Legal & Compliance Documentation

Privacy Policy

GDPR / DSGVO Compliant Google Play & App Store Aligned Version: 2026-06 Last Updated: October 1, 2026
Table of Contents
  1. Data Controller & Responsible Entity
  2. Our Core Privacy Principles
  3. Categories of Data We Collect
  4. Google Sign-In & Authentication
  5. Health & Biometric Data Handling
  6. Device Permissions Explained
  7. Third-Party Processors & Infrastructure
  8. Legal Bases for Processing (GDPR)
  9. Data Retention & Automatic Anonymization
  10. User Rights & Account Deletion Instructions
  11. Minors & 18+ Age Restriction
  12. Contact & Data Protection Officer

1. Data Controller & Responsible Entity

The controller responsible for processing your personal data within the meaning of the EU General Data Protection Regulation (GDPR / DSGVO) and the German Telecommunications-Telemedia Data Protection Act (TTDSG) is:

AURALIS Wellness UG (haftungsbeschränkt)
Musterstrasse 21, 50667 Köln, Deutschland
Phone: +49 221 12345670
Legal Representative: Lena Hartmann (Verantwortlicher i.S.d. TMG §5)
Official Privacy & Support Inquiries: auralisapp.official@gmail.com

We take the protection of your personal information very seriously. This Privacy Policy informs you about the nature, scope, and purpose of the collection and use of personal data when using the Auralis mobile application and our associated digital services.

2. Our Core Privacy Principles

Thermal wellness and sauna culture are practices of mindfulness and physical vulnerability. Our technology stack reflects these values:

  • Data Minimization: We only collect data strictly necessary to fulfill our service (finding saunas, scheduling rituals, and logging personal wellbeing).
  • No Data Brokering or Ad-Tracking: We never sell, rent, or lease your personal or health data to third-party advertisers, data brokers, or insurers.
  • On-Device Health Privacy: Apple Health and biometric readings remain on your physical device and are never streamed to remote analytical databases.
  • European Sovereign Hosting: All persistent databases, backups, and user credentials reside exclusively within the European Union (Frankfurt am Main, Germany).

3. Categories of Data We Collect

Depending on your interactions with Auralis, we collect and process the following categories of information:

A. Account & Registration Data

  • Direct Registration: Name / display name, email address, password hash (encrypted via bcrypt, never stored in plain text), and optional phone number.
  • Age Verification: Explicit confirmation that you are at least 18 years of age.
  • Consent Records: Cryptographic timestamp and version identifier of your acceptance of our Terms of Service and Privacy Policy (`gdpr_consent_at`, `gdpr_consent_version`).

B. Profile & Community Details

  • Profile Details: Bio, region, personal wellness interests, and uploaded avatar photographs (stored in private user-owned paths within Supabase Storage).
  • Social Interactions: Mutual connection requests, approved connections, and group memberships. Private messages and reports are strictly moderated to uphold community safety.

C. Wellness Logs, Rituals & Preferences

  • Rituals & Packing Lists: Custom contrast therapy steps (heat duration, cold immersion, rest intervals), packing lists, and item checkmarks.
  • Wellness Journal & Mood: Mood selections (Exhausted, Stressed, Balanced, Active), pre/post visit reflection notes, and self-reported wellness sliders (Stress, Energy, Wellbeing).
  • Facility Interactions: Bookmarked favorite saunas, verified visits, reviews, and community ratings.

D. Technical & Diagnostic Logs

  • Device model, operating system version, app build identifier, IP address (truncated), language preferences, and anonymized crash logs recorded via Sentry to resolve software bugs.

4. Google Sign-In & Authentication Handling

Auralis provides the option to sign up and authenticate using Google Sign-In. We adhere strictly to the Google API Services User Data Policy and Google Play Developer Policies:

  • Data Accessed: When choosing Google Sign-In, our app utilizes the official Google Sign-In SDK with OpenID Connect (OIDC). We request only standard authentication scopes: openid, email, and profile.
  • Authentication Flow: Google issues a signed cryptographic ID token containing your Google ID, verified email address, and name. This token is securely validated by Supabase Auth using a one-time cryptographic nonce (`rawNonce` and SHA-256 hash) to prevent replay attacks.
  • Use of Google User Data: Information received from Google is used exclusively to create and authenticate your account on Auralis. We do not inspect your Google contacts, Google Drive, or calendar without explicit separate permission.
  • No Advertising or Brokering: Google user data is never transferred to data brokers, used to train generalized artificial intelligence models, or used for third-party behavioral retargeting.

5. Health & Biometric Data Handling

Important Architecture Notice: Auralis treats health and biometric data as Special Category Data under GDPR Article 9. Raw health records never leave your physical device.

If you choose to enable integration with Apple Health (iOS HealthKit) or Android Health Connect:

  • Read-Only Access: The app requests permission to read selected wellness metrics (e.g., resting heart rate, workout timestamps, mindful minutes).
  • Local Execution: Our algorithms calculate your Recovery Score entirely on your smartphone. The calculation takes place in client memory; raw biometrics are never uploaded to remote servers.
  • Zero Marketing Sharing: Under no circumstances will health data derived from Apple HealthKit or Health Connect be shared with advertisers or third parties.
  • Revocation: You can disconnect Apple Health synchronization at any time within your device's operating system settings or within the Auralis App Settings.

