Skip to content

Privacy Center

Privacy Policy

How we collect, use, and share your data, when it is linked to an account, and the controls and retention limits that apply.

Effective: September 30, 2026 · Version 2026-09-30.1

Your fitness and food history should feel personal, private, and under your control.

AuraMind handles fitness, nutrition, goal, AI, purchase, and optional health data. We treat this information as sensitive and explain when it is linked to an account, which processors receive it, and what controls are available.

Local-first history

Your logs live on your device first. Sign in and they sync to your own access-controlled account.

No advertising tracking

We do not use collected data for advertising or to track you across apps or websites owned by other companies.

Export & delete

Export your workout and nutrition data anytime, or request full account deletion.

Named processors

We identify the backend, AI, diagnostics, subscription, and barcode processors used by the shipped app.

The full policy

1. Data we collect

  • Account & profile: sign-in identity, email, username or display name, goals, training preferences, units, and settings you enter.
  • Workout logs: exercises, sets, reps, weights, durations, and notes you add.
  • Nutrition logs: meals, food items, and macros. A barcode value is processed only if the separately gated food-data capability is enabled; it is off in the current public build.
  • Submitted AI content: the submitted text and photos and the raw recorded voice audio you choose to process, relevant account context needed for the feature, and generated output.
  • Apple Health data: if you connect HealthKit, AuraMind requests read-only access to the data types you approve: steps, active energy, and body weight, plus sleep analysis if you allow it. If you grant sleep access, AuraMind may use recent sleep to personalize your fitness guidance, and missing sleep never counts against you. Raw sleep samples, sleep times, and sleep stages stay on your device. When you use Ask AuraMind, a short summary of last night's sleep (about how long you slept, whether that was less than your recent usual, and how it shaped today's plan) may be included in the request sent through AuraMind's Supabase backend to OpenAI to generate a personalized response. AuraMind's product analytics record a coarse sleep category for the day (for example, short or typical), whether sleep changed your guidance, or that sleep was unavailable. If you complete a workout AuraMind adjusted partly because of a short night, the saved workout notes that reason in your account's cloud backup. Neither analytics nor the backup includes sleep durations or times. If you do not grant sleep access or have no usable sleep data, AuraMind uses and shares no Apple Health sleep information, and analytics can only note that sleep was unavailable and why (for example, no recent data). Sleep you enter yourself is handled like your other logs: what you tell Adjust Today (for example, how long you slept) can be included in Ask AuraMind requests sent to OpenAI, a sleep rating in a workout note is saved with that workout in your cloud backup, and a daily check-in stays on your device, though guidance it shaped can appear in Ask AuraMind requests. Apple Health sleep is not sent to Google Gemini. AuraMind does not write to HealthKit.
  • Product analytics, only if you enable it in Settings: sanitized feature and interaction events stored in Supabase. For a signed-in user, each event is linked through the raw account user ID (user_id); it is not de-identified or unlinked.
  • Diagnostics, only if you enable crash reporting in Settings: sanitized JavaScript crash, error, and other diagnostic data sent to Sentry. AuraMind does not send Sentry your account ID, email, name, or a stable account hash, so these reports are not linked to your AuraMind account.
  • Purchases: RevenueCat receives your AuraMind account ID, available email and display name, and App Store purchase, subscription, and entitlement history.
  • Support & feedback you send us: if you use Feedback & Support or Report a Problem, the message you write, the category or severity you choose, and the app version, build, and platform at the time you sent it; Feedback & Support also sends your OS version, device model, and the screen you were on. These are stored with your account so we can follow up, and the report form also keeps a contact email if you type one. Report a Problem also attaches a hashed account reference and the names (not the contents) of your most recent in-app events, which can show, for example, that guidance was adjusted for sleep. We do not attach your workouts, meals, photos, or chat history to a report.
  • Device info: app version, build, platform, and device model for diagnostics.
  • Push notifications: a device token if you enable notifications.
  • Aura Arena / private challenges: only if a future build enables Aura Arena, challenges you create or join and your progress within them. Aura Arena is off in this build.

