Privacy Policy
Last updated: August 15, 2026 · Applies to the iOS app “Aura: Try-On & Color Analysis”
This policy explains what personal data Aura collects, how it is collected, what it is used for, and which third parties it is shared with — including the third-party artificial-intelligence service that powers Aura’s analysis and virtual try-on features.
The short version. To create your beauty profile and to render virtual try-ons, Aura sends the photos you take or upload — including photos of your face — together with the answers you gave in setup, to Google’s Gemini API (Google LLC) for processing. We ask for your explicit permission inside the app before any photo is sent, and you can withdraw that permission at any time. We do not sell your personal data, and we do not use your photos to train any AI model.
1. Who we are
Aura is developed and operated by Nicholas Marcenelle (“Aura”, “we”, “us”). For any privacy question, request, or complaint, contact us at marcenelle25@gmail.com. We respond to privacy requests within 30 days.
2. What data we collect, and how
2.1 Photos and camera data
- Face photos. Collected when you take a photo with the in-app camera during setup or a re-scan, or when you upload an existing photo from your photo library. Used to generate your beauty profile (skin depth and undertone, seasonal color analysis, eye and lip characteristics) and to render virtual makeup try-ons.
- Product photos. Collected when you photograph a makeup product or your makeup bag. Used to identify the product and rate how well it matches your profile.
- Live camera frames. While a scan screen is open, the camera feed is processed on your device (Apple ARKit / Vision) to check that your face is aligned in frame. These live frames are not uploaded; only the photo you actually capture is.
2.2 Information you give us
- Setup answers. Your beauty goal, how often you wear makeup, your skin type, where you shop, and your typical spend, collected through the setup questions.
- Account details. Your email address, and a password if you create an email account. If you sign in with Apple or Google, we receive the identifier and email address those services return. Passwords are handled by Firebase Authentication and are never stored by us in readable form.
- Voice input. If you use the optional voice feature, your speech is transcribed to text using Apple’s speech recognition on your device, and the resulting text is sent with your request. We do not store audio recordings.
- Feedback and support messages you choose to send us.
2.3 Information collected automatically
- Usage and diagnostic data. Screens viewed, features used, subscription events, and crash or error information, collected automatically as you use the app.
- Device and app data. Device model, operating-system version, app version, language and region, and a randomly generated app-install identifier.
- Advertising measurement data. If — and only if — you grant App Tracking Transparency permission when iOS asks, we and our advertising partners may use the Apple Advertising Identifier (IDFA) to measure which ad brought you to Aura. If you decline, no IDFA is collected.
- Purchase data. Subscription status, trial state, renewal and cancellation events, received from Apple through RevenueCat. We never receive your card number or other payment credentials — Apple handles all payments.
3. AI processing: what is sent to Google Gemini
Aura’s analysis, matching, and virtual try-on features are powered by Google’s Gemini API, operated by Google LLC. This is a third-party artificial-intelligence service. When you use a feature that requires it, the following data leaves your device and is transmitted to Google:
| Feature | What is sent to Google Gemini | What comes back |
|---|---|---|
| Beauty profile / face scan | Your face photo (resized before upload) and your setup answers | Your skin, eye, lip and color-season analysis |
| Virtual try-on | Your face photo and the name of the product being tried on | A generated image of the product applied to your face |
| Product scan / makeup bag | The product photo you took, plus your beauty profile | Product identification and a match rating |
| Recommendations and tutorials | Your beauty profile and any text or transcribed voice request | Product suggestions and step-by-step guidance |
We ask before we send. Before Aura transmits any photo or profile data to Google Gemini for the first time, the app shows you a screen that names Google Gemini, describes exactly what will be sent, and asks you to agree. Nothing is sent to Google until you agree. You can withdraw your agreement at any time in Profile → Settings → AI & Data; once withdrawn, Aura stops sending data to Google and the features that depend on it become unavailable.
Google’s protections. Google processes this data as our service provider under the Gemini API Terms of Service and Google’s privacy commitments. Aura uses the paid tier of the Gemini API, under which Google states that it does not use the data submitted through the API to train its models, and retains data only transiently for abuse monitoring and to return a result. We require our third-party processors to provide protections for your data equivalent to those described in this policy, and we do not permit them to use your data for their own independent purposes.
What we do not do. We do not use your photos to train any AI model, our own or anyone else’s. We do not sell your photos or personal data. We do not publish your photos or make them visible to other users.
4. How we use your data
- To create and update your beauty profile and color analysis.
- To generate virtual try-on images and personalized product recommendations.
- To identify and rate the products you scan or add to your makeup bag.
