Skip to content
auriabyuxflows

Privacy notice

Last updated: 26 August 2026

This notice explains which personal data is processed when you visit this website or use the auria app, why that happens, and what rights you have.

The principle behind it is simple: auria earns money from the product, not from your data. There is no advertising, no cross-site tracking, no sharing with data brokers, and no selling of profiles. What we process, we need in order to run the service.

Controller

The controller within the meaning of Article 4(7) GDPR is:

uxflows UG (haftungsbeschränkt)
Auenstr. 134
80469 München
Germany

Email: hello@auria-app.de

Telephone: +49 151 29120669

Further details are given in our legal notice.

Data protection officer

We have not currently appointed a data protection officer. On our current assessment, the statutory appointment requirements do not apply; in particular, fewer than 20 people are permanently engaged in automated processing of personal data. We reassess this and the need for a data protection impact assessment when the product changes materially. For any data protection question, write to hello@auria-app.de.

When you visit this website

Server log files

When you open this website, your browser transmits technically necessary data that our host records in log files. A page cannot be delivered without them. Recorded are the IP address, date and time, the URL requested, the status code, the amount of data transferred, browser and operating-system identifiers, and, where applicable, the page previously visited.

The purpose is delivering the page, detecting faults, and defending against attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in secure and functioning operation. This data is not combined with other sources and is not analysed on an individual basis. We create no separate copy or log drain. The logs remain available only for the standard runtime-log period of the active production hosting plan and are then removed automatically.

Cookies and browser storage

This website sets no cookies for advertising or analytics purposes. There is no analytics tool, no tracking pixel, no social media button, and no embedded third-party content.

Only strictly necessary cookies are set:

  • cc_cookie stores your choice in the consent dialog so that we do not have to ask again on every visit. Lifetime six months.
  • Operations portal session cookies are only for signed-in staff in the internal area. As an ordinary visitor to the website you never receive these cookies.

No consent is required for strictly necessary cookies (Section 25(2)(2) TDDDG). Should services requiring consent be added later, they will only run after your express agreement; the legal basis would then be Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. You can change your choice at any time: .

Fonts

Plus Jakarta Sans is downloaded when the website is built and served from our own server. Visiting the website therefore creates no connection to Google, and your IP address is not transmitted to Google.

Waitlist

If you join the waitlist, we process your email address in order to notify you as soon as a place in the test phase opens up. We do nothing else with it: no newsletter, no advertising, no sharing.

Sign-up uses a double opt-in procedure. After you submit the form you receive a confirmation email; your address is only added to the list once you click the link inside it. If you do not respond, nothing happens. Our processor Brevo handles sending and managing the list. The legal basis is your consent under Article 6(1)(a) GDPR.

You may withdraw your consent at any time without giving reasons through the unsubscribe link in any email, or informally to hello@auria-app.de. The address is then deleted. We delete all entries at the latest when the waitlist ends.

Two safeguards keep the form from being abused by machines. The first is a field invisible to you and a check of how long the form was open. Neither uses a cookie or tracking, and nothing is stored. The second is a limit on attempts: for this we derive a one-way checksum from your email address and your IP address (HMAC-SHA256 with a server-side key) and count only those. The addresses themselves are not stored. The counters are deleted automatically after two days. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in preventing abuse.

When you use the auria app

Account and sign-in

For an account we process your first name or display name, your email address, and a password hash. The password itself is never stored in plain text. In addition, we record registration and most recent sign-in, your acceptance of the terms and test-phase conditions with version and timestamp, and your confirmation that the account holder is at least 18.

The legal basis is Article 6(1)(b) GDPR because the service cannot be provided without an account. We keep records of contract acceptance and the 18+ confirmation under Article 6(1)(b) and (f) GDPR; our legitimate interest is in being able to demonstrate the agreed and permitted account access.

Household, people, and content

In auria you create a household and, within it, people, appointments, tasks, routines, shopping lists, and meal plans. Profile pictures and notes are optional additions. You enter this content yourself; it is processed solely in order to display it to you and to the other members of your household.

