Skip to content
AuraStudy
HomeSupportTermsPrivacy

LEGAL / 02

Privacy Policy.

What AuraStudy uses to keep your study space working, and the choices available to you.

Draft for legal reviewEffective date: 28 September 2026

On this page

ScopeInformation we useWhy we use itWho receives itClass setup sharingSecurityRetention & deletionYour choicesTracking & websiteChildrenLocations & lawChangesContact
Before publication

This draft still needs the hosting configuration and retention facts in brackets. The 13+ eligibility choice without a guardian-consent step needs counsel review. The app links to this policy during its custom sign-up flow. See the reviewer notes before publishing.

01

Who we are and what this covers

Jonas Coleman (“AuraStudy,” “we,” “us,” or “our”), based in Ghana, provides the AuraStudy study-planning app and this website. This policy explains how information is used when you create an account, keep a personal study plan, choose cover images, and share or import class setups. Contact us at buildwithcole007@gmail.com.

Some features rely on services described below. Their own notices may apply when you sign in with them, view a photo from their servers, open their websites, or send a file through your device.

02

Information we use

Account and profile. You may sign up with an email address and password, verify your email, reset your password, or choose Google or Apple sign-in. Clerk handles the sign-in process. AuraStudy copies your Clerk account ID, name, verified primary email address, and available profile photo URL into its planner database. We also store the display name, institution, programme or field of study, study level, semester, and optional programme cover that you provide.

Study plan and notifications. We store the courses and weekly class sessions you enter, including course names, codes, credits, instructors or tutors, rooms and times; your semesters and timezones; tasks, due dates and optional due times, priorities and completion; and calendar activities. You can choose class, task, calendar and plan-update alerts, and how early local reminders arrive. If alerts are on and your device permits them, the app schedules selected class, activity and task alerts locally. Upcoming selected reminders appear in the app, and selected reminders can appear as temporary in-app toasts while the app is open even if device notification permission is unavailable. Local alert text can include a task or class name, time and room, and may be visible on your lock screen depending on device settings. The app refreshes its local schedule when it opens and when your saved plan changes. When plan updates are enabled, the app registers an Expo push token with our backend so a generic update can be sent to your other registered devices after a planner change. This generic push contains no user-entered study text. A device refreshes its detailed plan when reopened.

Cover images. If you open the cover picker, it suggests a search based on your programme or course title; you can edit the words and choose between Unsplash and AuraStudy’s curated image collection. We process your search words, selected provider and photo ID, and store your chosen image reference and selection record. Neutral artwork is available without choosing a remote cover.

Messages to us. If you email the contact address in this policy, we receive your email address, message, and any information you choose to include so we can respond to you.

App analytics, logs, and errors. The PostHog mobile SDK records app lifecycle events such as opens and backgrounding, including a launch URL if one is present. The app also sends events when you complete onboarding, add or edit courses, tasks or activities, change task completion, select a cover, or share or import a class setup. These events include limited details such as an item’s category, priority, or counts, rather than the title or text you entered. The app sends structured logs for app starts, notification-onboarding outcomes, and failed study-record or class-setup operations; those logs use fixed messages and limited categories, without your entered titles or raw error messages. The logs include a PostHog identifier, session ID, and app state. PostHog receives device and app details, your IP address, and approximate location inferred from it. The SDK captures uncaught JavaScript errors and unhandled promise rejections; reports can contain messages, stack traces, and device or app context. After sign-in, the app sends your Clerk user ID to PostHog to associate records with your account, and resets the local PostHog identity when you sign out. Automatic screen tracking is enabled by the SDK by default, but its behavior with this app’s Expo Router setup has not been verified. [CONFIRM PRODUCTION-BUILD EVENTS AND LOGS, SCREEN EVENTS, AND ANY DASHBOARD-ENABLED FEATURES.]

Technical records. Our backend stores account-linked authentication event IDs and times, image-selection records, rate-limit counts and windows, class-setup import receipts and mappings, an account deletion marker, and, when enabled, Expo push tokens, device platform and push-ticket records. These records help the service authenticate requests, prevent duplicate processing and abuse, deliver and check plan-update pushes, and complete imports and deletions. Supabase, Vercel, Cloudflare Pages, and other network providers may also record function invocations, website requests, IP addresses, device or browser information, and request times. The exact contents and retention of live provider and website-host logs are [CONFIRM PROVIDER AND HOST LOGGING].

03

Why we use it

We use account information to create and protect your account, verify sign-in, recover access, and connect your saved plan to you. We use your academic and planner entries to show courses, calendar events, tasks, and due states; save your edits; and import or export a class setup when you request it. We use image information to search and display optional covers, credit photographers, and record selections. We use limited technical records to enforce request limits, prevent replayed events, and respond to deletion requests. We use PostHog events, logs, and error reports, when enabled, to understand app usage and diagnose problems.

[CONFIRM LEGAL BASES FOR PROCESSING WHERE REQUIRED BY APPLICABLE LAW.]

04

Services that receive information

Clerk handles account creation, authentication, verification, recovery, and session storage. Supabase hosts AuraStudy’s account-linked planner database, notification choices, push tokens and server functions. The app sends a Clerk session token to Supabase when accessing your records. Expo receives a device push token and a generic plan-update message when the server sends a cross-device push; Apple or Google device push systems carry it to your device.

Google or Apple participate if you choose their sign-in option. Their sign-in screens and account practices are governed by their own notices. Google also provides the Gmail inbox used for support and privacy-request messages sent to our contact address.

PostHog receives the analytics, account identifier, and error information described above when its app integration is configured. Its data-hosting location and retention settings are [CONFIRM POSTHOG REGION AND RETENTION].

