Aurei logoAurei

Privacy Policy

How we collect, use, share, and protect your personal data — and the records of the collection you keep in Aurei — when you use our apps and services.

Effective 1 September 2026  ·  Last updated 1 September 2026  ·  Version 1.0

Aurei is a private register of the things you own. That makes the data we hold unusually sensitive — not health data, but a list of valuables, what they are worth, and where they are kept. This policy explains, in plain language, what we collect, why, who ever sees it, and the control you have over it.

It is written to comply with the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the privacy requirements of the Apple App Store and Google Play.

01Who we are

The controller responsible for processing your personal data under the GDPR is:

Toan Le — sole proprietor, trading as “Aurei”
Schnirchgasse 9, 1030 Vienna, Austria
Privacy: privacy@aurei.app
General: support@aurei.app

02Scope of this policy

This policy applies to the Aurei mobile applications (iOS and Android), our website at aurei.app, our content delivery domain cdn.aurei.app, and our backend services at api.aurei.app (together, the “Services”). It does not apply to third-party products or platforms we link to or integrate with — the app stores, identity-verification providers, market-data sources, or the independent partners who authenticate items — each of which is governed by its own privacy policy.

03Data we collect

CategoryExamples
Account & identityEmail address, username, country, profile photo, preferred display currency, language, and — if you register with a password — a hashed password (we never store the password itself). If you use Sign in with Apple or Google we store the stable subject identifier from your provider, and for Apple a refresh token so we can revoke the link when you delete your account.
SecurityTwo-factor settings and secrets (authenticator or email code), one-time codes and their expiry, session and refresh tokens, email-verification tokens.
Your assetsEverything you record about an item: category, brand, model or name, year, condition, serial number, manufacturer reference number, who signed or inscribed it, category-specific attributes (for example box and papers for a watch), condition notes and free-text notes.
Financial detail per assetPurchase price, currency and date, your own estimated value, any outstanding debt secured on the item, the sale price if you record a sale, and the market value we retrieve or calculate together with its history over time.
Where items are keptThe locations you define (for example “home”, “bank vault”, “second residence”) and which asset sits in which location.
Photos & documentsAsset photographs and the documents you attach — invoices, certificates, service records, appraisals, provenance papers — plus your profile image.
Provenance & verificationOwnership transfers recorded in the app, partner validation requests and verdicts, trust level and verification status, generated passports and certificates.
Social & marketplaceWho you follow and who follows you, comments and reactions, feed activity, offers you make or receive, conversations and messages, watchlist items, wanted items, badges, and leaderboard standing.
AdvisorAdvisor sessions and the messages you exchange with the AI Advisor, including the portfolio context sent with a question (see section 13).
ModerationReports you file on a comment, reports filed against your content, comment strikes and any temporary posting lock.
Device & technicalDevice model and platform, operating-system and app version, language, time zone, IP address, push-notification token, crash reports and diagnostic logs.
UsageFeatures used, screens viewed, in-app events, and aggregate interaction metrics.
Identity verificationIf you choose to verify your identity: your name as submitted and a reference identifier for the verification. The identity documents and selfie themselves are handled by our verification provider — see section 10.
BillingSubscription tier and status, the store's transaction identifier or purchase token, renewal and expiry dates. Payments are processed by the Apple App Store or Google Play; we never receive or store your card details.
SupportCorrespondence you send us and the contents of support requests.

04Why collection data is sensitive — and how we treat it

An inventory of valuables, their serial numbers, their value and their location is exactly the information a burglar or a fraudster would want. We treat it accordingly:

Your vault is private by default.

Every asset you add starts as private. Nothing about it — not the item, not the value, not the location — is visible to any other user unless you deliberately change its visibility, share a passport link, make an offer, or record a transfer. We do not publish your collection, and we never sell your data.

05What you choose to make public

Aurei has optional social and marketplace features. These are the only routes by which your data reaches other people, and each one is a decision you make:

If you…Then…
Set an asset's visibility to followers or publicIts photos and descriptive details become visible to that audience, and it may appear in the showcase, search and feed. Purchase price, debt, notes, documents and location are not included.
Make your profile publicYour username, profile photo, badges and — subject to your value-display setting — your collection value become visible, including on the leaderboard.
Mark yourself or an asset “open to offers”Other eligible users can see that and send you offers and messages.
Generate a passport link for an assetAnyone holding the link can view that asset's provenance record. The passport is deliberately built to omit the owner's identity. You can revoke the link at any time.
Record a transfer of ownershipThe counterparty sees the asset record and the provenance chain you pass to them.
Comment, react or post to the feedThat content is visible to the audience of the item or profile it belongs to.
Report an asset lost or stolenIt is excluded from your totals and blocked from offers. A stolen report also raises an alert so the rest of the network can be warned if the item resurfaces — see section 14.

06Device permissions

The app asks for a permission only when you use a feature that needs it. Each is optional and can be granted or revoked at any time in your device settings.

PermissionWhy we ask
CameraTo photograph your assets and to scan transfer and passport QR codes.
Photo libraryTo attach existing photos and documents to an asset, and to set a profile picture.
NotificationsTo tell you about offers, messages, price alerts on your watchlist, transfer requests and validation verdicts.

Aurei does not request or use your location, contacts, microphone, or health data, and it does not ask for iOS App Tracking Transparency permission — because it does not track you (section 22).

07How we obtain your data

08Why we use your data

09Legal bases for processing

ProcessingLegal basis (GDPR)
Your account, vault, valuations and the features you usePerformance of a contract — Art. 6(1)(b)
Security, fraud and theft prevention, product improvementLegitimate interests — Art. 6(1)(f)
Identity verification, partner validation, sharing to public audiences, optional analytics and marketingConsent — Art. 6(1)(a)
Service emails, tax and commercial record-keeping, lawful requestsLegal obligation / legitimate interest — Art. 6(1)(c)/(f)

Where we rely on consent you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.

