Skip to content
AuraStudy
HomeSupportTermsPrivacy

LEGAL / 02

Privacy Policy.

What AuraStudy uses to keep your study space working, and the choices available to you.

Draft for legal reviewProposed effective date: 29 September 2026

On this page

ScopeInformation we useWhy we use itWho receives itClass setup sharingSecurityRetention & deletionYour choicesTracking & websiteChildrenLocations & lawChangesContact
Before publication

This policy describes the current app and known providers. Live vendor retention and transfer settings, deletion of stored profile photos and analytics records, and the 13+ eligibility rule still need operational and legal review.

01

Who we are and what this covers

Jonas Coleman (“AuraStudy,” “we,” “us,” or “our”), based in Ghana, provides the AuraStudy study-planning app and this website. This policy explains how information is used when you create an account, keep a personal study plan, choose cover images, and share or import class setups. Contact us at buildwithcole007@gmail.com.

Some features rely on services described below. Their own notices may apply when you sign in with them, view a photo from their servers, open their websites, or send a file through your device.

02

Information we use

Account and profile. You may sign up with an email address and password, verify your email, reset your password, or choose Google or Apple sign-in. Clerk handles credentials and sign-in. AuraStudy copies your Clerk account ID, name, verified primary email address, and available provider photo URL into its planner database; the planner database does not store your password. We also store the display name, institution, programme or field of study, study level, semester, and optional programme cover that you provide.

Custom profile photo. If you choose or take a photo in Profile, the app asks for the relevant photo-library or camera permission. It creates a square JPEG on your device and uploads that image to Supabase Storage when you save. The image is displayed from a public URL that contains your Clerk account ID: anyone with the URL may be able to view it, even without an AuraStudy account. The app stores the image path on your profile and attempts to remove the previous image when you replace or remove it.

Study plan and progress. We store the courses and weekly class sessions you enter, including course names, codes, credits, instructors or tutors, rooms and times; your semesters and timezones; tasks, due dates and optional due times, priorities and completion; and calendar activities. Completed Study tasks and study sessions can store a completion time, local study date and timezone, and any session minutes you enter. The app derives course progress and study streaks from those records; it does not fetch academic records from your institution.

Notifications. We store your choices for class, task, calendar, study-streak and plan-update alerts and reminder times. When selected alerts are on, the app schedules detailed reminders on your device; some may also appear as temporary in-app toasts. Reminder text can include a task or class name, time and room, and may appear on your lock screen depending on device settings. When Plan updates is on and your device permits notifications, the app registers a push token so a generic change alert can be sent to your other registered devices. That push does not contain your study text. Detailed plan changes are fetched when a device reopens.

Cover images. If you open the cover picker, it suggests a search based on your programme or course title; you can edit the words and choose between Unsplash and AuraStudy’s curated image collection. We process your search words, selected provider and photo ID, and store your chosen image reference and selection record. Neutral artwork is available without choosing a remote cover.

Messages to us. If you email the contact address in this policy, we receive your email address, message, and any information you choose to include so we can respond to you.

App analytics, logs, and errors. When configured, PostHog records app lifecycle events such as opens and backgrounding, including a launch URL if one is present. The app sends events for sign-in and account creation, onboarding, course and task changes, completed study days and streak milestones, cover selection, and class setup sharing or importing. These event calls use categories, counts or status rather than user-entered titles. Fixed-message logs cover app starts, notification-onboarding results, and selected failed save or class setup operations; they include a PostHog identifier, session ID and app state. PostHog also receives device and app details, your IP address and approximate location inferred from it. Its SDK captures uncaught JavaScript errors and unhandled promise rejections, which can include messages, stack traces and device context. After sign-in, the app sends your Clerk user ID to PostHog to associate records with your account; it resets the local identity on sign-out. The SDK can track screens, although screen-event delivery with this app has not been verified.

Technical records. Our backend stores account-linked authentication event IDs and times, image-selection records, rate-limit counts and windows, class-setup import receipts and mappings, an account deletion marker, and, when enabled, push tokens, device platform and push-ticket records. These help authenticate requests, prevent duplicate processing and abuse, deliver plan-update pushes, and complete imports and deletions. Hosting and network providers may also record requests, IP addresses, device or browser details and request times. The exact contents of their live logs depend on provider settings.

03

Why we use it

We use account information to create and protect your account, verify sign-in, recover access, and connect your saved plan to you. We use your academic and planner entries to show courses, calendar events, tasks, due states, course progress and study streaks; save your edits; and import or export a class setup when you request it. We use image information to display your chosen profile photo or optional covers, credit photographers, and record cover selections. We use technical records for security, request limits, duplicate-event prevention and deletion handling. We use PostHog events, logs and error reports, when configured, to understand app use and diagnose problems. We use support messages to answer you.

Where a legal basis is required, we rely on performance of our agreement with you for accounts and core planner features; our legitimate interests in securing, maintaining and improving the Service for security records and proportionate diagnostics; and compliance with legal obligations when applicable. Optional device permissions and notification choices are controlled through the app and your device. The current app has no separate analytics-consent control; whether one is required in a particular market needs review before release there.

04

Services that receive information

Clerk handles account creation, authentication, verification, recovery, and session storage. Supabase hosts AuraStudy’s account-linked planner database, custom profile photos, notification choices, push tokens and server functions. The app sends a Clerk session token to Supabase when accessing your records. Expo receives a device push token and a generic plan-update message when the server sends a cross-device push; Apple or Google device push systems carry it to your device.

