Our philosophy
Your fitness and food history should feel personal, private, and under your control.
AuraMind handles fitness, nutrition, goal, AI, purchase, and optional health data. We treat this information as sensitive and explain when it is linked to an account, which processors receive it, and what controls are available.
Privacy at a glance
Local-first history
Your logs live on your device first. Sign in and they sync to your own access-controlled account.
No advertising tracking
We do not use collected data for advertising or to track you across apps or websites owned by other companies.
Export & delete
Export your workout and nutrition data anytime, or request full account deletion.
Named processors
We identify the backend, AI, diagnostics, subscription, and barcode processors used by the shipped app.
The full policy
1. Data we collect
- Account & profile: sign-in identity, username, goals, training preferences, units, and settings you enter.
- Workout logs: exercises, sets, reps, weights, durations, and notes you add.
- Nutrition logs: meals, food items, and macros. A barcode value is processed only if the separately gated food-data capability is enabled; it is off in the current public build.
- Submitted AI content: the submitted text and photos and the raw recorded voice audio you choose to process, relevant account context needed for the feature, and generated output.
- Apple Health data: if you connect HealthKit, AuraMind requests read-only access to the data types you approve: steps, active energy, and body weight. AuraMind does not write to HealthKit.
- Product analytics: sanitized feature and interaction
events stored in Supabase. For a signed-in user, each event is linked
through the raw account user ID (
user_id); it is not de-identified or unlinked. - Diagnostics: sanitized JavaScript crash, error, and other diagnostic data sent to Sentry. AuraMind does not send Sentry your account ID, email, name, or a stable account hash, so these reports are not linked to your AuraMind account.
- Purchases: RevenueCat receives your AuraMind account ID, available email and display name, and App Store purchase, subscription, and entitlement history.
- Device info: app version, build, platform, and device model for diagnostics.
- Push notifications: a device token if you enable notifications.
- Aura Arena / private challenges: only if a future build enables Aura Arena, challenges you create or join and your progress within them. Aura Arena is off in this build.
2. How we use data
We use data to provide account sync, workout and nutrition logging, AI-assisted features, subscriptions, support, product analytics, fraud and abuse controls, and service reliability. AuraMind does not use collected data for advertising or to track you across apps or websites owned by other companies.
3. Third-party processors
- Supabase — authentication, database, storage, edge functions, and product-event storage. Signed-in product events include the raw Supabase account user ID.
- OpenAI — processes submitted text and photos plus bounded workout, nutrition, goal, preference, profile, and body-metric context used by shipped parsing, coaching, Ask, and nutrition-estimation features. That context can include body weight imported from Apple Health when available. Steps and active energy are not sent to OpenAI. AuraMind sends this content through its Supabase backend.
- Google Gemini — processes raw recorded voice audio for transcription and, when you request source-backed research for certain external goals, the submitted goal text plus bounded profile context such as age, sex, height, weight, and training history. When AI meal visuals are on for your account, Google Gemini also receives the names of the foods in a meal you logged and which meal it was, so it can generate an illustrative image of that meal; no photo of yours is sent for this. AuraMind sends this content through its Supabase backend. These Google Gemini paths are enabled in this build. On-device dictation, where shown, stays on the device and is not sent to Google.
- Sentry — processes sanitized JavaScript crash, error, and other diagnostic data. AuraMind does not provide Sentry with an AuraMind account identifier.
- Expo Push — delivers AuraMind reminder notifications. When you allow notifications, AuraMind sends Expo Push a device push token and the text of the reminder so it can be delivered to your device. No workout, nutrition, or body data is sent to Expo Push. Turning notifications off in Settings stops this.
- RevenueCat — manages subscription status and receives the account identity and purchase/entitlement information described above. Apple processes App Store payments and transaction records.
- FatSecret — the verified-food and barcode provider when the separately gated food-data capability is enabled. In the current public build, that capability is off, so AuraMind does not send barcode numbers or food search terms to FatSecret. If enabled in a later build, FatSecret would receive only the barcode number or food search term used for lookup, not your account identity, meal history, or any health data.
These processors handle data under their own service terms and retention practices. AuraMind does not authorize them to use AuraMind data for cross-app advertising or tracking.
4. Storage, security & retention
Data is stored locally on your device and, when you sign in or use a cloud feature, in AuraMind's Supabase backend. Access controls are intended to limit signed-in users to their own account data.
We keep account content while it is needed to provide the service or until it is deleted. Analytics and diagnostics may remain for the retention periods configured with Supabase or Sentry. Submitted AI content may be subject to Supabase's, OpenAI's, and Google's retention practices.
For costly AI-request reliability, a client-inaccessible Supabase ledger stores the linked account ID, operation, opaque request key, semantic hash, state, attempts, timestamps, and service-safe failure metadata. It never stores the raw prompt, photo, or audio. A bounded completed Ask answer, which may reflect the submitted question or context, or a structured food/menu estimate may be cached for response replay and is scheduled for clearing within 24 hours by an hourly retention job. If that job misses or fails, monitoring flags the delay for operator remediation. The remaining request tombstone stays until account deletion to prevent duplicate provider work. The ledger is excluded from workout/nutrition exports and is deleted with the account.
A local-data deletion affects that device only. Account deletion is the separate way to request removal of cloud account content. We do not promise immediate removal from backups, security logs, processor systems, or App Store transaction records where temporary or legally required retention applies.
5. Your rights & choices
- Export your workout and nutrition data (JSON/CSV) from Settings → Data & Privacy. The export does not include telemetry, diagnostics, submitted photos or audio, or App Store records.
- Delete local data on this device at any time.
- Request full account/data deletion (see the Data Deletion page).
- Turn product analytics and crash reporting on or off in Settings → Data & Privacy. Turning a toggle off stops future eligible uploads; it does not erase records already received by Supabase or Sentry.
- Allow or turn off third-party AI processing in Settings → Data & Privacy. Turning it off stops future submissions; it does not undo prior processing or remove data already on your device.
- Revoke HealthKit and notification permissions in device settings.
- Manage or cancel an App Store subscription through Apple. Deleting an AuraMind account does not itself cancel the subscription or erase transaction records Apple or RevenueCat must retain.
6. Children
AuraMind is not directed at children under 13. The app asks for age during setup and accepts ages 13 and older. Do not create an account if you are under 13. If we learn that an account belongs to a child under 13, we will delete it.
Some third-party AI providers impose additional age rules. Google Gemini’s current API terms restrict API clients to professional or business use and users 18 and older; AuraMind still admits ages 13 and older and does not currently collect verifiable parental consent. OpenAI’s current services agreement requires parent or guardian consent before a minor uses OpenAI services; AuraMind does not currently collect verifiable parental consent.
7. Changes
We may update this policy. Material changes will prompt you to review and accept again in-app.
8. Contact
Questions or requests: supportauramind@gmail.com