Privacy Policy
Aura Twin is built around a simple principle: your chats are yours alone. They are encrypted on your device before they leave it, and the server is a blind router — we cannot read them, ever. We collect what we need to run the matching service and the AURA token ledger, nothing more. We never sell your data, never run third-party ad trackers, and never hand your personal information to third parties for their own use. You can access, correct, or delete your data at any time by writing to us. This policy tells you exactly what we collect, why, and for how long.
1.Who we are
Aura Social Pty Ltd (trading as Aura Twin) is the data controller for personal information collected through the Aura Twin app and this website. We are an Australian company (ACN 696 919 963), operating under the laws of Queensland, Australia.
Our registered address and contact details are set out in Section 15. Where this policy refers to “we”, “us”, or “our”, it means Aura Social Pty Ltd.
This policy covers personal information collected through:
- The Aura Twin Android application
- The website at auratwin.co
- Any email or other communication you send us
2.What we collect
We collect only what the service needs to function. Here is exactly what that is:
Account information
- Email address — used to sign in, verify your account, and contact you about your gigs.
- Passkey or password — a passkey is a cryptographic credential created on your device via Android Credential Manager; we store the public key only and your private key never leaves your device. If you use a password instead, we store only a one-way hash of it, never the password.
- Display name — the name you choose to be known by in the app.
- Suburb — optional, used for hyper-local matching. We keep only your suburb — never your street address — and build no location history. If you share your location, precise GPS is used only briefly to place you in a suburb, then discarded within 30 minutes.
Optional profile details
Everything beyond the basics above is optional — you choose whether to add it: your bio, interests, skills, rates, languages, pronouns, photos, and, if you choose, your date of birth and phone number. Your date of birth and phone number are kept private and are not shown to other users.
Licences a tasker chooses to declare (taskers only)
We do not require government photo ID, a date of birth, or an ABN to become a tasker or to bid, and we do not collect any government identity document. A tasker may choose to list, in text, any licences, qualifications, or an ABN they say they hold — for example a licence type and, optionally, a licence number they type in.
We do not collect, store, or scan any licence document or image. What a tasker types is their own claim, and we do not verify it — not that it is genuine, not that it is current with any regulator. Posters are reminded to check it directly. See Section 3 for what we don't do here (including background checks).
Gig metadata
- Gig title, category, and suburb
- Bid amounts in Aura credits
- Gig status and completion timestamp
- Dispute flags (if raised)
Communication metadata (not content)
When messages are sent between users, we record:
- Sender and recipient account identifiers
- Timestamp
- Approximate message size
We never record the message body. Chat plaintext and bid contents are encrypted on your device before transmission. The server cannot decrypt them.
Device information
- Firebase Cloud Messaging (FCM) push token — used to deliver notifications when you are offline
- App version and OS version — used for support and compatibility
Map state (transient)
When you view the map, Mapbox receives your viewport bounds to serve the correct map tiles. This is transient — we do not log your map history or derive your movement patterns from it.
Waitlist information
If you submit a waitlist request via this website, we collect your email address, mobile number, postcode, role, and an optional one-sentence note. This data is submitted directly to Supabase via a REST POST and stored in our Supabase project database. Supabase is listed as a sub-processor in Section 6 of this policy and is subject to the same data-handling commitments. We do not use a mailto: link or any other third-party form processor for this data.
3.What we don't collect
Beyond chat content, we also do not collect:
- Bid contents — also encrypted end-to-end
- Card or bank details — gig payments happen directly between people and never pass through Aura. Optional AURA top-ups are processed by our payment provider (Stripe); we never see or store your full card number.
- Continuous GPS location — suburb-level only, no location history
- Advertising identifiers — no IDFA, no GAID, no ad-tech tracking
- Contacts, photos, or files from your device, unless you explicitly attach them to a gig
- Anything from third-party social networks
- Criminal background check data — we do not conduct background checks
4.How we use what we collect
We use your information only for the following purposes:
- Running the service — matching posters with taskers, routing encrypted messages, maintaining the Aura credit ledger, showing you relevant gigs in your suburb.
