Privacy Policy
AURA Team (the “Operator”) handles information in AURA (the “Service”) as follows.
1. Information we collect
| AURA page content | The display name, bio, links, icon image, page URL and background settings entered by the creator. If imported from Linktree, the content fetched at the creator’s request |
|---|---|
| Verified badge | The verified Linktree username (shown publicly on the AURA page) |
| Passkeys | The passkey’s public key and identifier. Biometrics such as your face or fingerprint are used only on your device and never reach the Service |
| Edit keys | The key in the edit URL is stored only in an irreversible form (a hash) |
| Views and clicks | Only daily view counts per AURA page and total clicks per link. Nothing that identifies who viewed or clicked is stored |
| Reports | The reason and note, and a value computed from the reporter’s IP address to prevent duplicates (the IP address itself is not stored) |
| Contact and AURA Post | The category, your name (optional), reply email address (optional) and message (the same for AURA Post) |
| Connection data | Your IP address, browser type and similar data are processed when you connect. IP addresses are used to limit rapid repeated actions (to prevent abuse) but are not stored |
Payments on Ko-fi, reached from “Support” in AURA Post, are handled by Ko-fi and payment services such as Stripe. The Service never receives your card details.
The Service does not use cookies. Your edit keys and settings such as turning music off are stored in your own browser (local storage).
2. How we use it
- Providing the Service (creating, showing, editing and deleting AURA pages, making share images and QR codes, and showing view and click counts)
- Verification, preventing impersonation and abuse, and handling reports
- Answering inquiries and considering ideas sent to AURA Post
- Maintaining and improving the Service
3. Sharing with third parties
Except as required by law, the Operator does not share personal information with third parties without consent. AURA page content is published on the internet by the creator’s choice.
4. External services (processing outside Japan)
The Service uses the following external services. These providers are based in the United States, and information may be processed outside Japan, including in the United States. For the US data protection system, see the information published by Japan’s Personal Information Protection Commission.
| Cloudflare, Inc. | Servers, database and image storage for the Service, including delivery of the QR code library used on the create screen (cdnjs) |
|---|---|
| Google LLC | Fonts on the create screen (Google Fonts). Your IP address and similar data are sent to Google when fonts load |
| Linktree | When you import or verify, the Service’s server fetches the Linktree page you specified |
5. Retention and deletion
- Information about an AURA page (including passkeys, views and clicks) is kept until the page is deleted, and erased when it is. Creators can delete their page anytime from the edit screen.
- Reports, inquiries and AURA Post messages are erased once they have been handled or considered.
6. Security
All connections are encrypted (HTTPS). Edit keys are stored as hashes, and the admin screen is protected by an admin key.
7. Requests to disclose, correct or delete
To request disclosure, correction, suspension of use or deletion of your information, use the contact form and choose “Request to disclose, correct or delete personal data”. After confirming your identity, we will respond as required by law.
8. Changes
The Operator may revise this Policy when necessary. Changes take effect when posted on the Service.
9. Operator and contact
Operator: AURA Team
Contact: contact form
The Operator’s address and representative’s name will be provided without delay upon request.