Legal
Privacy Policy
Last updated June 11, 2026
The short version: Aurelia is private by design. Your moods, journal entries, habits, and gratitude logs sync securely to your own private account, encrypted in transit and isolated by database row-level security so that only you can read them. The Developer does not sell your data, does not show ads, and does not use third-party tracking. You can export or permanently delete everything at any time.
1. Who is responsible for your data
Aurelia is operated by an independent individual creator (the “Developer”), who is the party responsible for the data described here. You can reach the Developer at medisummarize@gmail.com.
2. What the Developer collects
Account data — your email address and a password. Passwords are never stored in plain text; they are securely hashed by the authentication provider (Supabase Auth). Your name and username are optional.
Wellness data you create — mood check-ins, journal entries, habits, gratitude notes, companion conversations, and preferences — is stored in your private account in the database so it can sync across your devices. Every row is tied to your user ID and protected by row-level security, so no other user can access it.
Social data— if you use friends, the Developer stores your friend connections, the messages (“kind notes”) you send or receive, and any blocks or reports you create, so those features can work.
Stored only on your device— some sensitive items never leave your device: your app-lock passcode (stored as a salted hash) and your personal safety plan are kept in your browser’s local storage and are not sent to the Developer’s servers.
3. AI features & message moderation
When you use an optional AI feature (such as the AI companion, reflections, thought reframing, or weekly summaries), only the specific text you submit for that request is sent to the AI provider (Groq) to generate a response in real time. To keep the community safe, messages you send to other users are also screened by automated moderation, which may send the message text to the AI provider for classification.
This content is processed to produce your result or moderation decision and is not used by the Developer to build a profile of you or to train AI models. You can use the entire app without ever invoking an AI feature.
4. What the Developer does not do
- The Developer does not sell or rent your personal data.
- The Developer does not use third-party advertising or tracking pixels in the app.
- The Developer does not currently use third-party analytics that profile you; if this ever changes, this policy will be updated first.
- Your private entries are not shared with other users — row-level security enforces this at the database.
- Your journal or mood content is not used to train AI models.
5. Your rights & control
You are always in control. From Settings you can download a complete copy of your data (a data request) and permanently delete your entire account and all associated data — when you delete your account, the underlying records are erased. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA/CPRA, including the right to access, correct, delete, or port your data, and to object to certain processing. To exercise any right, use the in-app controls or email the Developer.
6. Data retention
The Developer keeps your data for as long as your account is active so the Service can function. When you delete an entry it is removed; when you delete your account, your account and associated data are deleted. Backups or logs held by service providers may persist for a limited period under those providers’ standard retention before being overwritten.
7. Service providers
The Developer relies on a small set of trusted processors to run Aurelia: Supabase (authentication and encrypted database), Vercel (application hosting), Groq (AI responses and message moderation for features you use), and Resend (transactional email such as confirmations). Each processes only the data needed to provide its service and is bound by its own data-protection terms. Some providers may process data in the United States or other countries.
8. Security
The Developer uses reasonable measures to protect your data, including encryption in transit and database row-level security. However, no method of transmission or storage is completely secure, and the Developer cannot guarantee absolute security. You are responsible for keeping your account credentials safe.
9. Cookies & local storage
Aurelia uses only essentialcookies and local storage — there are no advertising or third-party tracking cookies. Specifically: a secure session cookie (set by Supabase) keeps you signed in across pages and devices, and your browser’s local storage holds presentation preferences (theme, accent, check-in fields) and the device-only data described in Section 2.
Because these are strictly necessary for the app to function and for your own convenience, they are not used to profile or track you. Clearing your browser data removes them; signing out clears the session cookie.
10. Children
The Service is not directed to children under 13, and the Developer does not knowingly collect personal data from them. If you are under 18, a parent or legal guardian must read and agree to the Terms on your behalf. If you believe a child under 13 has provided personal data, contact the Developer and it will be removed.
11. Not medical advice
Aurelia supports self-reflection and is not a medical device, diagnosis, or a substitute for professional care. If you are in crisis, please contact a local emergency number or a crisis line such as 988 (US).
12. Changes & contact
The Developer may update this policy as Aurelia evolves; material changes will be reflected here with a new date. Questions? Reach the Developer at medisummarize@gmail.com.