Skip to content

Legal

Privacy policy

Version 2.0. Last updated 29 July 2026.

This policy describes what Aurora Organics actually does with your data. Where it states a limit, that limit is enforced in code. Where a decision is yours, you can change it in Privacy settings.

1. Who we are

Aurora Organics (Aurora Organics) is the controller of the personal data described in this policy. You can reach us at info@auroraorganics.co or by post at Kampala, Uganda.

Aurora Organics is a cosmetic skin wellness service. It provides cosmetic and lifestyle guidance only. It does not diagnose, treat, or prevent any medical condition, and it is not a medical device. See our Terms of use for the full disclaimer.

2. What we collect

  • Account information. Email address, name, authentication method, and a profile image if you sign in with Google or Apple.
  • Session metadata. IP address and browser user agent, stored against your active session for security and account management.
  • Wellness profile. Age band derived from your date of birth, skin type, sun sensitivity, Ayurvedic lean, concerns, goals, allergies, current routine, prescriptions, medications, and lifestyle answers. Every field is optional except those needed to run a scan.
  • Location and climate. City, region, country, and approximate coordinates if you share them, plus the climate bands we derive from them.
  • Consent records. What you agreed to, which version of this policy you agreed to, and when.
  • Scan results. The assessment produced for each scan: bands, notes, summary, and recommendations, along with the profile and climate snapshot used to produce it.
  • Chat. Messages you send and replies you receive, including any photo you attach to a chat message.
  • Usage records. Which model handled each request and how many tokens it used, for billing and abuse prevention.

3. Photos and how they are handled

Photos are handled differently depending on where you upload them, and it matters, so we are specific.

Scan photos

A scan photo is checked in your browser first, using an on-device face detector. The image never leaves your device unless it passes that check and you continue. It is then sent to Google's Gemini API for analysis, and discarded once the assessment comes back. We do not store scan photos. Only the resulting text assessment is saved.

Live scan

If you use a live scan, video frames stream to Google in real time for the duration of the session. We keep the session transcript and the final assessment. We do not keep the video.

Chat photos

A photo you attach to a chat message is different: it is stored with that message so the conversation still makes sense when you return to it. These images are automatically deleted after 30 days, and you can delete them sooner by deleting your chat data.

Reports

Downloadable reports contain the text of your assessment. They contain no photographs.

4. Health and biometric data

A photograph of your face, together with the skin concerns, allergies, medications and prescriptions in your profile, is treated as special category data under the UK and EU GDPR (Article 9), and may be treated as biometric data under laws such as the Illinois Biometric Information Privacy Act and the Texas Capture or Use of Biometric Identifier Act.

We process it only on the basis of your explicit consent, which you give during onboarding before any photo is processed, and which you can withdraw at any time by deleting your data or your account. Withdrawing consent does not affect processing that already happened.

We do not use face images to identify you, to match you against any other person, or to build a faceprint. The image is analysed for cosmetic surface characteristics and then discarded, per the retention schedule in section 9. We do not sell biometric data, and we do not disclose it to anyone other than the processors listed in section 7.

5. Why we use it, and our legal basis

Purpose and legal basis for each category of processing
What we doWhyLegal basis (UK and EU GDPR)
Create and run your accountSo you can sign in and keep your historyPerformance of a contract (Art. 6(1)(b))
Analyse a scan photo and produce an assessmentThe core service you asked forExplicit consent (Art. 9(2)(a)), plus contract (Art. 6(1)(b))
Personalise guidance using your profile and climateSo advice matches your skin and where you liveExplicit consent (Art. 9(2)(a))
Store session IP and user agentAccount security and abuse preventionLegitimate interests (Art. 6(1)(f))
Record per-call model usageBilling, cost control, and abuse detectionLegitimate interests (Art. 6(1)(f))
Send marketing emailProduct updates, only if you opt inConsent (Art. 6(1)(a))
Measure page usageUnderstanding which parts of the product get usedConsent (Art. 6(1)(a))

6. Automated analysis

Your assessment is produced entirely by an automated system. No person reviews your photo or your results unless you explicitly request an expert review, and that feature is not yet available.

This automated processing does not produce legal effects or similarly significant effects on you within the meaning of Article 22 of the GDPR: the output is cosmetic guidance, it does not determine access to anything, and you are free to disregard it. It can also be wrong. If you want to challenge or discuss a result, or ask for it to be deleted, write to info@auroraorganics.co.

We do not use your photos, chats, or profile to train AI models, ours or anyone else's.

7. Who we share it with

We do not sell personal data and we do not share it for advertising. We use the processors below, each bound to process data only on our instructions.

