Mark Wealth - wellness assistant
  • Blog
  • Success Stories
  • Resources
    • About us
    • About product
    • Research
    • Contact
  • Partnership
  • FAQ
Try Mark app
  1. Home
  2. Aurora
  3. Aurora – Privacy Policy

Aurora - Privacy Policy

Last updated: September 21, 2026 Operator: Mark Wealth C Corp. ("Mark Wealth", "Aurora", "the Application", "we", "us", "our") Address: 254 Chapman Rd, Ste 209, Newark, DE 19702, United States Contact: support@markwealth.me  

Introduction

Aurora is an AI health-and-wellness concierge application for iOS. Each day it turns the health data you choose to share into a single, plain-language wellness readout — a daily "Brief", a wellness score, and one prioritised recommendation — rather than a dashboard of raw numbers. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, who we share it with, how long we keep it, and the rights and choices available to you. It applies to the Aurora iOS application and any related websites, support channels, and services that link to it (together, the "Service"). This Application provides informational and educational wellness support only. It is not a medical device, does not provide medical advice, diagnosis, or treatment, and is not a substitute for a qualified clinician. You should consult a licensed healthcare professional before making any health-related decision. You are solely responsible for the accuracy and completeness of the information you provide, and for any decisions you make based on the Service. Although we are not a HIPAA "covered entity" or a medical provider, we voluntarily implement administrative, technical, and physical safeguards for the health information you share with us that are consistent with the standards of the U.S. Health Insurance Portability and Accountability Act (HIPAA) and the HITECH Act. By creating an account or using the Service, you confirm that you are at least 13 years old and that you have read and understood this Policy. If you are under the age of majority (18 in most U.S. states), you may use the Service only with the involvement of a parent or guardian. The Service is offered in the United States, Denmark, and Ukraine.  

1. Scope and your consent

This Policy covers personal data we process as a controller of your information. Where we process special-category / sensitive data (such as health data), we do so only on the basis of your explicit consent, captured through the in-app permission prompts, toggles, or consent screens, or another lawful basis described in Section 4. You may withdraw consent at any time (Section 9); withdrawal does not affect processing already carried out, and some features will become unavailable without the underlying data.  

2. Information we collect

2.1 Information you provide directly

  • Account data: your email address, used for our passwordless email-code sign-in, and the verification codes themselves.
  • Onboarding & profile data: age or date of birth, biological sex, height and weight, wellness goals and preferences, and — only if you choose the women's-health path — cycle status and related inputs you enter.
  • Logged content: mood check-ins, hydration and meal logs, meal photos you upload for food recognition, photos of blood-test or lab reports you choose to upload and the values read from them, and the messages you send to Ava, our in-app AI assistant.
  • Support communications: the contents of emails or in-app messages you send us.

2.2 Health and wellness information (sensitive data)

Aurora is designed around health and wellness data, which is sensitive personal data. Depending on the features you enable, this includes: sleep duration and stages, heart-rate variability (HRV), resting heart rate, steps and activity, recovery and strain metrics, body measurements, mood, nutrition/hydration, blood-test values you upload, and — if you enable it — menstrual-flow and estimated-cycle information. We process this data only to deliver the features you request, and only with your explicit consent.

2.3 Information from your device and connected sources (only with your permission)

  • Apple HealthKit: with your permission, we read sleep, HRV, resting heart rate, steps, and — if you enable it — menstrual-flow data. We read this data to calibrate your Brief and score; we do not write data back to Apple Health.
  • Connected wearables (e.g. WHOOP, Oura): if you connect a wearable through OAuth, we read recovery, sleep, readiness, HRV, SpO₂, cycle, workout, and body-measurement metrics from that provider, on a read-only basis, to power your daily wellness readout.
  • Calendar (optional): if you connect it, we read event/meeting-load signals to shape the timing and content of your Brief.
  • Device & technical data: push-notification token, time zone, locale, device model and OS version, app version, and a transient IP address used only to deliver responses. We do not store your IP address for profiling. Your device's advertising identifier (IDFA) is read only if you allow tracking in the iOS prompt. Other device data — the identifier for vendor (IDFV), device model, OS and app version, and your IP address — reaches the advertising partners in Section 6.2 whenever their SDKs send anything; the TikTok SDK sends nothing at all unless you allow tracking, while Meta's still reports without an advertising identifier.

