Legal
Last updated: September 14, 2026. Questions? Email [email protected].
Terms of Service
These terms are an agreement between you and Aurora Lab Inc. ("Aurora", "we", "us"), the company that operates the Aurora products, covering your use of our websites, apps, and services — including Aurora Chat, Aurora Drive, Aurora Docs, and the account dashboard (together, the "Services"). By creating an account or using the Services, you agree to these terms. If you're using Aurora for an organization, you're agreeing on its behalf.
1. Eligibility & your account
You must be at least 16 years old to use Aurora. Keep your login credentials secure — you're responsible for activity under your account. Tell us promptly at [email protected] if you suspect unauthorized use.
2. The Services
Aurora gives you AI-assisted chat, file storage, documents, and related tools. We improve the Services continually, so features may change, be added, or be removed. We aim for high availability but don't guarantee the Services will be uninterrupted or error-free.
3. Acceptable use
You agree not to use Aurora to:
- break the law, or infringe others' privacy, IP, or other rights;
- generate or distribute malware, spam, or content that is unlawful, harassing, hateful, or sexually exploitative of minors;
- attempt to bypass usage limits, security, or access controls, or disrupt the Services or other users;
- resell or provide the Services to third parties except as expressly permitted.
AI features must be used responsibly. AI output can be inaccurate — don't rely on it for professional, legal, medical, or financial decisions without independent verification.
4. Plans, billing & refunds
Paid plans are billed in advance through our payment processor, Stripe, on a recurring basis (for example, monthly) until cancelled. Some plans also allow opt-in pay-as-you-go usage beyond your included limits, billed against your balance up to a cap you set. You can change or cancel your plan anytime from the billing dashboard; cancellation takes effect at the end of the current billing period and you keep access until then. Except where required by law, payments are non-refundable, though we'll always look at good-faith billing issues — just reach out.
5. Your content & AI output
You keep ownership of the content you upload or create with Aurora ("Your Content"). You grant us the limited rights needed to operate the Services — to store, process, and transmit Your Content to provide features you request (for example, sending a message to the AI model to generate a reply). Subject to these terms and applicable law, output the AI generates for you is yours to use. You're responsible for Your Content and for ensuring you have the rights to it.
6. Intellectual property
Aurora, our logos, software, and the look and feel of the Services are owned by us or our licensors and are protected by law. These terms don't grant you any right to our trademarks or branding.
7. Third-party services
Aurora relies on trusted third parties to operate (see the Privacy Policy for the list). Your use of features powered by them may also be subject to their terms. We're not responsible for third-party services we don't control.
8. Disclaimers
The Services are provided "as is" and "as available", without warranties of any kind, whether express or implied, including merchantability, fitness for a particular purpose, and non-infringement, to the fullest extent permitted by law.
9. Limitation of liability
To the fullest extent permitted by law, Aurora will not be liable for any indirect, incidental, special, consequential, or punitive damages, or for lost profits or data. Our total liability for any claim relating to the Services is limited to the amount you paid us in the twelve months before the event giving rise to the claim.
10. Termination
You can stop using Aurora and delete your account at any time. We may suspend or terminate access if you breach these terms or to protect the Services or other users. On termination, your right to use the Services ends; we'll handle your data as described in the Privacy Policy.
11. Changes to these terms
We may update these terms as Aurora evolves. If we make material changes, we'll update the date above and, where appropriate, notify you. Continuing to use the Services after changes take effect means you accept them.
12. Governing law
These terms are governed by the laws of the State of Georgia, United States, without regard to conflict of law rules, and the courts located there will have jurisdiction over any disputes, except where applicable law gives you the right to bring a claim elsewhere.
13. Contact
Questions about these terms? Email [email protected].
Privacy Policy
Your privacy matters. Aurora Lab Inc. is the data controller responsible for the personal information described here. This policy explains what we collect, why, and the choices you have. We collect only what we need to run Aurora. We never sell your personal information.
1. Information we collect
- Account information — your name, email, and password (stored hashed) when you sign up.
- Content — the messages, files, and documents you create or upload to use the Services.
- Billing information — your plan and usage. Card details are handled directly by Stripe; we never see or store full card numbers.
- Connected Google data — only if you choose to connect a Google account, the Google data described in the "Google User Data" section below.
- Usage & device data — basic logs (such as request times and error diagnostics) needed to operate, secure, and debug the Services.
- Sign-in and device details. The device and browser or app you sign in with, and your approximate country. See Sign-ins and devices in section 8.
2. How we use your information
To provide and maintain the Services, process your messages and files for features you request, handle billing, keep Aurora secure, prevent abuse, comply with the law, and communicate with you about your account. We do not use Your Content to train our own foundation models.
