Privacy Policy
- Data Controller & Responsible Entity
- Our Core Privacy Principles
- Categories of Data We Collect
- Google Sign-In & Authentication
- Health & Biometric Data Handling
- Device Permissions Explained
- Third-Party Processors & Infrastructure
- Legal Bases for Processing (GDPR)
- Data Retention & Automatic Anonymization
- User Rights & Account Deletion Instructions
- Minors & 18+ Age Restriction
- Contact & Data Protection Officer
1. Data Controller & Responsible Entity
The controller responsible for processing your personal data within the meaning of the EU General Data Protection Regulation (GDPR / DSGVO) and the German Telecommunications-Telemedia Data Protection Act (TTDSG) is:
Musterstrasse 21, 50667 Köln, Deutschland
Phone: +49 221 12345670
Legal Representative: Lena Hartmann (Verantwortlicher i.S.d. TMG §5)
Official Privacy & Support Inquiries: auralisapp.official@gmail.com
We take the protection of your personal information very seriously. This Privacy Policy informs you about the nature, scope, and purpose of the collection and use of personal data when using the Auralis mobile application and our associated digital services.
2. Our Core Privacy Principles
Thermal wellness and sauna culture are practices of mindfulness and physical vulnerability. Our technology stack reflects these values:
- Data Minimization: We only collect data strictly necessary to fulfill our service (finding saunas, scheduling rituals, and logging personal wellbeing).
- No Data Brokering or Ad-Tracking: We never sell, rent, or lease your personal or health data to third-party advertisers, data brokers, or insurers.
- On-Device Health Privacy: Apple Health and biometric readings remain on your physical device and are never streamed to remote analytical databases.
- European Sovereign Hosting: All persistent databases, backups, and user credentials reside exclusively within the European Union (Frankfurt am Main, Germany).
3. Categories of Data We Collect
Depending on your interactions with Auralis, we collect and process the following categories of information:
A. Account & Registration Data
- Direct Registration: Name / display name, email address, password hash (encrypted via bcrypt, never stored in plain text), and optional phone number.
- Age Verification: Explicit confirmation that you are at least 18 years of age.
- Consent Records: Cryptographic timestamp and version identifier of your acceptance of our Terms of Service and Privacy Policy (`gdpr_consent_at`, `gdpr_consent_version`).
B. Profile & Community Details
- Profile Details: Bio, region, personal wellness interests, and uploaded avatar photographs (stored in private user-owned paths within Supabase Storage).
- Social Interactions: Mutual connection requests, approved connections, and group memberships. Private messages and reports are strictly moderated to uphold community safety.
C. Wellness Logs, Rituals & Preferences
- Rituals & Packing Lists: Custom contrast therapy steps (heat duration, cold immersion, rest intervals), packing lists, and item checkmarks.
- Wellness Journal & Mood: Mood selections (Exhausted, Stressed, Balanced, Active), pre/post visit reflection notes, and self-reported wellness sliders (Stress, Energy, Wellbeing).
- Facility Interactions: Bookmarked favorite saunas, verified visits, reviews, and community ratings.
D. Technical & Diagnostic Logs
- Device model, operating system version, app build identifier, IP address (truncated), language preferences, and anonymized crash logs recorded via Sentry to resolve software bugs.
4. Google Sign-In & Authentication Handling
Auralis provides the option to sign up and authenticate using Google Sign-In. We adhere strictly to the Google API Services User Data Policy and Google Play Developer Policies:
- Data Accessed: When choosing Google Sign-In, our app utilizes the official Google Sign-In SDK with OpenID Connect (OIDC). We request only standard authentication scopes:
openid,email, andprofile. - Authentication Flow: Google issues a signed cryptographic ID token containing your Google ID, verified email address, and name. This token is securely validated by Supabase Auth using a one-time cryptographic nonce (`rawNonce` and SHA-256 hash) to prevent replay attacks.
- Use of Google User Data: Information received from Google is used exclusively to create and authenticate your account on Auralis. We do not inspect your Google contacts, Google Drive, or calendar without explicit separate permission.
- No Advertising or Brokering: Google user data is never transferred to data brokers, used to train generalized artificial intelligence models, or used for third-party behavioral retargeting.
5. Health & Biometric Data Handling
If you choose to enable integration with Apple Health (iOS HealthKit) or Android Health Connect:
- Read-Only Access: The app requests permission to read selected wellness metrics (e.g., resting heart rate, workout timestamps, mindful minutes).
- Local Execution: Our algorithms calculate your Recovery Score entirely on your smartphone. The calculation takes place in client memory; raw biometrics are never uploaded to remote servers.
- Zero Marketing Sharing: Under no circumstances will health data derived from Apple HealthKit or Health Connect be shared with advertisers or third parties.
- Revocation: You can disconnect Apple Health synchronization at any time within your device's operating system settings or within the Auralis App Settings.
