Privacy Policy
Last updated 16 September 2026
This Privacy Policy explains how Aurora First, Inc. (Aurora, we, us or our) handles personal data when you use the Aurora mobile application, Aurora Journey at https://journey.aurorafirst.ai, the website at https://aurorafirst.ai, or another Aurora product that links to this Policy (together, the Services).
I. Controller and scope
1. Controller
Aurora First, Inc. is the controller responsible for the personal data covered by this Policy.
Aurora First, Inc.
510 SE 5th Ave, Apt 712
Fort Lauderdale, Florida 33301
United States
Privacy inquiries: dpo@aurorafirst.ai
Support and privacy requests: support@aurorafirst.ai
Support page: https://aurorafirst.ai/support
You can use either email address for a privacy request. Publication of the privacy-inquiry address does not identify or name an individual Data Protection Officer.
2. Current Services
The Aurora App provides AI-assisted routines, reminders, everyday lists and chat. Aurora Journey provides authored sequences of Cards, which may include practical instructions or prompts you can use in a third-party AI tool. Journey is currently a free public service. The Website explains Aurora and hosts support and legal pages.
Features may differ by device, release, country, account or gradual rollout. A feature described as coming soon is not treated as currently available.
Aurora does not currently operate a public website funnel for new subscription purchases. We may still hold limited records for past website purchases and support them as described below.
II. Personal data we handle
3. Data you provide
Depending on the Service and features you use, you may provide:
- account and contact data, such as name, email address and sign-in method;
- messages, routines, reminders, lists, goals, preferences and other content you submit;
- optional onboarding answers about lifestyle, focus, wellbeing or personal circumstances;
- feedback, survey responses and communications with support;
- subscription or purchase information needed to locate a transaction; and
- information you choose to provide through an optional connected service.
Please do not send passwords, full payment-card numbers, security codes, government identifiers, or information you do not need Aurora to process.
4. Sensitive information
Your messages or optional onboarding answers may reveal health, mental-health, disability, religious, sexual-orientation or other information treated as sensitive under some laws. For example, a user may voluntarily mention anxiety or ADHD when describing routines or support needs.
Providing this information is optional unless a feature clearly explains otherwise. We use it to provide or personalize the feature you request, not to determine eligibility for employment, credit, insurance or housing. Where applicable law requires explicit consent or another special legal condition, that condition applies. You can withdraw consent where consent is the basis, delete content where the feature allows, or contact us. Withdrawal does not make earlier lawful processing unlawful.
Do not use Aurora as the only place to store important health information, and do not use it for emergencies.
5. Data collected automatically
When you use the Services, we may receive:
- device, operating-system, App version, browser and language information;
- IP address and approximate region derived from it;
- timestamps, pages or screens viewed, feature interactions and referring links;
- crash, diagnostic, performance and security logs;
- push-notification token and delivery status where notifications are enabled; and
- identifiers provided by the device, app store or analytics service, subject to platform settings and applicable choices.
We do not claim to collect precise location unless a feature expressly requests device permission for that purpose.
6. Purchases
Apple App Store, Google Play and payment processors handle payment credentials under their own privacy notices. Aurora normally receives transaction identifiers, product, price, currency, purchase or renewal date, subscription status, country or tax region, and limited account information needed to provide access and support. We generally do not receive a complete card number.
For historical website purchases, records may also be held by Stripe or by the provider named on the receipt, such as PayPal or Paddle.
7. Optional Google or Gmail connection
If the published App shows a Google or Gmail connection and you choose to enable it, the connection may request the permissions displayed on Google's consent screen, including basic account information and read-only Gmail access. An enabled email feature may process message content and metadata needed for the feature and may store OAuth credentials so the connection continues to work.
This does not describe Google Calendar access. If the connection is not shown or enabled for your account, Aurora does not newly collect Gmail data through that connection.
You can revoke access through the App where available or at https://myaccount.google.com/permissions. Revocation stops new access but does not automatically erase information already lawfully processed. You may request deletion as described below.
Aurora's use and transfer of information received from Google APIs must comply with the Google API Services User Data Policy, including its Limited Use requirements.
III. Why we use personal data
8. Providing the Services
We use personal data to:
- create and authenticate accounts;
- provide chat, routines, reminders, lists, Journey and requested integrations;
- generate and deliver AI-assisted responses;
- synchronize settings and content across supported devices;
- provide subscriptions and purchase access;
- send service messages, reminders or notifications you request; and
- respond to support and privacy requests.