- Public marketplace activity — to show that Aura is active, a live sample of open gig posts may be shown publicly on our homepage, including to visitors who are not signed in. This displays only the job title, category, price, general suburb and time posted — never your name, contact details, exact address, or precise location, all of which are removed before a post is shown publicly.
- Self-declared credentials — showing posters what a tasker says they hold, clearly labelled as self-declared and not verified by us. This is never our endorsement or validation — it is the tasker's own claim, and posters are told to check it themselves.
- Dispute trail — if a dispute arises, the gig record, bid record, and communication metadata (not the message content) form a factual trail that we surface to both parties and, during the pilot, to the founder as escalation contact.
- Push notifications — delivering messages queued while your device was offline, via FCM.
- Support and safety — responding to support requests, investigating abuse reports, and enforcing these policies.
- Legal compliance — retaining data as required by law and responding to lawful government requests.
We do not use your information for advertising, profiling, or sale to third parties.
5.How we store and protect it
Our production database is hosted on Supabase (managed PostgreSQL). Data at rest is encrypted using AES-256, consistent with Supabase’s default storage encryption. During the pilot, the Supabase project is hosted on AWS infrastructure in the United States. We intend to migrate to an Australian region after the pilot concludes, and will update this section and notify users when that move is complete. See Section 7 for what this means for you.
We collect no licence documents or images, and no government identity documents. A tasker’s declared licences are stored only as the text they typed — a licence type and an optional licence number.
End-to-end encrypted message payloads are never stored in decryptable form. The server stores the ciphertext envelope (sender ID, recipient ID, timestamp, size, ciphertext) only. The private key component for E2EE is held on your device, in encrypted storage. We do not hold a usable copy of it. The one exception is if you switch on encrypted chat backup: that uploads a copy of your key wrapped with your own recovery code, so you can restore your history after a reinstall. We store that wrapped blob and cannot open it — without your recovery code it is useless to us, and we cannot recover it for you if you lose the code.
Access to our production database is restricted to named team members via Supabase’s access control. We do not share database credentials externally.
7.International transfers
Aura Twin is an Australian product, but during the pilot phase your personal information is stored on Supabase’s AWS infrastructure in the United States. By using the service, you consent to this transfer and storage. Supabase encrypts data at rest and in transit. The chat messages and bid contents you exchange with other users are end-to-end encrypted on your device before transmission and the Supabase server cannot decrypt them — see Section 3. We plan to migrate to an Australian AWS region after the pilot and will notify users via in-app message and email when that migration completes.
If you are in the European Economic Area (EEA) or United Kingdom, we rely on standard contractual clauses (incorporated into Supabase’s data processing agreement) as the legal basis for any international transfer of your data.
If you are in Australia, international transfers are governed by Australian Privacy Principle 8. We take reasonable steps to ensure that any overseas recipient handles personal information in a way that is consistent with the Australian Privacy Act 1988 (Cth).
8.How long we keep it
| Data type | Retention period |
|---|---|
| Account data (email, display name, suburb, passkey or password hash) | While your account is active, plus 90 days after a verified deletion request to allow dispute resolution on any open gigs. |
| Self-declared licences (a tasker’s typed text) | While your tasker account is active; deleted on account closure. We collect no licence documents or images, and no government identity documents. |
| Gig metadata (title, bids, status, timestamps) | 24 months from gig completion, then anonymised. Retained longer only if the gig is subject to an active legal dispute. |
| Communication metadata (sender/recipient IDs, timestamps) | 90 days from message transmission. |
| Chat ciphertext (E2EE message payloads) | Deleted from server after the recipient’s device has acknowledged delivery, or after 30 days if unacknowledged. |
| FCM push token and device metadata | While your account is active. Deleted on account closure or when the token is invalidated by the device. |
| Waitlist email and mobile number | Until you receive a pilot invite and create an account, or until you opt out, whichever comes first. Automatically deleted if the pilot does not launch within 12 months of your submission. |
9.Your rights
Under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
If you are in Australia, you have the following rights under APP 12 and APP 13:
- Access — you can request a copy of the personal information we hold about you.
