This policy is an early draft and will evolve (with clearer detail and, where relevant, supporting documentation) before Auracle’s public launch. Material changes will be communicated in-app or by email.
Who we are
Auracare Health LTD (“we”, “us”) is the data controller for the personal data described in this policy. We are a company registered in England & Wales. For any privacy question, or to exercise your rights, contact privacy@auracare.org.uk.
What this policy covers
This policy covers Auracle, our consumer product that builds a personal health “digital twin” from the wearables and apps you connect, and checks in with you over the messaging apps you already use, such as iMessage, WhatsApp or RCS.
Auracle is a general-wellness product, not a medical device. It is designed to help you understand your own patterns. It does not diagnose, treat, dose or clinically interpret your data. Aura is an AI companion, and will always tell you so: you are never talking to a person.
Auracle launches in the United Kingdom, the United States, Canada and Australia. The whole of this policy applies wherever you are; the regional terms section adds the rights and commitments specific to your region, and Washington and Nevada residents also have a dedicated Consumer Health Data Privacy Policy.
The data we process
Account data
When you join, we process the details needed to run your account (such as your name, email address and the mobile identity you use to message Auracle), together with basic app and delivery logs that keep the service reliable and secure.
Health & wellness data you connect
When you connect a source, Auracle processes the general health and wellness information it provides, such as sleep, activity and recovery trends from the wearables and apps you choose to link. You decide which sources to connect, and you can disconnect any of them at any time.
What you tell Aura in conversation
Talking to Aura is how the service works, so your conversations are part of the data we process: the things you tell it about how you feel, what you ate and your habits, and the wellness inferences your twin draws from them (for example, your sleep baseline). Voice notes are transcribed and the audio is then discarded; we do not create voiceprints and we do not use biometric identification.
Precise location, only if you opt in
If you separately opt in, Auracle processes your precise location to give your guidance context, such as time zones, travel and where your routines happen. This is optional: Auracle works fully without it, and you can turn it off at any time. We never use your location to infer visits to healthcare facilities, and we do not geofence health services.
Optional app analytics
The iPhone and Android apps ask before sending anonymous product analytics to PostHog’s EU service. If you allow it, we send limited feature-use and reliability events together with basic device and app-version information. We do not send health data, clinical records, messages, location, profile details, URLs, free text or screen recordings. Analytics is off until you make a choice, and you can withdraw consent at any time in the app’s Settings.
Health data, whether it comes from a source you connect or from something you tell Aura, is sensitive personal data: special-category data under UK and EU law, and sensitive information under US, Canadian and Australian law. We treat it with the heightened protection that classification requires, wherever you are.
Our lawful basis
We rely on your explicit consent (Article 9(2)(a) UK GDPR, and its regional equivalents such as EU GDPR Article 9, US state opt-in rules, Australian Privacy Principle 3 and Canadian express consent) to process your health signals. That consent is:
- Explicit: you actively opt in before any health data is processed.
- Per-source: you consent to each connector separately, and can connect or disconnect them one at a time.
- Revocable at any time: withdrawing consent is as easy as giving it, and stops future processing of that source.
How we use your data
We use your data to:
- build and maintain your personal health digital twin;
- learn your baselines and notice meaningful changes;
- send you check-ins: a morning brief, an evening wrap, and nudges when your data warrants one — you control how present Aura is, and you can quieten or stop check-ins at any time;
- operate, secure and improve the service.
We do not use your health data for advertising, and we do not sell data that identifies you.
Cookies & analytics
This website sets no analytics cookies and sends no analytics data until you accept. Until then nothing about your visit leaves your browser, and declining keeps it that way.
If you accept, we start PostHog, a product analytics tool, to understand how the site and the product are used and where they are confusing. PostHog processes this on EU infrastructure. We configure it deliberately narrowly: no autocapture of the elements you interact with, no session recording, and page text and element attributes are masked before anything leaves your browser. It measures the shape of a visit, not its contents.
Your health data never reaches it. Nothing you connect from a wearable or app, nothing you tell Aura in conversation, no email or message content, no imported file, and no location is sent to analytics, whether or not you accept.
Your choice is remembered in your browser rather than in a profile we hold about you, and you can change it whenever you like: in the product, under Settings → Privacy & analytics, or by clearing this site's storage in your browser. Declining costs you nothing — Auracle works identically either way.
Wearable connectors
Auracle only pulls data from the sources you explicitly connect. Nothing is collected from a source you have not authorised. Connections use each provider’s standard authorisation flow, and the access tokens we hold on your behalf are encrypted at rest. When you disconnect a source, we stop pulling new data from it.
Where your data is processed
We are building Auracle to process your data within our own UK/EU cloud tenant. This is a direction of travel, not a guarantee of every processing arrangement today; we will update this section as that infrastructure matures. Where data is processed outside your country, we put appropriate safeguards in place as required by applicable data protection law.
