AuraStyle

AuraStyle Privacy Policy

Last updated: 17 August 2026 Effective: 17 August 2026


1. Who we are

AuraStyle is operated by ASSISTTECH CORP., a C corporation incorporated in the State of New Jersey ("AuraStyle", "we", "us", "our").

Registered office 213 John Street, Harrison, NJ 07029
Privacy contact privacy@assisttechcorp.com
General support support@assisttechcorp.com
Data deletion https://aurastyle.assisttechcorp.com/delete-account

This policy explains what we collect when you use the AuraStyle mobile application and related services (the "Service"), why, and what control you have. It applies to the app and our API. It does not apply to retailer websites you reach through our links — see §7.


2. The short version


3. Information we collect

3.1 Information you give us

Data Required? Why
Email address Required Account identity, sign-in, password reset, service notices
Password Required (email sign-up only) Authentication. Stored only as a salted scrypt hash — we cannot read it
Display name Optional Personalising the app
Gender identity, body type, measurements Optional Sizing and fit recommendations. Blank unless you fill them in
Provider account identifier If you use Google or Apple sign-in Links your social account to your AuraStyle account. We receive an identifier and, where you permit, your email and name — never your provider password
Wardrobe item names and notes Optional Labelling garments you add

3.2 Information generated by using the Service

3.3 Device information

3.4 What we do NOT collect

We do not collect or request: precise or approximate location; your contacts; your calendar; your SMS, call logs or messages; audio recordings; files or documents outside a photo you deliberately select; your web browsing history; biometric identifiers; health or medical information; government identifiers; or payment card numbers (see §8).

The app requests only three Android permissions: CAMERA (only when you open the scanner), READ_MEDIA_IMAGES (only when you pick a photo), and INTERNET. Storage-write permissions are explicitly blocked in our build configuration.


4. How outfit photos are handled

This section describes a technical guarantee, not an intention.

When you scan an outfit:

  1. The image is uploaded over TLS to our API.
  2. It is held in server memory only. It is never written to a file, a temporary directory, a cache, an object store, a queue or a backup.
  3. Our analyser extracts derived attributes: a colour palette (a handful of hex codes), garment proportions, surface pattern, and style tags.
  4. The memory buffer holding the image is overwritten with zeros and released. This happens whether the analysis succeeded, failed, or was cancelled.
  5. Only the derived attributes are returned to you and, if you confirm, saved.

Consequences you can rely on:

These properties are enforced by automated tests in our build pipeline, not merely by policy: a change that introduced image persistence would fail the build.

Optional AI enrichment. If enabled for your account or region, a copy of the frame may be transmitted to a third-party model provider (OpenAI) purely to compute style tags in real time. In that case: the provider acts as our service provider under contract, is prohibited from using your image to train models, and does not retain it beyond the request. Nothing about this changes §4 steps 2–5 on our side. If this feature is disabled, your image never leaves our server. We will state the current status in-app on the scanner screen.


5. Why we use your information (and our legal bases)

Purpose Data used GDPR legal basis
Create and secure your account Email, password hash, provider id Contract
Personalise recommendations Style signals, Style DNA, saved/hidden items, profile Contract
Analyse a scanned outfit Photo (ephemeral), derived attributes Contract
Send alerts you enabled Push token, notification preferences Consent
Send password resets and essential service emails Email Contract
Attribute affiliate commission Click record, tracking identifier Legitimate interests (operating a free service)
Enforce free-tier limits and prevent abuse Usage counters, rate-limit counters Legitimate interests (service integrity)
Provide and verify Premium Subscription identifier and status Contract
Comply with law As required Legal obligation

We do not use your data for profiling that produces legal or similarly significant effects, and we do not make automated decisions of that kind.


6. Your control over what the agent knows

These are product features, available immediately in the app — not requests you file and wait on.

You may also exercise these rights by writing to privacy@assisttechcorp.com.


7. Affiliate links and how we make money

AuraStyle is free to use. We earn affiliate commission when you buy something after tapping a link in the app. We participate in the Amazon Associates Program. Every product in the app is sold on Amazon, and every outbound link goes there.