- To create and secure your account and sign you in.
- To provide, restore, and manage your subscription and free trial, and to send trial-expiry and re-engagement notifications you have allowed.
- To operate and improve the app: understanding which features are used, diagnosing crashes, and fixing problems.
- To measure the effectiveness of our advertising, where you have permitted tracking.
- To respond to your support requests and to comply with legal obligations.
We do not use your data for automated decisions producing legal or similarly significant effects, and we do not use it for advertising profiling beyond the measurement described above.
5. Where your data is stored
Your account, beauty profile, saved looks, and saved products are stored in Google Firebase (Firebase Authentication, Cloud Firestore, and Cloud Storage), operated by Google LLC, on servers in the United States. Your captured face photo is stored in your account so your profile and try-ons can be regenerated without re-scanning. Some data — such as your setup answers and app preferences — is also stored locally on your device.
6. Third parties we share data with
We share personal data only with the service providers listed below, only for the purposes listed, and only to the extent needed. Each is contractually bound to protect your data to a standard equivalent to this policy and may not use it for its own purposes.
| Provider | What it receives | Why |
|---|---|---|
| Google LLC — Gemini API | Face and product photos, beauty profile, setup answers, text requests | AI analysis, matching, and try-on image generation |
| Google LLC — Firebase | Account details, beauty profile, saved items, face photo | Authentication, database, and file storage |
| Google LLC — Google Sign-In | Sign-in identifier and email (only if you choose Google sign-in) | Account sign-in |
| RevenueCat, Inc. | App-install identifier, subscription and purchase events | Subscription management and entitlement checks |
| Mixpanel, Inc. | App-install identifier, feature-usage events, device data | Product analytics |
| Meta Platforms, Inc. | App-install identifier, install and purchase events, IDFA if you allow tracking | Advertising measurement |
| TikTok (ByteDance Ltd.) | App-install identifier, install and purchase events, IDFA if you allow tracking | Advertising measurement |
| Apple Inc. | Payment details, subscription state; speech audio if you use voice input and on-device recognition is unavailable | Payments, Sign in with Apple, speech recognition |
No photos go to advertising or analytics partners. Mixpanel, Meta, and TikTok never receive your photos, your face data, or your beauty profile.
We may also disclose data if legally required to do so, or to protect our rights or the safety of our users. If Aura is ever acquired, your data may transfer to the acquirer under this same policy.
7. How long we keep your data
- Photos and beauty profile: kept while your account is active, and deleted when you delete your account. A new scan replaces the previous one.
- Data sent to Google Gemini: processed to return a result and retained by Google only transiently for abuse monitoring, per Google’s API terms; it is not added to a long-term Google-side profile of you.
- Account and subscription records: kept while your account is active and for as long as needed to meet tax and legal obligations.
- Analytics data: retained in aggregate or pseudonymous form for up to 24 months.
8. Your choices and rights
- Consent to AI processing. Grant or withdraw it at any time in Profile → Settings → AI & Data. Withdrawing stops all further transmission to Google Gemini.
- Camera, photo library, microphone, and notification permissions are requested when first needed and can be changed at any time in the iOS Settings app.
- Tracking. You may decline App Tracking Transparency, or turn it off later in iOS Settings → Privacy & Security → Tracking.
- Access, correction, and deletion. You can delete your account and all associated data — including your stored photos and beauty profile — from Profile → Settings → Delete Account, or by emailing marcenelle25@gmail.com. Deletion is permanent.
- Data portability and objection. If you are in the EEA, the UK, or a US state with a comprehensive privacy law (including California), you may request a copy of your data, ask us to correct or delete it, object to or restrict certain processing, and appeal a refusal. We will not discriminate against you for exercising these rights. Email us to make a request.
Where we rely on consent — AI processing of your photos, tracking, and notifications — you may withdraw it at any time without affecting processing already carried out.
9. Children
Aura is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us data, email us and we will delete it.
10. Security
Data in transit is encrypted with TLS. Stored data is protected by Firebase security rules that limit access to your own account. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data, and we will notify you and the relevant authorities of a breach where the law requires it.
11. International transfers
We and our providers process data in the United States. If you use Aura from outside the United States, your data is transferred there. Where required, our providers rely on Standard Contractual Clauses or equivalent safeguards for such transfers.
12. Changes to this policy
If we change how we use your data in a material way — for example, by adding a new AI provider or a new category of data — we will update this page, change the “last updated” date above, and ask for your consent again in the app before the change takes effect for you.
13. Contact
Nicholas Marcenelle · marcenelle25@gmail.com