Privacy Policy

Effective date: 18/07/2026

This Privacy Policy explains how ProfileAura ("we", "us") collects and processes personal data when you use profileaura.app (the "Service"). We are committed to processing only what we need, keeping it briefly, and being transparent about it.

1. Data controller

The data controller is ProfileAura, based in Greece.
Contact for all privacy matters: hello@profileaura.app

2. What the Service does with data

ProfileAura analyzes publicly available data from public social media profiles to generate an AI-powered entertainment report. Two categories of people are involved: users (you, using the site and possibly buying a report) and analyzed profiles (the public profile submitted for analysis, which may belong to you or to someone else).

3. Data we process

About you (the user)

  • Payment data: handled entirely by Stripe as merchant of record. We never see or store your card details. We receive confirmation that a payment succeeded and a transaction reference.
  • Email address: if provided during checkout, used by Stripe for your receipt and by us to help with support or refunds.
  • IP address: processed transiently for rate limiting, abuse prevention, and security.
  • Usage events: we record basic, aggregate product analytics (e.g., that a preview was viewed, a report was generated or shared). These are counted per session and stored as daily aggregate counters — not as behavioral profiles.

About analyzed profiles

When a profile is submitted for analysis, we collect only publicly available data from that profile, which may include: username, display name, bio, profile picture, public posts, public captions, public comments and the usernames of commenters, like counts, and follower/following counts. We do not access private profiles, private messages, or any data requiring login to the analyzed account.

This public data is processed by AI to produce the report (e.g., identifying frequent commenters and engagement patterns).

4. Legal bases (GDPR)

  • Performance of a contract (Art. 6(1)(b)): providing previews and paid reports to you.
  • Legitimate interests (Art. 6(1)(f)): processing publicly available profile data at a user's request to generate an entertainment report; preventing fraud and abuse; measuring aggregate product performance. Given that we only process data the profile owner has chosen to make public, retain it briefly, and use it for a limited entertainment purpose, we believe this processing does not override the interests or rights of profile owners. Profile owners may object at any time (see Section 8).
  • Legal obligation (Art. 6(1)(c)): transaction records retained where required by tax and accounting law (held by Stripe as merchant of record).

5. How long we keep data

  • Scraped profile data: automatically deleted within 24 hours.
  • Generated reports: automatically deleted 30 days after generation.
  • IP-based rate-limiting records: short-lived technical records, automatically expired within a short period.
  • Aggregate analytics counters: retained as anonymous daily totals (no personal data).
  • Payment records: retained by Stripe in accordance with legal requirements.

6. Who we share data with (processors and recipients)

We use a small number of service providers to run the Service:

  • Stripe — payment processing (merchant of record)
  • Apify — collection of publicly available profile data
  • Anthropic — AI processing to generate the report text
  • Upstash — temporary data caching (Redis)
  • Vercel and Railway — hosting of the website and backend

Some of these providers are located in the United States. Where personal data is transferred outside the EEA, transfers rely on appropriate safeguards such as the EU–US Data Privacy Framework and/or Standard Contractual Clauses.

We do not sell personal data, and we do not share it with advertisers.

7. Cookies and tracking

We use only what is necessary to operate the Service (e.g., session handling and payment flow). We do not use third-party advertising cookies or cross-site tracking.

8. Your rights

If you are in the EU/EEA (and in many other jurisdictions), you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate data;
  • erase your data ("right to be forgotten");
  • restrict or object to processing, including processing based on legitimate interests;
  • data portability; and
  • withdraw consent where processing is based on consent.

If your profile was analyzed by someone else and you would like the cached data and any associated report deleted — or you want to object to your public profile being analyzed at all — email us at hello@profileaura.app with your username. We will delete the associated data promptly and can block your profile from future analysis on request.

To exercise any right, email hello@profileaura.app. We will respond within the timelines required by law (normally one month).

You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Hellenic Data Protection Authority (www.dpa.gr), but you may also contact the authority in your own country.

9. Children

The Service is not directed at children and reports may only be purchased by adults. We do not knowingly process data of children as users of the Service.

10. Security

Data is transmitted over encrypted connections (HTTPS). Access to production systems is restricted, secrets are kept out of source control, and cached data expires automatically. No system is perfectly secure, but we deliberately minimize what we store and how long we store it.

11. Changes to this policy

We may update this policy from time to time. The current version will always be available on this page, with its effective date shown at the top.

12. Contact

Privacy questions, deletion requests, objections: hello@profileaura.app