Legal

Privacy Policy

Aura by First24 · iOS App Store ID 6760242207 · Android package com.first24.aura.safety

Last updated: July 5, 2026

The short version

  • Routine verification photos are processed on-device; we do not keep the image bytes for adherence checks — only hashes and classification results where applicable.
  • Sealed receipts and family memories you choose to save are stored encrypted; you can delete them from the app.
  • We never sell your personal data. Aura does not run third-party ads inside the app.
  • We never synthesize a family member's voice or face.
  • Location: Aura is not a continuous GPS tracker. Location is used only when a feature you start requires it (e.g. visit records, clearance city label, optional address on a receipt) — not background family surveillance.
  • Delete everything: Settings → Delete Account.

Who we are

First-24-Health LLC ("First24," "we," "us," or "our") operates Aura by First24 (iOS) and Aura Safety (Android), together with related Coramly-branded services (Closeout, Sign, Verified Visit).

Registered address: 1216 Litchfield Ln, Burleson, TX 76028-8226, United States.

1. Information we collect

1a. Account

Data typeHow collectedStored whereRetention
Email, name, locale, timezoneSign-up (Apple / Google / magic link via Supabase Auth)Supabase (encrypted at rest, RLS-protected)Until account deletion
Device info (platform, OS version, app version, model)AutomaticSupabase (encrypted)Until account deletion

1b. Family / Kin

Data typeHow collectedStored whereRetention
Kin Circles, memberships (display name + relationship label)You invite family membersSupabase (encrypted, RLS to active members)Until circle or membership is revoked
Personal Add Link invites, Kin Verify challengesYou generate themSupabase (encrypted)14 days, deleted on accept/revoke
FCM / APNs device tokens (push notifications)Registered by the appSupabase (encrypted)Until you sign out or delete the app

1c. Pulse / Steady

Data typeHow collectedStored whereRetention
Ritual day-keys, local notification preferencesYou configure themMostly on-device; minimal sync to Supabase for cross-device stateUntil account deletion
3-second Pulse presence resultsDerived from Secure Enclave / StrongBox key operationSupabase (encrypted) — result markers only, no biometricsRolling 90 days

1d. Presence receipts (Verified Visit / Care / Meeting)

Data typeHow collectedStored whereRetention
Meeting / visit / care visit seals: labels, optional counterparty name, timestampsUser-initiated captureLocal SQLite on device; optional share by user actionUntil you delete the seal or delete your account
Optional location label / address on a receiptOnly when you tap to attach location to that specific receiptBound to the seal record (encrypted)Same as the seal

1e. Coramly Closeout

Data typeHow collectedStored whereRetention
Job metadata, scope deltas, customer approval recordsYou create them in the appLocal first; synced to Supabase when online (encrypted, RLS)Until you delete the job or your account

1f. Coramly Sign

Data typeHow collectedStored whereRetention
Signing request metadata; approver email for OTP deliveryYou (or the requester) enter itSupabase (encrypted, RLS)Until the request is resolved + audit-log window (2 years)
Execution Seal receiptsDerived at approval timeSupabase (encrypted, append-only)Until account deletion

1g. Dating / Date Pass

Data typeHow collectedStored whereRetention
Session ids, seal metadata (no dating profile content)User-initiatedSupabase (encrypted)Until session expiry or account deletion

1h. Device attestation (anti-fraud)

Data typeHow collectedStored whereRetention
Apple App Attest receipts (iOS) / Google Play Integrity tokens (Android)Apple / Google services attest device integrityVerification result + public key + sign counter in SupabaseUntil account deletion

1i. Aura Watch — HRV alert markers

Data typeHow collectedStored whereRetention
HRV time seriesApple Watch via HealthKitOn-device only (watch + phone). Never transmitted.Managed by HealthKit
Alert markers (event + timestamp + user id)Triggered on-device when the HRV pattern crosses thresholdSupabase (encrypted) — only the event marker, not raw HRV30 days

