Privacy Policy
Last updated on 11/09/2026
We update this document whenever our practices change. If anything here is unclear, write to ola.aurean@gmail.com: privacy should not need a translator.
1. Who we are
Aurean is a brand operated by a sole proprietor registered under Brazilian company number (CNPJ) 47.378.637/0001-80, based in Curitiba, Paraná, Brazil. We are the controller of the personal data processed in the Aurean app and on this site, under the Brazilian General Data Protection Law (Law 13.709/2018, the LGPD).
This policy covers the app, this site and our official support channels. It is part of the Terms of Use and should be read alongside them.
For any privacy matter, including reaching our data protection officer, write to ola.aurean@gmail.com or message us on WhatsApp at +55 41 98532-2939.
2. What data we collect and why
In the app, this is what we collect:
- Sign-up: name or nickname, email and date of birth. Gender, phone number and profile photo only if you choose to provide them. The date of birth is used to verify age and to trigger guardian consent when needed.
- Legal guardian data: for Travelers aged 13 to 15, the email of a parent or legal guardian. It is used only to record the consent required by art. 14 of the LGPD.
- What you write: journal entries, messages exchanged with Aurean and any other reflections you add. This content is treated as sensitive data, described in section 3.
- Usage and device: screens visited, features used, session time, device identifier, operating system and aggregate performance data. Alongside it, your progress counters: Karma, usage streak and Soul Fragments collected.
- Subscription: whether the plan is free or Guardian, start, renewal or cancellation dates and transaction history. We neither receive nor store card details: those stay with the app store.
- Notifications: your device token and the preferences you have set.
- Access logs: date, time and IP address, kept for the minimum period set by the Brazilian Internet Civil Framework.
The legal bases are these. Sign-up, usage and subscription data are processed to perform the contract set out in the Terms of Use (art. 7, V of the LGPD). Aggregate, depersonalised usage data supports product improvement and fraud prevention, on the basis of legitimate interest (art. 7, IX). What you write in the journal and in conversations depends on specific, highlighted consent (art. 11, I).
On this site, collection is far smaller. Google Analytics 4 writes cookies to estimate visits and traffic sources, and only switches on after you accept the cookie notice. Vercel Web Analytics records aggregate page and performance data, with no cookie and no personal identifier. Neither of them reads what you write in the app. You can review your cookie choice at any time through the link in the footer of this page, and refusing removes nothing from the site.
3. Sensitive data: conversations and journal
Aurean only works if you say what you are feeling. That means the journal and the conversations reveal information about your emotional state and, at times, about your mental health. The LGPD calls this sensitive personal data (art. 5, II), and that is how we treat it.
This content is used for three things, and only these:
- letting the artificial intelligence answer within the context of what you have already shared, by retrieving your own earlier entries, which we call long-term memory;
- generating, for you alone, insights and the thematic classification of your conversations inside the Kingdom of Arven;
- triggering the risk-signal protocol described in the Terms of Use.
Access to long-term memory is isolated per Traveler. Aurean never brings another person's journal, conversations or insights into your conversation.
We do not use the content of your journal or your conversations for targeted advertising, to build a consumer profile or to sell to third parties. Under no circumstances.
In the internal technical logs of the artificial intelligence, your identifier appears in pseudonymised form, which reduces the exposure of identifying data in those records.
4. Who we share data with
We do not sell personal data and do not hand it over for advertising. We share only with suppliers acting as processors, under our instruction and bound by contractual confidentiality:
- Google (Firebase and Google Cloud Platform): authentication, database, server functions, storage, messaging and app analytics.
- Google (Gemini models): processing of messages and journal entries to generate the artificial intelligence's replies and the long-term memories.
- RevenueCat: subscription lifecycle management and syncing of the contracted plan.
- Brevo: transactional email, such as cancellation confirmations and the guardian consent flow.
- Cloudflare: storage of the images used in gamification.
- Vercel: hosting of this site and aggregate performance metrics.
