Privacy
Privacy Policy
Last updated: [DATE]
Document status: Draft for human legal review. This document must be reviewed and completed before the Aura Project is made publicly available.
1. About this policy
This Privacy Policy explains how the Aura Project collects, uses, stores, protects and deletes personal information when you:
- visit aura-project.org;
- create or use an Aura Project account;
- write or save journal entries;
- complete the four-week journal programme;
- contact us for support;
- export or delete your information; or
- otherwise use our website and services.
In this policy, “Aura Project,” “we,” “us” and “our” refer to:
Data controller: [DATA-CONTROLLER IDENTITY] Registered or business address: [ADDRESS] Privacy contact: privacy@aura-project.org Legal jurisdiction: [LEGAL JURISDICTION]
The Aura Project is the controller of the personal information described in this policy unless stated otherwise.
2. The nature of the service
The Aura Project provides a private online journalling tool accompanying the book The Authenticity Cleanse: 4 Weeks to Release Resentment and Rediscover Your Voice by Mike Graham.
The journal is intended as a self-reflection tool. It is not medical care, psychological treatment, crisis support or a substitute for professional advice.
Journal entries may contain deeply personal information. We have designed the service on the principle that journal content should only be processed as necessary to provide, secure and maintain the journal service.
3. Information we collect
3.1 Account information
When you create an account, we may collect:
- your name or chosen display name;
- your email address;
- an encrypted or cryptographically hashed representation of your password;
- email-verification status;
- account creation and update dates;
- preferred language;
- time zone;
- interface and accessibility preferences;
- reminder preferences; and
- account-security information.
We do not have access to your original password.
3.2 Journal information
When you use the journal, we collect and store information that may include:
- free-form journal entries;
- answers to structured reflection questions;
- the journal day and week associated with an entry;
- whether an entry is not started, in progress or completed;
- creation, modification and completion timestamps;
- current programme progress;
- autosave and entry-version information; and
- journal export and deletion requests.
Your journal content is stored so that you can save, retrieve, edit, export and delete it.
3.3 Sensitive and special-category information
The Aura Project does not require you to disclose medical information or other sensitive details. However, because the journal is free-form, you may choose to write about matters such as:
- physical or mental health;
- addiction or recovery;
- religious or philosophical beliefs;
- racial or ethnic origin;
- political opinions;
- trade-union membership;
- sexual orientation or sexual life;
- trauma, relationships or family matters; or
- other information considered sensitive under applicable law.
Under European and UK data-protection law, some of these categories receive additional legal protection.
Before journal content is stored, users should be asked to provide a separate, specific and explicit confirmation that they understand the journal may contain sensitive information and consent to its storage for the purpose of providing the private journal service.
You may withdraw that consent through the account privacy centre or by contacting us. Withdrawal does not affect processing that occurred lawfully before consent was withdrawn.
Legal-review requirement: The wording, placement, recording and withdrawal mechanism for this explicit consent must be independently reviewed before launch.
3.4 Technical and security information
When you access the service, our systems may automatically process:
- Internet Protocol address;
- browser and device type;
- operating system;
- date and time of requests;
- pages or system routes requested;
- authentication and session identifiers;
- failed-login attempts;
- security events;
- server errors; and
- information needed to detect abuse or maintain the service.
We configure the application so that journal text is not intentionally written to application logs, access-log URLs, analytics systems or error-reporting services.
3.5 Support communications
When you contact us, we may retain:
- your name and email address;
- the date of the communication;
- the subject of the request;
- the contents of your message; and
- our response.
Do not send journal entries or highly sensitive information through ordinary email. Email is not intended to be used as a journal-storage channel.
4. How we use personal information
We use personal information to:
- create and administer user accounts;
- authenticate users;
- provide the private journal;
- save and retrieve journal entries;
- track journal progress;
- provide exports in JSON and Markdown format;
- process entry, journal and account deletion requests;
- send account-verification and password-reset messages;
- send optional reminders when requested;
- respond to support enquiries;
- protect accounts and the service from misuse;
- investigate errors and security incidents;
- maintain backups and business continuity;
- comply with legal obligations; and
- establish, exercise or defend legal claims where necessary.
