser extension that supports GPC. Aura automatically honors GPC signals and will not load any tracking scripts when GPC is detected.
  • Email us at support@aura-app.ai with the subject "Do Not Sell" and we will process your request within 15 business days.

Opting out will not affect your ability to use Aura's services. We do not sell personal information in the traditional sense (exchanging data for monetary compensation).

Global Privacy Control & Do Not Track

Global Privacy Control (GPC)

We honor the Global Privacy Control (GPC) browser signal. When your browser sends a GPC signal, we automatically:

  • Reject all non-essential cookies without showing a consent banner.
  • Prevent loading of advertising and attribution tracking scripts (Meta Pixel, HYROS, Google Tag Manager).
  • Disable visitor session tracking on public pages.

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), the GPC signal is treated as a legally binding opt-out request. We do not attempt to override, ignore, or circumvent this signal.

Do Not Track (DNT)

While the older Do Not Track (DNT) browser header lacks a legal framework, we treat it similarly to GPC: if DNT is enabled and no explicit consent has been given, we default to essential-only cookies.

Subprocessors

We work with carefully selected third-party providers to deliver our service. These providers have contractual obligations to protect your data.

What We DON'T Share

  • Raw meeting recordings or transcripts with advertisers or marketers.
  • Individual participant information outside your organization.
  • Personal identifying information for commercial purposes.
  • Data with data brokers, aggregators, or information resellers.

Subprocessor Change Notice

We will notify customers 30 days before adding a new subprocessor that processes customer personal data. Customers may object to a new subprocessor by emailing support@aura-app.ai. The current list of subprocessors is maintained on this page; a complete change history is available upon request.

Current Subprocessors

ProviderPurposeLocationSecurity
Vercel Inc.Application hosting, edge network, and AI Gateway routingUS / Global
SOC 2 Type II, ISO 27001:2022, PCI DSS v4.0
Supabase, Inc.Database and file storage (including meeting recordings)US (AWS)
SOC 2 Type II, ISO 27001
Clerk, Inc.Authentication and organization membershipUS
SOC 2 Type II
Functional Software, Inc. d/b/a SentryError tracking and performance monitoringUS (EU region available)
SOC 2 Type II
Inngest Inc.Background job execution; job payloads may contain lead dataUS
SOC 2 Type II (no public DPA or subprocessor list)
Upstash, Inc.Rate limiting and cachingUS / EU
SOC 2 (report type not publicly stated)
Statsig, Inc.Feature flag evaluation (an OpenAI group company)US
Not publicly verified
Hyperdoc Inc. (Recall.ai)Meeting recording and transcription; receives meeting audio and videoUS (us-west-2)
SOC 2 (report type not publicly stated), HIPAA BAA available
Mux, Inc.Video hosting and playback for meeting recordingsUS
Not publicly verified
Nylas, Inc.Calendar connectivity, availability, and event managementUS / EU (AWS, GCP)
SOC 2 Type II, ISO 27001, ISO 27701
Zoom Communications, Inc.Meeting SDK and conferencing join tokensUS / Global
SOC 2 Type II, ISO 27001
Anthropic, PBC (Anthropic Ireland, Limited for EEA)AI analysis of meeting transcripts (Claude), via AI GatewayUS / Ireland
Commercial terms prohibit training on customer content
OpenAI, L.L.C. (OpenAI Ireland Ltd for EEA)AI extraction and drafting, via AI GatewayUS / Ireland
API inputs not used for training; up to 30-day abuse logs
Google LLC (Google Ireland Limited for EEA)AI classification and translation (Gemini), via AI GatewayUS / EU
ISO 27001, SOC 2; paid tier not used for training
Plus Five Five, Inc. (Resend)Transactional email deliveryUS
No public SOC 2 or ISO claim
Twilio Inc. (Twilio Ireland Limited for EEA)SMS delivery for appointment notificationsUS / Global
SOC 2 Type II, ISO 27001
Intercom, Inc. (Intercom R&D Unlimited Company for non-US)Customer support messagingUS (EU hosting available)
SOC 2 Type II
Hertza L.L.C. (ZeroBounce)Email address validationUS / EU
SOC 2 Type II, ISO 27001:2022
Sanity ASMarketing content management (no end-user personal data)Norway (EEA) / US
Not publicly verified
Kit, Inc.Waitlist and marketing email; receives name and emailUS
Not publicly verified
Dub Technologies, Inc.Link analytics and referral attributionUS
Not publicly verified
Vidalytics, LLCVideo hosting for onboarding and marketing contentUS
No public DPA, certification, or transfer mechanism
Microsoft Corporation (Clarity)Session replay and heatmaps. Microsoft acts as an independent controller under the Clarity-specific terms and may use the data for its own purposes, including advertising. Form inputs are masked and are not transmittedUS
Microsoft corporate certifications; none Clarity-specific
Meta Platforms Ireland Ltd / Meta Platforms, Inc.Advertising measurement and conversion tracking. Meta acts as a processor for measurement and analytics, as a joint controller for event data used in ad targeting, and as an independent controller once data is transmitted to Meta Platforms, Inc.US / EU
ISO 27001; audit reports available on request
Hyros, Inc.Advertising attribution trackingUS
SOC 2 Type II (DPA available on request only)
Slack Technologies, LLCCustomer-configured event notifications (lead and call lifecycle)US
SOC 2 Type II, ISO 27001
HubSpot, Inc.Customer-configured CRM synchronizationUS / EU / AU / CA (customer-selectable)
SOC 2 Type II, ISO 27001
Elastic Inc. d/b/a CloseCustomer-configured CRM synchronizationUS
Not publicly verified
HighLevel, Inc. (GoHighLevel)Customer-configured CRM synchronizationUS / India
Not publicly stated on DPA
Zapier, Inc.Customer-configured workflow automationUS
SOC 2
ablefy GmbHCustomer-configured order and payment synchronizationGermany (EEA)
Art. 28 GDPR processing agreement concluded in-account
Stripe, Inc. (Stripe Payments Europe, Ltd for non-US)Subscription billing and customer payment processingUS / Ireland / Global
PCI-DSS Level 1