Unsplash receives the search words sent by our server when you search its photos. When you select a photo, our server requests its photo details and sends a required download event. Unsplash-hosted photos load directly on your device, and credit links open Unsplash. ImageKit supplies the curated photo collection: our server retrieves a fixed catalog and ranks your query itself, so this search route does not send your literal search words to ImageKit. Selecting an ImageKit cover requests that file’s details. Displaying either provider’s remote image makes a direct image request from your device that can reveal ordinary connection information to that provider.

Vercel and Cloudflare Pages host this website and may process website request and diagnostic data when a visitor loads it. Your device’s operating-system share sheet and any recipient service you choose receive a class setup file only when you share it. [CONFIRM ANY ADDITIONAL HOSTING OR SUPPORT PROVIDERS OUTSIDE THIS REPOSITORY.]

05

Class setup sharing

You can create a file containing a class setup title, timezone, semester name and dates, selected course names, codes and credits, and weekly session times, tutor names and rooms. The export is designed to leave out your account ID, profile, tasks, and personal calendar activities. Review the file and recipient before using the share sheet: someone else may keep or forward their copy, and deleting your AuraStudy account cannot recall it.

An outgoing file is temporarily written to app cache and the app removes that copy after the share sheet completes. A file sent into AuraStudy may be staged in app document storage until you open or clear the import. Importing a received setup adds the selected details to your own account.

06

How the app protects records

Clerk manages sign-in and the native app uses its token cache. AuraStudy checks the current signed-in session for server requests. Its database has account-owner access rules and keeps operational tables outside the student-facing API. Clerk webhook messages are signature checked. The server handlers are written to avoid returning or application-logging passwords, tokens, request bodies, provider errors, or secret keys.

No security system guarantees absolute protection. [CONFIRM LIVE SECURITY CONFIGURATION, VENDOR CONTROLS, AND INCIDENT CONTACT PROCESS BEFORE PUBLICATION.]

07

How long records remain and what deletion does

Your profile and saved study records remain with your account unless you edit or delete them. The app has no automatic age-based or time-based expiry for these records. When its Delete account flow succeeds, the server requests deletion of your Clerk identity and removes the AuraStudy profile and linked courses, tasks, activities, semesters, cover selections, import mappings, push tokens and push-ticket records from the active database. Disabling Plan updates or signing out attempts to unregister the device's push token; invalid tokens are removed after failed delivery reports. A deletion marker, account-linked event IDs and timestamps remain in private operational tables to prevent an old event from recreating the account. The current database code has no automatic purge for those records.

Deleting an account does not currently send a deletion request to PostHog; its account-linked analytics and error records may remain there under separate retention settings. Provider systems, backups, already-shared class setup files, and a staged file on your device may follow different retention or cleanup paths. [CONFIRM POSTHOG, BACKUP, PROVIDER, SUPPORT-REQUEST AND WEBSITE-LOG RETENTION PERIODS.] The account deletion function exists in this repository, but its availability in the hosted app has not yet been verified.

08

Your choices and requests

You can edit your display name and academic details in Profile; the verified account email is shown there but cannot be edited in that screen. You can edit or delete planner items, choose notification categories and lead times in Profile, change device notification permission in your phone settings, and choose neutral artwork instead of a remote cover. You can export selected class setup information. This export is not a download of all account data.

Profile includes a confirmed Delete account action. If it cannot confirm deletion, the app shows a retry message. You can also write to buildwithcole007@gmail.com about access, correction, deletion, or other rights that apply where you live. We may need to verify a request and preserve limited information when the law permits or requires it. [CONFIRM REQUEST-HANDLING PROCESS AND RESPONSE TIME REQUIRED BY APPLICABLE LAW.]

09

Analytics, ads, and this website

The mobile app includes PostHog analytics and JavaScript error tracking when its public project configuration is present. The code does not include an advertising SDK. Detailed study reminders are scheduled locally through your device’s notification system; generic cross-device plan updates use Expo push delivery when a supported app build is installed. This standalone website uses local images and CSS; it has no app-written analytics script, form, or cookie-consent control. It is hosted on Vercel and Cloudflare Pages, which can generate request and diagnostic records. Clerk documents SDK usage telemetry for development instances, which it says does not include end-user information. Supabase documents automatic function invocation logging. The live PostHog, Vercel, and Cloudflare project settings, provider records, and any additional scripts or diagnostics still need review. [CONFIRM LIVE HOSTING AND PROVIDER TECHNICAL DATA PRACTICES.]

10

Children and eligibility

AuraStudy is designed for students worldwide, but the app does not check age or verify school enrolment. It is intended for people aged 13 and above. The current app does not request or verify parent or guardian consent. Local laws may impose additional requirements for younger users. If you believe someone under 13 has used the Service, contact buildwithcole007@gmail.com.

11

Locations and applicable rights

Our publisher is based in Ghana, and AuraStudy is intended for users in all countries and regions. Service providers, including Clerk, Supabase, PostHog, Vercel, Cloudflare, and the image providers, may process information outside your country. [CONFIRM INTERNATIONAL TRANSFER SAFEGUARDS AND JURISDICTION-SPECIFIC DISCLOSURES.] Privacy rights and complaint routes depend on where you live; contact buildwithcole007@gmail.com to make a request under applicable law.

12

Changes to this policy

We may revise this policy as the service changes. We will post the updated policy with a new effective date and give any additional notice required by applicable law.

13

Contact

For questions or privacy requests, contact Jonas Coleman at buildwithcole007@gmail.com.

Review before publishing. Fill the bracketed facts, verify the deployed account deletion path, and have a qualified attorney review this policy.
AuraStudy

Your study space, thoughtfully kept.

SupportTerms of ServicePrivacy Policy