We do not intentionally use journal content to profile users, assess their mental health, determine their emotional state or make decisions about them.
5. Our legal grounds for processing
Where the EU General Data Protection Regulation, UK GDPR or similar legislation applies, we rely on one or more of the following legal grounds.
Contract
We process account information, journal entries and preferences where necessary to provide the service you requested, including saving, retrieving, exporting and deleting journal entries.
Explicit consent
Where journal content contains special-category information, we propose to rely on your explicit consent as the additional legal condition permitting us to store that information for you.
We may also rely on consent for optional reminders, newsletters or non-essential cookies if such features are introduced.
Legitimate interests
We may process limited technical and security information where necessary for legitimate interests such as:
- securing accounts;
- preventing fraud and abuse;
- diagnosing technical failures;
- maintaining service reliability; and
- protecting our legal rights.
We will not rely on legitimate interests where our interests are overridden by your rights and freedoms.
Legal obligation
We may process or retain information when required to comply with applicable law, regulation, court orders or valid requests from authorised public bodies.
Legal claims
Where permitted by law, limited information may be retained or processed when necessary to establish, exercise or defend legal claims.
The GDPR recognises rights including access, correction, deletion, restriction, objection and data portability. It also requires organisations to identify and communicate their purposes and legal grounds for processing.
6. What we do not do with journal entries
Journal entries are not intentionally:
- read by us as part of normal service operation;
- sold;
- rented;
- exchanged for commercial benefit;
- used for advertising;
- used to select advertisements;
- used for cross-context behavioural advertising;
- shared with data brokers;
- sent to artificial-intelligence or machine-learning services;
- used to train artificial-intelligence models;
- analysed to diagnose medical or psychological conditions;
- included in third-party analytics;
- included in session-replay or heat-map services;
- included in email messages;
- made public; or
- shared with other users.
We do not provide a routine administrator interface for reading users’ journal entries.
Authorised infrastructure administrators may technically be able to access database contents when performing essential system administration, security investigation, backup restoration or incident recovery. Such access should be restricted, logged where practical and limited to circumstances where it is genuinely necessary.
7. Artificial intelligence and automated decisions
Journal entries are not intentionally submitted to AI services or used to train AI models.
We do not use journal content to make automated decisions that produce legal or similarly significant effects concerning you.
If this changes, this policy and the technical service must be updated before the new processing begins. Where required, we will provide additional notice and obtain consent.
8. Cookies and local storage
The Aura Project may use cookies or similar browser storage that are necessary to:
- keep you signed in;
- protect forms against forgery or misuse;
- maintain secure sessions;
- remember interface preferences; and
- preserve temporarily unsaved journal text following a network failure.
These are intended to support functionality and security rather than advertising.
We do not propose to use advertising cookies, cross-site tracking cookies, session-replay tools or third-party behavioural analytics.
If non-essential cookies or analytics are introduced later, they must be subject to a separate privacy review and, where required, must not be activated until the user has provided valid consent.
9. How information is shared
We may disclose limited personal information to carefully selected service providers that operate systems on our behalf, such as:
- website and server hosting providers;
- database and backup infrastructure providers;
- transactional email providers;
- security and abuse-prevention providers;
- professional advisers; and
- contractors providing authorised technical maintenance.
Before launch, this section must identify the actual providers used:
- Hosting provider: [PROVIDER AND COUNTRY]
- Server location: [COUNTRY OR REGION]
- Backup provider and location: [PROVIDER AND COUNTRY]
- Email provider and location: [PROVIDER AND COUNTRY]
- Other processors: [LIST OR “NONE”]
Service providers should be contractually restricted to processing information only as necessary to provide their services and should be required to protect it appropriately.