About the artificial intelligence. Every message you send to Aurean, and the journal entries used for long-term memory, must be transmitted to the language model provider for the reply to exist at all. This happens through our own infrastructure, without exposing credentials on your device. We do not authorise, and contractually forbid, that provider from using Travelers' content to train or improve general-purpose models. Processing is limited to generating your reply and your memories.
These suppliers keep servers outside Brazil, so there is an international data transfer. It is carried out with the safeguards of art. 33 of the LGPD and contractual instruments requiring protection equivalent to Brazilian law.
We may also share data when there is a court order, a request from a competent authority, or a need to exercise rights in legal proceedings.
5. How long we keep it
Each type of data has its own period:
- What you create in the app is kept while your account exists.
- Access logs (date, time and IP) are kept for at least 6 months, as required by art. 15 of the Brazilian Internet Civil Framework. That period runs even if you request deletion earlier.
- Subscription and transaction records are kept for as long as tax and contractual obligations require.
- Measurement data from this site follows Google Analytics' own retention period, set to the shortest available.
When you request account deletion, we erase the associated personal data, including journal, conversations, insights and long-term memories, except what the law requires us to retain. Section 6 explains how.
6. How to delete your account and your data
Deletion is done by you, inside the app, in your account settings, and it erases your content along with it. If you have already uninstalled the app, you can request deletion by email: write to ola.aurean@gmail.com from the same address you registered with, using the subject Account deletion.
We confirm the request within 15 days and complete the erasure within 30 days, counted from the request.
The Account deletion page details both paths, what is erased and what the law requires us to keep.
7. Minors
Aurean is allowed from the age of 13. Below that, use is forbidden even with a guardian's authorisation, given the nature of the subjects that come up in conversation.
Between 13 and 15, the account depends on specific, verified consent from a parent or legal guardian, as art. 14 of the LGPD requires. The flow is this: the teenager provides the guardian's email at sign-up, the guardian receives a message with an approval link valid for a set period, and the account is only activated after that confirmation. Without confirmation within the deadline, the account is suspended and the data is erased. From the age of 16 there is no guardian consent step: the Traveler signs up directly.
The guardian's email and the approval date are kept only to evidence that consent.
A legal guardian may, at any time, request information about the data processed, withdraw consent or ask for the account to be deleted, by writing to ola.aurean@gmail.com.
8. Your rights under the LGPD
Art. 18 of the LGPD guarantees that you may request, at any time:
- confirmation that we process your data;
- access to your data;
- correction of incomplete, inaccurate or outdated data;
- anonymisation, blocking or erasure of unnecessary data or data processed outside the law;
- portability of your data to another provider;
- erasure of data processed on the basis of your consent, except what the law requires us to keep;
- information about who we share your data with;
- information about the option not to consent and about what happens if you do not;
- withdrawal of consent already given;
- review of automated decisions that affect your interests.
Just write to ola.aurean@gmail.com. We answer within 15 days.
One consequence that needs to be clear: withdrawing consent for the sensitive data in section 3 stops the journal and the conversations with the artificial intelligence, because those features depend entirely on that processing.
9. Security
The measures we take include mandatory authentication to reach the account, rules restricting each Traveler to their own data, credentials for the artificial intelligence services kept on the server alone and never in the app installed on your device, encrypted connections (HTTPS) across the site and the app, and infrastructure from providers holding international information security certification.
No system is infallible. If an incident with relevant risk occurs, we notify the Brazilian data protection authority (ANPD) and, where applicable, you, within the deadlines and in the form the LGPD requires.
Found a flaw? Write to ola.aurean@gmail.com. The channel is open for exactly that.
10. Changes to this policy
This policy is updated whenever our practices change. The version in force is the one identified by the date at the top of this page, and relevant changes are announced through Aurean's official channels.
A change that widens collection never applies retroactively. If we widen the purposes for processing the sensitive data in section 3, we ask for new consent first, whenever the LGPD requires it.

