Privacy policy.
How AuraOne, Inc. collects, uses, shares, and protects information in connection with our websites, products, and services. Built on privacy-by-design principles, aligned with GDPR, CCPA, and HIPAA where they apply.
Last updated April 15, 2026
Where applicable.
Reach the DPO path below.
Controller and processor context.
This Policy applies to personal information we process as a data controller when you interact with our websites, documentation, and marketing communications, and as a data processor when we provide Services to enterprise customers.
For processing performed on behalf of enterprise customers, our Data Processing Addendum governs the relationship. Customer organizations maintain control over personal data processed within their AuraOne environments.
Primary data categories.
We collect the categories of information below in the course of providing our websites, products, and services. Specific items vary by product surface and customer configuration.
- Account & contact
- Name, email, company, job title, and authentication credentials.
- Usage & telemetry
- Feature usage patterns, interaction events, performance metrics, and error rates.
- Support data
- Ticket content, help desk communications, and troubleshooting logs.
- Technical logs
- IP addresses, browser type, device identifiers, and security logs.
- Payment info
- Billing contact and transaction history processed via Stripe.
Operational use cases.
We use the information described above to operate, secure, and improve the Service, and to meet our legal and contractual obligations.
- Service delivery and operations
- Security and fraud prevention
- Service improvement and analytics
- Legal compliance and obligations
- Contractual enforcement
- Communications and notifications
- Safety research using anonymized data
- Business administration
Why processing is permitted.
Where GDPR applies, we rely on the following lawful bases for processing personal data.
- Contractual necessity
- Processing required to perform our contract with you, including providing the Service.
- Legitimate interests
- Service improvement, security monitoring, fraud prevention, and internal administration.
- Legal obligations
- Compliance with tax laws, financial reporting, and data protection regulations.
- Consent
- Where required, we obtain explicit consent, including for marketing communications.
Privacy controls for the open authoring app.
Rubric Studio Open is designed as a local-first authoring tool. These controls apply to the desktop app, browser editor, CLI companion, telemetry controls, crash reporting, and AuraOne intake export flow.
- Local-first authoring
- Desktop projects stay on the user's machine unless the user explicitly exports, shares, or connects a hosted service. Browser edition projects use browser storage and user-provided provider keys where configured.
- Telemetry controls
- Rubric Studio Open telemetry is opt-in and transparent. Users can keep it off, review the event log, and disable submission without losing local authoring functionality.
- Intake export
- AuraOne intake export sends rubric packages only after an explicit user action. The export preview and redaction flow is designed to avoid silent background transfer.
- Crash reporting
- Crash reporting is default-off for the open app until enabled by the user. Crash payloads are intended to exclude API keys, credentials, and user-authored rubric content.
Security posture summary.
We implement technical and organizational measures designed to protect personal information, including encryption in transit and at rest, access controls, and security monitoring.
Specific controls and configurations vary by deployment and customer requirements. We can share details during a security review.
- Full encryption
- Access controls and MFA
- VPC network segmentation
- Vulnerability management
- Incident response team
Customer data stays opt-in.
We do not use customer data to train internal AI models without explicit consent.
- Customer-controlled training: you retain full ownership of your models and training data.
- Aggregated analytics: we use anonymized telemetry for platform improvement.
- Safety research: conducted using synthetic or public data only.
Questions about this policy?
For questions about this policy or to exercise your rights, use the privacy contact below or reach our team directly.
548 Market Street, PMB 71519
San Francisco, CA 94104-5401
United States