10Identity verification

Verifying your identity is optional. If you start a check, the identity documents and any selfie you submit are collected and assessed by our verification provider (Onfido, part of Entrust) acting as a separate controller under its own privacy notice. Aurei receives the name you submitted, an applicant reference and the outcome — verified or not. We do not receive or store copies of your identity documents. You can decline verification and continue to use Aurei; some trust-related features simply remain unavailable.

11Partners & specialists

Aurei works with independent partners — authenticators, dealers, appraisers and specialists — who can validate an item. Data reaches a partner only for the asset you submit and only when you submit it: the asset's details, photos and the documents attached to it, plus what is needed to arrange a specialist visit if you request one. Your other assets, your locations, your portfolio totals and your other personal data are not disclosed. Partners decide for themselves how to run their own business records and act as separate controllers in that respect; while acting on your request through Aurei they are bound by an agreement with us.

If you apply to become a partner, we process the application details you submit in order to assess it.

12Valuation & catalog data

Market values and catalog information are retrieved from third-party market-data sources for the type of item you own — including WatchCharts, Hagerty, StockX, Wine-Searcher, and image sources used to illustrate catalog entries — and daily currency rates from an exchange-rate provider. These lookups are made by our servers on the basis of the model or reference in question. They do not identify you: we do not send your name, email, account identifier, serial numbers or location to a market-data source.

Valuations are estimates only. Section 7 of our Terms of Service explains what they are and are not.

13AI Advisor

The AI Advisor answers questions about collecting and about your portfolio. When you send a message, that message and the relevant portfolio context are processed by Microsoft Azure OpenAI Service, which acts as our processor. Azure OpenAI processes the request to generate the response and, under Microsoft's enterprise terms, your prompts are not used to train models. We store your advisor sessions and messages in your account so you can return to a conversation, and you can delete them. Please avoid putting information into a chat that you do not need the Advisor to see. Advisor answers are informational and are not financial, legal, tax or appraisal advice.

14Lost, stolen & fraud checks

Aurei exists partly to make stolen and counterfeit goods harder to move. Two mechanisms follow from that:

If you report an item stolen, we raise an alert within Aurei so that the item cannot be quietly offered or transferred on the platform.

15Sharing & recipients

We share personal data only as described here:

We do not sell your personal data, we do not share your collection with data brokers, insurers or advertisers, and we do not use your data for third-party advertising.

16Service providers (processors)

We use carefully selected providers under data processing agreements meeting Article 28 GDPR:

ProviderPurpose
Hosting & database (European data centre)Running the Aurei API and its PostgreSQL database, and encrypted nightly backups.
Cloudflare (R2 object storage, CDN, DNS)Storing and delivering asset photos, documents and profile images via cdn.aurei.app; protecting and routing traffic.
Google Firebase (Google Ireland Ltd.)Push notifications and anonymous product analytics.
SentryCrash and error reporting. Configured not to send personal identifiers by default.
Microsoft Azure OpenAIGenerating AI Advisor responses (section 13).
OnfidoOptional identity verification (section 10).
Email deliverySending verification emails, one-time codes and service notices from noreply@aurei.app.
Apple & GoogleSign-in token verification, app distribution, subscription billing and receipt validation.

An up-to-date list is available on request at privacy@aurei.app.

17International data transfers

Your account data, assets, photos and documents are processed in the European Union by default. Where a provider transfers data outside the European Economic Area — for example Apple, Google or Microsoft group companies in the United States — we rely on appropriate safeguards under Chapter V GDPR: the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You may request a copy of the relevant safeguards.

18How long we keep data

19Security

We apply technical and organisational measures appropriate to the sensitivity of a collection register:

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. We will notify you and the competent supervisory authority of a personal data breach where legally required.

20Your rights

Subject to applicable law, you have the right to:

Much of this is immediate inside the app: Settings lets you edit your profile, currency, visibility and notification preferences, export your data, revoke a passport link, and delete your account outright. To exercise any right manually, email privacy@aurei.app from the address on your account. We respond within the statutory time limit, generally one month. You may also complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, dsb.gv.at) or the authority in your country of residence.

21Children

Aurei is intended for adults and is not directed to children. You must be at least 18 to hold an account. We do not knowingly collect personal data from minors; if you believe a minor has provided us data, contact us and we will delete it.

22Analytics & tracking

We do not show third-party advertising and we do not track you across other companies' apps or websites for advertising. Analytics is limited to understanding which features are used and where errors occur, in aggregated or pseudonymised form.

Aurei contains no advertising or attribution software. Nothing in the app reads your device's advertising identifier (IDFA), and the product analytics we do use runs first-party only: the ad-related consent signals — advertising storage, ad-user-data sharing and ad personalisation — are switched off in the app itself, not merely left unused. Because we do not track you as Apple defines it, the app deliberately ships no App Tracking Transparency prompt: there is nothing we would be asking your permission for.

You can disable analytics collection at any time from your operating-system privacy settings.

23Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Market valuations, trust levels, integrity scores, badges and Advisor answers are informational signals, not such decisions, and a human reviews any consequential action such as suspending an account or acting on a fraud flag.

24Cookies & our website

These legal pages and our marketing site use only strictly necessary cookies, and any analytics cookie is set only with your consent via a cookie banner. The mobile app uses no advertising cookies.

25Changes to this policy

We may update this policy to reflect changes in our practices or the law. The updated version is posted here with a new effective date, and for material changes we give notice in the app and, where consent is required, ask for it again before continuing.

26Contact us

Questions or requests about privacy?
Email privacy@aurei.app
Or write to us at the address in section 1.