2.4 Purchase and subscription information

Subscriptions are sold through Apple In-App Purchase. We receive your subscription status and transaction identifiers from Apple and our subscription-management provider (RevenueCat). We never receive or store your payment-card number.

2.5 Usage, product-analytics, and advertising-measurement data

We collect limited product-analytics events (for example, which screens you view and which features you use) to understand and improve the Service. Our analytics provider also records session replays — a reconstruction of how the app looked and what you tapped during a session — so that we can see where the app confuses people. Chat content, names, email codes, support messages and the screens that show your own health numbers — your readouts and anything read from a lab report — are masked in those recordings. We advertise Aurora on TikTok and on Meta's platforms (Facebook and Instagram), and we use their measurement tools solely to learn which of our ads bring people to Aurora — for example, that an app install, an account registration, or the start of a free trial followed one of our ads. Section 6.2 sets out exactly what each partner receives, when, and how to stop it. We never share your health data, cycle information, Apple Health data, Ava conversations, or meal photos with an advertising partner. When Aurora asks, iOS shows you the App Tracking Transparency prompt. If you choose Ask App Not to Track, the TikTok SDK does not run at all and your advertising identifier (IDFA) is not used anywhere; Meta's SDK, the registration event our server sends, and our subscription provider's reporting still run, without your IDFA — though the device-level identifier for vendor (IDFV) still reaches them (Sections 6.1 and 6.2). You can change that choice at any time in iOS Settings → Privacy & Security → Tracking. In the app, the Do Not Sell My Data switch (Profile → Settings → About & Support → Privacy controls) stops the TikTok SDK immediately and stops the Meta reporting we control — the registration event our server sends, the app's Meta events, and the identifiers we hand our subscription provider. Aurora works exactly the same either way.

2.6 Aggregated and de-identified data

We may create aggregated or de-identified data that cannot reasonably be linked back to you. Such data is not treated as personal data under applicable privacy laws, and we may use it for research, analytics, and product improvement.  

3. How we use your information

We use your information to:
  • generate your daily Brief, your wellness score (AvaScore), recommendations, and — for women's-health users — estimated cycle context (always "estimated", never a diagnosis or prediction);
  • operate Ava, our AI assistant, and personalise the experience to your data;
  • recognise foods from the meal photos you upload, for your food log;
  • read the values from any blood-test or lab report you upload, so they can be shown back to you and used in your wellness readout;
  • send the notifications you have enabled (daily brief, reminders);
  • create and manage your account and subscription, and provide customer support;
  • maintain security, prevent fraud and abuse, debug, and ensure the Service works;
  • improve the Service using aggregated / de-identified data;
  • measure how well our own advertising works — which ads lead to installs, registrations, and free trials, as described in Section 6.2; and
  • comply with legal obligations and enforce our Terms.
We do not sell your personal data, we do not use your health data for advertising, and we do not process your sensitive data for targeted advertising or profiling that produces legal or similarly significant effects. The limited device and app-event data we disclose to our advertising partners for measurement (Section 6.2) may count as "sharing" or as "targeted advertising" under some U.S. state privacy laws; Section 9.3 explains how to opt out, and the Do Not Sell My Data switch in the app is the fastest way to do it.  

