Privacy Policy
Last updated 5 September 2026
Aura is built so that most privacy questions have a structural answer rather than a promised one: we cannot disclose a key we never receive. This page covers what that leaves.
The short version
Aura is a non-custodial wallet. There is no account, no sign-up and no profile, so there is very little to attach data to in the first place.
We never receive your recovery phrase, your private keys, your passcode or your backup passphrase. Those exist only on your device, and there is no code path in the app that transmits them. Everything we do receive is listed below, along with why.
If you want the engineering detail rather than the policy language, the security page lists every outbound flow row by row.
What we never collect
- Your recovery phrase, in whole or in part.
- Any private key derived from it.
- Your passcode, or the encryption key stretched from it.
- Your cloud backup passphrase, or the contents of your backup file.
- Your name, email address, phone number or government identifiers.
- Contacts, photos, precise location or advertising identifiers.
We do not run third-party advertising or analytics SDKs in the app, and we do not sell, rent or share personal data with data brokers. There is no cross-app tracking to opt out of because there is none to begin with.
What we do process, and why
Public blockchain addresses
To show balances across many networks quickly, the app can ask our indexing service for several addresses at once instead of querying each chain individually. The service receives public addresses. If it is unavailable, the app reads the chains directly from your device instead.
Submitted swap records
When you sign and broadcast a swap, the app registers it with our backend so it can follow the transaction — including the second leg of a cross-chain route — and tell you when it settles. The record holds the wallet address involved and the identifiers needed to track status. It does not hold quotes you looked at and did not take.
Push notification tokens and watched addresses
Only if you enable notifications for incoming transfers. We store the push token issued by Apple or Google for your device, and the addresses you asked us to watch, so a server can notice a deposit and notify you. Turning notifications off removes the reason to keep either.
Ordinary server logs
Our services and this website record the usual request metadata — IP address, timestamp, user agent, endpoint — for reliability and abuse prevention. These are operational logs, not a profile, and they are not joined to a wallet identity.
Third parties your device talks to
Some requests go from your phone directly to services we do not operate. We do not proxy them, which means we do not see them — and equally that we cannot make privacy promises on another company's behalf. Those services can see the network address your request arrives from, as with any internet request.
- Blockchain RPC nodes, to read balances and broadcast signed transactions.
- Swap routers — Jupiter, LI.FI, Uniswap, 0x and Relay — to price a swap you are considering.
- Price and token metadata providers, to fetch rates and logos.
- Apple and Google, for app distribution and push delivery, and iCloud or Google Drive if you choose to store an encrypted backup there.
This website
This site is a set of static pages. It sets no advertising or tracking cookies, embeds no third-party trackers, and loads no remote fonts. The interactive phone on the home page is a demo with sample balances and no network layer — it cannot hold a key or move a coin.
This website will never create, import, store or ask for a recovery phrase. Any page that does, anywhere, is not us.
Retention and deletion
Swap tracking records are kept only as long as needed to report a transaction's outcome and to diagnose failures. Push tokens and watched addresses are removed when you disable notifications, and stale tokens are discarded when Apple or Google reports a device as unreachable. Operational logs are rotated on a short schedule.
Deleting the app removes the wallet data from your device. It does not, on its own, delete a server-side notification registration; disable notifications first, or write to us and we will remove it.
Your rights
Depending on where you live, you may have rights to access, correct, delete or export personal data, and to object to certain processing. Because we operate no account system, the practical route is to tell us the address or push registration concerned and we will act on it.
One limit is worth stating honestly: data written to a public blockchain is not ours to erase. A transaction, once confirmed, is a permanent public record held by every node on that network. No wallet, ours included, can remove it.
Children
Aura is not directed to children, and it is not intended for anyone under the age at which they can lawfully agree to these terms in their country. We do not knowingly process data from children.
Changes and contact
If this policy changes materially we will update the date at the top and, where the change affects how the app behaves, say so in the app itself.
Questions about privacy: privacy@aura.finance. Security reports: security@aura.finance. We will never ask you for your recovery phrase, and you should never send it to us or to anyone else.