Every household is separated at the technical level: the database enforces through row-level security that an account can only see data from households it belongs to. This is not a setting in the interface but a rule inside the database itself. For data concerning account holders and signed-in users, the legal basis is Article 6(1)(b) GDPR. Where an entry concerns another household member without an account, the necessary processing is based on Article 6(1)(f) GDPR. Our legitimate interest and that of the household using the service lies in the expressly requested shared organisation. We give particular weight to children’s interests and therefore limit the feature to concise organisational information.

If you enter information about other people, such as a collection time for your child or a family member’s name, you decide what information to provide. Please respect the rights and interests of the people concerned and enter only what is necessary to organise your household. Our own data-protection obligations remain unaffected. Titles are free text and can reveal sensitive information despite the limited feature set. auria neither asks for special-category data under Article 9 GDPR nor infers health or other sensitive profiles. It is not intended for diagnoses, medication plans, religious or political information, or similarly sensitive details. Please keep organisational entries concise and do not use free-text fields for such information.

Brain Dump and AI

When you submit a Brain Dump, the text you typed or dictated is sent to our server function and from there to Google’s Gemini interface. What comes back is a structured suggestion that you can accept, adjust, or reject.

The text, current date, and time zone are transmitted so that “Thursday” can be placed correctly. If you mention a family member, only that person’s first name, a short-lived reference, and the self marker for the speaker are added so auria can suggest an assignee. Your email address, account identifier, and existing appointments and tasks are not transmitted. The model has no free access to your database and cannot create, change, or assign anything itself. An entry is created only after your express confirmation.

For data concerning the account holder, the legal basis is Article 6(1)(b) GDPR because the Brain Dump is a core function of the service. Where the text concerns other household members, the legitimate interest under Article 6(1)(f) GDPR described above also applies. Our AI transparency page explains this in more detail.

Voice input

You can dictate a Brain Dump instead of typing it. The conversion from speech to text is handled by your operating system’s speech recognition: Apple’s on iPhone and iPad, Google’s on Android devices.

Depending on the device, language, and settings, that recognition happens on the device or on the respective provider’s servers. We cannot influence this and therefore do not promise you that the recording stays on your device. What happens to the voice data there is governed by Apple’s and Google’s own privacy notices. Only the finished text reaches us, never an audio recording, and we store no voice recordings. You grant microphone access in the operating system and can withdraw it there at any time. The text field always remains available.

Calendar subscriptions

You can add calendars from school, clubs, or your local authority, either through an address in ICS format or as an uploaded file. With an address, our server fetches the calendar regularly; the provider in question then learns our server’s IP address, not yours. The retrieved appointments are stored in your household. With an uploaded file, no retrieval takes place at all.

The legal basis is Article 6(1)(b) GDPR. You decide which calendar to add; a subscription can be removed at any time, and the appointments created from it are then deleted.

Push notifications

If you allow push notifications, your operating system issues a device token that we store in order to deliver reminders to you. Delivery runs through Expo’s push service to Apple or Google. Server-sent notifications keep their content generic: names, household names, task titles and event titles are not sent to Expo, Apple or Google. A category and count may still reveal how you use the app. Depending on your device settings, a notification may appear on the lock screen.

Event reminders are instead scheduled locally on your device and may show the event title you entered. That title is not sent to Expo, Apple or Google for delivery, but it may be visible on your lock screen.

The legal basis is your consent under Article 6(1)(a) GDPR. You give it deliberately in auria by choosing ‘Sure’ or ‘Allow notifications’, then confirm the operating-system permission. We retain the time it is recorded, state and version of that choice as a consent record until account deletion. You can withdraw it at any time in your device settings. Once auria observes the changed system permission when you next open the app, the device token is disabled and no longer used for new notifications; disabled tokens are deleted within 30 days. Technical delivery receipts are retained for no more than 26 hours and content-free queue metadata for no more than 30 days.

