Legal
Privacy Policy
Aura by First24 · iOS App Store ID 6760242207 · Android package com.first24.aura.safety
Last updated: July 5, 2026
The short version
- Routine verification photos are processed on-device; we do not keep the image bytes for adherence checks — only hashes and classification results where applicable.
- Sealed receipts and family memories you choose to save are stored encrypted; you can delete them from the app.
- We never sell your personal data. Aura does not run third-party ads inside the app.
- We never synthesize a family member's voice or face.
- Location: Aura is not a continuous GPS tracker. Location is used only when a feature you start requires it (e.g. visit records, clearance city label, optional address on a receipt) — not background family surveillance.
- Delete everything: Settings → Delete Account.
Who we are
First-24-Health LLC ("First24," "we," "us," or "our") operates Aura by First24 (iOS) and Aura Safety (Android), together with related Coramly-branded services (Closeout, Sign, Verified Visit).
Registered address: 1216 Litchfield Ln, Burleson, TX 76028-8226, United States.
- Privacy / DPO: privacy@first24.io
- General support: hello@first24.io
1. Information we collect
1a. Account
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| Email, name, locale, timezone | Sign-up (Apple / Google / magic link via Supabase Auth) | Supabase (encrypted at rest, RLS-protected) | Until account deletion |
| Device info (platform, OS version, app version, model) | Automatic | Supabase (encrypted) | Until account deletion |
1b. Family / Kin
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| Kin Circles, memberships (display name + relationship label) | You invite family members | Supabase (encrypted, RLS to active members) | Until circle or membership is revoked |
| Personal Add Link invites, Kin Verify challenges | You generate them | Supabase (encrypted) | 14 days, deleted on accept/revoke |
| FCM / APNs device tokens (push notifications) | Registered by the app | Supabase (encrypted) | Until you sign out or delete the app |
1c. Pulse / Steady
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| Ritual day-keys, local notification preferences | You configure them | Mostly on-device; minimal sync to Supabase for cross-device state | Until account deletion |
| 3-second Pulse presence results | Derived from Secure Enclave / StrongBox key operation | Supabase (encrypted) — result markers only, no biometrics | Rolling 90 days |
1d. Presence receipts (Verified Visit / Care / Meeting)
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| Meeting / visit / care visit seals: labels, optional counterparty name, timestamps | User-initiated capture | Local SQLite on device; optional share by user action | Until you delete the seal or delete your account |
| Optional location label / address on a receipt | Only when you tap to attach location to that specific receipt | Bound to the seal record (encrypted) | Same as the seal |
1e. Coramly Closeout
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| Job metadata, scope deltas, customer approval records | You create them in the app | Local first; synced to Supabase when online (encrypted, RLS) | Until you delete the job or your account |
1f. Coramly Sign
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| Signing request metadata; approver email for OTP delivery | You (or the requester) enter it | Supabase (encrypted, RLS) | Until the request is resolved + audit-log window (2 years) |
| Execution Seal receipts | Derived at approval time | Supabase (encrypted, append-only) | Until account deletion |
1g. Dating / Date Pass
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| Session ids, seal metadata (no dating profile content) | User-initiated | Supabase (encrypted) | Until session expiry or account deletion |
1h. Device attestation (anti-fraud)
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| Apple App Attest receipts (iOS) / Google Play Integrity tokens (Android) | Apple / Google services attest device integrity | Verification result + public key + sign counter in Supabase | Until account deletion |
1i. Aura Watch — HRV alert markers
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| HRV time series | Apple Watch via HealthKit | On-device only (watch + phone). Never transmitted. | Managed by HealthKit |
| Alert markers (event + timestamp + user id) | Triggered on-device when the HRV pattern crosses threshold | Supabase (encrypted) — only the event marker, not raw HRV | 30 days |
1j. Analytics & crash reports
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| PostHog aggregate events (opt-out in Settings → Privacy) | Automatic while opted-in | PostHog | Rolling 12 months |
| Sentry crash reports (PII-scrubbed; user UUID + route breadcrumb) | Automatic on crash | Sentry | 90 days |
1k. Billing
| Data type | How collected | Stored where | Retention |
|---|---|---|---|
| Subscription tier, entitlements, App Store / Play purchase ids | RevenueCat webhook after Apple / Google purchase | Supabase (encrypted) | Until account deletion |
| Payment instrument data | NEVER collected by us | Apple / Google handle payments | n/a |
2. How we use information
- Provide the Aura and Coramly services you signed up for.
