Privacy Policy
Your privacy is important to us. Learn how we collect, use, and protect your data.
Effective: ยท Updated:
About Aura
Aura A.I LLC ("Aura," "we," "us," or "our") is a sales activity tracking and coaching platform that helps sales teams analyze their meeting performance and improve outcomes through data-driven insights. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our service.
We take your privacy seriously. If you have any questions, please contact us at support@aura-app.ai.
Information We Collect
Account and Authentication Data
When you create an Aura account, we collect information through Clerk, our authentication provider:
- Email address and identity credentials
- Full name and optional profile information
- Organization membership and role
- Multi-factor authentication (MFA) settings
- Session tokens and login history
- Authentication method (password, SSO, OAuth)
Calendar Data (via Nylas Integration)
When you connect your calendar account (Google Calendar, Microsoft Outlook, etc.) through Nylas, Aura accesses:
Calendar Events:
- Meeting events and metadata (title, time, participants, description)
- Conference or meeting room information
- Attendee lists and response status
Meeting Recordings & Transcripts (via Recall.ai):
- Meeting recordings (audio and video) captured by a notetaker that joins the meeting
- Meeting transcripts generated from those recordings
- Participant information and join or leave times
- Conference session metadata
Recording and transcription are performed by Recall.ai (Hyperdoc Inc.), which holds the captured media for a limited retention window before deleting it. Aura stores its own copy. We do not directly access Google Drive.
Booking Page Data
When you use a booking page to schedule a meeting, we collect:
- Name, email address, and optionally phone number
- Responses to custom prequalification questions set by the meeting organizer
- Browser metadata (timezone, user agent) for scheduling purposes
- Visitor session ID for cross-session identification (with consent)
- UTM parameters and referral data for marketing attribution (with consent)
What We DON'T Collect
- Personal emails or email content (except booking-related transactional emails)
- Documents unrelated to meetings
- Personal photos or files
- Browser history or device information (except basic analytics)
SMS and Text Messaging
When you book an appointment on a business's Aura-hosted scheduling page, you may optionally opt in to receive SMS text messages about that appointment. SMS consent is collected through a separate, unchecked checkbox on the booking form. You are not required to opt in to complete your booking.
What we send
If you opt in, you may receive automated appointment-related messages from the business you booked with, such as booking confirmations, meeting reminders, and reschedule or cancellation notices. Message frequency varies and is typically up to five messages per appointment, depending on that business's notification settings. We do not send promotional or marketing SMS under this program.
Rates, opt-out, and help
Message and data rates may apply. You can opt out at any time by replying STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT. You may re-subscribe by replying START, UNSTOP, or YES. For help, reply HELP or contact support@aura-app.ai.
How we use mobile numbers
We use your mobile phone number solely to deliver appointment-related messages you requested and to record your opt-in and opt-out preferences with an audit trail. We do not sell or share mobile phone numbers with third parties or affiliates for their marketing or promotional purposes. SMS delivery is provided by Twilio, our subprocessors list describes Twilio's role, and our Terms of Service govern use of the platform.
For privacy questions about SMS, contact support@aura-app.ai.
Data Architecture and Multi-Tenant Isolation
How Your Data is Stored
All Aura user and organizational data is securely stored in Supabase, a PostgreSQL-based database platform. Aura operates as a multi-tenant platform, meaning multiple organizations use the same infrastructure while remaining completely isolated from each other.
Row Level Security (RLS)
We enforce Row Level Security (RLS) at the database level, which means:
- Organization-Based Access: Every query is automatically filtered by organization ID, ensuring you can only access your organization's data.
- Database-Enforced Access Control: The database itself, not application code, evaluates the isolation rules on every query.
- Administrative Access: Background jobs, webhook handlers and administrative tooling run under a service credential that is not subject to these row-level rules. Access to that credential is restricted to authorized personnel.
- Audit Logging: Administrative and data-modifying actions are logged and can be audited for compliance purposes.
Infrastructure Providers
- Supabase: PostgreSQL database hosting in the US (AWS N. Virginia region)
- Vercel: Application hosting and edge network for global access
Both providers are SOC 2 Type II certified for security and reliability.
How We Use Your Data
Primary Use Cases
- Meeting Analysis: Analyze meeting patterns, duration, and participant engagement.
- Sales Performance: Classify meetings as sales-related and provide performance insights.
- Content Processing: Process transcripts to identify key topics, sentiment, and action items.
