Privacy Policy
Last updated: February 11, 2026This Privacy Policy ("Policy") describes how Aurora Technologies LLC ("Company," "we," "us," or "our"), a Pennsylvania limited liability company, collects, uses, and discloses information in connection with the TrueRune mobile application ("App") and related services (collectively, the "Services"). By accessing or using the Services, you ("User" or "you") acknowledge that you have read, understood, and agree to be bound by this Policy. This Policy applies to all users worldwide, including users in the United States, European Economic Area ("EEA"), United Kingdom ("UK"), Switzerland, and all other jurisdictions.
1. Information We Collect
1.1 Information You Provide
TrueRune is designed with a privacy-first architecture. We do not require account creation, and we do not collect names, email addresses, phone numbers, or other personally identifiable information ("PII") through the App.
If you contact us via email at support@auroratechnologies.xyz, we will collect the information you voluntarily provide (e.g., your email address and message content) solely for the purpose of responding to your inquiry.
1.2 Information Collected Automatically
The App does not employ analytics frameworks, advertising SDKs, tracking pixels, cookies, or browser/device fingerprinting. We do not collect device identifiers (IDFA, GAID), IP addresses, usage logs, or telemetry data.
Our API proxy (hosted on Cloudflare Workers) maintains temporary, in-memory rate-limit counters keyed to anonymized device identifiers or IP addresses provided by Cloudflare. These counters are not logged, not persisted to disk, and are automatically purged on worker restart. Cloudflare may independently process connection metadata (such as IP addresses) pursuant to its own privacy policy as part of its standard infrastructure services.
1.3 AI Interpretation Data
When you request an AI-powered rune interpretation, the following data is transmitted through our Cloudflare Worker proxy to Google Gemini:
- The rune(s) drawn and their orientation (upright/reversed)
- Any optional question text you provide
- A system instruction prompt (controlled by us, containing no user data)
Important: Do not include personal, sensitive, or identifying information in your question text. Questions are transmitted to Google for AI processing.
This data is transmitted in real time and is not stored, logged, or cached by our proxy. Google processes this data subject to the Google Privacy Policy and Gemini API Terms of Service. We have no access to or control over Google's data retention practices for API requests. Google may process this data on servers located in the United States or other countries.
1.4 Subscription & Payment Data
All payment transactions are processed exclusively by Apple (via the App Store) or Google (via Google Play). We do not receive, process, or store any payment card numbers, billing addresses, or financial account information.
We use RevenueCat, Inc. ("RevenueCat") as a subscription management platform. RevenueCat receives anonymized transaction data from Apple/Google to manage entitlement status. RevenueCat may process an anonymous app user ID and transaction identifiers. RevenueCat's processing of data is governed by the RevenueCat Privacy Policy.
1.5 Local Device Storage
The App stores the following data locally on your device using AsyncStorage:
- Your app preferences and settings
- Reading journal entries you create
- Cached daily rune interpretations
- Streak tracking data
- Push notification preferences
This data never leaves your device and is not transmitted to any server. Uninstalling the App permanently deletes all locally stored data.
1.6 Push Notifications
The App may request your permission to send push notifications (e.g., daily rune reminders) using the Expo Notifications framework. Push notification tokens are processed locally on your device and through Apple Push Notification Service (APNs) or Google Firebase Cloud Messaging (FCM) as applicable. We do not store push notification tokens on our servers. You may disable push notifications at any time through your device settings. Disabling notifications does not affect the functionality of the App.
2. How We Use Information
To the limited extent we process any information, it is used exclusively to:
- Provide and maintain the Services
- Process AI interpretation requests in real time
- Enforce rate limits to prevent abuse
- Deliver push notifications you have opted into
- Respond to support inquiries
- Comply with legal obligations
We do not sell, rent, lease, or trade any user information to third parties. We do not "share" personal information for cross-context behavioral advertising as defined under the CCPA/CPRA. We do not engage in behavioral advertising, profiling, or automated decision-making.
3. Third-Party Services
The Services integrate with the following third-party providers, each of which operates under its own privacy policy:
- Apple Inc. (App Store, APNs) — App distribution, payment processing, subscription billing, and push notification delivery (Privacy Policy)
- Google LLC (Google Play, FCM, Gemini API) — App distribution, payment processing, push notification delivery, and AI-powered rune interpretations (Privacy Policy)
- RevenueCat, Inc. — Subscription entitlement management (Privacy Policy)
- Cloudflare, Inc. — API proxy hosting and DDoS protection (Privacy Policy)
We encourage you to review the privacy policies of these third parties. We are not responsible for the privacy practices of third-party services.
