Privacy Policy

Privacy Policy

Last updated · June 10, 2026

This policy explains how Aurum Technology Limited ("Aurum," "we," "our," or "us") handles personal data for Aurum Life (our local-first personal life-management app) and for this website. Aurum Technology Limited is a company incorporated in England and Wales (company no. 17127517), registered office 61 Bridge Street, Kingston, HR5 3DJ, United Kingdom (also registered in Trinidad and Tobago), and is the data controller for this processing.

We are established in the United Kingdom, and our lead supervisory authority is the UK Information Commissioner's Office (ICO). During the current private beta, Aurum Life is offered to users in the United Kingdom, Trinidad and Tobago, and the United States, and is not directed to the European Economic Area.

Local-first by default

Aurum Life stores your life data (your pillars, areas, projects, tasks, notes, and calendar) as files on your own device. By default none of it is sent to our servers or any third party. If you use Aurum Life entirely offline and never enable a cloud feature, we do not process your personal life data on our servers at all. Cloud processing happens only when you explicitly turn on an optional feature (the AI agent, cloud connectors, cloud backup, or notifications). Each is off by default and can be turned off at any time.

What we process, and only when

  • You create an account: email address and authentication credentials, to sign you in and sync across your devices.
  • We send you email: your email address and the message content, for account, security, and notification emails, via our email provider (Resend).
  • You enable the AI agent (cloud): the life data needed for the task you requested (task/project titles, statuses, dates; note bodies only where needed for the output), to generate the briefing, review, audit, or triage you asked for.
  • You connect a connector (Gmail, Calendar, Notion, Slack, QuickBooks Online, etc.): items fetched from that service, turned into a proposed structure you review before anything is saved. For QuickBooks Online (Intuit)specifically, we read your accounting data (company info, invoices, and a profit-and-loss summary) to display and organize it inside your Life OS. We do not write to your QuickBooks account, we never use QuickBooks data for advertising or model training, and we do not share it with third parties.
  • You capture a photo or a voice note (mobile): the image or audio file you captured, uploaded to private per-user storage so it reaches your other devices, together with any caption you add. Voice notes are additionally sent for speech-to-text transcription so the words can become a task or note. Both are deleted when you delete the capture, and when you delete your account.
  • You enable push notifications (mobile): a device push token and the notification content, to deliver reminders you've turned on, via platform push services (Expo → Apple APNs / Google FCM).
  • You enable cloud backup: an encrypted archive of your vault, to let you restore on another device.
  • Always, if you use cloud features: limited diagnostic/decision logs (references, not verbatim content where an identifier suffices), for security, auditability, and to show you why the agent did what it did.

We do not sell your personal data, and we do not use your life content to train AI models. Our AI processing uses the Google Gemini API on a paid tier, under which Google does not use your prompts, content, or the generated responses to train its models; they are processed only to produce the output you requested, under Google's data-processor terms.

Sub-processors

When you use cloud features, we rely on a small set of processors who act on our instructions under data-processing agreements: Google (Gemini AI inference, paid tier, no training on your content), Supabase (hosting, database, authentication, encrypted storage), Resend (email delivery), Expo (push-notification delivery, if enabled), and Sentry (crash and error reporting, only if you opt in; reports carry the error and stack trace, never Life OS content, chat history, or API keys). The third-party services you choose to connect (Gmail, Calendar, Notion, Slack, QuickBooks Online) are your own data sources under their own terms, not Aurum sub-processors. Connector access tokens are exchanged and stored server-side, encrypted at rest (AES) with the decryption key held in a secrets vault and never exposed to client apps; you can disconnect any connector at any time, which revokes the token at the provider and deletes our stored copy.

Legal bases (UK GDPR)

  • Consent: for all optional cloud processing (AI agent, connectors, backup, notifications). You may withdraw consent at any time; withdrawal stops that processing going forward.
  • Contract: to provide the account and the service you sign up for.
  • Legitimate interests / legal obligation: limited security logging and record-keeping, balanced against your rights.

Your rights

Depending on where you live, you have the right to access, correct, delete, export (portability), restrict or object to processing, and to withdraw consent. Aurum Life makes the core rights self-service in the in-app Privacy Center: export a full copy of your cloud-held data and your agent's decision history; request account deletion (which cascades a purge of your life data, agent traces, embeddings, push tokens, cloud backups, connector tokens, and authentication record); edit your data directly; and turn off the agent, a connector, or notifications to halt that processing immediately.

The same controls are available on the web at aurum-life.com/account, so you can exercise them without having the app installed — sign in there to export your data, change your password or email, manage two-step verification, turn cloud processing off, or delete your account.

To exercise rights that aren't self-service, email privacy@aurumtechnologyltd.com. If you are in the UK, you may also lodge a complaint with the Information Commissioner's Office (ICO); users elsewhere may contact their local data-protection authority.

Retention

  • Diagnostic / agent decision logs: retained 90 days, then deleted.
  • Connector ingest items / proposals: retained until you apply or dismiss them.
  • Your synced life data: retained until you delete it or close your account.

We keep personal data only as long as needed for the purpose it was collected for.

International transfers

Our infrastructure and providers process data in the United States (our host Supabase, model provider Google, and email provider Resend operate there). For transfers of UK personal data, we rely on appropriate safeguards: the UK International Data Transfer Agreement (IDTA) or the UK Extension to the EU-US Data Privacy Framework, as provided in each sub-processor's data-processing agreement.

Security

We protect your data with TLS 1.3 in transit, AES-256 encryption at rest, row-level security scoping every record to its owner, encrypted storage of connector tokens, prompt-injection screening on imported content, rate limiting, and access-masked logging. No system is perfectly secure, but cloud processing is minimized by design and off unless you opt in. To report a vulnerability, email security@aurumtechnologyltd.com.

AI & automated processing

When the AI agent produces something for you, it is clearly labeled as AI-generated, and you approve every consequential action before it takes effect: the agent drafts, you decide. It supports your own thinking; it does not provide licensed professional advice, diagnosis, or specific investment recommendations. We do not use solely-automated decision-making that produces legal or similarly significant effects on you.

This website

On this site we collect what you submit to the beta waitlist or contact us with (your email address), and privacy-friendly, cookieless analytics that don't set advertising cookies or build a profile of you. If we later add advertising or conversion tracking, we'll ask for your consent first.

Children & changes

Aurum Life is not directed to children under 16, and we do not knowingly collect their data. We may update this policy; material changes will be notified in-app or by email before they take effect, with the updated date shown above.

Contact

Aurum Technology Limited
Company no. 17127517 (England & Wales)
Registered office: 61 Bridge Street, Kingston, HR5 3DJ, United Kingdom
Privacy: privacy@aurumtechnologyltd.com
Security: security@aurumtechnologyltd.com

← Back to home

Aurum Life

Your Life OS: a personal AI layer for your whole life, quietly working on your own device.

Product

Legal

Contact

support@aurumtechnologyltd.com
© 2026 Aurum Technology LimitedBuilt from Trinidad & Tobago, for everyone.