Skip to content

Privacy

Privacy Policy

Last updated: July 23, 2026

Policy version: 2026-07-23

1. About This Policy

This Privacy Policy explains how Aura Project collects, uses, stores, protects, exports and deletes personal information when you visit aura-project.org, create an account, use the private journal, contact us, submit a privacy request, or otherwise use the website and journal service.

In this policy, "Aura Project", "we", "us" and "our" refer to the controller below.

  • Controller: Mike Graham
  • Business/trading name: Rock Paper Scissors
  • Published address: Norra Vägen 4, 30232 Halmstad, Sweden
  • Establishment and legal jurisdiction: Sweden / Sweden
  • Privacy contact: Mike Graham, privacy@aura-project.org
  • Data Protection Officer contact: Mike Graham, privacy@aura-project.org

2. The Service

Aura Project provides a private online journal that accompanies The Authenticity Cleanse: 4 Weeks to Release Resentment and Rediscover Your Voice by Mike Graham. The journal is a self-reflection tool. It is not medical care, psychological treatment, crisis support or a substitute for professional advice.

Journal entries can be deeply personal. The service is designed so journal content is processed only as needed to provide, secure, maintain, export and delete the private journal.

3. Information We Collect

Account Information

When you create or use an account, we process information such as:

  • name or display name;
  • email address;
  • password hash and authentication records;
  • email verification status;
  • account creation and update dates;
  • language, time zone, theme and accessibility preferences;
  • optional reminder settings; and
  • security events, sessions and password-reset records.

We do not have access to your original password.

Journal Information

When you use the journal, we process information such as:

  • free-form journal entries and private notes;
  • answers to structured reflection prompts;
  • the journal day, week, content version and completion status;
  • creation, autosave, update and completion timestamps;
  • programme progress; and
  • export and deletion records.

Sensitive Information

The journal does not require you to disclose sensitive information, but free-form writing may include health, addiction or recovery information, religious or philosophical beliefs, sexuality, relationships, trauma, family matters, political opinions or other special-category information.

The journal consent flow records consent for storing journal content that may contain sensitive personal information. Consent records include the user, policy version, consent-text hash, consent timestamp, withdrawal timestamp where applicable, and source. You may withdraw journal consent in the account privacy centre. Withdrawing consent deletes active journal content, subject to temporary backup retention.

Technical, Security and Support Information

When you use the site or contact us, we may process:

  • IP address, browser, device and operating-system details;
  • request dates, routes, status codes and server errors;
  • authentication, session and failed-login events;
  • privacy-request messages and status records;
  • support correspondence and our responses; and
  • information needed to detect misuse, investigate errors or maintain the service.

Do not send journal entries or highly sensitive information by ordinary email. Email is used for account, privacy, verification, reset and support messages, not as a journal-storage channel.

4. How We Use Information

We use personal information to:

  • create and administer accounts;
  • authenticate users and protect accounts;
  • provide, save, retrieve and display journal entries;
  • track journal progress;
  • provide exports in JSON and readable Markdown inside a ZIP file;
  • process entry, journal and account deletion requests;
  • record, withdraw and evidence journal consent;
  • send account verification, password reset, privacy and export messages;
  • respond to privacy, support, legal and security enquiries;
  • diagnose technical failures and investigate security incidents;
  • maintain backups and business continuity; and
  • comply with legal obligations or establish, exercise or defend legal claims.

5. Legal Grounds

Where the EU GDPR, Swedish data-protection law, UK GDPR or similar legislation applies, we rely on one or more of the following legal grounds:

  • Contract: to provide the account and private journal service you request.
  • Explicit consent: to store journal content that may include special-category information.
  • Consent: for optional features where consent is required.
  • Legitimate interests: to secure, maintain, debug and protect the service, provided those interests are not overridden by your rights and freedoms.
  • Legal obligation: where processing or retention is required by applicable law.
  • Legal claims: where limited processing is necessary to establish, exercise or defend legal claims.

