1. Who we are
Aura (bundle identifier com.b4udie.aura) is an iOS application published by
Valentyn Bratkevych (“we”, “us”). Aura is a privacy tool: it sets up a
private DNS configuration on your device that blocks known trackers, ad networks and malicious
domains. This policy explains what personal data the app handles, why, and what you can do about
it. It applies to the app only, not to any other product or website.
For data protection purposes, Valentyn Bratkevych is the controller of the personal data described below. You can reach us at bratkevychv@proton.me.
2. The short version
- Aura filters DNS for your whole device. To do that, our resolver processes the domain names your device looks up — it does not see the content of your traffic or the pages you open.
- You do not create an account. We identify your device only by a random installation identifier, not by your name, email or Apple ID.
- We do not track you across other apps or websites, we do not use advertising SDKs, and we do not sell your data.
- The app sends anonymous usage events (which screens you open, how far you get through setup) to a product analytics service hosted in the United States. These events are tied to the random installation identifier only and never include the domains your device looks up.
- You can ask us what we hold about you and ask us to delete it.
3. Information we collect
3.1 Information you provide
- Support messages — if you email us, we receive your address and whatever you write.
3.2 Information collected automatically
- Installation and device details — when the app first runs it creates a random installation identifier and sends it to our servers, together with a device label (such as “iPhone”), the platform, the operating system version and the app version. The installation identifier lets the service recognise your device without an account; it is not derived from your identity and is reset if you reinstall the app.
- DNS query data — because Aura protects your whole device, our resolver receives the domain names that apps on your device look up (for example
example-tracker.com), whether each lookup was blocked or allowed, the category of the domain, an approximate label of the app that made the request, and the time it happened. This is what powers the filtering and the activity list you see in the app. It is domain-level data only: we do not see the full web addresses you visit, the content of pages, or the content of your traffic. - Technical request data — when the app talks to our servers we process the request itself, the app and operating system version, and the IP address the request comes from. IP addresses are used for delivery and abuse prevention, not to build a profile of you.
- Purchase status — whether a purchase or subscription is active, and the transaction identifiers Apple gives us. We never receive your card number or full billing details.
- Product analytics — the app records how it is used: which screens are opened, how far you get through setup, whether protection is turned on or off, and paywall events such as viewing plans or starting a trial, together with the app version, operating system version and device model. These events are processed for us by Amplitude, Inc. on servers in the United States and are tied only to the random installation identifier — never to your name, email or Apple ID. Analytics events never include DNS query data: the domains your device looks up are not sent to Amplitude. A side effect of Aura’s own protection: the resolver’s blocklist blocks analytics domains device-wide, including ours, so once filtering is active for your device some of these events simply never reach us — we accept that by design.
3.3 Information from third parties
Apple tells us whether a purchase succeeded and whether a subscription is active. Aside from Apple’s role in processing purchases, we do not buy or receive personal data about you from anyone.
4. How Aura’s protection works
To protect you, Aura installs a private DNS configuration on your device, which you approve when you set the app up. From then on, whenever any app on your device needs to find a website address, that lookup is sent to Aura’s DNS resolver. The resolver blocks lookups for known trackers, ad networks and malicious domains and passes the rest through.
Two consequences follow, and we want them to be clear:
- The resolver processes DNS lookups from every app on your device while protection is on, not only from Aura. That is how device-wide filtering works.
- DNS is domain-level. We can see that your device asked for a domain; we cannot see the specific page, the content, or anything you send or receive over the connection.
You are in control: you can turn protection off inside the app, and you can remove the DNS configuration in Settings › General › VPN & Device Management › DNS. When protection is off, no DNS lookups are sent to our resolver.
5. Why we use data, and on what legal basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Filter DNS and show your protection status and activity | Installation and device details, DNS query data | Performance of a contract (Art. 6(1)(b)) |
| Unlock and restore paid features | Purchase status, transaction identifiers | Performance of a contract (Art. 6(1)(b)) |
| Keep the service reliable and prevent abuse | Technical request data, including IP address | Legitimate interest in a working, secure service (Art. 6(1)(f)) |
| Understand how the app is used and improve it | Product analytics events (installation identifier, app usage events) | Legitimate interest in improving the product (Art. 6(1)(f)) |
| Answer support requests and meet legal obligations | Support messages, minimal records | Legitimate interest / legal obligation (Art. 6(1)(f), (c)) |
We do not use your data to make automated decisions with legal effects, and we do not profile you.
