Aurelius includes a public website and a signed-in mentoring app. We collect the information needed to operate those services, and we explain here what we store, why we use it, and which service providers process it.
What we collect
This website itself collects nothing from you directly — there are no forms and no sign-up. Browsing pages is anonymous apart from the analytics described below.
Aurelius previously ran an early-access waitlist. That form has been removed now that the app is available, and no new waitlist information is collected. Records already submitted (name, email address, optional phone number, and the technical and campaign context stored with them) are retained only to send the launch announcement those people asked for, and are deleted on request.
When you use the Aurelius app, we identify your app installation by a random identifier generated on your device (no account is required) and store, where applicable, account and sign-in information, saved quotes, conversation messages, conversation summaries, subscription status, your IP address (recorded when your device first connects and when it makes later requests, to help us prevent abuse and diagnose problems), and — if you enable notifications — a device push token. We also record limited operational metadata such as the AI provider and model used, token counts, response time, and errors. API keys, passwords, and authentication tokens are never written to application logs.
Cookies
The website sets no cookies of its own. Google Analytics (below) sets its own first-party cookies (_ga and similar) to recognize returning browsers. There are no advertising cookies.
Analytics (Google Analytics)
We use Google Analytics 4 to understand how people find and use the site — which pages are read, roughly where visitors come from, and which channels lead to signups. Google Analytics collects usage data such as pages viewed, approximate location, and device and browser characteristics; GA4 does not log or store full IP addresses. We use this data only in aggregate.
Google's handling of this data is described in the Google Privacy Policy. You can opt out with the Google Analytics opt-out browser add-on, or by using a browser or extension that blocks analytics scripts — the site works fully without them.
AI mentoring (OpenAI and Anthropic)
To generate a mentoring response, our server sends the current message and the relevant conversation context to the AI provider selected in the app's server-side configuration: either OpenAI or Anthropic. Only the active provider receives a given request. Do not include information in a conversation that you would not want processed for this purpose.
Aurelius keeps the full conversation in our database. When a conversation becomes long, we create a compact summary and send that summary plus the most recent messages to the active provider so the request stays within the model's context limit. The summary is stored with the conversation and can be regenerated when the model or summarization method changes.
Subscription purchases (Apple)
Membership subscriptions are purchased through Apple's App Store. Apple processes the payment; we never see your payment details. To confirm a purchase and keep your membership current, our server exchanges purchase transaction identifiers with Apple's App Store Server API and receives Apple's signed status updates (renewals, expirations, refunds). We store the transaction identifier, product, and expiry date with your account so your membership follows your Apple ID across devices.
How we use your information
We use retained waitlist information only for what that form promised: to tell those people the app is available. It is not used for anything else.
We use app information to authenticate your account, provide saved quotes and conversation history, generate AI mentoring responses, manage access and subscriptions, deliver notifications you request, prevent abuse, and operate and improve the service.
We do not sell your information, share it with advertisers, or use it for any purpose beyond Aurelius.
Where your data lives
Waitlist signups and app data are stored in a database on infrastructure operated by DigitalOcean, our hosting provider. Access is restricted to the people building Aurelius. Production traffic to the website and API is encrypted (HTTPS).
We may disclose information if required to by law.
How long we keep it
We keep retained waitlist records through the launch communications they exist for, then delete them. App data is kept while your installation or account is active. If you ask us to remove your information, we delete it.
We keep app account and conversation data while your account is active. Deleting your account removes its authentication sessions, identities, saved quotes, conversations, messages, summaries, device tokens, subscription records, and related usage records from the live database. Encrypted backups may retain deleted data temporarily until they expire through the normal backup cycle.
Your rights
You can ask us at any time to see the information we hold about you, correct it, or delete it entirely. Email us and we will handle it — no forms, no friction. Depending on where you live (for example the EU/EEA under GDPR, or California under the CCPA), these rights may also be backed by law; we honor such requests regardless of where you live.
Children
The site is not directed at children under 13, and we do not knowingly collect information from them.
Changes to this policy
If our data practices change, we will update this page and its "last updated" date. Significant changes affecting members will be announced by email or in the app when appropriate.
Contact
Questions or requests about your data: privacy@stoicai.app.