Technical diagnostics and security logs

When you are signed in, the auria app, our server-side functions, and the internal web portal may send technical errors and security-relevant events to our product database at Supabase. These events may include a pseudonymous account ID, timestamp, event type, sanitized error message and stack trace, app, runtime and platform version, and a session ID that is valid only for the current app launch.

Errors that occur during a failed request are also recorded: the name of the database table or server function involved, the HTTP status, and the technical error code. Errors arising in our server-side functions are recorded in the same way. If an event cannot be transmitted immediately, typically because the connection has dropped, it is held on your device for a short time and sent with the next app launch.

Task, appointment, shopping, meal, or Brain Dump content, passwords, authentication tokens, request headers, IP addresses, and persistent device identifiers are not logged. Text fields are additionally sanitized for common email addresses, phone numbers, URLs, UUIDs, and token patterns before transmission.

The purpose is to detect and resolve technical errors and protect the service. Processing is based on our legitimate interest in a secure and reliable service under Article 6(1)(f) GDPR. Technical events are automatically deleted after no more than 90 days. Diagnostic errors disappear immediately when the account is deleted. Short-lived security records remain without an account ID until the end of the 90-day period so an administrative account cannot erase its own MFA or sign-in trail by being deleted. App users cannot read them; access is limited to the secured operations portal, which displays only the number of accounts affected by an error, never their identity.

When an authorised person accesses an account in the internal operations portal or performs a support or security action, we record the time, acting administrator account, action type, target account or display name at that time, and a concise reason. Task, appointment, and Brain Dump content does not belong in this audit. The basis is our legitimate interest in access control, abuse investigation, and accountability for administrative actions under Article 6(1)(f) GDPR. Read-only access records are kept for no more than twelve months and interventions for no more than 36 months. Evidence of a deletion may therefore remain without access to the deleted product content.

System emails

We only send messages that are necessary to operate your account: registration confirmation, password reset, sign-in codes, changes to your email address, household invitations, and notices about security-relevant events. The legal basis is Article 6(1)(b) GDPR. There is no newsletter and there are no marketing emails.

Children and young people

Holding an auria login account requires a minimum age of 18. This applies to the whole account and therefore also to access to the AI-assisted Brain Dump. Parental consent does not replace this requirement.

Children can be added to a household as a person without an account of their own. Those details are managed by the responsible adult in the household, who decides what is entered and can change or delete it at any time. We do not create login accounts for minors.

Who we involve

We use carefully selected service providers. Where a provider acts as our processor, we put the agreement required by Article 28 GDPR in place. The list below reflects the currently intended product operation and is updated when it changes.

For this website

Vercel Inc.

Registered office
United States
Processing location
Global edge network; dynamic functions currently in region fra1 (Frankfurt)
Purpose
Hosting and delivery of this website
Data
IP address, timestamp, requested URL, status code, amount of data transferred, browser and operating-system identifier, referrer
Legal basis
Article 6(1)(f) GDPR: legitimate interest in secure, reliable operation
Transfer outside the EU
Static content is delivered through a global network; processing outside the EU may occur in that delivery and in support and operations. Safeguards include standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.

Data processing agreement under Article 28 GDPR in place

Supabase, Inc.

Registered office
United States
Processing location
Frankfurt am Main, Germany (region eu-central-1)
Purpose
Abuse protection for the waitlist form and operation of the internal operations portal
Data
One-way checksums of email and IP addresses used as counters; for signed-in staff additionally the portal’s session and audit data
Legal basis
Article 6(1)(f) GDPR: legitimate interest in preventing abuse and in secured operational access
Transfer outside the EU
The primary project database is in Frankfurt. Support, maintenance, logging or individual platform services may involve processing outside the EU, safeguarded by standard contractual clauses.

Data processing agreement under Article 28 GDPR in place

Brevo (Sendinblue SAS)

Registered office
France
Processing location
European Union
Purpose
Sending the confirmation email and maintaining the waitlist
Data
Email address plus the time and record of confirmation
Legal basis
Article 6(1)(a) GDPR: your consent, confirmed through double opt-in

Data processing agreement under Article 28 GDPR in place

For the auria app

Supabase, Inc.