Sub-processors
ProcessorWhat it doesWhat it seesWhere
Google (Gemini API)Analyses scan photos and generates cosmetic guidance and chat replies.Scan and chat photos, wellness profile, climate context, message textUnited States and other Google regions
VercelHosts the application and serves it worldwide.Request metadata, IP addressUnited States and global edge network
NeonHosts the PostgreSQL database.All stored account, profile, scan and chat dataConfigured database region
ResendDelivers sign-in codes and account emails.Email address, one-time codesUnited States
Vercel AnalyticsAggregate page usage measurement. Only with your consent.Page path, referrer, coarse device and country signalsUnited States
Google and Apple sign-inOptional federated sign-in, only if you choose it.Email, name, profile imageUnited States
OpenStreetMap NominatimTurns coordinates into a city name when you share a location.Approximate coordinatesEuropean Union
Open-MeteoSupplies weather data for climate-aware guidance.Approximate coordinatesEuropean Union

We will update this list before adding a new processor. If a change materially affects how your data is handled, we will tell you by email or in the product before it takes effect.

We may also disclose data where we are legally required to, or to establish or defend a legal claim.

8. International transfers

Several of our processors are based in the United States, so data leaves the UK and EEA. Those transfers rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the technical measures described in section 12. You can request a copy of the transfer mechanism we rely on for any given processor.

9. How long we keep it

These periods are enforced by an automated daily job, not by policy alone.

Retention schedule
DataRetained for
Scan photosNot retained. Discarded as soon as the assessment is produced.
Live scan videoNot retained. Only the session transcript is kept.
Chat photos30 days, then automatically deleted.
Expired sessions, including IP and user agentDeleted 7 days after expiry.
Sign-in codes and verification recordsDeleted 7 days after expiry.
Model usage and cost records400 days.
Scan results, reports, chat transcriptsUntil you delete them, or until you delete your account.
Profile, location, consent recordsUntil you delete them, or until you delete your account.

When you delete your account, everything above is deleted. Aggregate figures that cannot identify you may be retained.

10. Your rights

Depending on where you live, you have some or all of the following rights. Most of them you can exercise yourself, immediately, in Privacy settings.

  • Access. See what we hold.
  • Portability. Download everything we hold about you as a machine-readable JSON file, from Privacy settings.
  • Rectification. Correct your profile in Settings at any time.
  • Erasure. Delete individual scans, all scans, your profile, your location, all personal data, or your entire account. These take effect immediately.
  • Withdraw consent. Turn off marketing email or analytics at any time. Withdrawing photo-processing consent means deleting your data, since the service cannot run without it.
  • Restriction and objection. Ask us to pause or stop processing that relies on legitimate interests.
  • Complain.If you are in the UK or EEA you may complain to your local supervisory authority. In the UK that is the Information Commissioner's Office.

For anything not covered by the self-service controls, email info@auroraorganics.co. We respond within 30 days. See also our data deletion page.

11. Cookies and analytics

We use cookies and local storage for three things: keeping you signed in, remembering your theme, and remembering your analytics choice. Those are strictly necessary or set at your request, so they do not need consent.

Analytics. We use Vercel Analytics to count page views. It does not set advertising cookies, does not follow you across other sites, and never sees your scans or chats. It only loads if you accept the banner, and declining costs you nothing.

We do not use advertising cookies, ad networks, or cross-site tracking of any kind.

12. Children

Aurora Organics is not for children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone younger, and we do not knowingly process a photograph of a child.

If you believe a child has created an account or that a child's photograph has been uploaded, email info@auroraorganics.co and we will delete it.

13. Security and breaches

Data is encrypted in transit and at rest. Access to production data is limited to those who need it. Sign-in and one-time-code endpoints are rate limited. Scan photos are never written to storage, which removes an entire class of exposure.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify you directly without undue delay where the risk is high.

14. Regional notices

California (CCPA and CPRA)

The categories we collect, and why, are set out in sections 2 and 5. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. We do not use sensitive personal information for any purpose other than providing the service you asked for. You have the right to know, delete, correct, and to be free from discrimination for exercising those rights, all of which are available through Privacy settings.

Illinois and Texas biometric laws

Our written retention and destruction schedule is published in section 9. Face images are destroyed as soon as the assessment is produced, and in every case within the periods stated there. We obtain written consent before processing and we do not sell, lease, or otherwise profit from biometric identifiers.

UK and EEA

Our legal bases are in section 5, transfer mechanisms in section 8, and your rights, including the right to complain to a supervisory authority, in section 10.

15. Changes

This is version 2.0, last updated 29 July 2026. If we make a material change we will raise the version and ask you to review it before you continue using the service. Minor clarifications are published with an updated date.

16. Contact

Aurora Organics
Kampala, Uganda
info@auroraorganics.co