We may also disclose information:
- when legally required;
- in response to a valid and binding legal demand;
- where necessary to protect a person from immediate and serious harm, where the law permits or requires disclosure;
- in connection with the investigation of fraud, abuse or a security incident; or
- as part of a business transfer, subject to appropriate confidentiality and legal safeguards.
We will not voluntarily provide journal content to law-enforcement or government authorities merely because they request it informally. Any compulsory request should be assessed for validity, scope and legal authority.
10. International transfers
The website may be accessible internationally. The country in which your information is stored may differ from the country in which you live.
Primary storage location: [COUNTRY OR REGION]
Where personal information protected by the GDPR, UK GDPR or comparable legislation is transferred to another country, we will use an appropriate legal transfer mechanism where required. This may include:
- an adequacy decision;
- approved standard contractual clauses;
- the UK International Data Transfer Agreement or UK Addendum;
- contractual and technical safeguards; or
- another legally recognised transfer mechanism.
The final policy must identify the actual countries and transfer safeguards after the hosting, email and backup providers have been selected.
11. Information security
We use technical and organisational measures intended to protect personal information against unauthorised access, loss, alteration, disclosure or destruction.
These measures are proposed to include:
- HTTPS encryption for information transmitted between your device and the website;
- password hashing;
- authenticated access to journal pages;
- server-side ownership and authorisation checks;
- encrypted or otherwise appropriately protected backups;
- restricted database access;
- a dedicated database account;
- secure session cookies;
- request-forgery protection;
- login rate limiting;
- security headers;
- application and server updates;
- restricted infrastructure-administrator access;
- database and application backups; and
- monitoring for technical and security failures.
HTTPS protects information while it is being transmitted. Authentication and application controls restrict access to journal pages.
Journal data is stored in the site database. It is not end-to-end encrypted, and we do not claim that infrastructure administrators are technically incapable of accessing it.
No online service can guarantee absolute security. Users should use a unique password, protect access to their email account and sign out when using a shared device.
12. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, subject to legal requirements and the final retention schedule.
The proposed retention periods are:
Account information
Retained while your account remains active. Account information is deleted or anonymised following account deletion unless limited retention is required by law or for the defence of legal claims.
Journal entries
Retained until you delete the relevant entry, delete all journal entries or delete your account.
Generated exports
Export files should be automatically deleted after a short period.
Current configured export-file retention: 24 hours, subject to legal review.
Application and security logs
Logs should contain technical and security information but should not intentionally contain journal text.
Proposed log-retention period: 14 days.
Some security-event records may need to be retained longer where an incident is under investigation. Any exception should be documented and limited to what is necessary.
Backups
Encrypted backups may temporarily retain information that has been deleted from the active system.
Proposed backup-retention period: 30 days.
Deleted information contained in a backup will not normally be restored to the active service except where necessary for disaster recovery. If a backup is restored, deletion records should be reapplied where technically feasible.
Support correspondence
Proposed support-retention period: [PERIOD FOR LEGAL REVIEW]
Legal retention
We may retain limited information for longer when required by law or reasonably necessary to establish, exercise or defend legal claims.
13. Your account controls
The service is intended to let you directly:
- edit journal entries;
- delete an individual entry;
- delete all journal entries;
- request an account and journal export containing JSON and readable Markdown;
- update account information;
- change preferences;
- view the date and version of journal-consent records;
- withdraw journal consent;
- submit privacy requests;
- view the status of previous privacy requests;
- send messages relating to existing privacy requests; and
- delete your account.
Deleting an account should permanently remove the active account, journal entries, preferences and generated export files, subject to temporary backup retention and any overriding legal requirement.
Before destructive actions are completed, we may ask you to confirm your password or otherwise reauthenticate.
Many ordinary requests can be completed through the authenticated account privacy centre at https://aura-project.org/account/privacy. Unusual, representative, disputed, legally complex or security-sensitive requests may require human review and may not be fully automated.