As an Amazon Associate we earn from qualifying purchases.

What this means in practice:

This disclosure is made in accordance with the FTC's Guides Concerning the Use of Endorsements and Testimonials in Advertising (16 CFR Part 255).


8. Payments and subscriptions

If you purchase AuraStyle Premium, the transaction is processed by Google Play (or the Apple App Store), and subscription state is managed by our provider RevenueCat.

We never receive, see or store your payment card number, bank details, or billing address. We store only: whether your subscription is active, which store it came from, when it expires, and a subscription identifier.

Manage or cancel your subscription in your Google Play account. Cancelling does not delete your data or your Style DNA.


9. Who we share information with

We do not sell your personal information. We have never sold it and we do not share it for cross-context behavioural advertising. We do not disclose your personal information to data brokers or advertisers.

We use a small number of service providers, each contractually bound to process data only on our instructions:

Provider Purpose What it receives
[HOSTING PROVIDER] Application and database hosting All stored data, encrypted in transit and at rest
OpenAI Style tag extraction and semantic embeddings (optional) An ephemeral image frame and/or style text. Contractually barred from training on it
RevenueCat Subscription entitlement Subscription identifier and purchase state
Expo / Google Firebase Cloud Messaging Push notification delivery Device push token, notification title and body
[EMAIL PROVIDER] Transactional email Your email address and message content
Google / Apple Verifying your sign-in token, if you use social sign-in Standard OAuth verification traffic

We may also disclose information if required by law, valid legal process, or to protect the rights, property or safety of AuraStyle, our users or the public. If we are acquired or merge, your information may transfer as a business asset; we will notify you and this policy will continue to apply until superseded.


10. International transfers

We operate from the United States, and your information is processed in the United States and any region where our providers operate. If you use AuraStyle from the European Economic Area, the United Kingdom or Switzerland, transfers rely on the European Commission's Standard Contractual Clauses together with supplementary measures where required.


11. Retention

Data Retained
Outfit photographs Not retained. Destroyed within the request
Pending scan results Until you confirm or discard, and no more than 15 minutes
Account and profile Until you delete your account
Style signals and Style DNA Until you delete them, purge memory, or delete your account
Affiliate click records Up to 24 months, for commission reconciliation and accounting
Scan audit records Up to 12 months
Backups Purged on our standard rotation, no more than 35 days after deletion

12. Security

Data is encrypted in transit using TLS and at rest by our hosting provider. Passwords are stored as salted scrypt hashes. Sessions use signed tokens. Access to production data is limited to personnel who need it. We apply rate limits and abuse controls to authentication and AI endpoints.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant regulators as required by New Jersey law and any other applicable law.


13. Your rights

13.1 New Jersey residents

Under the New Jersey Data Privacy Act, you may confirm whether we process your personal data and access it; correct inaccuracies; delete it; obtain a portable copy; and opt out of targeted advertising, sale, or profiling with legal or similarly significant effects. We do not conduct any of those three activities, so there is nothing to opt out of. You may appeal a refused request by writing to privacy@assisttechcorp.com; if we deny the appeal you may contact the New Jersey Division of Consumer Affairs.

13.2 California residents

Under the CCPA as amended by the CPRA you have rights to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not process sensitive personal information for inferring characteristics. We will not discriminate against you for exercising any right.

13.3 EEA, UK and Switzerland

You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. You may lodge a complaint with your local supervisory authority.

13.4 Everyone

Use the in-app controls in §6, or write to privacy@assisttechcorp.com. We respond within 45 days (extendable once where permitted). We verify requests using the email address on the account. You may use an authorised agent where the law allows.


14. Children

AuraStyle is not directed to children and is not intended for anyone under 13 (or under 16 in the EEA and UK). We do not knowingly collect personal information from children. If you believe a child has provided us information, write to privacy@assisttechcorp.com and we will delete it.


15. Changes

We will post any changes here and update the date at the top. For material changes we will notify you in the app or by email before they take effect.


16. Contact

ASSISTTECH CORP. 213 John Street Harrison, New Jersey 07029 privacy@assisttechcorp.com