AURABack to AURA

LEGAL · PRIVACY

Privacy Policy

Effective date: August 7, 2026

1. Scope and developer identification

This Privacy Policy applies to AURA Wallet, its iOS and Android applications, public website, APIs, notification services, risk services, and related support channels. AURA Wallet is the product and service identified by this policy. Privacy questions may be submitted through the official support mechanism displayed in the app or on this website.

AURA is a self-custody wallet. Seed phrases, private keys, and signing authority are designed to remain on the user's device. AURA does not take custody of crypto assets and cannot approve or sign a transaction without direct user action.

2. Data processed only on the device

Wallet secrets, PIN-protected signing state, wallet labels, address-book entries, locally added assets, language, theme, display currency, and certain cached portfolio data may be stored locally. Biometric verification is performed by the operating system; AURA does not receive a copy of biometric templates.

The AURA entity may use wallet context to explain activity or prepare an action, but it is not permitted to access the seed phrase or cross the signing boundary. Data that remains exclusively on the device is not transmitted to AURA services.

3. Data AURA may collect or process

  • Public wallet addresses, network identifiers, balances, token holdings, and public transaction history.
  • Transaction hashes, contract addresses, approval details, dApp domains, and public risk evidence.
  • Device registration identifiers, authentication proofs, nonces, timestamps, app version, operating system, and language.
  • Push-notification tokens, notification preferences, delivery status, and device-session state.
  • IP address and request metadata automatically received by hosting, security, RPC, and API infrastructure.
  • Redacted crash, error, and performance diagnostics when diagnostics are enabled.
  • Support communications and information a user voluntarily submits to support.

Public blockchain activity is inherently public and may be observed, indexed, or retained by third parties independently of AURA.

4. Purposes of processing

  • Provide portfolios, prices, history, swaps, transaction status, notifications, and display-currency conversion.
  • Secure device access, authenticate API requests, prevent replay, rate-limit abuse, and maintain sessions.
  • Detect suspicious tokens, addresses, domains, contracts, approvals, and transaction behavior.
  • Operate customer support, investigate failures, and improve reliability and performance.
  • Comply with legal obligations and protect users, AURA, service providers, and the public.

5. Third-party services and sharing

AURA may use blockchain RPC and indexing providers, market-data and foreign-exchange providers, swap providers, WalletConnect infrastructure, push-notification services, cloud hosting, security services, and diagnostics providers. They may process public wallet data, network requests, IP addresses, device or delivery identifiers, and technical metadata necessary to provide their services.

AURA does not sell seed phrases, private keys, signing authority, or personal and sensitive user data. Data may be shared with service providers acting on AURA's behalf, when required by law, to investigate abuse or security incidents, or in a corporate transaction subject to appropriate safeguards. Third parties are expected to provide protections consistent with this policy and applicable platform requirements.

6. Permissions and user consent

AURA requests device permissions only when needed for a user-facing feature, such as camera access for QR scanning, notifications for wallet alerts, or biometrics for local unlock. Where platform rules require prominent disclosure or consent, AURA presents that disclosure before requesting the permission. Optional permissions can be denied or revoked in device settings.

7. Security

AURA applies technical and organizational safeguards including encrypted transport, device-bound authentication, nonce and timestamp checks, rate limits, restricted admin access, audit logs, and separation between read services and the native signing boundary. No storage or transmission system can be guaranteed completely secure.

8. Retention and deletion

Data is retained only as long as reasonably necessary for the feature, security requirement, legal obligation, fraud prevention, or dispute. Retention periods vary by data category. Device-local wallet data can be removed by deleting wallets or clearing the app. Revoking a device session prevents future authenticated access from that session.

AURA does not currently require a conventional hosted user account to create a self-custody wallet. If account-based services are introduced, AURA will provide both an in-app path and a publicly accessible web method to request account and associated-data deletion. Public blockchain records cannot be deleted by AURA.

9. User choices and rights

Users can manage notifications, disconnect dApps and WalletConnect sessions, revoke device sessions, change language and display currency, remove local wallets and app data, and avoid optional features. Depending on applicable law, users may request access, correction, deletion, restriction, or information about processing through the official support channel.

10. App Store and Google Play disclosures

AURA maintains Apple App Privacy responses and Google Play Data safety declarations that are intended to match the app's actual behavior, integrated SDKs, and this policy. On-device-only processing is distinguished from data transmitted to servers. Material changes to collection, sharing, permissions, SDKs, or purposes require corresponding updates to store disclosures and this policy.

11. Children

AURA is not directed to children and should not be used by anyone who is not legally permitted to use crypto-wallet services in their jurisdiction.

12. Changes and contact

This policy may be updated as AURA changes. The effective date will be revised when updates are published. Privacy inquiries may be submitted through the official support mechanism in the app or website. Never send a seed phrase, private key, PIN, or full recovery information to support.