The public request form is available at https://aura-project.org/privacy/request. Submitting the form does not require the requester to identify a particular statute.
14. Rights under European and UK data-protection law
Where the GDPR or UK GDPR applies, you may have the right to:
- be informed about how your personal information is used;
- access personal information held about you;
- correct inaccurate or incomplete information;
- request deletion of information;
- restrict certain processing;
- receive eligible information in a structured, commonly used and machine-readable format;
- object to processing based on legitimate interests;
- object to direct marketing;
- withdraw consent;
- complain to a competent supervisory authority; and
- receive information about relevant international transfers.
These rights are not absolute. A request may be restricted where an exemption applies or where retaining information is legally required.
We may need to verify your identity before completing a request. We will not ask for more information than reasonably necessary for verification.
Under the GDPR, organisations should normally respond to rights requests without undue delay and, in principle, within one month, subject to permitted extensions. All legal deadlines and jurisdiction-specific settings in this service are marked for human legal review.
You may contact:
Privacy contact: privacy@aura-project.org
You may also complain to:
Lead or relevant supervisory authority: [AUTHORITY NAME AND CONTACT DETAILS]
If the data controller is established in Sweden, the likely supervisory authority is the Swedish Authority for Privacy Protection, subject to legal confirmation.
15. Supplemental notice for United States residents
This section applies only where a United States federal or state privacy law applies to our processing.
Depending on your state and the law’s applicability thresholds, you may have rights to:
- confirm whether we process your personal information;
- access or obtain a copy of personal information;
- request correction;
- request deletion;
- obtain portable information;
- opt out of the sale of personal information;
- opt out of sharing for cross-context behavioural advertising;
- opt out of targeted advertising;
- opt out of certain profiling;
- limit certain uses of sensitive personal information;
- appeal a decision concerning a privacy request; and
- receive equal service without unlawful discrimination for exercising a privacy right.
California law gives eligible consumers rights concerning access to and control over personal information and requires covered businesses to explain how information is collected, used and retained.
Categories collected
Depending on how you use the service, we may process the following broad categories:
- identifiers, such as name, email address, IP address and account identifiers;
- account and authentication information;
- Internet or electronic network activity;
- user-generated journal content;
- sensitive personal information voluntarily included in journal content;
- preferences and programme progress;
- support communications; and
- approximate location inferred from an IP address, where generated automatically by infrastructure or security systems.
Business or operational purposes
We use these categories to:
- provide the service;
- maintain user accounts;
- authenticate users;
- secure the service;
- diagnose errors;
- respond to requests;
- comply with law; and
- perform the other purposes described in this policy.
Sale, sharing and targeted advertising
We do not intentionally sell personal information.
We do not intentionally share personal information for cross-context behavioural advertising.
We do not use journal entries for targeted advertising.
We do not knowingly sell or share the personal information of children.
Because we do not propose to sell personal information or use it for targeted advertising, an advertising opt-out should not be necessary for the current service. This conclusion must be reassessed if analytics, advertising technology, embedded social-media content or additional third-party services are introduced.
Sensitive information
Sensitive journal information is used only to provide the private journal functionality requested by the user and for necessary security, legal and operational purposes.
It is not intentionally used to infer characteristics about users for advertising or profiling.
Exercising US privacy rights
Requests may be submitted to:
Privacy email: privacy@aura-project.org Request form: https://aura-project.org/privacy/request Do Not Sell or Share preference form: https://aura-project.org/privacy/do-not-sell-or-share
We may verify the requester’s identity before responding. Where permitted, an authorised agent may submit a request on your behalf, but we may require evidence of the agent’s authority and may verify your identity directly.
Where applicable law provides an appeal right, you may appeal a refusal by writing to privacy@aura-project.org with the subject “Privacy Request Appeal.”
16. Rights in Canada, Australia, New Zealand, Switzerland and other countries
Privacy rights differ by country and may depend on whether a particular law applies to the Aura Project.
