Privacy Policy
Last updated: August 23, 2026
Aura Hub ("we", "our", or "us") operates the Aura Diary mobile application (the "App"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
A journal is about as personal as data gets. We have tried to write this in plain language rather than hide the important parts. The three things most people want to know are: your entries are encrypted before they reach us, voice transcription happens on your phone and not on our servers, and § 4 states the one exception, where AI features decrypt an entry you chose to run them on.
1. Who We Are
Aura Hub is an independent software company based in Lagos, Nigeria, and is the data controller for your personal data. We are subject to the Nigeria Data Protection Act 2023, and we are regulated by the Nigeria Data Protection Commission.
Aura Diary is not currently offered in the European Economic Area, the United Kingdom, or Switzerland. We have chosen not to sell there yet. Even so, the rights in § 9 are given to everyone who uses Aura Diary, wherever they live — we would rather hold one standard than the minimum each country requires.
- Email: support@auradiary.app
- Website: https://aurahub.com.ng
2. Age
Aura Diary is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18.
The Nigeria Data Protection Act treats anyone under 18 as a child, and processing a child's data requires a parent's or guardian's consent. We have chosen to make Aura Diary an adults' service rather than build around that — it is a paid product with an in-app currency and advertising, and that is not something we want to sell to children.
If you believe someone under 18 has an account, contact us at support@auradiary.app and we will delete it.
3. What Data We Collect
Data you provide directly
| Data | Why we collect it |
|---|---|
| Email address | Account creation and login via Supabase Auth |
| Display name | Shown on your profile and, if you use the social features, to friends and on leaderboards |
| Journal entries (text) | Core app functionality — storing your diary |
| Voice recordings (audio) | Voice-to-text transcription and audio playback |
| Mood ratings | Mood tracking and analytics |
| Tags and labels | Entry organisation |
| Photos attached to entries | Shown in your entries and the photo timeline |
| Notification preferences | Sending you reminders you configure |
Data collected automatically
| Data | Why we collect it |
|---|---|
| App crash reports | Diagnosing and fixing bugs (via Sentry) |
| Feature usage events | Understanding how the app is used (via PostHog) |
| Purchase and subscription records | Verifying entitlements (via RevenueCat and the app stores) |
| Ad impressions and interactions | Serving ads to free-tier users (via AdMob) |
| Device identifiers | Required by AdMob for ad delivery |
| IP address | Included by default in server requests |
Sensitive data
Mood ratings and journal entries can reveal information about your health or state of mind. That makes them sensitive personal data under the Nigeria Data Protection Act, and the equivalent of "special category data" in other regimes. We process it only on the basis of your explicit consent, given when you create an account and use the App for its stated purpose, and you can withdraw that consent at any time by deleting your account (§ 10). We do not use it for anything other than providing the App to you, and we never sell it or use it to train AI models.
4. How We Use Your Data, and Our Legal Basis
| What we do | Why | Our lawful basis |
|---|---|---|
| Store and sync your journal, moods, tags, audio and photos | To provide the App you signed up for | Contract — and explicit consent for the health-adjacent content itself |
| Create and secure your account | To let you sign in and protect the account | Contract |
| Process payments and verify Pro entitlement | To sell and honour subscriptions and Embers | Contract |
| Send reminders you configured | Because you asked for them | Consent — withdraw them in the App at any time |
| Crash reporting | To find and fix faults | Legitimate interests — keeping the App working. You can turn this off in the App |
| Product analytics | To understand which features are used | Consent where required. You can turn this off in the App |
| Serve personalised ads to free users | To fund the free tier | Consent, collected through Google's consent form before any ad loads |
| AI polish, summaries and digests | Because you tapped the button | Contract, and your explicit request for that entry |
| Enforce our Terms, prevent abuse and fraud | To keep the service safe | Legitimate interests |
Advertising and consent. The App asks for your consent before the ads SDK starts, using Google's consent form, and where that form applies you can reopen it at any time from Profile → About → Privacy options to change or withdraw your choices. We keep this in place for European regions even though we do not sell there, so that anyone who reaches the App from one is handled correctly. Pro users see no ads at all.
No automated decision-making. We do not make any decision about you that produces legal or similarly significant effects by automated means, and we do not profile you for that purpose.
5. Where Your Data Is Stored, and How It Is Protected
| Data type | Where stored | Encryption |
|---|---|---|
| Journal entries (text) | Supabase (PostgreSQL, EU region) | Encrypted at rest — your entries are encrypted with a per-user key before being stored. Our engineers cannot casually read them |
| Voice recordings and photos | Supabase Storage (EU region) | Encrypted at rest and in transit (TLS) |
| Authentication data | Supabase Auth | Managed by Supabase |
| Local device data | On-device only (Room on Android; WatermelonDB on iOS and web) | Device-level encryption |
Free-tier users' entries are stored locally only and are never uploaded. Free accounts have no cloud footprint for journal data at all.
We describe this as "encrypted at rest", not as end-to-end encryption. The distinction matters and we will not blur it: we hold the infrastructure your encrypted data sits on, and the AI exception below means we can, in one specific circumstance, see the text of an entry.