3. AI processing
When you use AI chat, the content of your request is sent to our AI provider, Anthropic, to generate a response. When you generate images, that runs on Aurora's own hardware and your prompt is not sent to a third-party image service. Web image search fetches openly-licensed results from public sources (such as Openverse and Wikimedia Commons) using your search terms.
4. Google User Data
Aurora lets you optionally connect your Google account to bring your Google services into Aurora. We request access to your Google data only when you explicitly connect your Google account, and only to the scopes you approve on Google's consent screen. We never access your Google data unless you have connected it. Specifically, when connected we access:
- Gmail — to surface and search your email inside your Aurora dashboard and to help you read, summarize, draft, and act on messages when you ask the Aurora AI assistant to.
- Google Calendar — to display your events and schedule in Aurora and to let the AI assistant help you review, plan, and manage events at your request.
- Google Drive — to list, open, search, and work with the files you choose so you can reference and act on them in Aurora and through AI assistance you request.
- Google Contacts — to show your contacts in Aurora (for example, to address messages and events) and to assist with actions you ask the AI assistant to perform.
We use this Google data solely to provide these user-facing features — surfacing your information in the dashboard and powering the AI assistance you request. We do not sell your Google data, do not use it for advertising, and do not use it to train generalized or foundation AI/ML models. Human access is limited to what you authorize or to the narrow cases permitted by Google's policy (such as security, abuse, or legal compliance, or with your explicit consent).
Aurora Lab's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention & deletion. Connecting your Google account is always revocable. You can disconnect it at any time from your Aurora account settings, or revoke Aurora's access directly from your Google Account permissions. When you disconnect, we delete the stored Google access and refresh tokens and any cached Google data we held to power the features above. We retain Google data only as long as your connection is active and you are using these features.
5. Cookies
We use a small number of strictly necessary cookies, mainly to keep you signed in, plus optional functional and analytics categories that stay off until you allow them. We do not use third-party advertising or cross-site tracking cookies. Choose Necessary only, Accept all, or pick categories in the cookie banner, and change your choice at any time in Your privacy choices in the footer. For every cookie we set, see the Cookie Policy.
6. Service providers (subprocessors)
We share data only with the providers that help us run Aurora:
- Stripe — payment processing.
- Anthropic — AI model that powers chat responses.
- Cloudflare — network delivery and security.
- Resend — transactional email (such as welcome and account messages).
Each processes data only as needed to provide its service to us. The full register is on the Subprocessors page.
7. Data retention
We keep your information for as long as your account is active or as needed to provide the Services, then delete or anonymize it within a reasonable period, unless a longer period is required by law (for example, billing records).
8. Security
We protect your data with commercially reasonable measures, including encryption in transit, hashed passwords, and access controls. No system is perfectly secure, but we work to keep your information safe and will notify you of significant incidents as required by law.
Sign-ins and devices. When you sign in, we record the device and browser or app you used (for example “Chrome 128 on macOS” or “Nisu on iPhone 13 Pro Max”) and your approximate location at the country level. Our network provider, Cloudflare, determines the country from your IP address. We show this in your account’s Security settings so you can recognize your sign-ins and sign out devices you don’t, and we use it to warn you about sign-ins from new devices. We don’t store your IP address with your sessions; to detect new networks we keep a one-way code derived from it for 90 days. A cookie named aurora_device, holding a random identifier, keeps sign-ins from the same browser together for up to 400 days. Session records are deleted 30 days after a session ends or stops being used.
9. Your rights
You can access, correct, export, or delete your personal information — most of it directly from your account, or by emailing [email protected]. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to object to or restrict certain processing.
10. International transfers
Aurora and our providers may process your data in the United States and other countries. Where required, we rely on appropriate safeguards for international transfers.
11. Children
Aurora isn't directed to children under 16, and we don't knowingly collect their personal information. If you believe a child has provided us data, contact us and we'll delete it.
12. Changes to this policy
We may update this policy from time to time. We'll revise the date above and, for material changes, take reasonable steps to let you know.
13. Contact
Questions or requests about your privacy? Email [email protected].
Acceptable Use Policy
This policy sets out what you may and may not do with the Services. It forms part of the Terms of Service, and applies to everyone who uses Aurora — account holders, their team members, and anyone acting through their account. Breaking it can cost you access, so it is written plainly rather than exhaustively: if something is clearly abusive but not listed below, assume it is prohibited.
1. Built on Claude — Anthropic's policies apply too
Aurora Chat and the AI features across the Services run on models provided by Anthropic. Your use of those features must therefore also comply with Anthropic's Usage Policy. Where that policy is stricter than this one, it controls. We are required to pass those obligations on to you, and to act when they are broken.