2. How we use data

We use data to provide account sync, workout and nutrition logging, AI-assisted features, subscriptions, support, product analytics, fraud and abuse controls, and service reliability. AuraMind does not use collected data for advertising or to track you across apps or websites owned by other companies. AuraMind does not sell your health data, and health and fitness data is not used for advertising.

3. AI data sharing and your permission

AuraMind sends personal data to a third-party AI service only after you choose “Allow and Continue” on the “Share data with AI services?” screen. That screen appears before the first time any AI feature would send anything, names each recipient, and lists what each feature sends. It is a separate choice from accepting these documents, and nothing is sent merely by opening it. If you choose “Not Now”, nothing is sent to OpenAI or Google, and manual workout, meal, and weight logging, your history, your plan, and on-device text reading keep working.

The two AI recipients are OpenAI (OpenAI API) and Google (Gemini API). The app never contacts either one directly: requests go over an encrypted connection to AuraMind’s backend (Supabase Edge Functions), which calls the provider with a key that is never in the app. AuraMind does not add your email address, account ID, or a device or advertising identifier to what it sends them. Your name and the profile details listed below are included in Ask AuraMind requests.

  • Ask AuraMind → OpenAI: Your question and recent conversation; your profile (name, age, gender, height, weight, goals, training experience, and equipment); recent workouts, meals and nutrition logs, body-weight trend, and notes you asked AuraMind to remember. If you connected Apple Health: body weight imported from Health and a short summary of last night’s sleep. Your Apple Health step count and active energy are not sent.
  • Food and menu photos → OpenAI: The photo you take or choose, and which meal it is for.
  • Typed meals and workouts → OpenAI: The text you type, and which meal it is for.
  • Voice logging and voice questions → Google: The audio recording of what you say.
  • Goal planning stays on your device in this release. External goal research is off; external requirements need your verification and no goal/profile context is sent to Google for research.
  • AI meal images (AuraMind Pro) → Google: The food names and meal type of a meal you save — never your photo. Once you allow this, it happens automatically each time you save a meal.

The data is sent only to produce what you asked for — an answer, a nutrition or workout estimate, a transcription, or a meal image. OpenAI and Google handle it under their own terms and privacy policies, which govern how long they keep it.

You can read the same disclosure again, and withdraw your permission, at any time in Settings → Data & Privacy → AI data sharing → Turn Off AI Data Sharing. Turning it off stops every later AI request from the app and switches off automatic meal images on the backend; it does not recall data OpenAI or Google have already received. AuraMind asks again whenever an AI recipient or a category of data sent to one changes.

AuraMind keeps your answer on your device, in the iOS keychain, with the disclosure version, its identifier, and the date and time you answered. It is tied to this installation, so deleting and reinstalling the app asks again, and it is removed when you delete your local data or your account.

4. Third-party processors

  • Supabase — authentication, database, storage, edge functions, and product-event storage. Signed-in product events include the raw Supabase account user ID.
  • OpenAI — processes submitted text and photos plus bounded workout, nutrition, goal, preference, profile, and body-metric context used by shipped parsing, coaching, Ask, and nutrition-estimation features. That context can include body weight imported from Apple Health when available and, in Ask AuraMind requests, a short summary of last night's sleep if you allow sleep access. Steps and active energy are not sent to OpenAI. AuraMind sends this content through its Supabase backend.
  • Google Gemini — processes raw recorded voice audio for transcription. External goal research is off in this release; goal planning stays on your device and external requirements need your verification. When AI meal visuals are on for your account, Google Gemini also receives the names of the foods in a meal you logged and which meal it was, so it can generate an illustrative image of that meal; no photo of yours is sent for this. AuraMind sends this content through its Supabase backend. These Google Gemini paths are enabled in this build. Live dictation, where shown, is handled by your device’s own operating-system speech recognition rather than by AuraMind or Google. On Apple devices that means Apple’s speech recognition, which may send the audio to Apple to transcribe it; AuraMind does not receive or store that audio, and it is never sent to Google.
  • Apple and Google — provide the sign-in options. When you choose Sign in with Apple or Sign in with Google, that provider authenticates you and returns a provider account identifier and, unless you hide it, an email address, which AuraMind stores to keep your account linked. Deleting your AuraMind account revokes that link with the provider. Apple’s speech recognition may also process live dictation audio as described above.
  • Sentry — processes sanitized JavaScript crash, error, and other diagnostic data. AuraMind does not provide Sentry with an AuraMind account identifier.
  • Expo Push — delivers AuraMind reminder notifications. When you allow notifications, AuraMind sends Expo Push a device push token and the text of the reminder so it can be delivered to your device. No workout, nutrition, or body data is sent to Expo Push. Turning notifications off in Settings stops this.
  • RevenueCat — manages subscription status and receives the account identity and purchase/entitlement information described above. Apple processes App Store payments and transaction records.
  • FatSecret — the verified-food and barcode provider when the separately gated food-data capability is enabled. In the current public build, that capability is off, so AuraMind does not send barcode numbers or food search terms to FatSecret. If enabled in a later build, FatSecret would receive only the barcode number or food search term used for lookup, not your account identity, meal history, or any health data.