- Activity Tracking: Create comprehensive records of sales activities for coaching.
Data Processing
- Automated Analysis: AI-powered analysis of transcripts for sales insights.
- Classification: Automatic categorization of meetings (sales calls, demos, follow-ups).
- Reporting: Generate performance dashboards and coaching recommendations.
- Storage: Securely store your meeting recordings, transcripts, AI-generated insights, and metadata in your organization's isolated, encrypted workspace.
Artificial Intelligence Processing
Aura uses AI to analyze meeting transcripts and generate sales insights. We believe in transparency about how AI processes your data.
AI Providers
Meeting transcripts are processed by the following AI providers:
- Anthropic (Claude): Transcript analysis and insight generation
- OpenAI (GPT-4): Transcript analysis and insight generation
- Google (Gemini): Transcript analysis and insight generation
How AI Processes Your Data
- In-Memory Processing: Transcripts are sent to AI providers via API and processed in-memory. They are not permanently stored by the AI providers.
- No Model Training: AI providers do not use data sent via their APIs to train their models (per their enterprise API terms).
- Output Storage: AI-generated insights (summaries, action items, coaching recommendations) are stored in your organization's Aura database.
- Routing: Model requests are routed through Vercel AI Gateway, which acts as the intermediary between Aura and the model providers named above.
What AI Analyzes
- Meeting transcripts (text only, not audio or video)
- Conversation topics and sentiment
- Action items and follow-up recommendations
- Sales performance patterns
AI-generated insights are recommendations only. Aura makes no warranties regarding AI accuracy. You are responsible for reviewing all AI-generated content before using it for business decisions.
Data Security and Storage
Security Measures
- Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256).
- Access Control: Role-based access. Multi-factor authentication is available and recommended.
- Infrastructure: Hosted on SOC 2 compliant cloud providers (Vercel, Supabase).
- Monitoring: 24/7 security monitoring and automated threat detection.
- Security Headers: Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and Permissions-Policy headers protect against XSS, downgrade attacks, and unauthorized browser API access.
- PII Redaction: Personal data (emails, phone numbers, names) is automatically redacted from error tracking and application logs.
Data Retention
- Recording Provider: Recall.ai holds the captured audio and video for a limited window configured by Aura, then deletes it.
- Aura's Copy: Recordings, transcripts, AI-generated insights, lead records, visitor session records and communications are stored in your organization's workspace and retained until deleted on request. We do not currently operate automated retention or deletion schedules for these records.
- Deletion Requests: Contact support@aura-app.ai to request deletion of specific records or of an organization's data. Requests are handled by our team rather than through a self-serve control.
- Analytics Data: Aggregated insights retained for historical reporting.
Your Rights and Controls
Universal Rights
Regardless of your location, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate information.
- Deletion: Request deletion of your data (subject to legal retention requirements).
- Portability: Request your data in a portable, machine-readable format.
- Object: Object to certain types of data processing.
GDPR Rights (European Economic Area)
If you are located in the EEA, UK, or Switzerland, GDPR grants you additional rights including the right to restrict processing and the right to lodge a complaint with your data protection authority.
Geo-Based Consent: We automatically detect visitors from EU/EEA countries using server-side geolocation. Visitors from these regions are shown a GDPR consent checkbox on booking forms and a cookie consent banner before any non-essential tracking is activated. No tracking scripts load until consent is explicitly given (zero-load consent policy).
CCPA/CPRA Rights (California Residents)
If you are a California resident, the CCPA grants you the right to:
- Know what personal information is collected, used, and shared.
- Request deletion of personal information collected from you.
- Opt-out of the sale or sharing of personal information.
- Receive equal service and pricing even if you exercise your rights.
- Correct inaccurate personal information.
We do not sell your personal information.
Exercising Your Rights
To exercise your rights, email us at support@aura-app.ai with your request, including sufficient detail to identify your account. We will respond within 30 to 45 days.
CCPA Categories of Personal Information
In the last 12 months, Aura has collected the following categories of personal information for California residents. Aura does not sell personal information.
| Category | Examples | Collected | Sold or Shared | Source | Retention |
|---|---|---|---|---|---|
| Identifiers | Email, name, IP address | Yes | No | Direct from user | Until deleted on request |
| Commercial information | Booking history, billing records | Yes | No | Service usage | Until deleted on request |
| Internet activity | Page views, UTM parameters | Yes (with consent) | No | Tracking pixels | Until deleted on request |
| Inferences | Lead scoring, qualification status | Yes | No | Derived from usage | Service duration |
| Geolocation | City, region, country, and approximate latitude and longitude (IP-derived) | Yes | No | Vercel edge | Until deleted on request |
Do Not Sell or Share My Personal Information
Under the California Consumer Privacy Act (CCPA) and similar US state privacy laws, you have the right to opt out of the "sale" or "sharing" of your personal information for targeted advertising purposes.
