AureliaAurelia.

Privacy Policy

Last updated October 6, 2026

This Privacy Policy explains what personal data Aurelia ("we", "us", "Aurelia") collects when you use the Aurelia application (the "Service"), how we use it, who we share it with, and the rights you have over your data. By using the Service you agree to this policy.

1. Data we collect

  • Account data: your email, name, and encrypted password (or OAuth identifier).
  • Business data you enter: company details, leads, invoices, contracts, follow-ups, chat threads with the AI advisor.
  • Billing data: subscription plan, status, and Stripe customer identifier. Payment card details are processed by Stripe and never touch our servers.
  • Usage data: feature and page usage, AI request counts, and error logs used to keep the Service reliable.
  • Uploads: files you upload (e.g. company logo) stored in your private, per-user folder.

2. How we use your data

  • To provide the Service — running your CRM, generating AI content, sending invoices you create.
  • To authenticate you and secure your account.
  • To process subscription payments via Stripe.
  • To send transactional email (receipts, password resets, weekly reports if enabled).
  • To improve reliability and diagnose issues.

We do not sell your data. We do not use your private business data or AI conversations to train third-party foundation models.

3. Subprocessors

We rely on a small number of vetted subprocessors to run the Service:

  • Supabase — database, authentication and file storage (EU region).
  • Stripe — subscription billing and payment processing.
  • Lovable AI Gateway — routed AI model requests for the advisor, outreach and reports.
  • Cloudflare — content delivery and DDoS protection.

4. Data retention

We retain your data for as long as your account is active. When you delete your account, all business data you created (leads, invoices, contracts, chat threads, uploads, follow-ups) is deleted from our primary database within 30 days. Encrypted backups are rotated within 90 days. Anonymised aggregate usage metrics may be retained.

5. Your rights (GDPR / UK GDPR)

You have the right to access, correct, export, restrict, or delete your personal data. You can:

6. Security

Data in transit is encrypted with TLS. Data at rest is encrypted by our infrastructure providers. Access is enforced via row-level security so users can only read and write their own records. We follow the principle of least privilege for internal access and log privileged operations.

7. Cookies

We use strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies.

8. Changes to this policy

We may update this policy from time to time. Material changes will be announced in-app or by email at least 14 days before they take effect.

9. Contact

Questions? Email privacy@aurelia.app.