Aura

Cookie Policy

Last updated:

This policy explains which cookies and similar technologies Aura uses on the website and in the apps, why, for how long, and how you can choose which ones to allow. The website does not use advertising or profiling cookies; the Aura apps show ads from Google AdMob, personalized only with your consent.

1. What cookies are

Cookies are small text files that a website saves in your browser. Similar technologies, such as the browser's local storage, work in a comparable way. Technical cookies are needed for the site to work and do not require consent; analytics cookies are used only if you allow them. The Aura apps do not use browser cookies, but similar technologies on your device, described in section 5.

2. Our cookies (first party)

NamePurposeTypeDuration
aura-sessionKeeps you signed in and keeps your session secureTechnicalSession / 2 hours of inactivity
XSRF-TOKENProtects forms and requests against cross-site request forgery (CSRF)TechnicalSession / 2 hours
remember_web_*Keeps you signed in when you choose "Keep me signed in"Technical, requested by youUp to 400 days or until you log out
localeRemembers the language chosen by visitors who are not signed inPreference (technical)Up to 400 days
aura_consentStores your cookie choicesTechnical6 months
Local storage: recent searchesShows your recent searches on this device; never sent to usFunctional, device onlyUntil you clear it

These cookies are necessary to provide the service you request, so they are always active.

3. Third-party cookies

ProviderNamePurposeWhenDuration
Google Analytics 4_ga, _ga_<ID>Anonymous statistics on visits and page viewsOnly with your consent13 months
Google reCAPTCHA v3_GRECAPTCHA and Google cookiesSecurity: tells humans from bots and prevents abuseOnly on pages with forms (sign-in, registration, password, support)Up to 6 months
Cloudflare__cf_bm, cf_clearanceSecurity and bot protection of the websiteWhen needed to protect the site30 minutes to 1 year
Stripee.g. __stripe_mid, __stripe_sidPayment security and fraud preventionOnly on Stripe's checkout page (checkout.stripe.com), under Stripe's own policy: we do not load Stripe on our pagesSet by Stripe
Google, Facebook, AppleProvider cookiesSign-in with your account at the providerOnly on the provider's pages, when you choose to sign in with itSet by the provider

Google processes reCAPTCHA and Analytics data according to its own privacy policy (policies.google.com/privacy), which may include transfers to the United States under the EU-US Data Privacy Framework. More details on how we process personal data are in our Privacy Policy.

4. Analytics (only with consent)

If you allow them, we use Google Analytics 4 to understand how many people visit Aura and which pages they use, so we can improve it. Advertising features are disabled.

Until you give consent, Google Analytics is not loaded at all and Google Consent Mode keeps every storage type set to "denied".

5. Mobile apps: advertising identifiers and SDKs

The Aura apps for iOS and Android do not use browser cookies, but they use similar technologies that store or read information on your device:

  • Your privacy choices (Aura): the choices you make in the app's privacy banner are saved in the app's local storage on your device, so we do not ask you again every time. Technical, always active, until you change them or uninstall the app.
  • Google Analytics for Firebase (only with your consent): measures screens viewed and in-app events through an app-instance identifier. It is off by default: until you choose "Accept all" or enable analytics under "Customize" in the privacy banner, Google Consent Mode keeps it set to "denied". No name, email address, username or user ID is sent. Advertising-related signals are shared with Google only if you also consent to personalized ads in Google's consent message.
  • Google Mobile Ads SDK (Google AdMob): shows ads in the video feed and full-screen between clips, may store data on your device and may access the advertising identifier: on iOS the IDFA, only if you allow tracking in the App Tracking Transparency prompt; on Android the advertising ID. Users in the EEA, the UK and Switzerland are asked for consent through Google's consent message (Google User Messaging Platform, based on the IAB TCF): ads are personalized only with your consent, otherwise Google shows non-personalized ads. Ad content is limited to a teen-appropriate rating (maximum T).

You can change your choices at any time in the app from Settings > Privacy & ads: "Analytics settings" for Google Analytics for Firebase and "Privacy settings for ads" for Google's consent message. On iOS you can also allow or deny tracking in Settings > Privacy & Security > Tracking; on Android you can reset or delete the advertising ID in the device settings. To learn more read How Google uses information from sites or apps that use its services and our Privacy Policy.

6. How to manage your choices

The cookie banner shown on your first visit has two categories: Necessary (always on) and Analytics (off unless you allow it). You can accept all, keep only the necessary ones or customize your choice, and change your mind at any time:

The same "Cookie settings" link is in the footer of every page. If you withdraw consent we stop measuring and delete the Google Analytics cookies that we can reach.

You can also block or delete cookies from your browser settings (Chrome, Safari, Firefox, Edge all have a privacy section for this). Blocking the necessary cookies may prevent you from signing in or using Aura.

In the Aura apps you manage your choices from Settings > Privacy & ads (see section 5).

7. Contact

For questions about cookies write to [email protected].

Questions about these documents or your data? Write to [email protected] and we will answer within 30 days.