Privacy Policy
Draft v0.1.0 · Not yet in force · Last updated 2026-07-23
Draft for review. This is a pre-launch draft pending review by qualified legal counsel. Items marked [FD-…] are decisions the founder must make; items marked [IA-…] are engineering assumptions to verify. They are intentional and not yet in force.
In plain English: we collect very little — mainly your email, and, if you sign in, your GitHub profile basics. Your code, notes, and project state stay on your device. When you invoke AI, only the content you choose is sent to the provider you picked. We store limited account and workspace metadata, session records (including IP, for security), and privacy-respecting analytics. We do not sell your data, run ads, or profile you. You can access, correct, export, or delete your data.
1. Who We Are and Our Role
Auric is operated by [FD-001], [FD-002], with registered office at [FD-004]. Auric is the operational continuity engine described in these documents.
Auric is the data controller (EEA/UK), the data fiduciary (India, where applicable [FD-006]) under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and the business (California). Our EEA/UK representative, where required, is [FD-007]. Our Grievance Officer for India, where applicable, is [FD-008].
2. Definitions
Capitalized terms have the meanings given in Auric's Master Definitions, published in the Terms of Service and shared across all of Auric's legal documents — including Services, Project Data, Operational State, Workspace, AI Provider, Telemetry, Account, and Session. No term is redefined here.
3. Where Your Data Lives
Auric's architecture is the foundation of its privacy posture. Understanding where data lives explains most of this Policy at a glance.
| Location | What it holds | Access |
|---|---|---|
| Your device (local-first) | Project Data, Operational State, and prompts. | You. Not transmitted to Auric [IA-004]. |
| Auric servers | Email, GitHub profile, waitlist and attribution data, Workspace metadata (repo remote URL and name), session records including full IP [IA-009], server analytics [IA-010], and support or contact messages. | Auric and our subprocessors, on a need-to-know basis. |
| AI Provider (only on invocation) | The prompt content you choose to include [IA-003]. | The provider you configured, under its own terms. |
4. Information We Collect
You provide: your email (waitlist, newsletter, or contact); your GitHub username; contact-form name, company, role, and message; and Feedback.
Via GitHub and WorkOS at sign-in: your GitHub numeric id, username, email (if public), name, and avatar. WorkOS access and refresh tokens are used transiently to read your profile and are never stored.
Automatically: device and browser information; coarse location as ipCountry/ipCity (not precise geolocation); device type; referrer and UTM attribution; usage and telemetry events; and, for CLI sessions, your full IP address for security audit [IA-009].
We do not collect: your Project Data or Operational State centrally; payment or card data (no billing system exists); or sensitive personal data (please do not submit it to us or include it in prompts).
5. How We Use Your Information
We use it to operate the Services; authenticate and secure Accounts and sessions; run the waitlist, referral, and beta programs; send service, security, and (with your consent) marketing email; provide support; measure and improve the Services via Telemetry; prevent abuse and fraud; and comply with law.
We do not sell your data or share it for cross-context behavioral advertising, we do not build behavioral profiles, and we do not use your project data or prompts to train our own models. Note that our server analytics may key on your email as a distinct identifier once known [IA-010].
6. Legal Bases (EEA and UK)
We rely on: performance of a contract (providing the Services, authentication, beta access); legitimate interests (security, analytics, product improvement, and service messages); consent (marketing and non-essential cookies); and legal obligation. For India, where applicable [FD-006], we rely on your consent and the legitimate uses recognized under the DPDP Act. You may withdraw consent, or object to legitimate-interests processing, at any time.
7. AI Provider Processing
Auric routes only what you invoke, to the AI Provider you configured [IA-003]; that provider's terms govern its retention and any model training. Nothing is sent in the background. Once content reaches a provider, Auric cannot retrieve or delete it. See the AI Usage Policy for detail.
8. GitHub Authentication
Sign-in is optional and handled by GitHub through WorkOS via OAuth, limited to the scopes shown to you. GitHub's and WorkOS's handling of your information is governed by their own policies. You can revoke Auric's access at any time in your GitHub settings.
9. Cookies and Telemetry
Vercel Web Analytics and Speed Insights (cookieless, aggregated) are always on; PostHog runs only if enabled [FD-011] [IA-008]; a server event log mirrors events for our own analysis. Admin sessions use a strictly-necessary cookie, and Cloudflare Turnstile may set a challenge token. Full detail is in the Cookie Policy. We honor Global Privacy Control signals.
