Aurei is a private register of the things you own. That makes the data we hold unusually sensitive — not health data, but a list of valuables, what they are worth, and where they are kept. This policy explains, in plain language, what we collect, why, who ever sees it, and the control you have over it.
It is written to comply with the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the privacy requirements of the Apple App Store and Google Play.
01Who we are
The controller responsible for processing your personal data under the GDPR is:
02Scope of this policy
This policy applies to the Aurei mobile applications (iOS and Android), our website at aurei.app, our content delivery domain cdn.aurei.app, and our backend services at api.aurei.app (together, the “Services”). It does not apply to third-party products or platforms we link to or integrate with — the app stores, identity-verification providers, market-data sources, or the independent partners who authenticate items — each of which is governed by its own privacy policy.
03Data we collect
| Category | Examples |
|---|---|
| Account & identity | Email address, username, country, profile photo, preferred display currency, language, and — if you register with a password — a hashed password (we never store the password itself). If you use Sign in with Apple or Google we store the stable subject identifier from your provider, and for Apple a refresh token so we can revoke the link when you delete your account. |
| Security | Two-factor settings and secrets (authenticator or email code), one-time codes and their expiry, session and refresh tokens, email-verification tokens. |
| Your assets | Everything you record about an item: category, brand, model or name, year, condition, serial number, manufacturer reference number, who signed or inscribed it, category-specific attributes (for example box and papers for a watch), condition notes and free-text notes. |
| Financial detail per asset | Purchase price, currency and date, your own estimated value, any outstanding debt secured on the item, the sale price if you record a sale, and the market value we retrieve or calculate together with its history over time. |
| Where items are kept | The locations you define (for example “home”, “bank vault”, “second residence”) and which asset sits in which location. |
| Photos & documents | Asset photographs and the documents you attach — invoices, certificates, service records, appraisals, provenance papers — plus your profile image. |
| Provenance & verification | Ownership transfers recorded in the app, partner validation requests and verdicts, trust level and verification status, generated passports and certificates. |
| Social & marketplace | Who you follow and who follows you, comments and reactions, feed activity, offers you make or receive, conversations and messages, watchlist items, wanted items, badges, and leaderboard standing. |
| Advisor | Advisor sessions and the messages you exchange with the AI Advisor, including the portfolio context sent with a question (see section 13). |
| Moderation | Reports you file on a comment, reports filed against your content, comment strikes and any temporary posting lock. |
| Device & technical | Device model and platform, operating-system and app version, language, time zone, IP address, push-notification token, crash reports and diagnostic logs. |
| Usage | Features used, screens viewed, in-app events, and aggregate interaction metrics. |
| Identity verification | If you choose to verify your identity: your name as submitted and a reference identifier for the verification. The identity documents and selfie themselves are handled by our verification provider — see section 10. |
| Billing | Subscription tier and status, the store's transaction identifier or purchase token, renewal and expiry dates. Payments are processed by the Apple App Store or Google Play; we never receive or store your card details. |
| Support | Correspondence you send us and the contents of support requests. |
04Why collection data is sensitive — and how we treat it
An inventory of valuables, their serial numbers, their value and their location is exactly the information a burglar or a fraudster would want. We treat it accordingly:
Every asset you add starts as private. Nothing about it — not the item, not the value, not the location — is visible to any other user unless you deliberately change its visibility, share a passport link, make an offer, or record a transfer. We do not publish your collection, and we never sell your data.
- Locations are never shared. The location you assign to an asset is for your own organisation. It is not shown to other users, not included in a public showcase or a passport, and not sent to partners.
- Serial numbers are not public. They are used to establish that an item is what you say it is, to match it to a catalog entry and to detect the same serial appearing twice across the network. They are not displayed on public pages.
- Value display is your choice. Where your profile is public, you control whether your collection's value is shown, hidden, or shown only as a band.
- Documents are private. Invoices, certificates and appraisals are visible to you, and to a partner only for the specific asset you ask them to validate.
