Aura

Privacy Policy

Last updated:

This policy explains what personal data Aura collects when you use the website aura.dnafactory.it and the Aura apps, why we use it, who we share it with and how you can exercise your rights under the EU General Data Protection Regulation (GDPR). For any question write to [email protected].

1. Who is responsible for your data

Aura is operated by DNAGroup SRL (registered office: Via dei Mille 40, 80121 Naples, Italy; operating office: Via Lucullo 71, 80070 Bacoli (NA), Italy; VAT no. IT08925651211; share capital €11,600 fully paid; SDI code M5UXCR1), an Italian company that runs the DNAFactory brand ("DNAFactory", "we", "us"). DNAGroup SRL is the data controller for the personal data processed through Aura.

You can contact us about anything related to privacy at [email protected]. We have not appointed a Data Protection Officer because we are not required to; the same address reaches the person responsible for data protection.

2. Data we collect

We only collect what we need to run Aura:

  • Account data: name, username (handle), email address, password (stored only as a secure hash), language, profile photo and bio, email verification status, two-factor authentication and passkey settings.
  • Sign in with Apple, Google or Facebook: if you choose it, the provider shares with us your name, email address (or an Apple relay address), a unique account identifier and, where available, your profile picture. We never receive your password for those services.
  • Content you publish: clips (video and thumbnail), solo lives and battles, titles and tags, comments, battle chat messages, gift messages, likes, follows, shares and reports.
  • Live video and audio: when you go live or join a battle, your camera and microphone are transmitted in real time to viewers through our streaming provider. Lives are not recorded by us, except the clips you upload yourself.
  • Aura, purchases and earnings: aura balance, free daily aura and welcome bonus used, gifts sent and received (with any gift message), leaderboard position and rank points, purchase history (pack, product, amount, date, status including refunds, cancellations and chargebacks and, for purchases in the apps, the App Store or Google Play transaction identifier) and creator earnings records (aura received, its value and the earnings accrued). We use the purchase records from the stores to deliver the aura, verify that each purchase is genuine and take back the aura of refunded purchases. Payments on the website are processed by Stripe, those in the apps by Apple or Google: we never see or store your full card number.
  • Consent records: when you accept the Terms of Service, the Privacy Policy or the purchase conditions we log the document, its version, the date and time, your IP address and device/browser.
  • Push notifications in the apps: when you allow notifications, we store your device's push token, the platform (iOS or Android), the app language and version and when the token was last used, so we can deliver notifications to your devices. The token is deleted when you sign out, when it stops working or when you delete your account.
  • Notification preferences and promotional notification choices: which notifications you turned on, the creators whose live alert (the bell on their profile) you turned on and, for promotional notifications, every activation, withdrawal of consent and objection, with the date and time, the version of the related text and its source (the app, the website, the default setting for accounts created before 26 September 2026, or Aura staff acting on your request, for example by email).
  • Support messages and bug reports: your email, the message, the topic and, for bug reports, the page address, platform and browser.
  • Technical and security data: IP address, device and browser type, language, log files, sign-in events, rate-limit counters and anti-abuse signals (including reCAPTCHA scores).
  • Analytics (only with your consent): on the website, pages visited and interactions measured with Google Analytics 4, without advertising features; in the apps, screens viewed and in-app events (for example opening a clip or a battle, sending a gift, following or sharing) measured with Google Analytics for Firebase through an app-instance identifier. We do not send your name, email address, username or a user ID to Google Analytics.
  • Advertising in the apps (Google AdMob): the Aura apps (not the website) show ads provided by Google AdMob, as native ads in the video feed and full-screen between clips. To deliver and measure ads, limit how often you see them and prevent fraud, Google may collect your device's advertising identifier (the IDFA on iOS, only if you allow tracking in the App Tracking Transparency prompt; the advertising ID on Android), IP address, device and app information and your interactions with ads. Ads are personalized only if you consent in Google's consent message; otherwise Google shows non-personalized ads.
  • Crash reports in the apps (Firebase Crashlytics): when the app crashes or hits a technical error, it sends a report with the device model, operating system and app version, the error details and stack trace, the screen in use and an installation identifier generated by Crashlytics. Reports contain no content and no name, email address, username or user ID. You can turn them off in Settings > Privacy & ads > Send crash reports.

We do not ask for special categories of data (for example health or religious beliefs). Please do not include them in your content or messages.