10. Sharing and Subprocessors
We share personal information only with the subprocessors below, with the AI Provider you invoke, for legal or safety reasons, or in a business transfer. We do not sell personal information and do not share it for cross-context behavioral advertising.
| Subprocessor | Function | Region |
|---|---|---|
| Vercel | Hosting, cookieless analytics, speed insights | United States |
| Supabase | Database for account and waitlist data | [FD-009 — confirm region] |
| WorkOS | GitHub OAuth and authentication | United States |
| GitHub | Identity provider | United States |
| Resend | Transactional email and delivery webhooks | United States |
| Upstash | Rate limiting and caching | [confirm region] |
| Cloudflare | Turnstile bot protection, network security | United States / global |
| PostHog | Product analytics, if enabled [FD-011] | [confirm region] |
| Anthropic, OpenAI, Google, local models | AI processing — only when you invoke AI | Provider-dependent |
11. International Data Transfers
Your information may be processed in the United States and elsewhere. For EEA/UK and other restricted transfers we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable. For India, where applicable [FD-006], we follow DPDP requirements and any Government-notified restrictions.
12. Data Retention
Retention periods are set by [FD-009]. Indicatively: waitlist data until you ask us to remove it or the program ends; Account and Workspace metadata for the life of the Account, then deleted or de-identified within [FD-009] days; session records until expiry or revocation; support communications up to [FD-009]; analytics up to [FD-009]; and security or legal records as required by law. Local data retention is entirely under your control.
13. Security
See the Security Policy for detail. Confirmed measures include storing only a hash of session tokens, immediate session revocation, bot protection, and rate limiting. Encryption in transit (TLS) [IA-001] and at rest [IA-002] is provided at the infrastructure layer. We do not claim SOC 2 or ISO 27001 certification.
14. Data Breach Notification
On a confirmed personal-data breach we act promptly to contain and assess it, and notify you and the relevant authorities where required. For the EEA/UK we notify the competent authority within 72 hours and affected individuals where the risk is high. For India, where applicable [FD-006], we notify the Data Protection Board and follow CERT-In timelines under the Information Technology Act.
15. Automated Decision-Making
We do not make decisions with legal or similarly significant effects about you through solely automated means, and we do not profile for such purposes.
16. Your Rights and Choices
Depending on where you live, you may have rights to access, correction, deletion, portability, objection and restriction, withdrawal of consent, and non-discrimination; India adds nomination and grievance. Today these are handled by email [FD-012] — self-serve export and deletion are not yet built. To exercise a right, email privacy@auric.cx; we respond within the timeframe required by law and may verify your identity first.
17. Regional Disclosures
EEA and UK: you may complain to your supervisory authority (in the UK, the ICO). California: you have the rights to know, access, correct, and delete, and to opt out of any sale or sharing — we do neither — and we honor Global Privacy Control and do not sell or share the data of consumers under 16. India, where applicable [FD-006]: you have Data Principal rights, may contact our Grievance Officer [FD-008], and may escalate to the Data Protection Board of India.
18. Children's Privacy
The Services are not directed to children, and we do not knowingly collect data from anyone under [FD-014]. For India, where applicable [FD-006], we do not knowingly process the data of anyone under 18 without verifiable parental consent, and we do not undertake tracking or targeted advertising directed at children.
19. Changes and Contact
We may update this Policy; material changes are notified per [FD-016] and take effect on the stated date. Contact us at privacy@auric.cx for privacy and data-rights requests, grievance@auric.cx for grievances (India) [FD-008], or hello@auric.cx for general enquiries. Postal: [FD-004].
Document control
| Field | Value |
|---|---|
| Document ID | AUR-LEG-002 |
| Version | 0.1.0 |
| Status | Draft — Pre-Counsel Review |
| Owner | Auric [FD-013] |
| Review frequency | Quarterly during beta, or on material change |
| Related documents | Terms (001), Cookie (003), AI Usage (005), Security (006), Beta (008) |
| Applies to | Auric Closed Beta — all deployment models |
Change log
v0.1.0 (2026-07-23): Initial draft. Supersedes the pre-architecture privacy draft; disclosures aligned to the actual data schema.
© 2026 Auric. All rights reserved.