Aurum OS
Privacy Policy
Last updated September 29, 2026
1. Overview
This Privacy Policy explains what personal data Aurum OS collects, how we use it, who we share it with, and the rights you have over it. It applies to everyone who uses aurumos.eu, aurumos.fr and the Aurum OS product.
2. Information we collect
We collect information in three ways: what you give us, what the product creates as you use it, and basic technical data.
- Account data: name, email address, and password (stored securely by our authentication provider, Supabase — we never see your raw password).
- Onboarding and profile data: your target industry, experience level, and career ambitions, used to personalize the roadmap, academy, and mentor.
- Product activity: tasks and roadmap progress, calendar entries and reminders you set, academy progress, and network contacts you add.
- Content you create: messages you send to the AI mentor and tutor, prompts and drafts generated in the content studio, and any text or files you submit.
- Billing data: if you subscribe to a paid plan, payment is handled by Stripe. We receive confirmation of your subscription status, not your full card number.
- Technical data: IP address, browser and device type, and basic usage logs, collected automatically for security and reliability.
3. How we use your information
- To provide, personalize, and maintain the Service (the mentor, roadmap, academy, studio, intelligence feed, and calendar).
- To send transactional and reminder emails you've requested (e.g. task reminders, account notices) via our email provider, Resend.
- To process payments and manage subscriptions via Stripe.
- To maintain security, prevent abuse, and enforce our Terms of Service.
- To understand product usage and improve the Service.
- To comply with legal obligations.
We do not sell your personal data.
4. How AI features process your data
When you use the AI mentor, tutor, roadmap task help, or content studio, the text you submit is sent to third-party AI model providers — currently Google (Gemini) and/or Groq — to generate a response. These providers process your input to return the AI output and may retain it briefly for abuse-monitoring purposes under their own policies; we don't control their retention independently of what their terms specify.
Please don't submit sensitive personal data (health information, government ID numbers, financial account details, etc.) in chat messages or prompts unless you're comfortable with it being processed by these providers to generate your response.
5. Legal basis for processing (EU/UK users)
If you're in the EU or UK, we process your data on these legal bases under GDPR:
- Contract: processing needed to provide the Service you signed up for.
- Legitimate interest: for security, fraud prevention, and improving the product.
- Consent: for optional communications you opt into (e.g. marketing emails), which you can withdraw at any time.
- Legal obligation: where we need to retain or disclose data to comply with the law.
7. How long we keep your data
We keep your account and product data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where we're required to keep certain records for longer (for example, billing records for tax purposes).
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to be forgotten").
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email hello@aurumos.eu. EU/UK users also have the right to lodge a complaint with their local data protection authority.
9. Security
We rely on Supabase's managed Postgres infrastructure with row-level security: your records are private to you unless you choose to share them with your team or company, and notes marked private are never shared. Data is encrypted in transit. No system is completely secure, so while we take reasonable precautions, we can't guarantee absolute security.
10. International data transfers
Our service providers may process data outside your home country. Where that involves a transfer out of the EU/UK, we rely on appropriate safeguards (such as Standard Contractual Clauses) as required by GDPR. Our database (Supabase) is hosted in the eu-west-2 (London) region. Our other providers (Cloudflare, Stripe, Resend and our AI providers) may process data in other countries, including the United States.
12. Children's privacy
Aurum OS is intended for professional use by adults. We don't knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we'll delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or an in-product notice before they take effect.
14. Contact
For any privacy question or request, contact hello@aurumos.eu. We haven't appointed a dedicated Data Protection Officer — under GDPR (Article 37), one is only required for large-scale systematic monitoring or large-scale processing of special-category data, which doesn't currently apply at our scale. We'll revisit this as the company grows.