Google or Apple participate if you choose their sign-in option. Their sign-in screens and account practices are governed by their own notices. Google also provides the Gmail inbox used for support and privacy-request messages sent to our contact address.

PostHog receives the analytics, account identifier, logs and error information described above when its app integration is configured. The active project's hosting region and retention settings have not been confirmed for this policy.

Unsplash receives the search words sent by our server when you search its photos. When you select a photo, our server requests its photo details and sends a required download event. Unsplash-hosted photos load directly on your device, and credit links open Unsplash. ImageKit supplies the curated photo collection: our server retrieves a fixed catalog and ranks your query itself, so this search route does not send your literal search words to ImageKit. Selecting an ImageKit cover requests that file’s details. Displaying either provider’s remote image makes a direct image request from your device that can reveal ordinary connection information to that provider.

Vercel and Cloudflare Pages are used for versions of this website and may process website request and diagnostic data when a visitor loads a hosted page. Your device’s operating-system share sheet and any recipient service you choose receive a class setup file only when you share it.

05

Class setup sharing

You can create a file containing a class setup title, timezone, semester name and dates, selected course names, codes and credits, and weekly session times, tutor names and rooms. The export is designed to leave out your account ID, profile, tasks, and personal calendar activities. Review the file and recipient before using the share sheet: someone else may keep or forward their copy, and deleting your AuraStudy account cannot recall it.

An outgoing file is temporarily written to app cache and the app removes that copy after the share sheet completes. A file sent into AuraStudy may be staged in app document storage until you open or clear the import. Importing a received setup adds the selected details to your own account.

06

How the app protects records

Clerk manages sign-in and the native app uses its token cache. AuraStudy checks the signed-in session for server requests. Its planner database has account-owner access rules and keeps operational tables outside the student-facing API. Clerk webhook messages are signature checked. The app's server handlers are written to avoid returning or application-logging passwords, tokens, request bodies, provider errors or secret keys. Custom profile photo files use a public bucket and should be treated as viewable by anyone with the URL.

No security system guarantees absolute protection. Email buildwithcole007@gmail.com if you believe your account or information has been exposed.

07

How long records remain and what deletion does

Your profile and saved study records remain with your account unless you edit or delete them. The app has no automatic time-based expiry for those records. If the Delete account request succeeds, the server requests deletion of your Clerk identity and removes the AuraStudy profile and linked courses, tasks, activities, semesters, cover selections, import mappings, push tokens and push-ticket records from the active database. Disabling Plan updates or signing out attempts to unregister the device's push token. A deletion marker, account-linked event IDs and timestamps remain in private operational tables to prevent an old event from recreating the account; the current database code has no automatic purge for these records.

The current Delete account function does not remove custom profile photo objects from Supabase Storage or send a deletion request to PostHog. Those images may remain accessible by their public URLs, and account-linked analytics, logs and errors may remain under PostHog's settings. Provider systems and backups, support email, website logs, files already shared with others and incoming setup files staged on a device may follow separate retention paths. We have not confirmed fixed deletion periods for these provider records. Contact buildwithcole007@gmail.com if you need help requesting removal of remaining account-linked information. The hosted Delete account path has not yet been verified end to end.

08

Your choices and requests

You can edit your display name, academic details and custom profile photo in Profile; the verified account email is shown there but cannot be edited in that screen. You can edit or delete planner items, change notification categories and times, adjust device permissions in your phone settings, and use neutral artwork instead of a remote cover. You can export selected class setup information. This export is not a download of all account data.

Profile includes a confirmed Delete account action. If it cannot confirm deletion, the app shows a retry message. You can also email buildwithcole007@gmail.com to request access, correction, deletion, a copy of your information, or to object to or restrict processing where your local law provides those rights. We may need to verify that you own the account and may retain limited information when law permits or requires it. We will respond within the period required by applicable law. You may also complain to a data-protection authority, including the Ghana Data Protection Commission or your local authority where applicable.

09

Analytics, ads, and this website

The mobile app includes PostHog analytics and JavaScript error tracking when its project configuration is present. It has no advertising SDK in the current app. The website files use local images and CSS and contain no app-written analytics script or form. Website hosts and app providers can still create request and diagnostic logs; their live settings may differ from what is visible in this repository. The current website files do not set their own analytics cookies.

10

Children and eligibility

AuraStudy is intended for people aged 13 and above, or any higher minimum age that applies where they live. It does not currently check age, verify school enrolment, or provide a parent-or-guardian consent flow. If you believe someone below the applicable age has used the Service, contact buildwithcole007@gmail.com so we can investigate and address their information.

11

Locations and applicable rights

Our publisher is based in Ghana, and AuraStudy is intended for users in multiple countries. Clerk, Supabase, PostHog, website hosts and image providers may process information outside your country. Their active processing locations and the transfer arrangements for each route have not been confirmed for this policy. Where applicable law requires a transfer safeguard, one must be in place before that transfer. Contact buildwithcole007@gmail.com to ask about your information or applicable local rights.

12

Changes to this policy

We may revise this policy as the service changes. We will post the updated policy with a new effective date and give any additional notice required by applicable law.

13

Contact

For questions or privacy requests, contact Jonas Coleman at buildwithcole007@gmail.com.

Review before publishing. Verify live vendor settings, photo and analytics deletion, international transfers, and minor eligibility with qualified counsel.
AuraStudy

Your study space, thoughtfully kept.

SupportTerms of ServicePrivacy Policy