Privacy Policy

Version 1.6 - August 2026

General Information and Your Rights

1) What is this about?

Aury is a conversational AI system that allows you to discuss topics related to your mental well-being.

In this Privacy Policy we explain:

  • what personal data we process,
  • for what purposes and on what legal basis,
  • how long we store it,
  • to whom we may disclose data,
  • and what rights you have.

This Privacy Policy applies to:

  • our consumer products,
  • our website,
  • as well as all contact channels (e.g., email, social media).

2) Who is responsible?

The controller responsible for data processing is:

Aury Care GmbH

Am Mühlenberg 11
14476 Potsdam
Germany

Email: info@aury.co

Managing Directors: Saskia Fester, Robert Wasenmüller, Maximilian Rank

3) Data Protection Officer

Frank Trautwein (external Data Protection Officer)

Fresh Compliance GmbH
Schönhauser Allee 43a
10435 Berlin
Germany
  • Data subject requests (e.g., access, erasure, data copy): dpo@aury.co
  • Confidential inquiries directly to the DPO: dsb@freshcompliance.de

4) What types of data do we typically process?

Depending on usage, we process in particular:

  • Account/contact details (e.g., email, name – if provided)
  • Communication content (e.g., chat messages, voice messages and the transcripts generated from them, feedback)
  • Usage/log data (e.g., timestamps, technical logs, IP address)
  • Device/browser data (e.g., device type, operating system, app/browser information, push token of the mobile apps)

Important note on sensitive data (health data):

If you share information about your mental state, symptoms, or health in conversations, this may constitute health data. We only process such data to the extent necessary for the use of Aury and on the legal bases specified in the respective section.

5) On what legal basis do we process data?

Depending on the purpose, we rely in particular on:

  • Art. 6(1)(b) GDPR (contract / use of the application)
  • Art. 6(1)(a) GDPR (consent, e.g., newsletter, optional analytics/tracking)
  • Art. 6(1)(f) GDPR (legitimate interest, e.g., IT security, abuse/error analysis)
  • Art. 6(1)(c) GDPR (legal obligations, where applicable)

Where health data is involved, an additional exception under Art. 9 GDPR applies (e.g., explicit consent, where required).

6) To whom do we disclose data?

We use processors (e.g., hosting, infrastructure, analytics tools) that process data exclusively on our instructions.

All processors are contractually bound under Art. 28 GDPR to process personal data solely on our instructions and not for their own purposes, to keep it confidential, and to implement appropriate technical and organisational safeguards. They are thereby committed to a level of protection for your data that is at least equivalent to the protection described in this Privacy Policy.

In addition, third-party providers may be independently responsible (e.g., messenger/social media platforms) when you use those channels. Details are provided in the respective sections.

7) How long do we store data?

We store personal data only as long as necessary for the respective purpose or as long as statutory retention obligations exist.

Specific storage periods are stated for the respective processing activities (e.g., hosting logs, analytics, newsletter).

8) Your rights

You have – subject to the applicable conditions – the following rights:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent at any time with effect for the future (Art. 7(3) GDPR)

To exercise your rights, contact us at: dpo@aury.co.

9) Right to lodge a complaint with a supervisory authority

You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht (Brandenburg)

Dagmar Hartge
Stahnsdorfer Damm 77
14532 Kleinmachnow

https://www.lda.brandenburg.de/lda/de/ueber-uns/kontaktanreise/

10) Automated decisions / Profiling

Aury generates responses automatically (AI-powered). We do not make solely automated decisions that produce legal effects concerning you or similarly significantly affect you.

11) Changes to this Privacy Policy

We may update this Privacy Policy if our processing, legal requirements, or products change. The current version is always available in the application or on our website.

The Application

1) Sub-processors

The following overview shows all sub-processors that we use for the data processing activities described in sections 2-5.

Sub-processorPurposeLocationMore Information
Scalingo SASApplication hosting, infrastructureFrance (EU)DPA
Outscale SASU (Dassault Systèmes SE)Infrastructure provider (servers)France (EU)--
Microsoft (Azure)AI model hostingEU Data ZonePrivacy Statement
Google (Vertex AI)AI model hostingEU Data ZoneZero Data Retention
Google (Cloud Speech-to-Text)Speech recognition (transcription of voice messages)EU (multi-region)Privacy
Datadog, Inc.Infrastructure monitoringEU operation/regionPrivacy
PostHog, Inc.Product analyticsEU operation/regionPrivacy
Langfuse GmbHLLM observability, quality assuranceGermany (EU)Privacy
Proton AGQuality assuranceSwitzerlandPrivacy
Expo (650 Industries, Inc.)Delivery of push notifications (mobile apps)USAPrivacy

(as of 27.08.2026)

2) Channels

We provide you with access to our applications through the following channels:

2.1 Web app and mobile apps (iOS and Android)

We provide Aury through a web app (in the browser) and through mobile apps for iOS and Android. In this Privacy Policy we refer to these access channels collectively as "the application". The processing described in this Privacy Policy applies equally to all of them.