6. Purchases and subscriptions
Purchases are processed by Apple through the App Store. Apple handles payment and receives your payment details; we receive only the purchase status and Apple’s transaction identifiers, which is what lets the app unlock paid features and restore them on a new device. Apple’s handling of your payment data is governed by Apple’s Privacy Policy.
7. Tracking and advertising
Aura is built to stop tracking, not to do it. The app contains no advertising SDKs, does not read Apple’s advertising identifier (IDFA), does not track you across other companies’ apps or websites, and does not build advertising profiles. Because of that, the app never shows the App Tracking Transparency prompt.
The app does use a first-party product analytics service (Amplitude — section 3.2) to understand how Aura itself is used. Those events describe your use of Aura only, are tied to the random installation identifier, are not combined with data from other companies’ apps or websites, and are not used for advertising.
8. Sharing and disclosure
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We do not hand DNS activity to advertisers or data brokers. We disclose data only when the law requires it (a valid legal request), to protect our rights or someone’s safety, or to a successor if the app changes hands — in which case this policy continues to apply until you are told otherwise.
We do use a small number of service providers that process data on our instructions and for our purposes only: Amplitude, Inc. (product analytics, United States — section 3.2) and the infrastructure providers that host our servers. They may not use your data for anything of their own.
9. International transfers
If data is processed outside your country, including outside the EEA, the transfer relies on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism. In particular, product analytics events (section 3.2) are processed by Amplitude, Inc. in the United States under such safeguards. Ask us at bratkevychv@proton.me if you want the specifics.
10. How long we keep data
We keep data only as long as it is needed for the purpose it was collected. DNS activity is kept for a short period so the app can show you a recent history and so the service can work, and older entries age out automatically. The installation record lasts while you use the service; purchase records are kept as long as tax and accounting law requires. Product analytics events are kept only as long as they are useful for improving the app, and are deleted from the analytics service on request together with your other data (section 12). When you stop using the service and delete the app, the associated data is deleted or anonymised within a reasonable period.
11. Security
Traffic between the app and our servers, and DNS lookups sent to our resolver, are encrypted in transit. Access to systems that hold personal data is limited to those who need it. No system is perfectly secure, so we keep the amount of data we hold as small as the service allows — that is the strongest protection we can offer.
12. Your rights and choices
- Access — ask what personal data we hold about you.
- Correction — ask us to fix data that is wrong.
- Deletion — ask us to delete your data.
- Objection and restriction — object to processing based on legitimate interests, or ask us to pause it.
- Portability — receive a copy of the data you gave us in a machine-readable format.
- Withdraw consent — where processing is based on consent, withdraw it at any time; this does not affect what happened before.
Write to bratkevychv@proton.me and we will respond within 30 days. Because Aura works without an account, we identify your data by the random installation identifier, so contacting us from the device or including that identifier helps us locate your records; we may need to verify that the request comes from you.
If you are in the EEA or the UK and you think we have handled your data wrongly, you may also complain to your national data protection authority.
California residents. You have the right to know what personal information we collect and why, to request deletion or correction, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so no “Do Not Sell or Share” mechanism is needed. To exercise a right, email bratkevychv@proton.me; an authorised agent may act for you with written proof.
13. Children
The app is not directed to children under 13 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, email bratkevychv@proton.me and we will delete it.
14. Apple and the App Store
Downloads, purchases and app analytics that Apple collects as the store operator are governed by Apple’s Privacy Policy, not this one. The privacy labels shown on our App Store page describe the same data practices set out here.
15. Changes to this policy
If we change how the app handles data, we update this page and the “Last updated” date above; material changes are announced in the app before they take effect. The current version is always the one published here.
16. Contact
Valentyn Bratkevych — bratkevychv@proton.me. Write in English or Ukrainian; we answer in the language you used.