1j. Analytics & crash reports

Data typeHow collectedStored whereRetention
PostHog aggregate events (opt-out in Settings → Privacy)Automatic while opted-inPostHogRolling 12 months
Sentry crash reports (PII-scrubbed; user UUID + route breadcrumb)Automatic on crashSentry90 days

1k. Billing

Data typeHow collectedStored whereRetention
Subscription tier, entitlements, App Store / Play purchase idsRevenueCat webhook after Apple / Google purchaseSupabase (encrypted)Until account deletion
Payment instrument dataNEVER collected by usApple / Google handle paymentsn/a

2. How we use information

  • Provide the Aura and Coramly services you signed up for.
  • Deliver kin notifications and Pulse results.
  • Prevent fraud (device attestation, replay-prevention counters).
  • Process subscriptions through Apple / Google via RevenueCat.
  • Improve stability (Sentry crashes, PostHog aggregate events).
  • Not for third-party advertising profiles. Aura does not run ads inside the app.

3. What we never do

  • We never sell your personal data.
  • We never store routine verification photo bytes for adherence checks.
  • We never synthesize a family member's voice or face.
  • We never use sealed memories or receipts for ad targeting.
  • We never expose raw HRV time series to our servers.

4. Data security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). High-trust actions (Pulse, Execution Seals, Kin Verify) are signed by the device's Secure Enclave (iOS) or StrongBox (Android). Postgres row-level security (RLS) on Supabase ensures each user can only read records they're authorized to. Webhook integrations require constant-time shared-secret comparisons. Deletion is user-controlled from Settings → Delete Account and is processed within 30 days.

5. Your rights

  • Access — Settings → Export Data (JSON of your records).
  • Delete — Settings → Delete Account (processed within 30 days).
  • Revoke kin links from your Kin Circle screen.
  • Opt out of analytics — Settings → Privacy.
  • Revoke camera, microphone, Bluetooth, location, or HealthKit permissions at any time in your iOS or Android device Settings.

6. California residents (CCPA)

California residents have the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact privacy@first24.io.

7. European residents (GDPR)

If you are in the European Economic Area, our legal basis for processing is: consent (camera, microphone, Bluetooth, HealthKit, location), contract performance (providing the service and processing payments), and legitimate interest (security, fraud prevention via device attestation, crash reporting). You have the right to access, rectify, erase, restrict processing, and port your data. Contact our Data Protection Officer at privacy@first24.io.

8. Children's privacy

Aura is not directed to children under 13. Family members under 13 may be added to a Kin Circle only by a parent or guardian, whose account controls the child's data. We do not knowingly collect personal information directly from children under 13.

9. Third-party services

ServicePurposeData sent
SupabaseDatabase, authentication, storageAll persisted Aura data
Apple (App Store, App Attest, Sign in with Apple, HealthKit)Auth, payments, device attestation, HRV inputAuth tokens, App Attest receipts, purchase events
Google (Play Store, Play Integrity, Sign-In)Auth, payments, device attestationAuth tokens, Play Integrity tokens, purchase events
RevenueCatSubscription state bridge between App Store / Play and our backendPurchase events, subscription state, your app user id
Firebase Cloud Messaging (FCM) / Apple Push Notification servicePush delivery for kin notificationsDevice push tokens, notification payloads
SentryCrash reportingPII-scrubbed error stacks + user UUID
PostHogAggregate product analytics (opt-out in Settings)Anonymized event counts; no message content
Meta SDKPlanned for advertising attribution only; no ad personalization inside AuraInstall / app-event signals if enabled

10. Changes to this policy

Material changes are communicated through an in-app notice and by updating the "Last updated" date at the top of this page. Continued use of Aura after material changes constitutes acceptance.

11. Contact

First-24-Health LLC
1216 Litchfield Ln, Burleson, TX 76028-8226, United States
Privacy / DPO: privacy@first24.io
General support: hello@first24.io

Aura is a wellness, family-connection, and verification tool. It does not diagnose, treat, cure, or prevent any disease. Sealed records are cryptographic attestations of device-signed events — not legal advice about admissibility in any proceeding.