  • Hosting of the application & infrastructure: Scalingo SAS as hosting provider; server operation via Outscale SASU (a brand of Dassault Systèmes SE) in France (EU). The mobile apps use the same infrastructure as the web app.
  • Storage & processing of personal data: exclusively within the EU/EEA and — for the quality assurance described in section 5 — in Switzerland.
  • AI-powered features (model hosting): Microsoft Azure Cloud (EU Data Zone) and Google Vertex AI (EU Data Zone).
  • Third-country transfer: Transfers outside the EU/EEA take place exclusively to Switzerland. The European Commission has issued an adequacy decision for Switzerland under Art. 45 GDPR; the level of data protection is therefore equivalent to that of the EU. Beyond that, solely for the delivery of push notifications in the mobile apps, the information listed in section 6.3 is transferred to the USA; conversation content is not affected. No further transfers of personal data to third countries take place in connection with the application.

3) Hosting & AI infrastructure

These details describe our technical service providers ("processors") for hosting and AI features.

3.1 Application hosting (website & Aury application)

Our website and our applications (web app and mobile apps) as well as the associated infrastructure (e.g., user management, database, backups, system logs) are operated by Scalingo SAS (hosting provider) using servers of Outscale SASU (a brand of Dassault Systèmes SE) as infrastructure provider exclusively in France (EU).

Data processed:

IP address, technical protocol/log data (e.g., timestamps, device/browser information), account/contact details (e.g., email; name, if provided), as well as content/information that you enter in the application, insofar as it is stored for usage purposes.

Purposes:

Operation and provision of the website/application, IT security, error/performance analysis, abuse and disruption prevention.

Legal basis:

Art. 6(1)(b) GDPR (provision/use of the application) and Art. 6(1)(f) GDPR (security, stability, abuse prevention).

Third-country transfer:

No transfer of data to third countries takes place.

Storage period:

Log/system data generally up to 180 days (security/error analysis), thereafter deletion/anonymization unless statutory obligations prevent it. Account and usage data stored in the application generally until deletion of the account or as long as required for usage.

3.2 AI model hosting in the EU (application)

For AI-powered features in the application, we use model hosting in EU data zones at:

  • Microsoft Azure (EU): https://www.microsoft.com/de-de/privacy/privacystatement (as of 26.02.2026)
  • Google Vertex AI (EU): https://cloud.google.com/privacy/gdpr?hl=de (as of 26.02.2026)

Training:

Google does not process customer data on Vertex AI for training/fine-tuning without prior permission/instruction.

For Azure-based GenAI services, it is likewise described that content is not used for training and may be temporarily stored for security/abuse monitoring.

Data processed:

We transmit to the model hosts the content of your messages together with the context Aury needs in order to give a meaningful reply:

  • your conversation history so far and summaries of earlier conversations,
  • the name you give us, your language setting and your time zone,
  • a short profile that Aury derives from your conversations (e.g., your concern, your goal, details that matter to you, and your feedback about Aury),
  • your progress in courses and methods, and reminders you have set up.

This information may contain health data (see section 1, "Important information on sensitive data (health data)").

Your email address, your login credentials and your payment data are not transmitted.

Purposes:

Generating responses for chatting with Aury.

Legal basis:

Art. 6(1)(b) GDPR (provision of AI features as part of the application). Where health data is involved, additionally Art. 9 GDPR (see section on "sensitive data/health data").

Third-country transfer:

No transfer of data to third countries takes place.

Storage period:

Depending on the provider/service, content is temporarily stored for service assurance and abuse/security monitoring (typically up to 30 days) and subsequently deleted, unless statutory obligations prevent it.

3.3 Speech recognition (voice messages)

When you send Aury a voice message, the recording is automatically converted into text (transcription). Only that text is processed further — exactly like a typed message.

Service provider:

Google Cloud Speech-to-Text, EU multi-region. The recording is processed exclusively within the European Union.

Data processed:

The audio recording of your voice message, the text generated from it, technical details of the recording (e.g., duration, format) and your language setting (German or English), so that recognition is more accurate. Voice messages may contain health data.

Purposes:

Converting your voice message into text so that Aury can respond to it.