05What you choose to make public
Aurei has optional social and marketplace features. These are the only routes by which your data reaches other people, and each one is a decision you make:
| If you… | Then… |
|---|---|
| Set an asset's visibility to followers or public | Its photos and descriptive details become visible to that audience, and it may appear in the showcase, search and feed. Purchase price, debt, notes, documents and location are not included. |
| Make your profile public | Your username, profile photo, badges and — subject to your value-display setting — your collection value become visible, including on the leaderboard. |
| Mark yourself or an asset “open to offers” | Other eligible users can see that and send you offers and messages. |
| Generate a passport link for an asset | Anyone holding the link can view that asset's provenance record. The passport is deliberately built to omit the owner's identity. You can revoke the link at any time. |
| Record a transfer of ownership | The counterparty sees the asset record and the provenance chain you pass to them. |
| Comment, react or post to the feed | That content is visible to the audience of the item or profile it belongs to. |
| Report an asset lost or stolen | It is excluded from your totals and blocked from offers. A stolen report also raises an alert so the rest of the network can be warned if the item resurfaces — see section 14. |
06Device permissions
The app asks for a permission only when you use a feature that needs it. Each is optional and can be granted or revoked at any time in your device settings.
| Permission | Why we ask |
|---|---|
| Camera | To photograph your assets and to scan transfer and passport QR codes. |
| Photo library | To attach existing photos and documents to an asset, and to set a profile picture. |
| Notifications | To tell you about offers, messages, price alerts on your watchlist, transfer requests and validation verdicts. |
Aurei does not request or use your location, contacts, microphone, or health data, and it does not ask for iOS App Tracking Transparency permission — because it does not track you (section 22).
07How we obtain your data
- Directly from you — when you register, add or edit assets, upload photos and documents, define locations, make offers, message another user, or contact support.
- Automatically — through your use of the app, including device, diagnostic and usage data.
- From your sign-in provider — Apple or Google, when you choose social sign-in: the subject identifier and, where you permit it, your email address and name.
- From market-data sources — public valuation and catalog data matched to the items you own (section 12). No personal data of yours is sent in order to fetch it.
- From partners and specialists — the outcome of a validation you requested (section 11).
- From our verification provider — the result of an identity check you started (section 10).
- From the app stores — subscription and purchase status from Apple and Google.
08Why we use your data
- To provide and operate your vault: storing, organising and displaying the assets, photos, documents and valuations you record.
- To calculate portfolio analytics, performance and currency conversions.
- To retrieve and update market values, and to keep valuation history.
- To operate the features you opt into — showcase, feed, following, offers, messages, transfers, passports, certificates, watchlist, wanted items, badges and leaderboard.
- To arrange partner validation and specialist visits you request.
- To answer your questions through the AI Advisor.
- To authenticate you, protect your account, and operate two-factor authentication.
- To detect and prevent fraud, theft, counterfeiting and abuse, including duplicate-serial and stolen-item checks.
- To moderate reported content and enforce our terms.
- To send the notifications you have enabled and service emails you need to receive.
- To manage subscriptions and entitlements.
- To diagnose crashes and improve the product, using aggregated or pseudonymised data.
- To comply with legal obligations, including record-keeping and, where applicable, anti-money-laundering and sanctions rules for high-value goods.
09Legal bases for processing
| Processing | Legal basis (GDPR) |
|---|---|
| Your account, vault, valuations and the features you use | Performance of a contract — Art. 6(1)(b) |
| Security, fraud and theft prevention, product improvement | Legitimate interests — Art. 6(1)(f) |
| Identity verification, partner validation, sharing to public audiences, optional analytics and marketing | Consent — Art. 6(1)(a) |
| Service emails, tax and commercial record-keeping, lawful requests | Legal obligation / legitimate interest — Art. 6(1)(c)/(f) |
Where we rely on consent you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
10Identity verification
Verifying your identity is optional. If you start a check, the identity documents and any selfie you submit are collected and assessed by our verification provider (Onfido, part of Entrust) acting as a separate controller under its own privacy notice. Aurei receives the name you submitted, an applicant reference and the outcome — verified or not. We do not receive or store copies of your identity documents. You can decline verification and continue to use Aurei; some trust-related features simply remain unavailable.