Aura uses tracking technologies (Meta Pixel, HYROS) on public pages that may constitute "sharing" of personal information under these laws. To opt out:
- Enable Global Privacy Control (GPC) in your browser settings or install a browser extension that supports GPC. Aura automatically honors GPC signals and will not load any tracking scripts when GPC is detected.
- Email us at support@aura-app.ai with the subject "Do Not Sell" and we will process your request within 15 business days.
Opting out will not affect your ability to use Aura's services. We do not sell personal information in the traditional sense (exchanging data for monetary compensation).
Global Privacy Control & Do Not Track
Global Privacy Control (GPC)
We honor the Global Privacy Control (GPC) browser signal. When your browser sends a GPC signal, we automatically:
- Reject all non-essential cookies without showing a consent banner.
- Prevent loading of advertising and attribution tracking scripts (Meta Pixel, HYROS, Google Tag Manager).
- Disable visitor session tracking on public pages.
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), the GPC signal is treated as a legally binding opt-out request. We do not attempt to override, ignore, or circumvent this signal.
Do Not Track (DNT)
While the older Do Not Track (DNT) browser header lacks a legal framework, we treat it similarly to GPC: if DNT is enabled and no explicit consent has been given, we default to essential-only cookies.
Subprocessors
We work with carefully selected third-party providers to deliver our service. These providers have contractual obligations to protect your data.
What We DON'T Share
- Raw meeting recordings or transcripts with advertisers or marketers.
- Individual participant information outside your organization.
- Personal identifying information for commercial purposes.
- Data with data brokers, aggregators, or information resellers.
Subprocessor Change Notice
We will notify customers 30 days before adding a new subprocessor that processes customer personal data. Customers may object to a new subprocessor by emailing support@aura-app.ai. The current list of subprocessors is maintained on this page; a complete change history is available upon request.
Current Subprocessors
| Provider | Purpose | Location | Security |
|---|---|---|---|
| Vercel Inc. | Application hosting, edge network, and AI Gateway routing | US / Global | SOC 2 Type II, ISO 27001:2022, PCI DSS v4.0 |
| Supabase, Inc. | Database and file storage (including meeting recordings) | US (AWS) | SOC 2 Type II, ISO 27001 |
| Clerk, Inc. | Authentication and organization membership | US | SOC 2 Type II |
| Functional Software, Inc. d/b/a Sentry | Error tracking and performance monitoring | US (EU region available) | SOC 2 Type II |
| Inngest Inc. | Background job execution; job payloads may contain lead data | US | SOC 2 Type II (no public DPA or subprocessor list) |
| Upstash, Inc. | Rate limiting and caching | US / EU | SOC 2 (report type not publicly stated) |
| Statsig, Inc. | Feature flag evaluation (an OpenAI group company) | US | Not publicly verified |
| Hyperdoc Inc. (Recall.ai) | Meeting recording and transcription; receives meeting audio and video | US (us-west-2) | SOC 2 (report type not publicly stated), HIPAA BAA available |
| Mux, Inc. | Video hosting and playback for meeting recordings | US | Not publicly verified |
| Nylas, Inc. | Calendar connectivity, availability, and event management | US / EU (AWS, GCP) | SOC 2 Type II, ISO 27001, ISO 27701 |
| Zoom Communications, Inc. | Meeting SDK and conferencing join tokens | US / Global | SOC 2 Type II, ISO 27001 |
| Anthropic, PBC (Anthropic Ireland, Limited for EEA) | AI analysis of meeting transcripts (Claude), via AI Gateway | US / Ireland | Commercial terms prohibit training on customer content |
| OpenAI, L.L.C. (OpenAI Ireland Ltd for EEA) | AI extraction and drafting, via AI Gateway | US / Ireland | API inputs not used for training; up to 30-day abuse logs |
| Google LLC (Google Ireland Limited for EEA) | AI classification and translation (Gemini), via AI Gateway | US / EU | ISO 27001, SOC 2; paid tier not used for training |
| Plus Five Five, Inc. (Resend) | Transactional email delivery | US | No public SOC 2 or ISO claim |
| Twilio Inc. (Twilio Ireland Limited for EEA) | SMS delivery for appointment notifications | US / Global | SOC 2 Type II, ISO 27001 |
