Legal
Privacy policy
The English version is the original and authoritative text; versions in other languages are machine-generated translations provided for convenience — in case of any discrepancy, the English version prevails.
Updated: 10 July 2026
In short: we build Aurora so that we simply don’t have data about your activity. You can’t hand over or lose what doesn’t exist.
1. Introduction
This Privacy Policy explains what personal data Aurora VPN processes, why, and your rights in relation to it. The data controller is Smedia Pro LTD, incorporated in the United Kingdom, registered address 7 Bell Yard, London, United Kingdom, WC2A 2JR. For privacy matters you can contact our privacy team / Data Protection Officer at privacy@auroravpn.org.
Where required, we will appoint and identify a representative in the EU for the purposes of the GDPR. We follow the principle of data minimisation: we collect only what the Service cannot work without, and nothing beyond that.
2. What we do NOT log
Because of how Aurora is designed, we do not record:
- Your browsing activity, or the websites and apps you use
- Your DNS queries
- The contents of your traffic
- The IP address you connect from, or the IP address you sign in from — neither is stored anywhere in our systems
- Individual connection records — we keep no session start or end times, and no session duration
3. What data we collect
We collect the minimum needed to operate your account and provide the Service:
- Account email — for sign-in, account recovery and essential service notices
- Limited billing data — your full card details are NOT stored by us; payment is processed by our payment provider
- Support correspondence — when you contact us for help
- Crash diagnostics — when the app crashes, a report (device model, OS and app version, stack trace, and a random installation identifier) is sent automatically to our crash-reporting provider so we can fix the fault. It contains no browsing activity, no DNS queries and no VPN traffic.
- Optional connection logs — from your device, sent only when you explicitly choose to share them with support.
- Service usage — the total traffic your plan has used, when your device was last online, and a per-day total of how much traffic passed through each country. The per-day totals are deleted after 30 days.
- Device identifiers — a random identifier generated when you install the app, and your device or browser user agent. They enforce your plan’s device limit and let you recognise and revoke a device that is not yours.
4. Legal bases for processing
Where the GDPR applies, we rely on the following legal bases under Article 6: performance of our contract with you (providing the Service and managing your account); your consent (for example optional diagnostics, and analytics or non-essential cookies where consent is required), which you can withdraw at any time; and our legitimate interests in keeping the Service secure, preventing fraud and abuse, and — where the law does not require consent — operating, measuring and improving our website, including basic analytics. You can object to any processing based on legitimate interests at any time.
5. Cookies and analytics
Strictly necessary cookies operate the website and keep you signed in. They cannot be turned off.
For analytics we use Google Analytics (loaded through Google Tag Manager) and Cloudflare's cookieless page-speed measurement. Where prior consent is required by law — in the EU/EEA, the UK and Switzerland — these load only after you accept; nothing reaches them before you choose, and Google Consent Mode denies every signal by default. Elsewhere they load on a legitimate-interest basis so we can run and improve the site. Either way you can change your choice or opt out at any time from the cookie link in the footer. We use no advertising or cross-site tracking cookies.
Our mobile apps contain no analytics. They send automatic crash reports only — see section 8.
6. Your rights
Subject to applicable law, you have the right to access your data, to have it corrected, to have it deleted, to data portability, to object to certain processing, and to request restriction of processing. You also have the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact privacy@auroravpn.org. We process such requests within 30 days. Deleting your account erases your email and payment link from our systems.
7. Data retention
We keep personal data only for as long as it is needed, and we delete it on a schedule rather than on request:
Account and billing data are kept while your account exists and for any period the law requires afterwards (for example, tax records). Sign-in sessions are kept until you revoke them, sign out, change your password, or they expire. One-time sign-in codes expire after 10 minutes. Per-day traffic totals are deleted after 30 days. Deleting your account erases your email, your sessions and your devices from our systems.
8. Sub-processors and other recipients
We use a small number of service providers to operate the Service. Each processes data only on our instructions and under appropriate data-protection terms. This list is accurate as of the date of this policy; for the current one, write to privacy@auroravpn.org.
- Cloudflare — hosting for our website and applications, content delivery, security, our database, and delivery of the email you send to our published addresses.
- Apple — purchases made inside our iOS app. Apple bills you and tells us the subscription’s status; we never see your payment details.
- Stripe — card payments on our website, and the local payment methods offered at checkout, including PayPal.
- CoinGate — cryptocurrency payments.
- Google — automatic crash reports from our mobile apps (Firebase Crashlytics) and, on the website, Google Analytics under the consent / legitimate-interest rules described in section 5.
- Telegram — support conversations you start with us there and, if you choose to sign in with Telegram, your one-time login code.
- Infrastructure providers who supply the servers our VPN nodes and management panel run on. They provide hardware and network capacity; the servers themselves are administered by us.
- An AI provider that turns the result of the in-app network diagnostic into a plain-language explanation. It receives only non-identifying facts — status flags, an exit country code, and latency figures in milliseconds. It never receives your IP address, your account, or anything about what you browse.
9. International transfers
Some of our sub-processors may process data outside your country. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) or transfers to countries recognised as providing an adequate level of protection.
10. Government and law-enforcement requests
We can only provide what we actually have — and by design we store almost nothing about your activity, so for most requests there is simply nothing to hand over. Where we do receive a legally valid request, we assess it carefully, provide only what we are legally required to provide, and challenge requests where it is lawful and appropriate to do so.
11. Children
The Service is not intended for, and may not be used by, anyone under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@auroravpn.org and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. For material changes we will notify you by email and/or in the Service. The "Updated" date above reflects the latest version.
13. Contact and DPO
For any privacy questions or to exercise your rights, contact our privacy team / Data Protection Officer at privacy@auroravpn.org. More about where the company is registered is on the Jurisdiction page.