Registered office
United States
Processing location
Frankfurt am Main, Germany (region eu-central-1)
Purpose
Database, authentication, file storage, and server-side functions of the auria app
Data
Account data, household and person data, appointments, tasks, shopping and meal lists, profile pictures, technical logs
Legal basis
Article 6(1)(b) GDPR for account holders; Article 6(1)(f) GDPR for necessary organisational information about other household members
Transfer outside the EU
The primary project database and file storage are in Frankfurt. Support, maintenance, logging or individual platform services may involve processing outside the EU, safeguarded by standard contractual clauses.

Data processing agreement under Article 28 GDPR in place

Google Ireland Limited (Gemini API)

Registered office
Ireland
Processing location
Google data centres, including outside the EU
Purpose
Turning a Brain Dump into a structured suggestion
Data
Typed or dictated text, current date and time zone, plus short-lived references and first names of family members actually mentioned in the text
Legal basis
Article 6(1)(b) GDPR for account holders; Article 6(1)(f) GDPR for other household members mentioned in the text
Transfer outside the EU
Processing outside the EU is possible; safeguarded by standard contractual clauses and Google LLC’s certification under the EU-US Data Privacy Framework.

Data processing agreement under Article 28 GDPR in place

Brevo (Sendinblue SAS)

Registered office
France
Processing location
European Union
Purpose
Sending system emails: confirmation, password reset, sign-in codes, invitations, security notices
Data
Email address, first name or salutation, and the content of the message
Legal basis
Article 6(1)(b) GDPR: the service cannot be used without these emails

Data processing agreement under Article 28 GDPR in place

650 Industries, Inc. (Expo / EAS)

Registered office
United States
Processing location
United States
Purpose
Delivering app updates and forwarding push notifications to Apple and Google
Data
Device push token, generic notification text, internal deep-link path, delivery metadata, and app and platform version and IP address when an update is fetched
Legal basis
Article 6(1)(b) GDPR for updates; push notifications only after you allow them in the operating system, Article 6(1)(a) GDPR
Transfer outside the EU
A transfer to the United States is possible. The transfer mechanisms stated in the applicable Expo contract or DPA govern that transfer; their current status is reviewed and documented before release.

Data processing agreement under Article 28 GDPR in place

Apple Inc. / Apple Distribution International Ltd.

Registered office
United States and Ireland
Processing location
Apple data centres, including outside the EU
Purpose
Distribution via the App Store, push delivery (APNs), and speech recognition when you dictate a Brain Dump
Data
Device push token, the audio recorded while you dictate, and store-related identifiers
Legal basis
Article 6(1)(b) GDPR for provision of the service; dictation is started by you, Article 6(1)(a) GDPR
Transfer outside the EU
Transfer to the United States is possible; Apple is certified under the EU-US Data Privacy Framework.

No data processing agreement. The provider acts as an independent controller for this processing

Google Ireland Limited (Play Store, Firebase Cloud Messaging, Spracherkennung)

Registered office
Ireland
Processing location
Google data centres, including outside the EU
Purpose
Distribution via Google Play, push delivery, and speech recognition on Android devices
Data
Device push token, the audio recorded while you dictate, and store-related identifiers
Legal basis
Article 6(1)(b) GDPR for provision of the service; dictation is started by you, Article 6(1)(a) GDPR
Transfer outside the EU
Transfer outside the EU is possible; safeguarded by standard contractual clauses and Google LLC’s certification under the EU-US Data Privacy Framework.

No data processing agreement. The provider acts as an independent controller for this processing

Beyond this, we disclose data only where we are legally obliged to do so, for example to law enforcement authorities on the basis of a valid order. Data is never sold, and nothing is passed on for advertising purposes.