2. Illegal and harmful content
Do not use the Services to create, store, or distribute content that:
- sexually exploits or endangers minors, in any form, real or generated;
- depicts non-consensual sexual content, or sexualises a real person without consent;
- promotes, plans, or provides instructions for terrorism or violent extremism;
- harasses, threatens, defames, or incites violence against a person or group;
- provides genuine operational guidance for weapons, explosives, or biological, chemical, radiological or nuclear harm;
- facilitates human trafficking, child endangerment, or the sale of controlled goods where doing so is unlawful.
Child sexual abuse material is reported to the National Center for Missing & Exploited Children and the account is terminated immediately, without notice and without refund. There is no appeal for this category.
3. Security and platform integrity
- Do not probe, scan, or test the security of the Services without our prior written permission. Responsible disclosure is welcome — email [email protected] before you touch anything.
- Do not attempt to access another customer's account, data, or workspace.
- Do not upload or distribute malware, or use the Services to stage an attack on any third party.
- Do not circumvent rate limits, usage windows, quotas, or billing — including by registering multiple accounts to obtain additional free allowance.
- Do not run cryptocurrency mining, distributed computing, or other workloads whose purpose is to consume compute rather than to use the product.
4. Model abuse
- Do not attempt to bypass model safety measures, extract system prompts, or manipulate the model into producing content this policy prohibits.
- Do not use outputs to train, fine-tune, or distil a competing AI model.
- Do not resell, sublicense, or proxy raw model access. Your plan entitles you to use Aurora; it is not a licence to operate an API reselling business on top of it.
- Do not present AI output as human-authored where doing so would deceive someone to their detriment, and do not use the Services to impersonate a real person or organisation.
5. High-stakes uses
Aurora is a general-purpose tool and its output can be wrong. Do not rely on it as the sole basis for medical, legal, financial, or employment decisions, and do not deploy it to make automated decisions that have a legal or similarly significant effect on a person without meaningful human review. It is not designed for, and must not be used in, safety-critical systems where failure could cause injury.
6. Other people's rights
- Do not upload content you have no right to use, or infringe anyone's copyright, trademark, patent, or trade secret.
- Do not upload personal data about other people without a lawful basis for doing so — you are the controller of what you choose to put into Aurora.
- Do not scrape or bulk-collect data through the Services in violation of a third party's terms.
7. Reporting and enforcement
Report abuse to [email protected]. Where we can, we prefer the lightest response that fixes the problem — a warning, or removing specific content. For serious or repeated breaches we may suspend or terminate the account, and where the law requires it we will report to the relevant authorities. Termination for a breach of this policy does not entitle you to a refund of fees already paid.
Subprocessors
A subprocessor is a company we engage that may process customer personal data on our behalf in the course of running the Services. This page lists every one of them, what they do, and what reaches them. It is the authoritative list referenced by section 6 of the Privacy Policy.
| Provider | Purpose | Data it may process | Primary location |
|---|---|---|---|
| Anthropic | AI model that generates chat and assistant responses | The content of prompts you send to AI features, and the conversation context needed to answer them | United States |
| Stripe | Payment processing, subscriptions, and invoicing | Billing email, plan, and payment metadata. Card numbers go directly to Stripe and never reach Aurora servers | United States |
| Cloudflare | DNS, network delivery, TLS termination, denial-of-service protection, determining the approximate country of each sign-in from your IP address for sign-in security, and cookieless page analytics, only if you allow the Analytics category | Connection metadata such as IP address and request headers, in transit. The analytics beacon sets no cookies and does not fingerprint you | Global edge network |
| Resend | Transactional email — account verification and password reset links, receipts, and account notices | Recipient email address and the contents of the message we send you | United States |
| Connecting your Google account, and the Google services you explicitly authorise | Your Google account identifier, plus data from the scopes you grant. See the Google User Data section of the Privacy Policy | United States | |
| Open-Meteo | Weather for the dashboard weather card, and city search when you choose a place | The coordinates of the place you choose, or the city name you type. No account details | Europe |
| OpenStreetMap Foundation (Nominatim) | Turning your location into a city name when you choose Use my location on the weather card | Your location rounded to about 1 km, sent only when you tap Use my location. No account details | United Kingdom |
| GitHub | Optional GitHub connection for repository features | Your GitHub account identifier and the repository data you authorise | United States |
What we deliberately do not use
Aurora runs no third-party advertising networks, no cross-site trackers, and no analytics product that builds a profile of you across the web. Image generation runs on Aurora's own hardware rather than a third-party image service, so those prompts leave our infrastructure only if you send them somewhere yourself.
Changes to this list
We update this page when a subprocessor is added or removed. If you have a data processing agreement with us that requires advance notice of changes, we will give you that notice at the address on your account before the new subprocessor begins processing. To object to a change, or to request our data processing agreement, email [email protected].