Where applicable, users may have rights to request:
- information about how their personal information is handled;
- access to personal information;
- correction of inaccurate information;
- deletion or erasure;
- restriction or objection;
- withdrawal of consent;
- a portable copy of information; or
- review by or complaint to a privacy regulator.
Canadian PIPEDA principles address collection, use, disclosure, access and correction of personal information. Australian privacy law provides access and correction rights for organisations covered by the Privacy Act. New Zealand privacy law similarly provides access and correction rights. Swiss law provides rights relating to information, correction, deletion and restriction in applicable circumstances.
We may choose to provide substantially similar account-access, export, correction and deletion controls to all users, even where a particular statutory right does not apply.
17. Children and young people
Proposed minimum age: 18. This is a product and legal decision requiring confirmation.
The Aura Project is not designed or directed toward children.
We do not knowingly collect personal information from children below the applicable minimum age. In the United States, COPPA imposes specific requirements on services directed to children under 13 and on general-audience services that knowingly collect personal information from children under 13.
If we learn that an ineligible child has created an account, we will take reasonable steps to delete the account and associated information.
A parent or guardian who believes a child has provided personal information may contact privacy@aura-project.org.
18. Information about other people
Your journal may refer to partners, relatives, colleagues or other people.
You should avoid including identifying information about another person unless it is reasonably necessary for your private reflection. Do not use the journal to store another person’s passwords, financial information, medical records or other confidential documents.
The ability to write something in a private journal does not remove your responsibility to respect the rights and privacy of others.
19. Data breaches
If a security breach affects personal information, we will investigate it and take reasonable steps to contain and correct the issue.
Where applicable law requires notification, we will notify the relevant regulator and affected individuals within the legally required period.
Notifications will describe the incident honestly and will not include journal content unless inclusion is strictly necessary and lawful.
20. Changes to this policy
We may update this policy when:
- the service changes;
- service providers change;
- data practices change;
- security measures change; or
- legal requirements change.
The updated version will be posted on this page with a revised “Last updated” date.
Where a change materially affects how journal content is used, we will provide additional notice and obtain consent where legally required.
We will not quietly introduce advertising, AI analysis, sale of information or materially different uses of journal content without updating this policy and completing an appropriate privacy review.
21. Contact and privacy requests
Questions, complaints and requests concerning personal information may be sent to:
Data controller: [DATA-CONTROLLER IDENTITY] Privacy contact: Privacy contact Email: privacy@aura-project.org Support: support@aura-project.org Security: security@aura-project.org Postal address: [POSTAL ADDRESS] Privacy request form: https://aura-project.org/privacy/request Authenticated privacy centre: https://aura-project.org/account/privacy
Please do not include journal text or unnecessary sensitive information in an ordinary email request.
We will acknowledge and respond to privacy requests in accordance with applicable law after appropriate identity verification where required. The request workflow may use email verification, authenticated sessions, recent password confirmation and human review depending on the request.
22. Legal-review checklist
Before publication, a qualified reviewer should confirm:
- the identity and address of the data controller;
- the controller’s legal jurisdiction;
- the applicable GDPR lawful bases;
- the Article 9 condition for special-category journal content;
- the explicit-consent wording and interface;
- the minimum user age;
- the hosting and database location;
- all subprocessors and service providers;
- international-transfer safeguards;
- the supervisory authority;
- the privacy contact address;
- the 30-day backup-retention proposal;
- the 14-day log-retention proposal;
- the 24-hour export-file retention setting;
- support-message retention;
- the privacy request centre workflow;
- configurable deadline calculations;
- identity-verification rules;
- request-record audit retention;
- whether the CCPA or other US state laws apply;
- whether UK, Canadian, Australian, New Zealand or Swiss laws apply;
- the deletion and backup-restoration process;
- the legal-request handling procedure;
- breach-notification procedures;
- whether a data-protection impact assessment is required;
- whether a data-protection officer or representative is required; and
- whether the published policy accurately matches the implemented system.