AuroxaLast updated: April 29, 2026

Privacy Policy

This Privacy Policy explains how Auroxa (“we”, “us”, or “our”) collects, uses, and protects information about you when you use our platform (the “Service”). By creating an account or using the Service, you agree to the practices described below.

1. Information We Collect

Account Information

When you register, we collect your name, email address, and password (stored as a secure hash — we never store your plaintext password). If you sign up via Google OAuth, we receive your name and email from Google.

Usage Data

We automatically log how you interact with the Service: pages visited, features used, AI generation requests, keyword queries, content created, and event timestamps.

Technical Data

We collect IP addresses, browser type, operating system, device identifiers, and error logs to maintain platform reliability and security.

Payment Information

Payments are processed by Stripe, Inc. We do not store your full card number. We retain your Stripe customer ID and subscription status to manage your plan.

Third-Party Integrations

If you connect external services (Google Search Console, WordPress, Shopify, Google Business Profile), we store the access tokens and data retrieved from those services solely to provide the features you requested.

2. How We Use Your Information

  • To provide, operate, and improve the Service
  • To process payments and manage your subscription
  • To send transactional emails (confirmations, invoices, password resets)
  • To monitor and maintain platform performance and security
  • To detect, investigate, and prevent fraud and abuse
  • To respond to support requests and feedback submissions
  • To comply with applicable legal obligations

We do not sell your personal data to third parties. We do not use your data to train AI models without your explicit, separate consent.

3. Data Sharing

We share data only with the third-party providers listed below, strictly as necessary to operate the Service. Each provider is contractually obligated to protect your data.

ProviderPurpose
SupabaseDatabase hosting and authentication
StripePayment processing and subscription management
VercelApplication hosting and edge delivery
Anthropic (Claude)AI content generation
Google (Gemini)AI strategy analysis
ResendTransactional email delivery
DataForSEOSEO data (SERP, keywords, backlinks)
SentryError monitoring and crash reporting

4. Data Retention

We retain your personal data for as long as your account is active. If you close your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law (e.g., billing records are retained for 7 years per financial regulations). Aggregated, anonymized usage statistics may be retained indefinitely.

5. Your Rights

Depending on your jurisdiction (including GDPR and CCPA), you may have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Deletion: Request deletion of your account and associated data
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to certain processing activities
  • Withdraw Consent: Where processing is based on consent, withdraw it at any time

To exercise any right, email us at privacy@auroxa.io. We will respond within 30 days.

6. Cookies

We use cookies to maintain your session and remember your preferences. We use Vercel Analytics for anonymized, aggregate traffic analysis — no personally identifiable information is transmitted. You may disable cookies in your browser settings; this may limit Service functionality.

7. Security

We apply industry-standard security measures: TLS encryption in transit, hashed passwords, row-level security on our database, SHA-256 hashed API keys, and periodic security reviews. No transmission over the Internet is 100% secure; we cannot guarantee absolute security and are not liable for unauthorized access beyond our reasonable control.

8. Children

The Service is not directed at individuals under 16. We do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it immediately.

9. International Transfers

Your data may be processed in countries other than your own (including the United States) by our service providers. By using the Service you consent to such transfers. We require all processors to maintain appropriate safeguards.

10. GDPR — Rights of EU / EEA Users

If you are located in the European Union or European Economic Area, the following applies to you under the General Data Protection Regulation (GDPR):

Legal Basis for Processing

We process your personal data on the following legal bases: (a) Contract performance — processing necessary to provide the Service you subscribed to; (b) Legitimate interests — fraud prevention, platform security, and service improvement; (c) Legal obligation — where required by applicable law (e.g., financial record keeping); (d) Consent — for optional marketing communications, which you may withdraw at any time.

Your GDPR Rights

In addition to the rights listed in Section 5, EU/EEA residents have the right to: (a) restrict processing of your data while a dispute is resolved; (b) not be subject to solely automated decision-making that produces significant legal effects. To exercise any right, email privacy@auroxa.io. We will respond within 30 days.

Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection supervisory authority. In the EU, you may contact the supervisory authority in your country of residence. A full list is available at edpb.europa.eu. We would, however, appreciate the opportunity to address your concerns directly before you contact a regulator.

Data Transfers Outside the EU

Your data may be transferred to and processed in countries outside the EU/EEA (including Canada and the United States) by our service providers. Canada is recognized by the European Commission as providing adequate data protection. For transfers to the United States, we rely on Standard Contractual Clauses (SCCs) or the service provider's participation in an approved transfer mechanism.

12. Changes to This Policy

We may update this policy periodically. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. Continued use after that date constitutes acceptance.

13. Contact

Questions or requests: privacy@auroxa.io