- Deliver kin notifications and Pulse results.
- Prevent fraud (device attestation, replay-prevention counters).
- Process subscriptions through Apple / Google via RevenueCat.
- Improve stability (Sentry crashes, PostHog aggregate events).
- Not for third-party advertising profiles. Aura does not run ads inside the app.
3. What we never do
- We never sell your personal data.
- We never store routine verification photo bytes for adherence checks.
- We never synthesize a family member's voice or face.
- We never use sealed memories or receipts for ad targeting.
- We never expose raw HRV time series to our servers.
4. Data security
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). High-trust actions (Pulse, Execution Seals, Kin Verify) are signed by the device's Secure Enclave (iOS) or StrongBox (Android). Postgres row-level security (RLS) on Supabase ensures each user can only read records they're authorized to. Webhook integrations require constant-time shared-secret comparisons. Deletion is user-controlled from Settings → Delete Account and is processed within 30 days.
5. Your rights
- Access — Settings → Export Data (JSON of your records).
- Delete — Settings → Delete Account (processed within 30 days).
- Revoke kin links from your Kin Circle screen.
- Opt out of analytics — Settings → Privacy.
- Revoke camera, microphone, Bluetooth, location, or HealthKit permissions at any time in your iOS or Android device Settings.
6. California residents (CCPA)
California residents have the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact privacy@first24.io.
7. European residents (GDPR)
If you are in the European Economic Area, our legal basis for processing is: consent (camera, microphone, Bluetooth, HealthKit, location), contract performance (providing the service and processing payments), and legitimate interest (security, fraud prevention via device attestation, crash reporting). You have the right to access, rectify, erase, restrict processing, and port your data. Contact our Data Protection Officer at privacy@first24.io.
8. Children's privacy
Aura is not directed to children under 13. Family members under 13 may be added to a Kin Circle only by a parent or guardian, whose account controls the child's data. We do not knowingly collect personal information directly from children under 13.
9. Third-party services
| Service | Purpose | Data sent |
|---|---|---|
| Supabase | Database, authentication, storage | All persisted Aura data |
| Apple (App Store, App Attest, Sign in with Apple, HealthKit) | Auth, payments, device attestation, HRV input | Auth tokens, App Attest receipts, purchase events |
| Google (Play Store, Play Integrity, Sign-In) | Auth, payments, device attestation | Auth tokens, Play Integrity tokens, purchase events |
| RevenueCat | Subscription state bridge between App Store / Play and our backend | Purchase events, subscription state, your app user id |
| Firebase Cloud Messaging (FCM) / Apple Push Notification service | Push delivery for kin notifications | Device push tokens, notification payloads |
| Sentry | Crash reporting | PII-scrubbed error stacks + user UUID |
| PostHog | Aggregate product analytics (opt-out in Settings) | Anonymized event counts; no message content |
| Meta SDK | Planned for advertising attribution only; no ad personalization inside Aura | Install / app-event signals if enabled |
10. Changes to this policy
Material changes are communicated through an in-app notice and by updating the "Last updated" date at the top of this page. Continued use of Aura after material changes constitutes acceptance.
11. Contact
First-24-Health LLC
1216 Litchfield Ln, Burleson, TX 76028-8226, United States
Privacy / DPO: privacy@first24.io
General support: hello@first24.io
Aura is a wellness, family-connection, and verification tool. It does not diagnose, treat, cure, or prevent any disease. Sealed records are cryptographic attestations of device-signed events — not legal advice about admissibility in any proceeding.