The one exception, stated plainly. The AI features — polish, enhance and summarise — cannot operate on encrypted text. When you tap one of them, the text of that entry is decrypted on your device and sent over TLS to our API and on to Together AI for the duration of that request, then discarded. This happens only for entries you explicitly run an AI action on; an entry you never use AI on is never decrypted off your device. AI features are Pro-only, so no free-tier entry is ever transmitted for any reason.
Voice transcription is the opposite case. Speech-to-text runs entirely on your phone, so your recording is never uploaded in order to be transcribed. Voice notes leave the device only if you are a Pro user with cloud sync enabled, and then only as encrypted audio.
6. Data Retention
- Active accounts: your data is kept for as long as your account exists
- Deleted accounts (in-app): your cloud data is deleted immediately when you delete your account from within the App. This is not a scheduled job — the records are removed as part of the deletion request
- Deleted accounts (by email request): we complete deletion within 30 days and confirm by email
- Crash logs: retained for up to 90 days on Sentry
- Analytics events: retained for up to 12 months on PostHog. On account deletion, events already collected are disassociated from your account within 90 days rather than deleted individually — after that they are not linkable to you
- Payment records: transaction records held by Apple, Google or Paystack follow their own retention policies and are outside our control. We may also need to keep basic transaction records to meet tax and accounting obligations
7. International Transfers
Your data crosses borders, and we would rather say exactly how than leave it vague:
- Journal entries, audio and photos are stored by Supabase in its EU region. We chose EU hosting because it is the strongest default available to us, not because we operate there
- We access it from Nigeria, where we are based
- Some processors are in the United States — Together AI, Sentry, PostHog and RevenueCat
Under the Nigeria Data Protection Act, personal data may be transferred abroad where the recipient is subject to a law or contract affording an adequate level of protection. We rely on the data-processing terms we have in place with each provider, which bind them to process data only on our instructions and to keep it secure. You can ask us which terms apply to a given provider by emailing support@auradiary.app.
Your journal content is encrypted before it leaves your device, so what sits with our storage provider is ciphertext, not readable text. The single exception is the AI path described in § 5.
8. Third Parties We Share Data With
We share data with the following third parties only to the extent necessary to operate the service. All of them act as our processors — handling data only on our instructions — except Google AdMob, which acts as an independent controller for advertising data. That means Google decides for itself how it uses ad-serving data, under its own privacy policy, and you have rights directly against Google for it as well as against us.
| Processor | Purpose | Data shared | Privacy policy |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All cloud data | https://supabase.com/privacy |
| Together AI | AI text polish and summarisation (Pro) | Journal text during API call only | https://www.together.ai/privacy |
| RevenueCat | iOS and Android subscription management | User ID, purchase receipts | https://www.revenuecat.com/privacy |
| Paystack | Web payment processing (NGN) | Email, payment details | https://paystack.com/privacy-policy |
| Google AdMob (independent controller, not a processor) | Ads for free-tier users | Device identifiers, usage data | https://policies.google.com/privacy |
| Sentry | Crash reporting and error tracking | Crash logs, device info, user ID | https://sentry.io/privacy |
| PostHog | Product analytics | Usage events, user ID | https://posthog.com/privacy |
We do not sell your personal data to any third party, and we do not share your journal content with anyone except as described in § 5.
9. Your Rights
These are given to everyone, wherever you live — not only where a law compels them:
- Access — request a copy of the data we hold about you
- Correction — request that inaccurate data be corrected
- Deletion — request that your account and all associated data be deleted (see § 10)
- Portability — export your whole journal from the app at any time as Markdown, JSON, or a full
.ziparchive that includes your voice recordings. This is free and needs no subscription — getting your data out is not a paid feature. You can import the same archive back. (A separately designed PDF book is also available to Pro subscribers) - Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved
- Objection — object to processing based on legitimate interests, including analytics and advertising
- Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect processing already carried out. Analytics and crash reports can be turned off under Profile → Privacy & security → Share usage data; ad consent under Profile → About → Privacy options
- Complain to a regulator — our supervisory authority is the Nigeria Data Protection Commission, and you can complain to them about how we handle your data. If your own country has a data protection authority, you may be able to complain to them too. We would rather you came to us first, but you do not have to
To exercise any of these rights, email support@auradiary.app or use the in-app account deletion feature. We respond within one month, and will tell you if we need longer because a request is complex.
10. Account and Data Deletion
You can delete your account and all associated data at any time:
In the app: Profile → Privacy & security → Delete account → confirm by typing "DELETE"
This permanently deletes:
- Your Supabase Auth account
- All journal entries, mood data, tags, photos and audio files stored in the cloud
- Your subscription record
- All AI usage logs
- Your friends list, friend code and challenge history
- Your Embers balance and everything bought with it — this is not refunded, and the App warns you before you confirm
Deletion is immediate and irreversible. Local data on the device you delete from is also wiped. Deleting your account does not cancel your store subscription — cancel that separately in your App Store or Google Play settings. See our Data Deletion page for full details.
11. Security
- Journal content is encrypted with a per-user key before it is uploaded
- Traffic is encrypted in transit with TLS
- Access to production systems is limited to those who need it
- We will notify you and the relevant regulator of a personal data breach where the law requires it, without undue delay
No system is perfectly secure, and we do not claim otherwise.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via in-app notification or email. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact Us
If you have questions about this Privacy Policy or how we handle your data:
Aura Hub Lagos, Nigeria support@auradiary.app https://aurahub.com.ng