3. Why we use your data and legal bases

  • To provide Aura (account, feed, battles, lives, clips, comments, aura, leaderboard, support): performance of the contract with you, Art. 6(1)(b) GDPR.
  • To process purchases of aura, verify them with Stripe, Apple or Google, handle refunds and chargebacks, calculate creator earnings and keep accounting records: contract, Art. 6(1)(b), and legal obligations, Art. 6(1)(c) (tax and accounting law).
  • To keep Aura safe: preventing fraud, spam, bots and abuse (reCAPTCHA, rate limits), securing accounts (two-factor authentication), moderating content and enforcing the community rules: our legitimate interest and that of our users in a safe service, Art. 6(1)(f).
  • To prove your consents, acceptances and choices (Terms, Privacy, purchases, promotional notifications, including withdrawals and objections): legal obligation and legitimate interest in being able to demonstrate them, Art. 6(1)(c) and (f).
  • To send service emails (verification, password reset, security alerts, answers to your requests): contract, Art. 6(1)(b). We do not send marketing emails without your consent.
  • To send service notifications in the apps (activity on your account such as new followers, gifts, comments, invites and battle results; live alerts, when you turn on the bell on a creator's profile, telling you that creator went live or started a battle; messages about your account): contract, Art. 6(1)(b). They do not require the consent below; you can turn them off in Settings > Notifications, turn off a creator's live alert from the same bell, or block notifications on your phone.
  • To send promotions and reminders as push notifications in the apps (for example event news, tips and "It's battle time" reminders, possibly at set times or recurring). If your account was created before 26 September 2026, Promotions and reminders is turned on by default, on the basis of our legitimate interest in keeping existing users informed about the service and its events, Art. 6(1)(f) GDPR: the first time you open the updated app we show you, once, a notice explaining this, with a button to turn them off. You have the right to object at any time, free of charge and with immediate effect, by turning off Settings > Notifications > Promotions and reminders or notifications for Aura on your phone. If your account was created from 26 September 2026, the legal basis is your consent, Art. 6(1)(a) GDPR: you can give it by ticking the optional box, unticked by default, when you sign up in the app or on the website, or later from the one-time prompt in the app or in Settings > Notifications > Promotions and reminders, and you can withdraw it at any time from the same setting or by turning off notifications for Aura on your phone. Aura staff change this setting only at your request (for example if you ask by email). We may use different wordings of the same message; they are not personalised through profiling, only by language. When you tap a promotional notification, the app records that it was opened (which notification and which version of the text, with the date), to measure which messages and wordings work best; this is not used for profiling or advertising.
  • To measure how Aura is used with Google Analytics 4 on the website and Google Analytics for Firebase in the apps: your consent, Art. 6(1)(a), which you can withdraw at any time from Cookie settings on the website or from Settings > Privacy & ads > Analytics settings in the app.
  • To show ads in the apps with Google AdMob, which helps keep Aura free: for non-personalized ads (delivery, measurement, frequency capping and fraud prevention), our legitimate interest in funding the service, Art. 6(1)(f); for personalized ads and access to the advertising identifier on your device, your consent, Art. 6(1)(a) GDPR and Art. 5(3) of the ePrivacy Directive, requested through Google's consent message. Google acts as an independent controller for its own advertising processing.
  • To find and fix crashes and technical errors in the apps with Firebase Crashlytics: our legitimate interest in a working, stable service, Art. 6(1)(f). Only technical data is used; you can object at any time by turning off Settings > Privacy & ads > Send crash reports.
  • To comply with the law and answer requests from authorities: Art. 6(1)(c).

4. Community safety and moderation

Anyone can report a clip, live, battle, comment or profile. To protect the community, some measures are applied automatically and then reviewed by our team:

  • content that receives 10 reports from different people is hidden until it is reviewed;
  • an account reported 20 times cannot publish new content until it is reviewed;
  • uploaded clips and profile photos are automatically analysed on our own servers with open-source image recognition models, to detect nudity, sexual content and violence: a few still frames of each clip (and the photo) are checked right after upload, and nothing is shared with third parties for this check. Content that is probably unsafe is held until our team reviews it, content that is almost certainly unsafe is not published and a photo is removed; you are always notified. Frames are deleted right after the check, except those flagged, which our team keeps to review the decision. Legal basis: our legitimate interest in keeping the community safe, Art. 6(1)(f) GDPR, and the Terms of Service;
  • our team may remove content, suspend or close accounts that break the Terms of Service.

These automatic measures are temporary and always subject to human review. You can contest any decision by writing to [email protected].

5. Who we share data with

We do not sell your personal data. We share it only with providers that help us run Aura, acting as data processors under a written agreement, or as independent controllers where stated:

  • Cloud hosting, database and storage providers (including Cloudflare for content delivery, protection and file storage);
  • LiveKit for real-time video and audio of lives and battles;
  • Stripe for payments (independent controller for its own anti-fraud and legal obligations);
  • Apple (App Store) and Google (Google Play) for in-app purchases (independent controllers for the payments they handle); if you give your consent when buying, when you ask Apple for a refund we tell Apple how much of that pack's aura you have already used;
  • Google (Google Ireland Limited and Google LLC) for reCAPTCHA (bot protection), Google Analytics 4 on the website and Google Analytics for Firebase in the apps (only with consent), Firebase Crashlytics for crash reports in the apps, Firebase Cloud Messaging to deliver push notifications in the apps (on iPhone through Apple's push notification service), Sign in with Google and, in the apps only, ads through Google AdMob, for which Google acts as an independent controller (How Google uses information from sites or apps that use its services);
  • Meta Platforms for Facebook Login, and Apple for Sign in with Apple, when you choose them;
  • email delivery providers for service emails;
  • authorities, when required by law.

