Privacy policy

Last updated: 06.10.2026

This policy explains which personal data Aura processes, for which purposes, on which legal basis, and what rights you have.

1. Controller

The controller responsible for processing your data (Art. 4(7) GDPR) is:

Steven Kelm
Merheimer Platz 12
50733 Köln
Germany
kontakt@aura-sport.de

2. Account and sign-in

To use Aura, you create an account. You can use the app with a guest account without providing contact details, sign in with a link sent by email, or sign in with Google or – on iPhone – with Apple. You can back up a guest account the same ways later. We process:

The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).

Signing in with Google is provided by Google Ireland Limited (address in section 6), signing in with Apple by Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. When you delete your account, we also revoke the sign-in with Apple.

We send the emails with the sign-in or confirmation link through Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France, which acts as our processor (Art. 28 GDPR). Your email address, the content of the email and technical delivery data such as the time and delivery status are processed.

To protect against automated sign-ins (bots), we use Cloudflare Turnstile by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, for guest and email sign-ins. Technical data such as your IP address and characteristics of your device are sent to Cloudflare. The legal basis is our legitimate interest in the security of the service (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-U.S. Data Privacy Framework.

3. Profile, food journal and workouts

To calculate your calorie and nutrient needs and to provide the core features of the app, we process:

This data may allow conclusions about your health and is then specially protected. We process it based on your explicit consent (Art. 9(2)(a) GDPR), which you give after signing in and before setting up your profile, and to perform the user agreement (Art. 6(1)(b) GDPR). As proof, we store in your account when you agreed to which version of the consent. You can withdraw your consent at any time by deleting your account.

The data is first stored on your device and synchronized with our backend, so that it is backed up and available on several devices. The backend is operated by Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992, as our processor (Art. 28 GDPR) on servers in the European Union. Access from outside the EU, e.g. for support purposes, is only permitted on the basis of the EU Standard Contractual Clauses.

4. Food database (Open Food Facts)

When you search for food or scan a barcode, we send the search term or barcode to the free food database Open Food Facts (Open Food Facts, 21 rue des Iles, 94100 Saint-Maur-des-Fossés, France). Product images are loaded directly from their servers. Your IP address is transmitted, but no account ID or other information about you. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).

5. Apple Health and Health Connect

If you connect Aura with Apple Health (iOS) or Health Connect (Android), the app reads the following data after your permission:

The app only reads this data and never writes any data. It is processed exclusively on your device to show your activity and to calculate your calorie needs. It is not sent to our servers or to third parties and is not used for advertising or analytics.

The legal basis is your explicit consent (Art. 9(2)(a) GDPR), which you give in the permission dialog of the operating system. You can disconnect at any time in the app (settings) or in the system settings.

6. Usage analytics (Google Firebase Analytics)

Only if you agree, we use Google Firebase Analytics to record how the app is used, in order to improve it. We record:

We never record the names of your foods, your search terms, nutrients, weights or health data. The data is not used for advertising.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data may be transferred to Google LLC in the USA; Google is certified under the EU-U.S. Data Privacy Framework. Event data is deleted after 2 months.

The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Until you agree, the collection is disabled. You can withdraw your consent at any time with effect for the future in the settings under "Privacy settings"; this also deletes the analytics data on your device.

7. Crash reports (Google Firebase Crashlytics)

So that we can detect and fix bugs quickly, the app sends a report to Google Firebase Crashlytics when it crashes or a technical error occurs. It contains:

Provider and data transfer as in section 6. Reports are deleted after 90 days. The legal basis is our legitimate interest in a stable app without bugs (Art. 6(1)(f) GDPR). You can object at any time by turning off crash reports in the settings under "Privacy settings"; reports that have not been sent yet are then discarded.

8. Fonts (Google Fonts)

On first launch, the app loads fonts from servers of Google Ireland Limited (provider and data transfer as in section 6). Your IP address is transmitted to Google. The legal basis is our legitimate interest in a consistent presentation (Art. 6(1)(f) GDPR).

9. Website (aura-sport.de)

Our website aura-sport.de is provided through GitHub Pages by GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. When you visit it, GitHub processes technically necessary data such as your IP address, the date and time of the request and information about your browser and operating system, in order to deliver the pages and protect them against attacks, and stores it temporarily in server logs. The legal basis is our legitimate interest in a secure and working website (Art. 6(1)(f) GDPR). GitHub is certified under the EU-U.S. Data Privacy Framework.

The website sets no cookies, uses no tracking and loads no content from other servers.

10. Contact by email

If you email us, we process your email address and the content of your message to answer your request. The legal basis is the performance of the user agreement if it concerns the use of the app (Art. 6(1)(b) GDPR), otherwise our legitimate interest in answering your request (Art. 6(1)(f) GDPR). We delete your message once your request is settled, unless statutory retention obligations apply.

Our mailbox is operated by Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, the Netherlands, as our processor (Art. 28 GDPR). The emails are stored in data centers in the EU.

11. Feedback in the app

If you send us a message in the app under Settings → Feedback (feedback, wishes, bug reports), we process:

We use this information to improve the app and fix bugs. The legal basis is our legitimate interest in developing the app further (Art. 6(1)(f) GDPR). Please don't include health data or passwords in your message.

Only if you agree, we may contact you about your message at your account's email address (Art. 6(1)(a) GDPR). You can withdraw this consent at any time by emailing us; section 10 then applies to our reply.

The messages are stored in our backend at Supabase (as in section 3). We delete them once we no longer need them to improve the app, at the latest when your account is deleted.

12. Retention and deletion

We store your account, profile, journal and workout data for as long as your account exists. You can delete your account at any time in the app under Settings → Profile → Delete account or request the deletion by email (see aura-sport.de/en/delete-account). This deletes all your data on our servers and on the device, unless statutory retention obligations apply. Guest accounts that haven't been used for 90 days are deleted automatically with all their data, since they can't be accessed anymore after signing out or deleting the app anyway. Analytics data and crash reports are deleted after the periods stated in sections 6 and 7, feedback as stated in section 11.

13. Disclosure of data

We only share your data with the service providers named in this policy, as far as necessary for the respective purposes, or if we are legally obliged to. We do not sell data and do not use it for advertising. There is no automated decision-making, including profiling (Art. 22 GDPR).

14. Your rights

You have the right to:

Right to object (Art. 21 GDPR)

Where we process data based on legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. You can also turn off crash reports directly in the settings.

To exercise your rights, contact us at the email address in section 1.

15. Changes

We update this privacy policy when the app or the law changes. The version shown in the app applies.