Information we process

We process a reduced photo copy for visual analysis, a watermarked finished preview retained temporarily for quality and abuse review, generated cards you choose to save, your Google account identifier and basic profile details when you sign in, order records, and limited product events. PayPal processes payment credentials; AuraPhotoAI does not store full card or bank details.

How images are used and retained

A reduced copy of the upload is sent to our AI provider to identify objective visual cues such as face count, visibility, composition, light, contrast, color temperature, and visible expression. We do not ask the model to infer identity, gender, age, ethnicity, health, personality, or relationship type. The source photo is not stored. For anonymous sessions, the watermarked finished preview—not the original upload—is stored privately in Cloudflare R2 for up to 72 hours so we can investigate generation quality, failures, and abuse; a scheduled deletion removes the image and its temporary D1 lookup record after expiry. If you save to the journal, that selected Aura card is stored separately in R2 with private ownership metadata until you delete it. Journal records are stored in D1 and can be exported as JSON.

Service providers and your choices

Cloudflare provides hosting and private storage, Replicate provides the AI photo-analysis service, Google provides account sign-in, and PayPal processes optional payments. Google sign-in shares your stable account identifier, name, email address, and profile photo. AuraPhotoAI does not request access to Gmail, Google Drive, contacts, or other Google content.

You may request access, correction, export, or deletion by emailing privacy@auraphotoai.com. We will verify requests before acting to protect your account.

Safety, analytics, and changes

We may retain limited security records to prevent abuse and fraud. We use aggregated product events to understand completion and failure rates. Material policy changes will be dated on this page.