6. What We Do Not Do With Journal Entries

Journal entries are not intentionally:

  • read by us as part of normal service operation;
  • sold, rented or exchanged for commercial benefit;
  • used for advertising, targeted advertising or cross-context behavioural advertising;
  • shared with data brokers;
  • sent to AI or machine-learning services;
  • used to train AI models;
  • analysed to diagnose medical or psychological conditions;
  • included in third-party analytics, session replay or heat-map services;
  • included in email messages;
  • made public; or
  • shared with other users.

We do not provide a routine administrator interface for reading users' journal entries. Authorised infrastructure administrators may technically access database contents when genuinely necessary for essential system administration, security investigation, backup restoration or incident recovery. Journal data is not end-to-end encrypted.

7. Cookies, Local Storage and Fonts

The service uses cookies and similar browser storage needed to keep you signed in, protect forms, maintain secure sessions, remember interface preferences and support journal autosave behaviour. These are used for functionality and security, not advertising.

The site loads browser fonts from Bunny Fonts. When your browser requests those font files, Bunny Fonts may receive ordinary technical request data such as IP address, browser details and request time.

We do not use advertising cookies, cross-site tracking cookies, third-party behavioural analytics, session replay tools or heat-map tools in the current service.

8. Infrastructure and Processors

The current production service uses the following infrastructure:

  • Application server: Amazon Web Services (AWS) Lightsail, eu-west-2 (London, United Kingdom).
  • Database: Amazon RDS, eu-west-2 (London, United Kingdom).
  • Database backups: retained in the same AWS region only for 30 days.
  • Local VPS backups: not used for this application.
  • Transactional email: AWS SES, eu-west-2 (London, United Kingdom), sent from noreply@aura-project.org.
  • Generated exports: stored on local private server storage outside the public web root until expiry.
  • Sessions and cache: database-backed Laravel sessions and database-backed Laravel cache.

Current processors and processor-like service providers are:

  • Amazon Web Services (AWS) - Lightsail application server: Application hosting, server logs, generated export files and operational server storage. Location: eu-west-2, London, United Kingdom Retention: Application logs: 14 days where configured; generated exports: 24 hours; local VPS backups: not used for this application.
  • Amazon Web Services (AWS) - Amazon RDS database: Account data, journal entries, structured answers, consent records, privacy requests, sessions and cache records. Location: eu-west-2, London, United Kingdom Retention: Active records follow account controls; database backups are retained for 30 days in the same AWS region.
  • Amazon Web Services (AWS) - AWS SES transactional email: Email addresses, transactional email metadata and generic account, privacy, verification and reset messages. Journal content is not intentionally included in email. Location: eu-west-2, London, United Kingdom Retention: Service and delivery logs are retained indefinitely unless provider settings or applicable law require a different period.
  • Bunny Fonts - Browser font delivery: Technical request data generated when a browser requests font files from fonts.bunny.net. Location: Provider network locations. Retention: Handled under the provider service terms and privacy practices.

No Cloudflare proxying, advertising analytics, CAPTCHA, external support-ticket platform or external VPS backup provider is listed for the current service. If Amazon S3, analytics, monitoring or external backup services are introduced for personal data, this policy and the internal processor register must be updated before that processing begins.

9. International Transfers

The primary application server, database and AWS SES email processing are in AWS region eu-west-2, described by AWS as London, United Kingdom. The website may be accessible internationally, and service providers may operate support, security or network infrastructure from other countries.

Where personal information protected by GDPR, UK GDPR or comparable law is transferred internationally, we use appropriate safeguards where required, such as adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, processor terms, and technical and organisational controls.

10. Security

We use technical and organisational measures intended to protect personal information, including:

  • HTTPS encryption in transit;
  • password hashing;
  • authenticated journal access;
  • server-side ownership and authorisation checks;
  • CSRF protection and secure session cookies;
  • login and request throttling;
  • security headers;
  • restricted database and infrastructure access;
  • database backups; and
  • operational monitoring and investigation of technical or security failures.