6. Device Permissions Explained

Auralis requests only runtime permissions that directly empower app functionality. You maintain full control to grant or revoke these permissions in your system settings:

Permission Platform Specific Purpose Storage Location
Location (GPS)
ACCESS_FINE_LOCATION
iOS / Android Calculating distance to nearby saunas and sorting the Discover feed by proximity. In-session RAM only; never stored on remote servers.
Notifications
POST_NOTIFICATIONS
iOS / Android Sending hydration reminders during visits, Aufguss countdowns, and connection requests. Device system notification manager & FCM push token.
Camera & Media
CAMERA, READ_MEDIA_IMAGES
iOS / Android Enabling you to take or select a profile avatar photo. Uploaded solely to your private, authenticated bucket path.
Calendar
NSCalendarsUsageDescription
iOS / Android Syncing scheduled bathhouse and sauna visits to your personal device calendar. Local device calendar only.
Health Data
NSHealthShareUsageDescription
iOS / Android Correlating contrast heat/cold sessions with recovery scores. On-device only; never uploaded.

7. Third-Party Processors & Infrastructure

To provide secure, scalable, and reliable services, we collaborate with select technical infrastructure providers bound by Data Processing Agreements (DPA) under GDPR Art. 28:

Provider Role & Service Location Safeguards
Supabase Inc. User Authentication, Relational Database, Row-Level Security, Encrypted Storage Frankfurt, Germany (EU) GDPR DPA, ISO 27001, SOC 2 Type II, RLS Enforcement
Google Ireland Ltd. / Firebase Firebase Cloud Messaging (FCM) & Anonymized Analytics EU / Global EU Model Clauses, Aggregated Event Telemetry (opt-out available)
Apple Inc. Sign in with Apple & App Store distribution Global / USA Apple Data Processing Terms, Pseudonymous Relay Option
Functional Software Inc. (Sentry) Crash reporting, error monitoring, performance diagnostics EU / USA Zero default PII (`sendDefaultPii = false`), IP masking

9. Data Retention & Automatic Anonymization

We retain your personal data only as long as your account remains active.

  • Active Accounts: Profile, ritual, and wellness log records are retained throughout your membership to present historical progress.
  • Deactivated Accounts: When an account deletion is initiated, your profile is immediately hidden from discovery, social groups, and search results.
  • 30-Day Purge Cycle: All database records enter a 30-day recovery grace period, after which our automated backend worker permanently anonymizes and purges all personally identifiable information (PII).
  • Analytics Logs: Anonymized Firebase telemetry logs are retained on a rolling 90-day window and cannot be re-associated with individual profiles.

10. User Rights & Account Deletion Instructions

Under European data protection laws (GDPR Articles 15 to 22), you hold comprehensive rights regarding your personal information:

  • Right to Access (Art. 15): Request a complete summary and copy of all personal data we maintain about you.
  • Right to Rectification (Art. 16): Correct inaccurate, outdated, or incomplete profile details at any time in-app.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): Have your personal data completely deleted.
  • Right to Restriction of Processing (Art. 18): Restrict the processing of your data in specific disputed situations.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to data processing based on our legitimate interests.
  • Right to Withdraw Consent: Revoke previously granted consents for location, notifications, or health sync at any time without penalty.

How to Delete Your Account and Data

You can execute account and data deletion in two straightforward ways:

  1. In-App Self-Service: Open the Auralis App → Go to Profile → Tap Settings → Select Account Security → Tap Delete Account → Type LÖSCHEN to confirm. Your profile will be instantly deactivated and scheduled for permanent deletion.
  2. Direct Support Email: Send an email from your registered address to auralisapp.official@gmail.com with the subject "Data Deletion Request". Our data protection team will process your request within 7 business days and confirm complete erasure.

11. Minors & 18+ Age Restriction

Auralis is exclusively designed and intended for individuals aged 18 and older. Given the nature of thermal wellness facilities, European sauna customs (which frequently involve textile-free environments), and social community features, we enforce an explicit 18+ verification gate during registration.

We do not knowingly collect or solicit personal information from minors under the age of 18. If we become aware that a minor has registered an account, we will immediately terminate the account and permanently delete all associated data. If you believe a minor has provided us with personal information, please alert us at auralisapp.official@gmail.com.

12. Contact & Data Protection Officer

If you have questions, feedback, or concerns regarding this Privacy Policy, or wish to exercise any of your statutory data protection rights, please contact our dedicated privacy team:

Auralis Privacy & Data Protection Team
Email: auralisapp.official@gmail.com
Mailing Address: AURALIS Wellness UG (haftungsbeschränkt), Musterstrasse 21, 50667 Köln, Deutschland
Responsible Representative: Lena Hartmann

You also have the right to lodge a formal complaint with the competent supervisory authority for data protection in your jurisdiction. For North Rhine-Westphalia (Germany), the responsible authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).