Public content (your profile, clips, lives, battles, comments, gift messages and position in the leaderboard) is visible to other users and, for public pages, to anyone on the web and to search engines. Gift messages are shown on screen, with your name, to everyone watching the live or battle.

6. Transfers outside the EU

Some providers (for example Google, Meta, Apple, Stripe, Cloudflare, LiveKit) may process data outside the European Economic Area, in particular in the United States. In those cases transfers rely on an adequacy decision (such as the EU-US Data Privacy Framework for certified companies) or on the Standard Contractual Clauses approved by the European Commission, with additional safeguards where needed. This also applies to Google AdMob and Google Analytics for Firebase in the apps: Google LLC is certified under the EU-US Data Privacy Framework and also uses the Standard Contractual Clauses.

7. How long we keep data

  • Account data and content: as long as your account exists. When you delete your account they are deleted, usually within 30 days, and removed from backups within a further 30 days.
  • Purchase, earnings and accounting records: 10 years, as required by Italian tax law, even after the account is deleted.
  • Consent records: for the life of the account and up to 10 years afterwards, to prove the acceptances in case of disputes.
  • Records of your choices on promotional notifications (consent given and withdrawn, objections and the default setting for accounts created before 26 September 2026): as long as your account exists and up to 2 years after you withdraw consent, object or delete the account, to prove them.
  • Opens of promotional notifications (which notification and which version of the text you opened, with the date): as long as the campaign statistics are needed, up to 2 years.
  • Support tickets and bug reports: up to 24 months after they are closed.
  • Security logs: up to 12 months.
  • Reports and moderation decisions: up to 24 months, longer if needed for legal claims.
  • Analytics data: 14 months in Google Analytics (website and apps).
  • Crash reports: 90 days in Firebase Crashlytics.
  • Push tokens: until you sign out of the app, the token stops working or you delete your account.

8. Your rights

Under the GDPR you have the right to:

  • access your data and receive a copy;
  • correct inaccurate data (you can edit most of it in your profile and settings);
  • delete your data (you can delete your account yourself from Settings);
  • restrict or object to processing based on our legitimate interest;
  • data portability, for data you gave us under a contract or consent;
  • withdraw your consent at any time, without affecting earlier processing;
  • lodge a complaint with a supervisory authority, in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority of your EU country.

Your ad and analytics choices in the apps: you can change your consent for personalized ads at any time from Settings > Privacy & ads > Privacy settings for ads, and your analytics choice from Settings > Privacy & ads > Analytics settings. On iOS you can also allow or deny tracking in the system Settings > Privacy & Security > Tracking; on Android you can reset or delete the advertising ID in the device settings. To learn more read How Google uses information from sites or apps that use its services.

Your notification choices: promotional notifications and reminders are sent only while Settings > Notifications > Promotions and reminders is on. For accounts created before 26 September 2026 it is on by default, based on our legitimate interest, and you can object at any time by turning it off; for newer accounts it is on only if you gave your consent, which you can withdraw at any time from the same setting. Service notifications can be turned off in Settings > Notifications, a creator's live alert from the bell on their profile, and all notifications from your phone's settings.

To exercise your rights write to [email protected] from the email address of your account. We answer within one month; we may ask you to confirm your identity.

9. Minimum age

Aura is intended for people aged 16 or over. If you are under 16 you may not create an account. If we learn that an account belongs to someone under 16 we will close it and delete its data. Parents or guardians can contact us at [email protected]. Ads shown in the apps are limited to content suitable for teenagers (maximum rating T).

10. Security

We protect your data with encrypted connections (HTTPS), hashed passwords, optional two-factor authentication and passkeys, access controls for our staff, rate limiting and monitoring. No system is perfectly secure: if a breach affects your data we will inform you and the authority as required by law.

11. Deleting your account

You can delete your account at any time from Settings > Account > Delete account on the website, or from the settings of the app. Your profile, clips, comments and personal data are deleted; data we must keep by law (for example purchase records) are kept only for the required period. Aura cannot be refunded after deletion: read the Terms of Service before deleting if you have unused purchased aura.

12. Changes to this policy

We may update this policy. If the changes are material we will ask you to read and accept the new version the next time you use Aura. The date of the latest version is shown at the top of this page.

Questions about these documents or your data? Write to [email protected] and we will answer within 30 days.