For users in the EEA or United Kingdom, this processing is generally necessary to perform our contract or take steps you request before entering into it.
9. Safety, security and operations
We use relevant data to prevent fraud and misuse, protect accounts, diagnose failures, maintain the Services, enforce our terms and establish or defend legal claims. The legal basis may be our legitimate interests, compliance with law, or protection of legal rights, depending on the context.
10. Product analysis and improvement
We analyze how features perform and how people use them so we can fix problems and improve Aurora. We try to use aggregated or de-identified information where reasonably possible. The legal basis may be legitimate interests or consent, depending on the technology and local law.
11. Legal obligations
We process data when reasonably necessary to comply with tax, accounting, consumer-protection, court, regulatory or law-enforcement obligations. We may also preserve evidence of a transaction, consent, cancellation or dispute.
12. Marketing
We may send marketing only where we have a lawful basis, such as consent or a legally valid existing-customer exception. Every marketing email will provide an unsubscribe route. Service, security, purchase and legal notices are not marketing and may still be sent when needed.
IV. AI and automated processing
13. AI providers
To generate an AI response, Aurora may send your prompt and relevant context, such as selected earlier messages, routines or preferences, to a model provider used by the feature. Current Aurora source includes services from Microsoft Azure OpenAI and Google Cloud Vertex AI or Gemini. If an internet-search feature is enabled, it may also use Perplexity.
The exact provider can depend on the feature, release and technical configuration. We do not state that every provider uses zero-data-retention or that every provider is contractually prohibited from all model improvement unless Aurora has verified that setting or term for the relevant service.
Do not submit information you do not want processed to generate the response. AI output may be inaccurate and should not be treated as professional advice.
14. Observability
We use error and AI-observability tools, including Sentry and, where enabled, Langfuse, to investigate failures, latency and response quality. These tools may receive technical data and limited prompt, response or account context depending on configuration. We restrict access to people and providers who need it for operational purposes and apply retention criteria described below.
15. Significant decisions
Aurora is not designed to make decisions producing legal or similarly significant effects about employment, credit, insurance, housing or eligibility for public services. Contact us if you believe a feature has been used that way.
V. Cookies, SDKs and similar technologies
16. Website
The Website uses storage necessary to remember your analytics choice and operate the site. Optional PostHog analytics starts only after you choose Allow analytics in the Website banner. If you choose Decline, Aurora does not intentionally initialize that optional Website analytics. You can change the stored choice by clearing site data and choosing again.
The current Website does not use the advertising pixels and session-replay tools that appeared in Aurora's historical acquisition funnel. Any future funnel must have its own reviewed disclosure and consent implementation before launch.
17. App SDKs
Depending on the App build, platform and enabled feature, Aurora may use:
- Firebase services for authentication, notifications, configuration, diagnostics or analytics;
- Google Sign-In and Sign in with Apple for login;
- Adapty, Apple App Store and Google Play for subscription access;
- Sentry for error monitoring;
- PostHog, Amplitude or Firebase Analytics for product analysis; and
- AppsFlyer or Meta App Events for install attribution or advertising measurement.
An SDK's presence in an App build does not mean every function is active for every user. Some SDKs may initialize when the App runs depending on the release and configuration. Platform privacy settings, operating-system permission prompts and applicable choices may limit advertising or analytics identifiers. You may also contact us to object or request deletion.
We do not treat every integrated SDK as strictly necessary merely because it is part of the App. Where local law requires a particular consent or opt-out, your rights under that law apply.
VI. When we share personal data
18. Service providers
We disclose personal data to providers only for services they perform for Aurora or as otherwise described here. Depending on the platform, feature and transaction, these providers include:
- Google Cloud and Firebase for hosting, authentication, configuration, notifications, diagnostics and analytics;
- Microsoft Azure OpenAI, Google Vertex AI or Gemini, and Perplexity where enabled, for AI generation or search;
- Sentry and Langfuse where enabled, for error and AI observability;
- Apple, Google and Adapty for App distribution, sign-in and subscriptions;
- Stripe for historical direct billing and its customer portal;
- PayPal or Paddle where identified on a historical receipt;
- PostHog, Amplitude, Firebase Analytics, AppsFlyer and Meta where enabled for the analysis or attribution purposes described above; and
- customer-support and transactional-email providers used to respond to requests and deliver Service messages, including Intercom where enabled.
Not every provider receives every category of data. A provider receives the data reasonably needed for its function and acts under its own terms, Aurora's instructions, or both, depending on its role.