Every third party receiving AuraMind user data must provide the same or equal protection described in this privacy policy and required by the App Store Review Guidelines. We limit sharing to the disclosed purposes and use the applicable service and data-protection terms, access controls, and security safeguards. AuraMind remains responsible for choosing and configuring these services; their separate retention practices do not reduce this protection requirement. AuraMind does not authorize them to use AuraMind data for cross-app advertising or tracking.

5. Storage, security & retention

Data is stored locally on your device and, when you sign in or use a cloud feature, in AuraMind's Supabase backend. Access controls are intended to limit signed-in users to their own account data.

We keep account content while it is needed to provide the service or until it is deleted. Analytics and diagnostics may remain for the retention periods configured with Supabase or Sentry. Submitted AI content may be subject to Supabase's, OpenAI's, and Google's retention practices.

For costly AI-request reliability, a client-inaccessible Supabase ledger stores the linked account ID, operation, opaque request key, semantic hash, state, attempts, timestamps, and service-safe failure metadata. It never stores the raw prompt, photo, or audio. A bounded completed Ask answer, which may reflect the submitted question or context, or a structured food/menu estimate may be cached for response replay and is scheduled for clearing within 24 hours by an hourly retention job. If that job misses or fails, monitoring flags the delay for operator remediation. The remaining request tombstone stays until account deletion to prevent duplicate provider work. The ledger is excluded from workout/nutrition exports and is deleted with the account.

A local-data deletion affects that device only. Account deletion is the separate way to request removal of cloud account content. We do not promise immediate removal from backups, security logs, processor systems, or App Store transaction records where temporary or legally required retention applies.

6. Your rights & choices

  • Export your workout and nutrition data (JSON/CSV) from Settings → Data & Privacy. The export does not include telemetry, diagnostics, submitted photos or audio, or App Store records.
  • Delete local data on this device at any time.
  • Request full account/data deletion (see the Data Deletion page).
  • Product analytics and crash reporting are optional and off until you enable each control in Settings → Data & Privacy. Older preferences without evidence of explicit consent are reset to off. Turning a toggle off stops future eligible uploads; it does not erase records already received by Supabase or Sentry.
  • Allow or turn off AI data sharing in Settings → Data & Privacy → AI data sharing, where the full disclosure can be read again at any time. Turning it off stops future submissions; it does not undo prior processing or remove data already on your device.
  • Revoke HealthKit and notification permissions in device settings.
  • Manage or cancel an App Store subscription through Apple. Deleting an AuraMind account does not itself cancel the subscription or erase transaction records Apple or RevenueCat must retain.

7. Children

AuraMind is for adults. You must be 18 or older to use the app. The app asks for your age during setup and does not accept ages under 18. Returning accounts without a valid adult age must confirm it before using app features; privacy controls, account deletion, and sign-out remain available. Do not create an account if you are under 18. If we learn that an account belongs to someone under 18, we will delete it.

AuraMind does not knowingly collect personal information from anyone under 18, and it does not collect parental consent because minors are not admitted. This also keeps AuraMind within the age requirements of its third-party AI providers (Google Gemini and OpenAI).

8. Changes

We may update this policy. Material changes will prompt you to review and accept again in-app.

9. Contact

Questions or requests: supportauramind@gmail.com