11Partners & specialists
Aurei works with independent partners — authenticators, dealers, appraisers and specialists — who can validate an item. Data reaches a partner only for the asset you submit and only when you submit it: the asset's details, photos and the documents attached to it, plus what is needed to arrange a specialist visit if you request one. Your other assets, your locations, your portfolio totals and your other personal data are not disclosed. Partners decide for themselves how to run their own business records and act as separate controllers in that respect; while acting on your request through Aurei they are bound by an agreement with us.
If you apply to become a partner, we process the application details you submit in order to assess it.
12Valuation & catalog data
Market values and catalog information are retrieved from third-party market-data sources for the type of item you own — including WatchCharts, Hagerty, StockX, Wine-Searcher, and image sources used to illustrate catalog entries — and daily currency rates from an exchange-rate provider. These lookups are made by our servers on the basis of the model or reference in question. They do not identify you: we do not send your name, email, account identifier, serial numbers or location to a market-data source.
Valuations are estimates only. Section 7 of our Terms of Service explains what they are and are not.
13AI Advisor
The AI Advisor answers questions about collecting and about your portfolio. When you send a message, that message and the relevant portfolio context are processed by Microsoft Azure OpenAI Service, which acts as our processor. Azure OpenAI processes the request to generate the response and, under Microsoft's enterprise terms, your prompts are not used to train models. We store your advisor sessions and messages in your account so you can return to a conversation, and you can delete them. Please avoid putting information into a chat that you do not need the Advisor to see. Advisor answers are informational and are not financial, legal, tax or appraisal advice.
14Lost, stolen & fraud checks
Aurei exists partly to make stolen and counterfeit goods harder to move. Two mechanisms follow from that:
- Duplicate-signal checks. Serial numbers are indexed so that the same serial appearing on two accounts, or a record inconsistent with its documents, can be flagged internally for review. This is a legitimate-interest processing in the interest of you, other collectors and the market.
- Stolen-property registers. Where the category warrants it — art and collectibles in particular — item details may be checked against an external register such as the Art Loss Register, and an item you report stolen may be notified to such a register or to law enforcement. The check concerns the object, not you; identifying details about you are not published.
If you report an item stolen, we raise an alert within Aurei so that the item cannot be quietly offered or transferred on the platform.
15Sharing & recipients
We share personal data only as described here:
- Other users — only what you choose to make visible (section 5).
- Partners and specialists — only for an asset you submit (section 11).
- Service providers — processors acting on our documented instructions (section 16).
- Verification and register providers — where you start a check, or where an item is reported stolen (sections 10 and 14).
- App stores and payment platforms — Apple and Google, for distribution and billing.
- Legal & safety — authorities or third parties where required by law, to enforce our terms, or to protect rights, property and safety.
- Business transfers — in connection with a merger, acquisition or asset sale, subject to this policy.
We do not sell your personal data, we do not share your collection with data brokers, insurers or advertisers, and we do not use your data for third-party advertising.
16Service providers (processors)
We use carefully selected providers under data processing agreements meeting Article 28 GDPR:
| Provider | Purpose |
|---|---|
| Hosting & database (European data centre) | Running the Aurei API and its PostgreSQL database, and encrypted nightly backups. |
| Cloudflare (R2 object storage, CDN, DNS) | Storing and delivering asset photos, documents and profile images via cdn.aurei.app; protecting and routing traffic. |
| Google Firebase (Google Ireland Ltd.) | Push notifications and anonymous product analytics. |
| Sentry | Crash and error reporting. Configured not to send personal identifiers by default. |
| Microsoft Azure OpenAI | Generating AI Advisor responses (section 13). |
| Onfido | Optional identity verification (section 10). |
| Email delivery | Sending verification emails, one-time codes and service notices from noreply@aurei.app. |
| Apple & Google | Sign-in token verification, app distribution, subscription billing and receipt validation. |
An up-to-date list is available on request at privacy@aurei.app.