4. Legal bases for processing (EU/EEA, Denmark, and where applicable)

Where data-protection law (such as the GDPR) requires a legal basis, we rely on:
  • Consent — for health/sensitive data and for connecting HealthKit, wearables, or your calendar. You may withdraw it at any time.
  • Consent (advertising measurement) — for measurement that uses your device's advertising identifier, which you give or refuse in the iOS App Tracking Transparency prompt and can change at any time.
  • Performance of a contract — to provide the Service you sign up for (account, Brief, subscription).
  • Legitimate interests — to secure the Service, prevent fraud, improve the product using de-identified data, and understand which of our own advertising brought new accounts, balanced against your rights.
  • Legal obligation — to comply with tax, accounting, and other legal requirements.   

5. AI features (Ava)

Ava is powered by third-party large-language-model and text-to-speech providers (see Section 6.1). Your conversations and the relevant context are processed to generate responses. Under our agreements with these providers, your content is not used to train their public/foundation models. Ava is informational only and is not a crisis line or a mental-health service. If you are in crisis, call or text 988 (the U.S. Suicide & Crisis Lifeline) or your local emergency number; in an emergency call 911 (U.S.) or your local emergency services.  

6. How we share your information

We share the minimum data necessary, and only as described here.

6.1 Service providers (subprocessors)

We use vendors who process data on our behalf under contract and only on our instructions:
Vendor Purpose Data involved
Anthropic, OpenAI AI assistant, recommendation generation, and reading the values from lab-report images Ava messages + relevant context; lab-report images after on-device redaction
OpenAI, ElevenLabs Text-to-speech for the voice Brief Brief text
OpenWeather Local weather context for recommendations Coarse location/locale
Apple HealthKit, In-App Purchase, push notifications Health permissions, purchase, push token
WHOOP, Inc. Wearable data via OAuth (WHOOP strap), only if you connect it Sleep, HRV, recovery, strain, workouts, body measurements
Oura Health Oy Wearable data via OAuth (Oura Ring) Sleep, HRV, readiness, SpO₂, heart rate
RevenueCat Subscription management, and matching subscription events to our advertising (Section 6.2) Subscription status, transaction IDs, an advertising identifier (IDFA where you allowed tracking, otherwise IDFV) and the Meta anonymous ID the app holds
Amazon Web Services (SES) Transactional email Email address
DigitalOcean Cloud hosting / infrastructure Application data at rest/in transit
Sentry Crash & error diagnostics Diagnostics with PII and request bodies stripped
PostHog Product analytics and session replay Usage events (no health-data payloads) and session recordings, with chat, names, codes and your health numbers masked
Blood-test and lab-report photos. Before the image leaves your phone, Aurora paints out the identity block — name, date of birth, record number, address and ordering physician — and shows you the masked image first; a PDF is turned into pixels first, so no text layer survives underneath. The masked image then goes to Mark Wealth's lab-recognition service, which uses a third-party vision-AI provider (Anthropic) to read the values printed on the page. We do not send these images to an advertising partner, and they are never used for advertising or marketing.

