Information we process
We process generated cards, mood and ritual selections, optional notes, Private Sync identifiers, order records, and limited product events. PayPal processes payment credentials; AuraPhotoAI does not store full card or bank details.
How images are used and retained
Original portraits are rendered locally in the browser. If journal saving is enabled, the finished Aura card—not the original source file—is stored in Cloudflare R2 with private ownership metadata until you delete it. Journal records are stored in D1 and can be exported as JSON.
Service providers and your choices
Cloudflare provides hosting and private storage, and PayPal processes optional payments. Private Sync uses a one-time recovery key rather than an email, password, or external identity provider.
You may request access, correction, export, or deletion by emailing privacy@auraphotoai.com. We will verify requests before acting to protect your account.
Safety, analytics, and changes
We may retain limited security records to prevent abuse and fraud. We use aggregated product events to understand completion and failure rates. Material policy changes will be dated on this page.