International Data Transfers

Aura is headquartered in the United States. If you are located in the European Economic Area or another jurisdiction with strict data transfer laws, your data is transferred internationally to our US-based servers. We comply with EU Standard Contractual Clauses (SCCs) for GDPR compliance.

Data Processing Addendum (DPA)

B2B customers may request a Data Processing Addendum (DPA) including EU Standard Contractual Clauses by emailing support@aura-app.ai. We use the European Commission's 2021 SCCs (Module 2: Controller-to-Processor).

Google-Specific Commitments

API Services User Data Policy Compliance:

  • Limited Use: Google user data used solely for stated purposes.
  • Human Review: Limited to authorized personnel for debugging or security only.
  • No Reverse Engineering: Will not attempt to extract additional data or capabilities.
  • Scope Minimization: Request only minimum necessary permissions.

Cookies and Tracking Technologies

Cookies are small text files stored on your device that help us remember your preferences and understand how you use Aura. They are essential for authentication, security, and improving your experience.

Geo-Targeted Consent Policy

We use IP-based geolocation (via Vercel's edge network) to determine your jurisdiction and apply the appropriate consent model:

  • GDPR countries (EU/EEA/UK and 45 regulated jurisdictions): No non-essential tracking scripts load until you explicitly accept cookies via the consent banner. No advertising pixels (Meta Pixel, HYROS), no third-party analytics, and no visitor tracking cookies are set before consent.
  • Non-GDPR countries (US, Canada, etc.): Tracking scripts load automatically. You may opt out at any time using the Do Not Sell My Information process above, or by enabling Global Privacy Control (GPC) in your browser.
  • Essential cookies (authentication, security) are always active regardless of jurisdiction.

Cookie Inventory

Cookie TypePurposeRequired
Essential CookiesLogin, session management, security
Required
Authentication (Clerk)Maintain your login session
Required
Security CookiesCSRF protection and attack prevention
Required
Google Analytics 4Page views, feature usage, performance
Optional
Microsoft ClaritySession replay and heatmaps. Runs without cookies until you consent
Optional
IntercomCustomer support messaging session
Optional
Third-Party (Stripe, Google)Payments and OAuth
Optional
Meta Pixel (Facebook)Advertising measurement and conversion tracking
Optional
HYROSAttribution and conversion tracking
Optional
Dub AnalyticsReferral and click attribution
Optional
Google Tag ManagerTag management for analytics scripts
Optional
Visitor ID (aura_visitor_id)Cross-session visitor identification for lead deduplication
Optional

Most browsers allow you to control cookies through settings. You can delete cookies or disable them, though some features of Aura may not work properly without essential cookies.

Legal Basis for Processing (GDPR)

  • Legitimate Interest: Business analytics and performance improvement.
  • Consent (Art. 6(1)(a)): Processing of personal data submitted via booking forms when consent is explicitly given via the GDPR consent checkbox.
  • Consent: Explicit consent for Google Workspace integration.
  • Contract Performance: Providing sales coaching services as agreed.
  • Legal Obligation: Compliance with applicable laws and regulations.

Children's Privacy

Aura is intended for business use by adults. We do not knowingly collect personal information from children under 16 in the European Economic Area, or under 13 in the United States and other jurisdictions. If you believe we have inadvertently collected such information, contact support@aura-app.ai and we will delete it promptly.

Changes to This Policy

We will notify users 30 days before material changes, obtain new consent for expanded data usage, and maintain historical versions of this policy.

Contact Information

Aura A.I LLC

26 Broadway
New York, NY 10004
United States

For questions about this policy: support@aura-app.ai

See also our Terms of Service.

Aura LogoAura

The AI-powered sales performance platform for coaches and agencies.

Product

  • Partner

Legal

  • Privacy
  • Terms
  • Do Not Sell My Information

2026 Aura. All rights reserved.

Google Meet is a trademark of Google LLC. Zoom is a trademark of Zoom Video Communications, Inc. Microsoft Teams is a trademark of Microsoft Corporation. Aura is not affiliated with or endorsed by these companies.

InstagramLinkedInYouTube