6. Device Permissions Explained
Auralis requests only runtime permissions that directly empower app functionality. You maintain full control to grant or revoke these permissions in your system settings:
| Permission | Platform | Specific Purpose | Storage Location |
|---|---|---|---|
Location (GPS)ACCESS_FINE_LOCATION |
iOS / Android | Calculating distance to nearby saunas and sorting the Discover feed by proximity. | In-session RAM only; never stored on remote servers. |
NotificationsPOST_NOTIFICATIONS |
iOS / Android | Sending hydration reminders during visits, Aufguss countdowns, and connection requests. | Device system notification manager & FCM push token. |
Camera & MediaCAMERA, READ_MEDIA_IMAGES |
iOS / Android | Enabling you to take or select a profile avatar photo. | Uploaded solely to your private, authenticated bucket path. |
CalendarNSCalendarsUsageDescription |
iOS / Android | Syncing scheduled bathhouse and sauna visits to your personal device calendar. | Local device calendar only. |
Health DataNSHealthShareUsageDescription |
iOS / Android | Correlating contrast heat/cold sessions with recovery scores. | On-device only; never uploaded. |
7. Third-Party Processors & Infrastructure
To provide secure, scalable, and reliable services, we collaborate with select technical infrastructure providers bound by Data Processing Agreements (DPA) under GDPR Art. 28:
| Provider | Role & Service | Location | Safeguards |
|---|---|---|---|
| Supabase Inc. | User Authentication, Relational Database, Row-Level Security, Encrypted Storage | Frankfurt, Germany (EU) | GDPR DPA, ISO 27001, SOC 2 Type II, RLS Enforcement |
| Google Ireland Ltd. / Firebase | Firebase Cloud Messaging (FCM) & Anonymized Analytics | EU / Global | EU Model Clauses, Aggregated Event Telemetry (opt-out available) |
| Apple Inc. | Sign in with Apple & App Store distribution | Global / USA | Apple Data Processing Terms, Pseudonymous Relay Option |
| Functional Software Inc. (Sentry) | Crash reporting, error monitoring, performance diagnostics | EU / USA | Zero default PII (`sendDefaultPii = false`), IP masking |
8. Legal Bases for Processing (GDPR)
We process your personal data under the following legal frameworks established by GDPR Article 6 and 9:
- Performance of Contract (Art. 6(1)(b) GDPR): Creating your account, managing your profile, delivering your custom rituals, and providing social messaging.
- Explicit Consent (Art. 6(1)(a) & Art. 9(2)(a) GDPR): Wellness self-assessment sliders, Apple Health metric correlation, push notifications, and GPS-based facility discovery.
- Legitimate Interests (Art. 6(1)(f) GDPR): Ensuring network security, preventing fraud, detecting bugs via Sentry, and maintaining service reliability.
- Legal Obligation (Art. 6(1)(c) GDPR): Retaining tax and commercial records where legally mandated under German and European law.
9. Data Retention & Automatic Anonymization
We retain your personal data only as long as your account remains active.
- Active Accounts: Profile, ritual, and wellness log records are retained throughout your membership to present historical progress.
- Deactivated Accounts: When an account deletion is initiated, your profile is immediately hidden from discovery, social groups, and search results.
- 30-Day Purge Cycle: All database records enter a 30-day recovery grace period, after which our automated backend worker permanently anonymizes and purges all personally identifiable information (PII).
- Analytics Logs: Anonymized Firebase telemetry logs are retained on a rolling 90-day window and cannot be re-associated with individual profiles.
10. User Rights & Account Deletion Instructions
Under European data protection laws (GDPR Articles 15 to 22), you hold comprehensive rights regarding your personal information:
- Right to Access (Art. 15): Request a complete summary and copy of all personal data we maintain about you.
- Right to Rectification (Art. 16): Correct inaccurate, outdated, or incomplete profile details at any time in-app.
- Right to Erasure / "Right to be Forgotten" (Art. 17): Have your personal data completely deleted.
- Right to Restriction of Processing (Art. 18): Restrict the processing of your data in specific disputed situations.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to data processing based on our legitimate interests.
- Right to Withdraw Consent: Revoke previously granted consents for location, notifications, or health sync at any time without penalty.
How to Delete Your Account and Data
You can execute account and data deletion in two straightforward ways:
- In-App Self-Service: Open the Auralis App → Go to Profile → Tap Settings → Select Account Security → Tap Delete Account → Type
LÖSCHENto confirm. Your profile will be instantly deactivated and scheduled for permanent deletion. - Direct Support Email: Send an email from your registered address to auralisapp.official@gmail.com with the subject "Data Deletion Request". Our data protection team will process your request within 7 business days and confirm complete erasure.
11. Minors & 18+ Age Restriction
Auralis is exclusively designed and intended for individuals aged 18 and older. Given the nature of thermal wellness facilities, European sauna customs (which frequently involve textile-free environments), and social community features, we enforce an explicit 18+ verification gate during registration.
We do not knowingly collect or solicit personal information from minors under the age of 18. If we become aware that a minor has registered an account, we will immediately terminate the account and permanently delete all associated data. If you believe a minor has provided us with personal information, please alert us at auralisapp.official@gmail.com.
12. Contact & Data Protection Officer
If you have questions, feedback, or concerns regarding this Privacy Policy, or wish to exercise any of your statutory data protection rights, please contact our dedicated privacy team:
Email: auralisapp.official@gmail.com
Mailing Address: AURALIS Wellness UG (haftungsbeschränkt), Musterstrasse 21, 50667 Köln, Deutschland
Responsible Representative: Lena Hartmann
You also have the right to lodge a formal complaint with the competent supervisory authority for data protection in your jurisdiction. For North Rhine-Westphalia (Germany), the responsible authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).