Privacy Policy for Aura

Aura App Privacy Policy

Last updated: August 11, 2026

Your privacy and the security of your health data are our absolute priority. This Privacy Policy explains how the Aura app ("Application") collects, processes, and protects your data. It is written in a clear and simple manner so you know exactly what happens to your information.

1. Data Controller

The Data Controller of your personal data is Jakub Kazimierczak. Any questions, requests, or concerns regarding privacy can be directed to the following email address: gnash.contact@gmail.com.

2. What data do we collect and why?

The Aura app is a specialized headache diary. We only collect data that is absolutely necessary for its functioning.

Account Data

To enable you to log in, save, and synchronize data, we collect your email address, optional display name, and password during registration. The password is never stored in plaintext – we use advanced cryptographic standards (hashing), making it completely invisible to anyone.

Medical Data (Article 9 GDPR)

We collect information about your health, such as:

Legal basis: We process this data EXCLUSIVELY based on your explicit, voluntary consent, granted during the first launch of the application or account creation (in accordance with Article 9(2)(a) GDPR).

Consent is Key

The fact that you grant consent for processing your health data is recorded in our system in the form of an anonymized audit log. This is necessary for us to demonstrate compliance with legal regulations.

3. Security and Encryption (Aura's Key Feature)

We apply the highest standards of protection for your most sensitive data. Your personal notes and the names of medications taken are cryptographically encrypted at rest (Transparent Column Encryption). This means that no one – not even the application administrator, developers, or cloud service providers – can read them. Only you, by logging into your account, can view the content of your entries.

4. Zero-Tracking and No Data Selling

5. Who do we share data with? (Data Recipients)

For the Application to function and synchronize your entries, we use the services of strictly selected and trusted partners acting as data processors:

6. Account Deletion and Backups

You have full control over your data. You can delete your account at any time directly in the Application settings.

What happens after account deletion?

7. Your Rights

Under the GDPR, you have the right to:

To exercise these rights, use the appropriate options in the Application or write to us at gnash.contact@gmail.com. If you believe that we are processing your data unlawfully, you have the right to lodge a complaint with the President of the Personal Data Protection Office or your local supervisory authority.

8. Children's Privacy

The Aura application processes health data and is not intended for persons under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or legal guardian and you learn that your child has provided us with their data, please contact us. Such data will be immediately removed from our systems.

9. Changes to the Privacy Policy

We reserve the right to update this Privacy Policy as the Application evolves or legal regulations change. We will inform you of any significant changes by updating the "Last updated" date at the top of this document or through a message in the Application.