Sharing your data
We do not sell personal data that identifies you. We do not share your health data with third parties without your consent. We use a small number of service providers (for example, cloud hosting, message delivery and, where you opt in, PostHog EU analytics) strictly to operate Auracle; they act on our instructions under contract and may not use your data for their own purposes. We may disclose data where we are legally required to do so.
Aggregated & de-identified data
We may combine and transform the information we hold into aggregated or de-identified form that no longer identifies you, or any individual, and cannot reasonably be linked back to a person. We take technical and organisational measures to make sure it stays that way, and it never includes your precise location. Once information has been de-identified in this way it is no longer personal data about you. We may use and share it, for example to understand health and wellness trends, to carry out research, to develop and improve our products and models, and for other business purposes. Whenever we do, we publicly commit to maintaining it in de-identified form, we will never attempt to re-identify anyone from it, and we contractually require anyone who receives it to commit to the same.
Retention & deletion
We keep your personal data only for as long as we need it to provide the service to you, or as required by law. When you delete your account, or ask us to erase your data, we delete or irreversibly anonymise it within a reasonable period, except where we must retain something to meet a legal obligation.
Your rights
Wherever you live, you have the right to:
- access the personal data we hold about you;
- rectify data that is inaccurate or incomplete;
- erase your data (“the right to be forgotten”);
- port your data: receive it in a portable, machine-readable format;
- withdraw consent at any time, per source, without affecting past processing;
- complain to your data protection regulator. The regulator for your region, and any additional local rights, are set out in Regional terms below.
To exercise any of these, email privacy@auracare.org.uk. We would always welcome the chance to resolve a concern directly before you approach a regulator.
Regional terms
Everything above applies wherever you are. This section adds the commitments and rights specific to each region we launch in. Whichever region you are in, the way to exercise a right is the same: email privacy@auracare.org.uk.
United Kingdom
The UK is our home market, and the policy above is written to UK law: we are the data controller, established in England & Wales, processing your health data as special-category data under the UK GDPR on the basis of your explicit consent, with the ICO as our supervisory authority. A few UK-specific points sit alongside that:
- Proactive check-ins are part of the service you sign up for. Any purely promotional messaging follows PECR: we ask for consent first and include an opt-out in every such message.
- Before launch we complete a Data Protection Impact Assessment covering the large-scale processing of health data and location that Auracle involves.
- You can complain to the Information Commissioner's Office, though we would always welcome the chance to resolve a concern with you first.
United States
Auracle is a consumer wellness product and is not covered by HIPAA; your protections come from federal consumer law and state privacy law, and from the promises in this policy. Where your state treats health data or precise location as sensitive data, we ask for your opt-in consent before processing it, whatever state you are in. You have the right to access, correct, delete and port your data, to appeal a decision we make about a request, and to withdraw consent at any time.
- We do not sell your personal data, and we do not share it for targeted advertising. Because we never do this, there is no need to opt out, but we still honour the Global Privacy Control signal.
- As a vendor of personal health records, we follow the FTC Health Breach Notification Rule: if your unsecured health data is ever breached or disclosed without your authorisation, we will notify you within 60 days.
- We never use your location to infer visits to healthcare facilities, and we do not geofence health services.
- Washington and Nevada residents: your consumer health data rights are set out in our separate Consumer Health Data Privacy Policy.
Canada
We handle your data under PIPEDA. At launch Auracle is offered in English and is not available in Quebec; if we open Quebec, we will first meet the requirements of its private-sector privacy law (Law 25), including service in French, and update this section. Your health data is sensitive, so we collect it only with your express consent, purpose by purpose. You can access and correct your data, withdraw consent, and ask us what we hold about you; optional features such as precise location can be switched off at any time. Proactive check-ins are part of the service and stay under your control. Promotional messages follow CASL: we send them only with your express consent, and every one identifies us and includes an unsubscribe. If we ever have a breach creating a real risk of significant harm, we will notify you and report it to the Office of the Privacy Commissioner of Canada. You may complain to the OPC.
Australia
We handle your data under the Privacy Act 1988 and the Australian Privacy Principles. Your health data is sensitive information, collected only with your consent. Your data is processed outside Australia, in the United Kingdom, the European Union and the United States by us and the service providers described above; we remain accountable for it under APP 8 wherever it is processed. Commercial electronic messages follow the Spam Act 2003: consent first, clear identification, and a working unsubscribe in every message. Eligible data breaches are notified to you and to the OAIC under the Notifiable Data Breaches scheme, and you may complain to the OAIC.
Ireland & the EEA
Auracle is not currently available in Ireland or the wider EEA. This release does not launch there, and we do not offer the service to, or collect data from, people in the EEA. When we do open an EEA market, we will appoint and name our EU representative (Article 27 EU GDPR) here, set out the EU-specific rights and the relevant supervisory authority (such as the Irish Data Protection Commission), and update this section before any EEA launch.
Contact
Questions about this policy, or about how we handle your data? Write to us at privacy@auracare.org.uk and we’ll be glad to help.