6.2 Advertising partners (TikTok and Meta)

TikTok and Meta receive the data below so that we can measure our own advertising campaigns. Unlike the service providers in Section 6.1, they are not acting only on our instructions: they may also use this data for their own purposes under their own privacy policies (TikTok; Meta). We never send them your health data, cycle information, Apple Health data, Ava conversations, meal photos, or anything else you type or log in the app. TikTok (TikTok Business SDK, inside the app)
  • When it runs: only if all of the following are true — you allowed tracking in the iOS prompt, you have not switched on Do Not Sell My Data, we have enabled TikTok measurement, this is the App Store build of Aurora, and the app is open in front of you. Leaving the app pauses it, and returning resumes it. Switching on Do Not Sell My Data, withdrawing the tracking permission, or our turning TikTok measurement off stops it for good on that device and deletes anything it had queued.
  • What it sends: your device's advertising identifier (IDFA) and identifier for vendor (IDFV); an identifier the SDK creates for this installation and one for each app session; your IP address; device model, iOS version, language and country setting, screen resolution, user agent, your answer to the tracking prompt, and the app's name, version, and build; and these events with the time they happened — app installed (once, the first time the SDK runs), account created ("Registration"), and free trial started ("StartTrial"). The trial event carries the event name only: no price, no currency, no transaction number.
  • Each time you open the app the SDK also requests its settings from TikTok and sends the same device information with that request, even when there is no event to report. TikTok can therefore see when the app is opened on your device.
  • Events waiting to be sent are held in a file on your device and may be sent in a later session. Switching on Do Not Sell My Data, or withdrawing the tracking permission, deletes them.
  • What it never sends: your name, your email address, or your Aurora account ID. Before including this SDK we removed its screenshot capture, crash reporting, automatic purchase tracking, and diagnostic uploads.
Aurora also takes part in Apple's SKAdNetwork. There, Apple — not Aurora — sends the ad network an aggregated install report that contains no identifier for you and that we cannot tie to your account. Meta (Facebook and Instagram)
  • Meta SDK, inside the app: records app installs and app opens, in-app purchase events, and when you reach the subscription screen, together with device information (such as device model, iOS version, and app version) and your IP address. It uses your advertising identifier (IDFA) only if you allowed tracking in the iOS prompt.
  • From our servers: when you create an account, our server tells Meta that a registration took place. It includes a one-way (SHA-256) hash of your email address and of your Aurora account ID so that Meta can match the event to its own records, the time of the event, that you registered with an email code, your app version and build, and whether you allowed tracking. This event is sent whether or not you allowed tracking, and it never contains an advertising identifier — your tracking choice travels only as a yes/no flag.
  • What the in-app switch reaches: Do Not Sell My Data stops the TikTok SDK on your device immediately, stops the app's Meta events and the identifiers we pass to our subscription provider, and tells our server not to send the registration event above. Our subscription provider still records the subscription itself, which it needs in order to bill you; without those identifiers it cannot match it to an advertising profile.
  • From our subscription provider: RevenueCat reports free-trial and subscription events to Meta on our behalf.

6.3 Apple Health data

Data obtained through Apple HealthKit is handled in accordance with Apple's requirements: it is never used for advertising or marketing, and is never sold or shared with third parties for their own purposes.

6.4 Legal and safety disclosures

We may disclose information where we believe in good faith it is necessary to comply with law, regulation, legal process, or a governmental request; to enforce our Terms; or to protect the rights, property, or safety of our users, the public, or Mark Wealth.

6.5 Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will provide notice (in-app or by email) before your data becomes subject to a materially different privacy policy.

6.6 What we do NOT do

We do not use Stripe or process card payments ourselves; we do not operate a supplement marketplace, drop-shipping, or product fulfilment; and we do not sell your personal data. Our only advertising-related use of your data is the measurement described in Section 6.2 — and we never use or share your health or other sensitive data, including the values from any lab report you upload, for advertising.  

7. Cookies and similar technologies

Aurora is primarily a native iOS application and does not rely on advertising cookies or cross-site trackers. Our analytics and diagnostics providers (Section 6.1) use device identifiers and similar technologies solely to operate and improve the Service. The TikTok and Meta SDKs described in Section 6.2 use device identifiers — including, where you allowed tracking, your advertising identifier — to measure our advertising. Any related website uses only the cookies necessary for its operation.  

8. Data storage, security, and retention

Consistent with the HIPAA/HITECH-aligned safeguards noted above, we encrypt data in transit (TLS) and encrypt sensitive fields at rest, restrict internal access on a need-to-know basis, and apply operational controls to protect against unauthorised access, loss, or misuse. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard measures. We retain your personal data only for as long as reasonably necessary for the purposes in this Policy: while your account is active, and for any additional period required to meet legal, tax, accounting, or anti-fraud obligations or to resolve disputes. When you delete your account (Section 9), we delete or de-identify your personal data, except for a limited subset of records we are legally required to retain for a defined period before final deletion.  

9. Your privacy rights and choices

9.1 Rights available to you

Subject to applicable law, you can: access a copy of your data; correct inaccurate data; delete your account and data; obtain your data in a portable format; restrict or object to certain processing; withdraw consent; disconnect HealthKit, wearables, or your calendar; and lodge a complaint with a supervisory authority.