How long we store data

  • Account data and content: for as long as your account exists. They are removed promptly from active systems after the account is deleted. Existing database backups may retain them until the end of the applicable backup period. Backups are used only to recover from technical failures and are automatically overwritten within the recovery period configured in the production account, which is no more than 30 days.
  • Website server log files: for the standard period of the active Vercel production plan; auria creates no separate extension or copy.
  • Technical events from the app, Edge Functions, and web server: no more than 90 days, then automatically deleted; account deletion works as described above.
  • Admin audit: read-only access for no more than twelve months; support and security interventions for no more than 36 months.
  • Contract and age records: for as long as the account exists; they are deleted along with it.
  • Brain Dump at auria: a local draft and incomplete server raw text for no more than 24 hours; raw text is cleared immediately after successful sorting. Open suggestions are deleted after 24 hours, fully decided suggestions after seven days, and content-free model-operation logs after no more than 90 days.
  • Brain Dump data at Google: under Google’s terms, the paid-service data-handling rules apply to access from the EEA, Switzerland, and the United Kingdom even when unpaid quota is used. Under those rules, inputs and outputs are not used to improve general models. Google may currently log them for up to 55 days for abuse and security monitoring, so we do not promise processing restricted to the request duration alone.
  • Invoices and accounting records: once paid plans exist, the statutory retention periods of up to ten years under Section 147 AO and Section 257 HGB apply.

Deleting your account and data

You can delete your account directly in the app, under “Delete account” in the settings, secured by entering the account email, creating a fresh password session, and confirming the final deletion a second time. This deletes your account, your profile data, your contract and age records, and content that you created yourself and that does not belong to a shared household which continues to exist. If you no longer have app access, follow our account deletion page or email hello@auria-app.de from the registered address.

Content belonging to a shared household remains available to the other members because it is their data too. If you are the last person in a household, the household and its content are deleted with you.

Your rights

Under the GDPR you have the following rights:

  • Access to information about whether and which data concerning you we process (Article 15 GDPR)
  • Rectification of inaccurate or incomplete data (Article 16 GDPR)
  • Erasure of your data, unless a statutory retention obligation stands in the way (Article 17 GDPR)
  • Restriction of processing (Article 18 GDPR)
  • Data portability in a structured, commonly used, machine-readable format (Article 20 GDPR)
  • Objection to processing based on a legitimate interest (Article 21 GDPR)
  • Withdrawal of consent with effect for the future (Article 7(3) GDPR)
  • Lodging a complaint with a supervisory authority (Article 77 GDPR)

An informal message to hello@auria-app.de is enough for any of these. After secure identity verification, access and portability requests receive a structured, machine-readable JSON export, including diagnostics and audit data that still relate to the account. We respond within one month. If it ever takes longer, we will tell you beforehand and explain why.

Right to object under Article 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you where that processing is based on Article 6(1)(f) GDPR. In our case this concerns the server log files and the technical diagnostics. If you object, we will no longer process your data in that respect unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing serves to establish, exercise, or defend legal claims.

Complaint to a supervisory authority

You may lodge a complaint with a data protection supervisory authority at any time, in particular in the Member State of your residence, your place of work, or the place of the alleged infringement. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Postfach 1349
91504 Ansbach

www.lda.bayern.de

Data security

Transmission between your device and our services is protected by TLS transport encryption. This is not end-to-end encryption, because our servers process data to provide the service. The primary product database and file storage are in Frankfurt am Main; the platform and international processing described above remains unaffected. Access to the production database is limited to a small number of people, requires two-factor authentication, and is logged. Passwords are stored only as hashes.

No automated decision-making

There is no automated decision-making, including profiling, within the meaning of Article 22 GDPR. The AI in auria produces suggestions that you can accept, change, or discard. It may suggest an assignee, but it decides nothing and assigns nobody by itself.

Changes to this notice

We update this notice whenever the processing changes, for instance when a new service provider is added or a feature is extended. The version published here is the one that applies; the date is shown at the top. For substantial changes we additionally inform signed-in users in the app or by email.