- Correction — you can ask us to correct personal information that is inaccurate, out of date, incomplete, or misleading.
- Deletion — you can ask us to delete your account and associated personal information, subject to the retention exceptions in Section 8.
- Complaints — if you are not satisfied with our response to a privacy concern, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Under the GDPR (European users)
If you are in the European Economic Area or UK, you also have the right to:
- Obtain a portable copy of your data in a structured, machine-readable format
- Restrict processing of your data in certain circumstances
- Object to processing based on our legitimate interests
- Request erasure (“right to be forgotten”), subject to legal retention obligations
- Lodge a complaint with your local supervisory authority
Our lawful basis for processing is, depending on context: performance of a contract (providing the service), compliance with a legal obligation, or our legitimate interests in operating a safe and fraud-resistant platform.
Under the CCPA (California users)
California residents have the right to know what personal information we collect and to request deletion. We do not sell personal information as defined by the CCPA. To exercise your rights, contact us at the address in Section 15.
To exercise any of these rights, email info@auratwin.co. We will respond within 30 days for Australian requests and within the applicable statutory period for EU and California requests.
11.Data breaches
We take the security of personal information seriously. If an eligible data breach occurs — meaning a breach that is likely to result in serious harm to any affected individual — we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Australian Privacy Act 1988 (Cth).
This means we will:
- Notify affected individuals as soon as practicable
- Notify the OAIC as required under the NDB scheme
- Take reasonable steps to contain the breach and reduce harm
12.Children
Aura Twin is restricted to users aged 18 years and over. The pilot is an adult service involving financial transactions in the form of Aura credits and real-world task arrangements. We do not knowingly collect personal information from anyone under 18. If you believe a minor has registered, please contact us immediately at info@auratwin.co and we will close the account and delete the information.
13.Changes to this policy
We may update this policy as the service evolves. When we make material changes — such as adding a new sub-processor, changing a retention period, or launching a new feature that involves personal data — we will notify registered users by in-app notification or email before the change takes effect.
The version number and “Last updated” date at the top of this page always reflect the current version. The previous version is available on request by emailing info@auratwin.co.
14.How to delete your account
You can delete your Aura Twin account and all associated personal data at any time, directly from the app:
- Open the Aura Twin app.
- Tap Profile (bottom-right icon).
- Tap the Settings icon (top-right).
- Scroll to the bottom and tap Delete Account.
- Confirm when prompted.
What gets deleted: your profile, display name, email address, photos, declared credentials, gig history, AURA credit balance, chat keys, push notification token, and all other personal data linked to your account.
What is kept (temporarily): anonymised transaction records required for dispute resolution on any open or recently completed gigs are retained for up to 90 days, then permanently deleted. Encrypted chat messages already delivered to your chat partner’s device remain on their device but are deleted from our servers immediately on account closure.
If you no longer have access to the app, you can also request account deletion by emailing info@auratwin.co from the address associated with your account. We will process your request within 30 days.
15.Contact and complaints
If you have a question or concern about this policy or the way we handle your personal information, contact us first:
Aura Social Pty Ltd (trading as Aura Twin)
ACN 696 919 963
Queensland, Australia
info@auratwin.co
We aim to respond to all privacy enquiries within 14 days. If you are not satisfied with our response, or if we do not respond within 30 days, you may escalate to:
Office of the Australian Information Commissioner (OAIC)
oaic.gov.au
1300 363 992
GPO Box 5218, Sydney NSW 2001
For EU residents, you may also contact your local data protection authority.