19. Third-party tools chosen by you
Journey Cards may invite you to copy a prompt into a third-party AI tool such as ChatGPT, Claude or Gemini. Aurora does not send that prompt to the tool for you merely because you view or copy it. If you submit it, the third party processes it under its own privacy notice and settings.
20. Legal and corporate disclosures
We may disclose information where reasonably necessary to comply with law, protect a person's safety, investigate fraud or security incidents, enforce legal rights, or respond to valid legal process.
If Aurora is involved in a merger, financing, reorganization, sale of assets or similar transaction, personal data may be reviewed or transferred subject to confidentiality, applicable law and continued notice of material changes.
We do not sell personal data for money. Some US state laws may define certain advertising or attribution disclosures more broadly as sharing or targeted advertising. Where such a law applies, you may opt out through relevant device settings or by contacting us.
VII. International processing
21. Locations
Aurora is based in the United States. We and our providers may process personal data in the United States, the European Economic Area, the United Kingdom and other countries where a provider operates. Those countries may have different data-protection laws from your country.
Applicable law may require a recognized transfer mechanism, contractual protection or another safeguard for a particular international transfer. You may contact us for information about the mechanism relevant to your data.
Aurora does not currently maintain an establishment in the EEA or United Kingdom. Residents may contact Aurora directly at the addresses in Section I. If Aurora appoints a local representative, we will add the representative's details to this Policy.
VIII. Retention and deletion
22. Retention criteria
We keep personal data only as long as reasonably needed for the purposes described here, including providing an active account or feature, honoring the user's choices, maintaining security, resolving support or payment issues, complying with tax and legal duties, and establishing or defending claims.
Retention varies by data type and provider. Account content may remain while the account is active. Transaction and consent records may be retained for the legally required period. Security logs and backups may remain for limited operational cycles. OAuth credentials should be removed or disabled when the connection is revoked or the account is deleted, subject to technical and legal requirements.
When data is no longer needed, we delete it, de-identify it, or isolate it until deletion is technically practicable. De-identified information that cannot reasonably be linked back to you may be kept for analysis.
23. Account deletion
Use the deletion option in the App where available or email support@aurorafirst.ai. We may need to verify that the request comes from the account holder. Account deletion does not cancel a subscription and may not immediately remove records that must be retained for law, security, fraud prevention, disputes or backups.
IX. Security
24. Safeguards
We use technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration or disclosure. The measures vary according to the data, system and risk.
No system is perfectly secure. We cannot promise that an incident will never occur. If a breach triggers a legal notification duty, we will notify affected people and authorities as required.
If you believe your account or Aurora data may be at risk, contact support@aurorafirst.ai.
X. Your choices and rights
25. Choices
You can:
- edit or delete available account content;
- control notifications in the App or device settings;
- revoke a connected Google account in Google settings;
- choose Allow analytics or Decline on the Website;
- use device privacy settings for App tracking where available;
- unsubscribe from marketing messages; and
- contact us to object, withdraw consent where applicable, or request deletion.
26. Privacy rights
Depending on your location and applicable law, you may have rights to receive information, access data, correct it, delete it, restrict or object to processing, receive portable data, withdraw consent, opt out of sale, sharing or targeted advertising, and appeal a decision. You may also complain to your local data-protection authority.
We offer reasonable access, correction and deletion assistance even when a particular state privacy statute does not apply, subject to identity verification, technical feasibility and lawful exceptions.
To exercise a right, email dpo@aurorafirst.ai or support@aurorafirst.ai. Describe the account or Service involved and the right you want to exercise. Do not send extra identity documents unless we ask for information reasonably needed to verify the request.
We will respond within the period required by applicable law. We will not unlawfully discriminate against you for exercising a privacy right.
XI. Children
27. Age limit
The Services are intended only for people aged 18 or older. We do not knowingly offer them to children. If you believe a person under 18 provided personal data, contact us so we can investigate and take appropriate action.
XII. Changes to this Policy
28. Updates
We may update this Policy as the Services, providers or law change. We will update the date above and provide additional notice where required or where a change materially affects how we use personal data.
The current version is available at https://aurorafirst.ai/privacy
XIII. Contact
29. Privacy and support channels
Aurora First, Inc.
510 SE 5th Ave, Apt 712
Fort Lauderdale, Florida 33301
United States
Privacy inquiries: dpo@aurorafirst.ai
Support and privacy requests: support@aurorafirst.ai
Website: https://aurorafirst.ai/support