| Intercom, Inc. (Intercom R&D Unlimited Company for non-US) | Customer support messaging | US (EU hosting available) | SOC 2 Type II |
| Hertza L.L.C. (ZeroBounce) | Email address validation | US / EU | SOC 2 Type II, ISO 27001:2022 |
| Sanity AS | Marketing content management (no end-user personal data) | Norway (EEA) / US | Not publicly verified |
| Kit, Inc. | Waitlist and marketing email; receives name and email | US | Not publicly verified |
| Dub Technologies, Inc. | Link analytics and referral attribution | US | Not publicly verified |
| Vidalytics, LLC | Video hosting for onboarding and marketing content | US | No public DPA, certification, or transfer mechanism |
| Microsoft Corporation (Clarity) | Session replay and heatmaps. Microsoft acts as an independent controller under the Clarity-specific terms and may use the data for its own purposes, including advertising. Form inputs are masked and are not transmitted | US | Microsoft corporate certifications; none Clarity-specific |
| Meta Platforms Ireland Ltd / Meta Platforms, Inc. | Advertising measurement and conversion tracking. Meta acts as a processor for measurement and analytics, as a joint controller for event data used in ad targeting, and as an independent controller once data is transmitted to Meta Platforms, Inc. | US / EU | ISO 27001; audit reports available on request |
| Hyros, Inc. | Advertising attribution tracking | US | SOC 2 Type II (DPA available on request only) |
| Slack Technologies, LLC | Customer-configured event notifications (lead and call lifecycle) | US | SOC 2 Type II, ISO 27001 |
| HubSpot, Inc. | Customer-configured CRM synchronization | US / EU / AU / CA (customer-selectable) | SOC 2 Type II, ISO 27001 |
| Elastic Inc. d/b/a Close | Customer-configured CRM synchronization | US | Not publicly verified |
| HighLevel, Inc. (GoHighLevel) | Customer-configured CRM synchronization | US / India | Not publicly stated on DPA |
| Zapier, Inc. | Customer-configured workflow automation | US | SOC 2 |
| ablefy GmbH | Customer-configured order and payment synchronization | Germany (EEA) | Art. 28 GDPR processing agreement concluded in-account |
| Stripe, Inc. (Stripe Payments Europe, Ltd for non-US) | Subscription billing and customer payment processing | US / Ireland / Global | PCI-DSS Level 1 |
International Data Transfers
Aura is headquartered in the United States. If you are located in the European Economic Area or another jurisdiction with strict data transfer laws, your data is transferred internationally to our US-based servers. We comply with EU Standard Contractual Clauses (SCCs) for GDPR compliance.
Data Processing Addendum (DPA)
B2B customers may request a Data Processing Addendum (DPA) including EU Standard Contractual Clauses by emailing support@aura-app.ai. We use the European Commission's 2021 SCCs (Module 2: Controller-to-Processor).
Google-Specific Commitments
API Services User Data Policy Compliance:
- Limited Use: Google user data used solely for stated purposes.
- Human Review: Limited to authorized personnel for debugging or security only.
- No Reverse Engineering: Will not attempt to extract additional data or capabilities.
- Scope Minimization: Request only minimum necessary permissions.
Legal Basis for Processing (GDPR)
- Legitimate Interest: Business analytics and performance improvement.
- Consent (Art. 6(1)(a)): Processing of personal data submitted via booking forms when consent is explicitly given via the GDPR consent checkbox.
- Consent: Explicit consent for Google Workspace integration.
- Contract Performance: Providing sales coaching services as agreed.
- Legal Obligation: Compliance with applicable laws and regulations.
Children's Privacy
Aura is intended for business use by adults. We do not knowingly collect personal information from children under 16 in the European Economic Area, or under 13 in the United States and other jurisdictions. If you believe we have inadvertently collected such information, contact support@aura-app.ai and we will delete it promptly.
Changes to This Policy
We will notify users 30 days before material changes, obtain new consent for expanded data usage, and maintain historical versions of this policy.
Contact Information
Aura A.I LLC
26 Broadway
New York, NY 10004
United States
For questions about this policy: support@aura-app.ai
See also our Terms of Service.