4. Data Retention
We do not maintain databases of user data. Rate-limit counters are ephemeral and exist only in volatile memory. Support correspondence is retained only as long as necessary to resolve your inquiry and for reasonable record-keeping purposes, after which it is deleted. Local device data persists until you uninstall the App or manually clear app data.
5. Data Security
All data transmitted between the App and our servers is encrypted using TLS 1.2 or higher. Our API proxy runs on Cloudflare's global edge network with enterprise-grade security protections. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. In the unlikely event of a data breach affecting your personal information, we will notify you and the applicable regulatory authorities as required by law.
6. Children's Privacy (COPPA Compliance)
The Services are not directed to children under the age of 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children under these ages. We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at support@auroratechnologies.xyz and we will promptly delete such information. If we become aware that we have collected personal information from a child without verified parental consent, we will take steps to delete that information as quickly as possible.
7. International Data Transfers
The Services are operated from the United States. If you access the Services from outside the United States, including from the EEA, UK, or Switzerland, you acknowledge that your information may be transferred to, stored, and processed in the United States and other jurisdictions where our service providers operate, which may have different data protection laws than your jurisdiction.
For users in the EEA, UK, and Switzerland: where data is transferred outside of the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms. By using the Services, you acknowledge these transfers.
8. Your Privacy Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information. Given that we do not collect or store PII through the App, most of these rights are satisfied by design. For any privacy-related requests, contact support@auroratechnologies.xyz. We will respond to verifiable requests within the timeframes required by applicable law.
8.1 California Residents (CCPA/CPRA)
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.), California residents have specific rights regarding their personal information, including:
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you
- Right to Delete: You have the right to request deletion of personal information we have collected
- Right to Correct: You have the right to request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information as defined under the CCPA/CPRA
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights
- Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined under the CPRA
To exercise these rights, contact us at support@auroratechnologies.xyz. We will verify your identity before processing your request. You may also designate an authorized agent to make a request on your behalf.
Categories of Personal Information: In the preceding 12 months, we have not collected any categories of personal information as defined under the CCPA/CPRA through the App. We have not sold or shared personal information. We do not use sensitive personal information for purposes beyond what is necessary to provide the Services.
8.2 European Economic Area, UK, and Switzerland (GDPR/UK GDPR)
If you are located in the EEA, UK, or Switzerland, you have the following rights under the General Data Protection Regulation (EU) 2016/679 and the UK GDPR:
- Right of Access (Art. 15) — Request access to your personal data
- Right to Rectification (Art. 16) — Request correction of inaccurate data
- Right to Erasure (Art. 17) — Request deletion of your personal data
- Right to Restrict Processing (Art. 18) — Request restriction of processing
- Right to Data Portability (Art. 20) — Receive your data in a structured, machine-readable format
- Right to Object (Art. 21) — Object to processing based on legitimate interests
- Right to Withdraw Consent (Art. 7(3)) — Withdraw consent at any time where processing is based on consent
Legal Bases for Processing: To the extent we process personal data, our legal bases are: (a) your consent (e.g., push notifications), (b) performance of a contract (e.g., providing the Services), and (c) our legitimate interests in operating, maintaining, and improving the Services, provided such interests are not overridden by your rights and freedoms.
Data Protection Officer: Given the minimal data processing activities, we have not appointed a Data Protection Officer. For privacy inquiries, contact support@auroratechnologies.xyz.
You have the right to lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu. For the UK, contact the Information Commissioner's Office (ICO) at ico.org.uk.
8.3 Other Jurisdictions
If you reside in a jurisdiction with applicable data protection laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, and other US states with consumer privacy laws), you may have similar rights to access, delete, correct, and opt out of certain data practices. Contact us at support@auroratechnologies.xyz to exercise your rights. We will process your request in accordance with applicable law.
9. Do Not Track Signals
The App does not track users across third-party websites or services, and therefore does not respond to Do Not Track ("DNT") signals. We do not engage in cross-site tracking.
10. Changes to This Policy
We reserve the right to modify this Policy at any time. Material changes will be indicated by updating the "Last updated" date at the top of this page and, where required by applicable law, by providing notice through the App or via email. Your continued use of the Services after any modification constitutes acceptance of the revised Policy. We encourage you to review this Policy periodically.
11. Contact Information
For questions, concerns, or requests regarding this Privacy Policy, including requests to exercise your privacy rights, contact:
Aurora Technologies LLC
Email: support@auroratechnologies.xyz
We will endeavor to respond to all privacy inquiries within 30 days (or within shorter timeframes where required by applicable law, such as 45 days under the CCPA or one month under the GDPR).