Legal
Privacy Policy
How the Aura AI mobile application collects, uses, and protects your personal data.
Last updated 20 August 2026
Adease LTD ("we", "our", "us"), a company registered in England and Wales (company number 14743980), registered office 124 City Road, London, EC1V 2NX, United Kingdom, is the data controller for personal data processed through the Aura AI app.
Contact for privacy matters: support@adease.io
1. Summary
- We process the photos you choose to upload in order to generate the images you ask for.
- Facial imagery is used only to produce the transformations you request. It is never used for identification, facial recognition, advertising, or model training.
- Uploaded source photos are deleted automatically after processing — typically within minutes, and no later than 24 hours.
- You can delete individual generations, or your whole account, from within the App.
- Uploading photos is optional; the App can be used without it.
2. Data we collect
Account data. Email address, display name, profile photo if you set one, and the identifier returned by Sign in with Apple or Google Sign-In. We never receive your Apple or Google password.
Photos and face data. Images you upload, which may contain identifiable facial features, and the images the App generates from them.
Generation data. The prompts, templates, styles, and options you select, and the status and error records of your generation jobs.
Purchase and subscription data. Your subscription status, entitlements, purchase history, and transaction identifiers, received from Apple, Google, and RevenueCat, together with your credit balance and credit ledger. We never receive or store your payment card details — payment is handled entirely by Apple or Google.
Device and usage data. Device model, operating system version, app version, language and region, crash diagnostics, feature usage events, IP address, and an app-instance identifier, collected through Firebase Analytics, Firebase Crashlytics, and Firebase App Check.
Push notification tokens. A Firebase Cloud Messaging token, if you enable notifications.
Support correspondence. Anything you send us by email.
3. Why we process it, and our lawful basis (UK/EU GDPR)
| Purpose | Lawful basis |
|---|---|
| Creating and running your account | Performance of a contract |
| Generating images and videos you request | Performance of a contract |
| Processing facial imagery within those generations | Your explicit consent (Art. 9(2)(a)) |
| Managing subscriptions, credits, and purchases | Performance of a contract; legal obligation |
| Sending push notifications about your generations | Performance of a contract, or consent where required |
| Fraud prevention, abuse detection, rate limiting, and security | Legitimate interests |
| Diagnostics, crash reporting, and product improvement | Legitimate interests |
| Content moderation and enforcing our Terms | Legitimate interests; legal obligation |
| Retaining transaction records | Legal obligation |
To the extent facial imagery constitutes special category biometric data, we rely on your explicit consent, given when you choose to upload a photo. You may withdraw consent at any time by ceasing to upload photos and deleting existing content or your account; withdrawal does not affect processing already carried out.
4. Face data — detail
What we collect. Photographs you voluntarily upload that contain facial features, for virtual try-on, hairstyle generation, body-type previews, and photo enhancement.
How we use it. To generate modified images showing you in different outfits, hairstyles, or body types, by processing the image through AI models that preserve facial features while altering other aspects of appearance. Face data is used exclusively to deliver features you request within the App.
What we never do. We do not use face data for facial recognition or identification, for advertising or marketing, or to train AI models. We do not sell it, and we do not publish it.
Who processes it. Face data is transmitted to Replicate (https://replicate.com/privacy) for model inference, and, where an image is generated without a user photo, to OpenAI (https://openai.com/policies/privacy-policy). These providers process the image to return a result and do not retain face data after processing completes. Images are stored in Firebase Storage (Google Cloud Platform) while a job is running.
How long we keep it. Source photos are retained only while the generation job is active — typically 1–5 minutes — and are deleted automatically once the output is delivered. Maximum retention is 24 hours, after which any remaining source images are purged. Generated outputs are stored in your account until you delete them or delete your account.
Your control. Uploading photos is entirely optional. You can delete any generated image from within the App, and deleting your account permanently removes your stored images and associated face data.
5. Who we share data with
We share personal data only with service providers acting on our instructions, and with the parties below:
- Google (Firebase) — authentication, database, storage, cloud functions, messaging, analytics, crash reporting, app integrity. https://firebase.google.com/support/privacy
- Replicate — AI model inference on uploaded and generated images. https://replicate.com/privacy
- OpenAI — image generation where no user photo is supplied. https://openai.com/policies/privacy-policy
- RevenueCat — subscription and entitlement management. https://www.revenuecat.com/privacy
- Apple and Google — payment processing, authentication, and app distribution, as independent controllers under their own policies.
We disclose data to law enforcement or regulators where legally required, and to professional advisers or an acquirer in connection with a corporate transaction, subject to equivalent protections.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
6. International transfers
We are based in the United Kingdom. Some providers listed above process data in the United States and other countries. Where personal data leaves the UK or EEA, we rely on the UK International Data Transfer Addendum, the European Commission's Standard Contractual Clauses, or an applicable adequacy decision.
7. Retention
| Data | Retention |
|---|---|
| Uploaded source photos | Until the job completes; maximum 24 hours |
| Generated images | Until you delete them or delete your account |
| Account data | Until you delete your account |
| Job and error records | Up to 12 months, then deleted or aggregated |
| Purchase and transaction records | Up to 7 years, as required by UK tax and accounting law |
| Analytics and crash data | Per Firebase defaults, up to 14 months |
8. Your rights
If you are in the UK or EEA, you have the right to access your data; to have inaccurate data corrected; to erasure; to restrict or object to processing; to data portability; and to withdraw consent at any time. You also have the right not to be subject to solely automated decisions producing legal or similarly significant effects — we do not make such decisions.
Exercise these rights in the App (Settings → Account) or by emailing support@adease.io. We respond within one month. You may complain to the Information Commissioner's Office (https://ico.org.uk, 0303 123 1113) or to your local supervisory authority.
California residents. You may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and are entitled not to receive discriminatory treatment for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
9. Children
Aura AI is not directed at children under 13, and we do not knowingly collect personal data from them. Where local law sets a higher age of digital consent, users below that age require parental consent. If you believe a child has provided us with personal data, email support@adease.io and we will delete it.
10. Security
We use TLS in transit and encryption at rest, Firebase Authentication for identity, Firebase App Check to block unauthorised clients, security rules restricting each user to their own data, and least-privilege access controls for staff. No system is perfectly secure; where a breach is likely to result in a risk to your rights, we will notify the ICO and, where required, you.
11. Permissions the App requests
Camera and photo library — so you can supply an image to generate from. Notifications — so we can tell you when a generation is ready. Network access — required to process generations on our servers. All are optional, and the App will ask before using them.
12. Changes to this policy
We may update this policy. The current version is always at https://adease.io/aura_privacy, with the date at the top. Material changes will be notified in the App or by email.
13. Contact
Adease LTD
124 City Road, London, EC1V 2NX, United Kingdom
Registered in England and Wales, company number 14743980
Email: support@adease.io