Legal basis:

Art. 6(1)(b) GDPR (provision of the voice feature as part of the application). Where health data is involved, additionally Art. 9 GDPR (see section on "sensitive data/health data").

Training:

The content is not used to train or improve AI models.

Third-country transfer:

No transfer of data to third countries takes place.

Storage period:

We do not store the audio recording: it is processed only for the duration of the conversion and then discarded. Only the generated text is stored permanently, as part of your conversation history; the storage periods in section 3.1 apply to it. The service provider likewise does not store the recording or the text after conversion.

4) Information pursuant to the EU AI Act

When you chat with Aury, you are interacting with an AI-powered system, not a human.

Aury is designed to provide general support and information on mental well-being. Aury is not a substitute for professional (psycho-)therapeutic, medical, or psychological diagnosis or treatment.

Important notes on usage:

  • AI responses may be inaccurate, incomplete, or biased. Do not use them as the sole basis for important decisions, especially in health matters.
  • If you are in an acute crisis or believe you or others are at risk: please contact local emergency/crisis services.

Reporting problematic responses:

  • By email to support@aury.co.

Note: Aury is not intended to perform emotion recognition or biometric categorization.

5) Analytics and tracking

We only use analytics and product optimization tools if you have explicitly consented (opt-in).

Data processed (with opt-in):

  • Usage data (e.g., timestamps, duration, features used)
  • Technical events (e.g., error codes)
  • Pseudonymized usage identifier, where applicable
  • Anonymized or heavily pseudonymized excerpts from interactions (e.g., for quality measurement), where technically provided, where applicable

Recipients / service providers:

The data is transmitted in pseudonymized form to the following processors. Processing takes place in the EU; in the case of Proton AG it takes place in Switzerland (adequacy decision of the European Commission under Art. 45 GDPR):

  • DataDog, Inc. (EU operation/region): https://www.datadoghq.com/legal/privacy/ (as of 26.02.2026)
  • PostHog, Inc. (EU operation/region): https://posthog.com/privacy (as of 26.02.2026)
  • Langfuse GmbH: https://langfuse.com/privacy (as of 26.02.2026)
  • Proton AG: https://proton.me/legal/privacy (as of 26.02.2026)

Legal basis:

  • Art. 6(1)(a) GDPR (consent)
  • Insofar as terminal device access/cookies are concerned: Section 25(1) TDDDG (consent)

Withdrawal:

You may withdraw your consent at any time with effect for the future.

Storage period:

  • Usage data: generally up to 180 days after last activity
  • Pseudo-/anonymized interaction excerpts, where applicable: generally up to 7 days or until your deletion request

6) Reminders and marketing

We only contact you if it is necessary for the provision of the service (service messages) or if you have consented (e.g., newsletter).

6.1 Service messages (no marketing)

We may send you necessary messages regarding usage (e.g., security/feature notices, confirmations).

Legal basis: Art. 6(1)(b) GDPR (contract) and, where applicable, Art. 6(1)(f) GDPR (security).

6.2 Reminders from Aury (only when activated)

Aury can send you reminders that you have actively set up (e.g., during onboarding). You can stop them at any time via your settings in the application.

Legal basis: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(b) GDPR (if part of a feature you activated).

In the mobile apps, reminders are delivered as push notifications (see section 6.3).

6.3 Push notifications (mobile apps)

In the mobile apps for iOS and Android you can enable push notifications. In addition to your consent, your device asks for permission; only then do notifications reach you. The web app does not send push notifications.

Service provider:

Delivery is handled by Expo (650 Industries, Inc., USA). From there the notification is passed to your operating system’s push service — Apple Push Notification service on iOS, Google Firebase Cloud Messaging on Android.

Data processed:

A push token that your device generates for our app, an internal identifier for your user account, the type of notification, and the notification text displayed. We store the push token in your user account.

Content of the notification:

The notification contains only a general prompt — for example a note that Aury has written to you, or that your session is starting in 15 minutes. No content from your conversations is transmitted, and none appears on your lock screen.

Purposes:

Letting you know that Aury has written to you, or reminding you of a session you have set up.

Legal basis:

Art. 6(1)(a) GDPR (consent). You can switch push notifications off at any time in your device or app settings; the permission applies going forward only.

Third-country transfer:

The information listed above is transferred to the USA for delivery. Content from your conversations is not affected. Expo states that it participates in the EU-U.S. Data Privacy Framework.

Storage period:

We store the push token for as long as you have push notifications enabled. If it becomes invalid — for example because you uninstall the app — we delete it from your user account. We do not store the notification itself.

6.4 Newsletter

If you subscribe, we will send you updates and information about Aury. You can unsubscribe at any time via the link in each email or via support@aury.co.

