Privacy Policy
Last updated: September 3, 2026
AuraHome (“we”, “us”) is an app that turns a photo of your room into an interior design. This policy explains which personal data we process, why, who we share it with, and how you can exercise your rights. It reflects our obligations under the EU General Data Protection Regulation (GDPR) and Turkey’s Personal Data Protection Law (KVKK, Law No. 6698).
1. Data Controller
The data controller for the AuraHome app and the aurahome.design website is Miroğlu Bilişim Limited Şirketi. Registered address: <COMPANY_ADDRESS>. Registration number: <COMPANY_REGISTRATION_NUMBER>. Contact: support@aurahome.design
2. Data We Process
- Account data: email address, password hash, name, username, profile preferences. Accounts are created with email only — there is no other way to sign in, and we collect no social-account or phone-number sign-in data.
- Room photos and designs (private): the photos you upload and the designs generated from them are private to your account — they are never published to the community and never shown to other users. They are processed only to generate, store and show you your design, and never used for advertising or to train models.
- Your community posts (public): the product photo, title, note, tags, purchase link, price and currency you share in the community, plus the store name derived from the link. This content is public — see the notice below.
- Your community interactions: likes, saves and collections, follow relationships, reports you file, users you block, and the notifications you receive.
- Moderation and report records: the moderation decision made on each submission (approved or rejected and its machine-readable reason), the reviewed image, title and link; reports about you or filed by you and their outcome; the record of a post being hidden.
- Product-click measurement: the fact that a product’s store link was tapped — counted to understand which products draw interest.
- Usage data: generation history, room-allowance usage; for service quality and debugging, device type, operating system, app version and error logs. If you allow notifications, your device push token.
- Taste profile: your answers to the Aura quiz (used to personalize suggestions).
- Purchase data: subscriptions are bought through the Apple App Store and Google Play. We receive only an anonymized transaction ID, product ID and verification signature; your card details never reach us.
What you share in the community is public. When you post a product, your product photo, title, note, tags, purchase link and price are visible to everyone in the app alongside your username and profile picture, and can be copied. This is a publication you choose to make, so make sure it contains no personal data before you post. You can remove your post at any time — a removed post disappears from every list, but we have no control over copies other people took beforehand. Your room photos and the designs you generate are never published to the community. What may be shared is set out on the Community Rules page.
3. Purposes and Legal Basis
We process your data under KVKK Article 5 and GDPR Article 6 on the following bases:
- Performance of a contract: creating and managing your account, generating designs, matching products, verifying room allowances and subscriptions.
- Legitimate interest: preventing abuse, keeping the community safe (moderating posts before publication, reviewing reports, keeping block records, identifying violating accounts), fixing errors, improving service quality, and measuring which products draw interest.
- Legal obligation: keeping financial records for the statutory period, answering lawful requests from authorities.
We do not send marketing notifications and we do not process your data for advertising.
4. Who We Share Data With
To deliver the service, data is shared with the following categories of recipients, only as needed:
- AI infrastructure provider: your room photo is transmitted for design generation, and a community post’s image and link for pre-publication moderation, only for the duration of that operation; the provider does not retain the data and does not use it for its own purposes.
- Cloud storage provider: access-controlled storage of your photos and designs, linked to your account.
- Apple App Store and Google Play: subscription and payment verification.
- Email and error-reporting providers: delivery of verification codes and transactional emails, crash/error reports (personal fields are masked).
Separately from these recipients, a post you share in the community is open to every user of the app. That is not a transfer by us but a publication you initiate. Your room photos and designs are never included in it under any circumstances.
These providers process data only on our behalf under written agreements. Your data is never sold to data brokers or advertising networks. Some providers operate servers abroad; such transfers rely on safeguards compliant with KVKK Article 9 and GDPR Chapter V (standard contractual clauses or equivalent measures).
5. Retention and Deletion
You can delete your account at any time from inside the app (Settings → Delete my account). On deletion your personal fields (email, name, username, bio, password hash) are permanently removed and all your sessions are signed out. Details on the account deletion page.
Retention periods:
- Account data: while the account exists; anonymized immediately on a deletion request.
- Room photos and designs: until you delete them; removed from storage within 30 days of account deletion.
- Community posts: until you remove them. When you delete your account your posts stop appearing anywhere in the app (feed, search, profiles, collection covers) and their images are removed from storage within 30 days along with the rest of your media.
- Likes, saves, collections and follows: removed together with your account.
- Moderation decisions, reports and block records: kept after account deletion, in a form that cannot be linked back to the deleted account, to prevent abuse and to answer app-store audits. Without them we could not stop a blocked or terminated account from deleting itself, signing up again and repeating the same violation; this is a necessary safety measure based on our legitimate interest. Report records are kept detached from the reporter’s identity.
- Financial records (subscriptions, purchases, room-allowance movements): for the statutory period, with personal identifiers masked.
- Error logs: purged automatically after 90 days.
6. Your Rights
Under GDPR Articles 15–22 and KVKK Article 11 you have the right to:
- Learn whether we process your data and request access to it
- Have incomplete or inaccurate data corrected
- Have your data erased
- Object to processing or request that it be restricted
- Receive your data in a portable format
- Have corrections and erasures communicated to third parties we shared data with
Send requests to support@aurahome.design; we respond within 30 days. If you are not satisfied, you can lodge a complaint with the Turkish Personal Data Protection Authority or the supervisory authority in your country.
7. Security
Data is encrypted in transit (TLS) and protected with access controls at rest; passwords are hashed irreversibly (argon2). Session keys are kept in your device’s operating-system secure storage.
8. Children
AuraHome is not directed at children under 13. If you believe we have processed a child’s data, write to support@aurahome.design and we will delete it promptly.
9. Cookies
Our website uses no marketing or analytics cookies; only the technical data needed to serve the pages is processed.
10. Changes
We may update this policy from time to time. Material changes are announced in the app; the current date is shown at the top of this page.
11. Contact
Email: support@aurahome.design
Post: Miroğlu Bilişim Limited Şirketi, <COMPANY_ADDRESS>