9.2 How to exercise your rights

Many controls are in the app: Profile → Settings → Account → Privacy & Data to connect, pause, or disconnect sources and to delete your account, and Profile → Settings → About & Support → Privacy controls for the Do Not Sell My Data switch, which stops the TikTok measurement described in Section 6.2. You can also stop Aurora from tracking you at any time in iOS Settings → Privacy & Security → Tracking. For other requests, email support@markwealth.me. We may need to verify your identity before acting, and we will respond within the timeframe the applicable law requires. You will not be discriminated against for exercising your rights.

9.3 United States — state privacy rights

Residents of states with comprehensive privacy laws have additional rights:
  • California (CCPA/CPRA): the right to know/access, delete, correct, and opt out of the "sale" or "sharing" of personal information and of targeted advertising; the right to limit use of sensitive personal information; and the right to non-discrimination. We do not sell your personal information. We do disclose the limited device and app-event data described in Section 6.2 to TikTok and Meta so that we can measure our own advertising, which may be "sharing" for cross-context behavioural advertising. We never share your health or other sensitive data for advertising. California "Shine the Light" and minors' provisions apply as written by law.
  • Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA): the rights to confirm processing, access, correct (where provided), delete, obtain a portable copy, and opt out of targeted advertising, "sale", and certain profiling. Colorado and certain states require prior consent before processing sensitive data, which we obtain via the in-app prompts. Where offered, you may appeal a decision on your request by replying to our response.
  • Nevada: you may opt out of the sale of certain covered information; we do not sell it.
  • Consumer health data (including Washington and Nevada): we do not sell consumer health data, and we do not share health data, cycle information, Apple Health data, or lab-report values with advertising partners. What we do share for advertising measurement is listed in Section 6.2.
How to opt out of the advertising measurement in Section 6.2. Each route does something different, so here is exactly what each one stops:
  • Do Not Sell My Data in the app (Profile → Settings → About & Support → Privacy controls) — stops the TikTok SDK on this device at once and deletes anything it had queued, stops the app's Meta events, and stops the registration event our server sends to Meta. It is saved to your account, so it applies on every device you sign in on.
  • iOS Settings → Privacy & Security → Tracking — stops all use of your advertising identifier, and stops the TikTok SDK entirely.
  • Email support@markwealth.me — for anything the two controls above do not cover, or to have us confirm in writing what is set for your account.

9.4 EU/EEA and Denmark (GDPR)

You are a data subject with the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent and to lodge a complaint with your supervisory authority (in Denmark, Datatilsynet). Our legal bases are set out in Section 4.

9.5 Ukraine

Residents of Ukraine have the rights provided under Ukraine's personal-data-protection law, including access, correction, and deletion.

9.6 Non-discrimination

We will not deny you the Service, charge different prices, or provide a different quality of service because you exercised your privacy rights, except where the difference is reasonably related to the value of the data, as permitted by law.  

10. International data transfers

We operate from and host data in the United States. If you use the Service from Denmark, Ukraine, or elsewhere, your data will be transferred to and processed in the United States and other countries where our service providers operate, which may have different data-protection laws. We take steps to ensure appropriate safeguards for such transfers as required by applicable law.  

11. Children's privacy

The Service is intended for users aged 13 and older and is not directed to children under 13. Consistent with COPPA, we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, contact support@markwealth.me and we will delete it.  

12. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, notify you in the app. Your continued use of the Service after an update means you accept the revised Policy.  

13. Contact

Questions, requests, or complaints: support@markwealth.me, Mark Wealth C Corp., 254 Chapman Rd, Ste 209, Newark, DE 19702, United States.
Mark Wealth - wellness assistant
  • Terms of Use
  • Privacy Policy
  • Certificates

© Copyright 2022 - 2026 Mark. All rights reserved.