Legal basis: Art. 6(1)(a) GDPR (consent).

6.5 User surveys

We may invite you (with your consent) to participate in voluntary surveys.

Legal basis: Art. 6(1)(a) GDPR (consent).

6.6 Storage period

We store contact information and preferences until you withdraw your consent. After withdrawal, we delete them unless retention is necessary for evidentiary purposes.

The Website

The following sections concern visits to our website (aury.co). The processing activities described here may involve third-country transfers and are independent of the application processing described in sections 2 and 3.

1) Server log files and website delivery

When you visit our website, we process server log data that is technically necessary to deliver and protect the website.

Data processed: IP address, date/time, page accessed, referrer URL, browser/OS, status codes, data volume.

Purposes: Delivery, IT security, error analysis, abuse prevention.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

Storage period: Generally up to 180 days (security/error analysis), thereafter deletion or anonymization.

2) Cookies and consent management

We use (i) technically necessary cookies or similar technologies and (ii) optional technologies (e.g., analytics) only after consent.

  • Technically necessary: Required for the function you have expressly requested. Legal basis: Section 25(2) TDDDG; Art. 6(1)(f) GDPR (or Art. 6(1)(b) GDPR, depending on the function).
  • Optional (e.g., analytics): Only after opt-in. Legal basis: Section 25(1) TDDDG; Art. 6(1)(a) GDPR.

You can change your selection at any time via the consent tool or browser settings (where available).

3) Web analytics (Google Analytics)

If you consent, we use Google Analytics (Google LLC). This may involve transfers to the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework.

Data processed: Online identifiers (e.g., cookie IDs), device/browser data, usage data, truncated IP address (where enabled).

Purposes: Reach measurement, website optimization.

Legal basis: Art. 6(1)(a) GDPR (consent) and Section 25(1) TDDDG.

Third-country transfer: Transfers to the USA on the basis of the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission).

Storage period: According to settings in Google Analytics (configuration).

https://policies.google.com/privacy (as of 26.02.2026)

Customer Service and Inquiries

When you contact us, we process your information to handle the inquiry.

Data processed: Email, name (if provided), content of the message, IP address and metadata where applicable.

Purpose: Handling and responding to your inquiry.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) or Art. 6(1)(f) GDPR (general communication).

Storage period: Up to 180 days after completion, unless longer retention is required.

Social Media

1) LinkedIn

We operate a company profile on LinkedIn. Provider: LinkedIn Ireland Unlimited Company.

LinkedIn processes personal data as an independent controller; processing may also take place in third countries (e.g., USA).

Communication via LinkedIn: If you contact us via LinkedIn, we process the data you provide to respond.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) or Art. 6(1)(f) GDPR (communication).

Storage period: As required; additionally, the platform's deletion/storage policies apply.

Page Insights / joint controllership: For so-called "Page Insights", we are jointly responsible with LinkedIn (Art. 26 GDPR). Within the scope of Page Insights, LinkedIn processes aggregated statistics about the use of our company page (e.g., page views, demographic characteristics of visitors, interactions with posts).

  • Agreement ("Joint Controller Addendum"): https://legal.linkedin.com/pages-joint-controller-addendum
  • LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy

Job Applications

If you apply to us (via email, form, or through platforms), we process your application data to carry out the recruitment process.

Data processed: Master data (name, contact details), application documents (CV, certificates), communication, salary expectations/start date where applicable; special categories (e.g., health data) only if you provide them voluntarily and to the extent permitted.

Purposes: Review and selection, communication, establishment of an employment relationship.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures); where applicable, Art. 6(1)(f) GDPR (legal defense). Where special categories are involved: Art. 9(2)(a) GDPR (explicit consent) or Art. 9(2)(b) GDPR (where required under employment law).

Recipients: Internal HR/recruiting staff; processors where applicable (e.g., email/hosting). Platform providers (e.g., LinkedIn) may be independently responsible.

Storage period: In the event of rejection, we generally delete application data within 180 days after completion of the process (including for defense against potential claims). In the event of hiring, relevant data is transferred to the personnel file and stored in accordance with statutory requirements.

Talent pool: Only with your consent; withdrawal possible at any time.

Business Contacts (B2B)

If you contact us as a representative of a company (e.g., via email, events, sales conversations), we process contact data for communication and contract initiation.

Data processed: Name, professional contact details, position, communication content.

Purpose: Communication, proposal preparation, contract initiation/performance.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) and/or Art. 6(1)(f) GDPR (legitimate interest in business communication).

Storage period: As long as required; business correspondence and contract-related communication may be retained under commercial/tax law requirements (up to 10 years).

Try it out: