Privacy Policy
Effective date: July 31, 2026
Auratype is an entertainment and self-improvement app that gives you an “aura” score and a plan to improve it. This policy reflects how the app actually works — in particular, your photo is never stored on our servers, and we never build or keep a face-geometry template. You do not create an account, and we do not know your name.
The short version
- No account. The app is tied to a random device identifier, not your name or email.
- Your photo stays yours. Our processing partner, OpenAI, receives your selfie in separate safety and scoring requests. Auratype discards it after processing and never writes it to our storage or logs. OpenAI does not train its models on API data by default and may retain inputs for abuse monitoring for up to 30 days unless our project is approved for Zero Data Retention.
- No biometric identifiers. We do not create, store, or share a face-geometry template.
- We store only your scores (numbers and text), so you can reopen your result and track progress.
- We don’t sell your data and don’t use it for third-party advertising.
- You can delete your Auratype data in one tap, anytime. Your legal consent record and Apple-managed subscription remain.
What we collect and why
| Data | Why | Stored? |
|---|---|---|
| Photo / selfie | Sent to OpenAI in separate safety and scoring requests. | Not by Auratype. We discard it after processing. OpenAI’s API abuse-monitoring retention may be up to 30 days unless Zero Data Retention is enabled. No face-geometry template is created or kept. |
| Device identifier | A random ID on your device, used to save your result, gate your subscription, and honor deletion. | Yes — not linked to your real identity. |
| Your scores & plan | So you can reopen your latest result and see progress. | Derived text/numbers only (never a photo), cached briefly on our servers and on your device. |
| Consent record | To record that you agreed and confirmed you’re 16+ before any processing. | Yes — device ID, timestamp, consent version. |
| Purchase status | To unlock and manage your subscription. | Handled by Apple and RevenueCat, keyed to your device ID. |
| Basic usage analytics | To understand which screens are used, so we can improve. Only if enabled. | Pseudonymous screen/action events keyed to a device ID; never photos, scan values, name, or contact details. Deletion queues removal of the keyed PostHog person, events, and recordings, and disables further analytics from that installation. Irreversibly aggregated statistics no longer identify a device. |
We do not collect your name, email, contacts, precise location, health data, messages, or browsing history.
How your photo is handled
Processing partner: OpenAI. When you take or upload a selfie and give affirmative consent, it is transmitted over encrypted connections in separate safety and scoring requests. The app may use a protected temporary cache file to resize it and deletes that file immediately after conversion. It is not saved to our database, object storage, server logs, or backups, and no biometric identifier or facial-recognition template is generated or retained. Only the resulting scores and text are kept. OpenAI does not train its models on API data by default and may retain API inputs for abuse monitoring for up to 30 days unless our project is approved for Zero Data Retention. The photo is never used to train Auratype. Because we never store your photo, there are no “before/after” photos of you anywhere — your progress is shown through your score history instead.
Biometric & photo data — retention & destruction
Because this can be sensitive, here is exactly what we keep, for how long, and how it’s destroyed. We do not collect, capture, store, or use biometric identifiers or biometric information for any purpose other than transiently generating your score, and we never sell, lease, trade, or otherwise profit from any such data. If any item below is ever determined to be a biometric identifier, it is destroyed at the earlier of (a) the purpose being satisfied or (b) the deadline in this schedule.
| Data | Stored? | Retention | Destruction |
|---|---|---|---|
| Your selfie / photo | Not retained by Auratype. The app may use a temporary protected cache file to resize the image, then deletes it immediately after conversion. | Auratype: only while local conversion and the safety/scoring requests run. OpenAI: up to 30 days for abuse monitoring unless Zero Data Retention is enabled. | Auratype deletes temporary app-cache files after conversion and never writes the photo to databases, server logs, object storage, or backups. |
| Face-geometry template / faceprint | Never created. | N/A | N/A |
| Derived scores (Aura Score, traits, history) | Yes, keyed to your device ID. | Server copy: up to 30 days. On-device history: until you delete it or remove the app. | Purged immediately when you use Delete Auratype data; server copies also expire automatically after 30 days. |
| Consent record | Yes (version, timestamp, age attestation). | Kept as a legal record of your consent. | Retained as required by law; contains no image or biometric data. |
Who we share data with
- Apple — subscription payments and the App Store.
- RevenueCat — subscription management (device ID + purchase status).
- OpenAI — receives your photo in separate safety and scoring requests; Auratype does not retain it. OpenAI does not train on API data by default and its API abuse-monitoring retention may be up to 30 days unless Zero Data Retention is enabled.
- Hosting provider — runs our servers.
- PostHog — product analytics, if enabled (aggregated, keyed to device ID).
We do not sell your personal information, and we do not share it for cross-app advertising or tracking.
Your choices and rights
- Delete your data: use the in-app deletion control or email us. Auratype immediately removes stored scores and derived data, cancels reminders, disables further analytics from that installation, and queues deletion of its keyed PostHog person, events, and recordings. PostHog processes that queue asynchronously; Auratype’s deletion SLA is within 30 days. Consent, subscription records, and irreversibly aggregated statistics are handled separately.
- Access: there’s no account, so your data is limited to the above; contact us with any request.
- California (CCPA/CPRA): we do not sell or “share” personal information as defined; you may request deletion.
Children
Auratype is for users 16 and older. It is not directed to children under 16, and we do not knowingly collect their data. Contact us if you believe a child has used the app and we’ll delete the associated data.
Security & changes
Data is transmitted over encrypted connections, and we minimize what we store (no photos, no biometric templates, no names). If we change this policy, we’ll update the effective date and surface a notice in the app for material changes.
Contact
Questions or requests: support@tryauratype.com