mskerba

Aura privacy policy

Last updated: 11 August 2026

The short version

Aura analyses a photo of your face to generate style recommendations. The photo is sent to a third-party AI service to do that, and Aura asks for your explicit consent first.

Aura runs no servers of its own and stores neither your photos nor your results. The AI providers are configured so your photo is not retained after processing and is not used to train AI models.

What Aura collects

Only what's needed for the app to work. Depending on how you use it:

  • A photo you take or choose from your library.
  • The AI-generated analysis of that photo.
  • Anonymous purchase and subscription information, handled by RevenueCat.
  • Local preferences — language, theme, onboarding status and your AI consent setting.

There is no account, so Aura does not collect your name, email address, contacts, precise location or any other profile information.

1. Face data

The photo

When you take or select a photo, Aura resizes it to a maximum width of 640 pixels and converts it to JPEG. Only after you give explicit consent is that image transmitted for analysis. It may contain your face, the facial geometry visible in the image, and your upper body if it's in frame.

What comes back

  • A face shape classification — oval, round, square or unknown.
  • Observations about visible features: eyes, nose, lips, jawline, cheekbones.
  • Optional notes on body or silhouette.
  • A confidence score.
  • Personalised style recommendations.

What Aura never creates

  • Biometric templates.
  • Face embeddings.
  • Face-recognition identifiers.

Aura does not use your photo to identify you.

2. How your data is used

Your photo is used for one thing: generating your style analysis.

  • The photo is sent as input to the AI model.
  • The model generates the analysis.
  • Results are displayed inside the app only.
  • Results stay in the app's temporary memory for the current session.

Aura does not build user profiles, sell personal data, use your photo for advertising, or store your photo on any server.

Model training and retention

The AI providers are configured so your photo is not used to train AI models and is not retained once your analysis is generated. Requests are sent through OpenRouter with data logging disabled and processed by Google's Gemini API under terms that do not permit submitted content to be used for model training.

3. Who receives your data

RecipientWhat they receiveWhy
OpenRouter, Inc. The selected photo (Base64 JPEG) and the analysis prompt Routes the request to the AI model
Google LLC (Gemini) The photo, received via OpenRouter Performs the analysis and generates recommendations
RevenueCat, Inc. Anonymous subscription information, an anonymous app user identifier, limited device information Subscription management — receives no photo

The AI request contains only the photo, the prompt, and technical attribution headers.

Aura does not send your name, email address, contacts, precise location or phone number. OpenRouter, Google and RevenueCat act as processors for the purposes above. Their policies: OpenRouter, Google, RevenueCat.

4. Storage and retention

On your device

Aura stores your language preference, theme preference, onboarding status and AI consent preference locally. Photos are written to your photo library only when you explicitly choose to save them.

On Aura's servers

There are none. No photos, no analysis results, no user accounts.

With the AI providers

Your photo is processed solely to generate the analysis you asked for and is not retained afterwards, per the configuration described in section 2.

5. Consent

Before the first analysis, Aura explains what will be sent, who receives it and why.

  • No photo is transmitted unless you tap Agree & analyse.
  • Choose Not now, or dismiss the screen, and nothing is sent.
  • Withdraw consent any time via Settings → AI photo analysis consent.

If you withdraw consent, Aura asks again before the next analysis.

6. Camera and photo library

Access is requested only when you choose to capture or select a photo for analysis. These permissions are never used for anything else.

7. Security

  • Encrypted HTTPS/TLS connections for everything transmitted.
  • Photos downscaled and compressed before transmission.
  • Requests sent with provider data logging disabled.
  • No photo storage on any infrastructure of mine.

8. Your rights

  • Decline AI analysis at any time.
  • Withdraw consent at any time.
  • Stop using the analysis feature without affecting the rest of the app.

Because Aura stores no photos or results on its own servers, and the AI providers don't retain your photo after processing, there is no stored photo data to export or delete. For anything retained by a third party under its own policy, contact that provider using the links in section 3.

Depending on where you live you may have rights under laws such as the GDPR or CCPA to access, correct or delete personal information. To exercise them, email mskerba13@gmail.com.

Children's privacy

This app is not directed to children under 13, or the higher minimum age that applies where you live if your jurisdiction sets one. I do not knowingly collect personal information from children. If you believe a child has provided personal information, email mskerba13@gmail.com and it will be deleted.

Changes to this policy

This policy may be updated when data practices or legal obligations change. The "last updated" date at the top of the page always reflects the most recent revision.

Contact

Questions about this policy, or a request about your data, go to mskerba13@gmail.com.

Developer: mskerba. This document describes how the app handles data and is not legal advice.