Privacy Notice
Effective October 3, 2026
Information AuraFi uses
AuraFi uses account and security information, member-provided financial settings, linked-account data authorized through Plaid, and statement data a member explicitly uploads. This information supports authentication, financial snapshots, budgeting, affordability calculations, and account operations.
Financial data and calculations
Financial calculations run deterministically on AuraFi systems. Access is limited by authenticated member ownership. Plaid access tokens and configured provider credentials are encrypted at rest and are not returned to browsers.
Optional AI, voice, photos, documents, and barcodes
AuraFi AI is disabled unless an authorized developer configures, verifies, and enables it. Financial questions and explanations send the member’s question plus a minimized, allowlisted context—not member identity, bank credentials, account numbers, institution names, raw statements, or merchant-level histories. Financial arithmetic, goal projections, cash-flow capacity, debt payoff estimates, and budget-opportunity calculations run deterministically inside AuraFi. Obvious off-topic requests are rejected locally; uncertain requests use the least-cost pinned classifier before financial reasoning.
To support follow-up questions such as changing a goal horizon, AuraFi may retain bounded structured planning state for up to twenty-four hours. That state can contain a goal amount, horizon, contribution, return assumption, and active planning generation; it does not contain raw chat transcripts, bank identifiers, transactions, or provider conversation IDs. A planning reset deletes the state, and a financial-plan change invalidates stale state.
Voice capture begins only after a member selects “Start recording” and can be stopped or removed locally. A recording is sent to OpenAI for transcription only after the member separately checks the consent box and selects “Transcribe recording.” AuraFi does not persist the recording or returned transcript; the transcript is placed into the question field so the member can review it before asking Aura. Optional “Read aloud” playback uses the browser’s local speech-synthesis capability and does not send additional audio to AuraFi or OpenAI.
If a member captures or selects a purchase photo, it remains on the device until the member checks the consent box and selects “Send photo for identification.” That image is sent solely to identify the primary purchasable item; AuraFi instructs the model not to identify people, documents, cards, or personal data and not to estimate price. Retail barcode frames are decoded locally in the browser and are not uploaded for recognition. After a member confirms a supported UPC/EAN code and enters a comparison price, AuraFi may send only that code—not identity, IP address, store price, balances, or financial-plan data—to UPCitemdb for exact-product metadata and provider-reported retailer offers. AuraFi stores a short-lived product-offer cache to reduce repeat requests; it does not store scanned codes with member identities, although security logs may record that a provider lookup occurred. Retail prices, shipping, tax, availability, and variants must be verified at checkout.
A selected text-based receipt, bill, or invoice PDF is sent only after separate consent. AuraFi rejects image files and scanned or image-containing PDFs from the document-analysis route because identifiers embedded in pixels cannot be reliably redacted. It validates the PDF, holds it in request memory only, and does not persist it through this analysis flow. Extraction is read-only and must be confirmed by the member; confirmation does not update an account, transaction, or budget. Bank and credit-card statement import is a separate deterministic workflow that accepts UTF-8 CSV or eligible selectable-text PDF files and does not send statement contents to AI.
AuraFi requests store: false for OpenAI Responses API calls. OpenAI states that API content may still be retained for abuse monitoring for up to 30 days, and limited exceptional retention or review may apply. See OpenAI’s API data controls. Do not submit people, payment cards, account or routing numbers, IDs, tax records, medical records, or other highly sensitive material.
Sharing and service providers
AuraFi uses service providers only to operate requested features, including hosting, PostgreSQL data storage, Plaid account connectivity, Stripe billing where configured, UPCitemdb for a member-requested exact-barcode product lookup, and OpenAI only when AuraFi AI is enabled and the specific AI action is requested.
Optional Location Spend Guard, map, and notifications
Location Spend Guard is off by default. After an approved member enables the feature, the web/PWA can either perform a member-requested current-location check or, with a separate preference enabled, monitor meaningful movement only while AuraFi remains open and visible. In a supported installed native app, the member may separately enable Background Arrivals and grant the operating system Always or Allow all the time location access. AuraFi then uses a current fix to resolve nearby businesses and gives the operating system a rolling set of no more than sixteen business regions that expire after twenty-four hours. Entry may produce a local notification with sound and a link to AuraFi. The regions refresh when the native app opens or resumes; they are not continuous tracking and may not cover businesses outside the refreshed area.
AuraFi uses device-provided coordinates transiently to request nearby point-of-interest data from OpenStreetMap's Overpass service. The optional interactive map embeds OpenStreetMap and sends the viewed map area and marker position to that provider when it loads. AuraFi does not write raw latitude or longitude to its database or retain a route trail. Native operating systems necessarily retain active region definitions while monitoring them. If the member chooses to retain merchant-presence history, AuraFi stores only the probable merchant, merchant category, confidence, approximate distance, financial relevance reason, and expiration time for zero to seven days. Members can disable foreground monitoring, remove native background regions, disable the feature, revoke operating-system permission, or delete retained history at any time.
Browser push and native notification permission are separate and may be disabled at any time. Browser push endpoints and encryption keys are encrypted at rest. Members independently choose bill-due, spending-pattern, cash-flow, and location-alert categories. AuraFi evaluates confirmed recurring bills, posted transaction aggregates, budget pacing, and deterministic cash-flow calculations on AuraFi systems; raw transaction histories are not sent to an AI provider to create these alerts. Delivery records use bounded retry and expiration controls to prevent duplicate or stale notifications. Location alerts also respect a configured cooldown of at least sixty minutes. Web/PWA monitoring stops when the app is no longer active and cannot provide reliable closed-app geofencing. Native closed-app monitoring requires a signed native app, explicit elevated operating-system authorization, supported device settings, and successful physical-device certification.
Retention and security
AuraFi retains account and financial records as needed to provide the service, maintain security and auditability, and meet applicable operational requirements. For CSV and PDF statement import, the raw file and filename are discarded after in-memory parsing. Normalized rows awaiting review are automatically deleted after seven days; confirmed normalized transactions and their statement provenance remain part of the member's financial history until deletion or another applicable retention requirement. Security controls include encrypted transport, hashed passwords and sessions, passkey MFA, encrypted provider credentials, tenant ownership constraints, audit events, and restricted production networking.
Your choices
Members can type instead of using voice and can use the affordability tool manually without camera, location, notifications, or AI. A local recording, selected file, or captured photo can be removed before provider analysis. Members can pause proactive alerts, independently disable bill, spending-pattern, cash-flow, or merchant categories, revoke browser permissions, remove push subscriptions, disable Location Spend Guard, delete retained merchant-presence history, disconnect linked accounts, and use AuraFi support channels for access, correction, export, or deletion requests.