17International data transfers
Your account data, assets, photos and documents are processed in the European Union by default. Where a provider transfers data outside the European Economic Area — for example Apple, Google or Microsoft group companies in the United States — we rely on appropriate safeguards under Chapter V GDPR: the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You may request a copy of the relevant safeguards.
18How long we keep data
- While your account is active — your account, assets, photos, documents, valuation history and social content are kept so the Services work.
- On deletion — deleting your account erases your personal data and wipes your photos, documents and profile image from object storage. Where you use Sign in with Apple, we also call Apple's revocation endpoint to sever the link.
- Soft-deleted assets — an asset you delete goes to a recoverable state first so you can restore it, then is removed.
- Records we must keep — invoicing, tax and commercial records are retained for the statutory period (in Austria, generally seven years), and security logs for a short period, even after account closure. Provenance entries that another user relies on — for example a transfer you completed to them — may be retained in de-identified form so that their record remains intact.
- Backups — encrypted backups roll off on a short retention cycle, so a deletion propagates out of backups within that window.
19Security
We apply technical and organisational measures appropriate to the sensitivity of a collection register:
- Encryption in transit — TLS 1.2 or above for all traffic between the app, our API and our storage.
- Encryption at rest — photos and documents are stored encrypted at rest by our object-storage provider; database backups are encrypted.
- Password handling — passwords are stored only as salted hashes; access tokens live in the operating-system keychain on your device.
- Two-factor authentication — available by authenticator app or email code, and recommended for a vault of any value.
- Least privilege — access to production data is restricted to what is necessary to operate the Services, the database is not exposed to the public internet, and administrative interfaces are gated.
- Rate limiting and abuse controls on authentication and public endpoints.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. We will notify you and the competent supervisory authority of a personal data breach where legally required.
20Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data (“right to be forgotten”);
- Restrict or object to certain processing;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time where processing is based on consent;
- Lodge a complaint with a supervisory authority.
Much of this is immediate inside the app: Settings lets you edit your profile, currency, visibility and notification preferences, export your data, revoke a passport link, and delete your account outright. To exercise any right manually, email privacy@aurei.app from the address on your account. We respond within the statutory time limit, generally one month. You may also complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, dsb.gv.at) or the authority in your country of residence.
21Children
Aurei is intended for adults and is not directed to children. You must be at least 18 to hold an account. We do not knowingly collect personal data from minors; if you believe a minor has provided us data, contact us and we will delete it.
22Analytics & tracking
We do not show third-party advertising and we do not track you across other companies' apps or websites for advertising. Analytics is limited to understanding which features are used and where errors occur, in aggregated or pseudonymised form.
Aurei contains no advertising or attribution software. Nothing in the app reads your device's advertising identifier (IDFA), and the product analytics we do use runs first-party only: the ad-related consent signals — advertising storage, ad-user-data sharing and ad personalisation — are switched off in the app itself, not merely left unused. Because we do not track you as Apple defines it, the app deliberately ships no App Tracking Transparency prompt: there is nothing we would be asking your permission for.
You can disable analytics collection at any time from your operating-system privacy settings.
23Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Market valuations, trust levels, integrity scores, badges and Advisor answers are informational signals, not such decisions, and a human reviews any consequential action such as suspending an account or acting on a fraud flag.
24Cookies & our website
These legal pages and our marketing site use only strictly necessary cookies, and any analytics cookie is set only with your consent via a cookie banner. The mobile app uses no advertising cookies.
25Changes to this policy
We may update this policy to reflect changes in our practices or the law. The updated version is posted here with a new effective date, and for material changes we give notice in the app and, where consent is required, ask for it again before continuing.