HTTPS protects information while it is transmitted. Authentication and application controls restrict access to journal pages. Journal data is stored in the database and is not end-to-end encrypted. No online service can guarantee absolute security.

11. Retention

We retain personal information only for as long as reasonably necessary for the purposes in this policy.

  • Account information: kept while the account remains active, then deleted or minimised after account deletion unless limited retention is required by law or legal claims.
  • Journal entries: kept until you delete the entry, delete all journal entries, withdraw journal consent, or delete your account.
  • Generated exports: expire after 24 hours and are single-use once downloaded.
  • Application and web logs: retained for 14 days where configured.
  • Database backups: retained for 30 days in the same AWS region.
  • Privacy-request audit records: retained for 360 days after closure, then request messages and identifying details are deleted or minimised by the maintenance workflow.
  • Support correspondence: kept while needed to respond to the request and manage the service, then deleted or minimised when no longer needed.
  • Security-event records: kept while needed for account security, abuse prevention, legal claims, privacy request handling or an active investigation.
  • AWS SES email logs: indefinite service and delivery logs unless the provider account settings or applicable law require a different period.

Deleted information may remain in encrypted database backups until the backup-retention period expires. If a backup is restored, deletion records should be reviewed and reapplied where technically feasible.

12. Your Account Controls

The service is intended to let you:

  • edit journal entries;
  • delete an individual entry;
  • delete all journal entries;
  • export account, journal, consent, privacy request and security-event information;
  • withdraw journal consent;
  • submit and track privacy requests;
  • update account information and preferences; and
  • delete your account.

The authenticated privacy centre is available at https://aura-project.org/account/privacy. The public privacy request form is available at https://aura-project.org/privacy/request.

Destructive actions may require recent password confirmation and typed confirmation text. Account deletion removes the active account, journal entries, structured answers, journey progress, preferences, sessions, password-reset tokens and generated export files, subject to temporary backup retention and any overriding legal requirement.

13. Your Rights

Depending on where you live and which law applies, you may have rights to be informed, access information, correct inaccurate information, request deletion, restrict processing, object, receive portable data, withdraw consent, appeal a privacy decision, and complain to a competent supervisory authority.

These rights are not absolute. We may need to verify your identity and may restrict a request where an exemption applies, where another person's rights are affected, where a request is abusive or excessive, or where retention is legally required.

Privacy requests may be submitted through https://aura-project.org/privacy/request or by emailing privacy@aura-project.org. Complaints may also be made to a competent data-protection supervisory authority in your country of residence, place of work or place of the alleged infringement.

14. United States Privacy Notice

The controller has confirmed that the service does not sell personal information, does not share personal information for cross-context behavioural advertising, does not use targeted advertising or profiling, and does not currently meet California or other US state privacy-law thresholds.

Even where a specific US state privacy law does not apply, we provide substantially similar self-service access, export, correction, deletion, consent-withdrawal and opt-out controls to users through the privacy centre and request forms.

The Do Not Sell or Share preference form is available at https://aura-project.org/privacy/do-not-sell-or-share.

15. Children and Young People

The service is not designed for children. You must be at least 16 years old to create an account or use the journal. If we learn that an ineligible child has created an account, we will take reasonable steps to delete the account and associated information.

16. Information About Other People

Your private journal may refer to partners, relatives, colleagues or other people. You should avoid including identifying information about another person unless it is reasonably necessary for your private reflection. Do not use the journal to store another person's passwords, financial information, medical records or confidential documents.

17. Data Breaches

If a security breach affects personal information, we will investigate, contain and correct the issue. Where applicable law requires notification, we will notify the relevant regulator and affected individuals within the legally required period. Notifications will not include journal content unless inclusion is strictly necessary and lawful.

18. Changes to This Policy

We may update this policy when the service, providers, data practices, security measures or legal requirements change. The updated version will be posted on this page with a revised date. We will not quietly introduce advertising, AI analysis, sale of information or materially different uses of journal content without updating this policy and completing the necessary privacy review.

19. Contact