Privacy Policy
Last updated: September 10, 2026
AuraHome (“we”, “us”) is an app that turns a photo of your room into an interior design. This policy explains which personal data we process, why, who we share it with, and how you can exercise your rights. It reflects our obligations under the EU General Data Protection Regulation (GDPR) and Turkey’s Personal Data Protection Law (KVKK, Law No. 6698).
1. Data Controller
The data controller for the AuraHome app and the aurahomeai.shop website is Miroğlu Bilişim Limited Şirketi. Contact: support@aurahomeai.shop
2. Data We Process
- Account data: email address, password hash (accounts created with a password), name, username, profile preferences. Accounts can be created with email and password or with Sign in with Apple / Google Sign-In; from the provider we receive only your name and email address (Apple’s Hide My Email relay address counts as a valid address) and nothing else. We never collect a phone number.
- Room photos and designs (private by default): the photos you upload and the designs generated from them are private to your account by default — processed only to generate, store and show you your design, and never used for advertising or to train models. Nothing is published on its own: a design reaches the community only if you choose to share it. The room photo you upload is never published — what gets shared is the design generated from it.
- Your community posts (what you publish): for a product post you choose to share, the product photo, title, note, tags, purchase link, price and currency, plus the store name derived from the link; for a room design post you choose to share, the design image, title, note and tags. This content is a publication — who can see it is described in the notice below.
- Your community interactions: likes, saves and collections, follow relationships, reports you file, users you block, and the notifications you receive.
- Moderation and report records: the moderation decision made on each submission (approved or rejected and its machine-readable reason), the reviewed image, title and link; reports about you or filed by you and their outcome; the record of a post being hidden.
- Product-click measurement: the fact that a product’s store link was tapped — counted to understand which products draw interest.
- Usage data: generation history, room-allowance usage; for service quality and debugging, device type, operating system, app version and error logs. If you allow notifications, your device push token.
- Taste profile: your answers to the Aura quiz (used to personalize suggestions).
- Purchase data: subscriptions are bought through the Apple App Store and Google Play. We receive only an anonymized transaction ID, product ID and verification signature; your card details never reach us.
What you share in the community is a publication. A post you choose to share — for a product post your product photo, title, note, tags, purchase link and price; for a design post the image of the design you generated — appears alongside your username and profile picture and can be copied. If your profile is public, the post is visible to everyone in the app and can appear in discover; if your profile is private, only your followers see it and it never enters discover. Switching a private profile to public makes those posts public too. A design you share is derived from the photo of your own room, so the frame shows your home: this is a publication you choose to make, and before you share it make sure it holds nothing that identifies you or your home (recognizable people, an address, a door number, a document). The room photo you uploaded is never published. You can remove a post at any time — a removed post disappears from every list, but we have no control over copies other people took beforehand. What may be shared is set out on the Community Rules page.
3. Purposes and Legal Basis
We process your data under KVKK Article 5 and GDPR Article 6 on the following bases:
- Performance of a contract: creating and managing your account, generating designs, matching products, verifying room allowances and subscriptions.
- Legitimate interest: preventing abuse, keeping the community safe (moderating posts before publication, reviewing reports, keeping block records, identifying violating accounts), fixing errors, improving service quality, and measuring which products draw interest.
- Legal obligation: keeping financial records for the statutory period, answering lawful requests from authorities.
We do not send marketing notifications and we do not process your data for advertising.
4. Who We Share Data With
To deliver the service, data is shared with the following categories of recipients, only as needed:
- AI infrastructure provider: your room photo is transmitted for design generation, and a product post’s image and link for pre-publication moderation, only for the duration of that operation; the provider does not retain the data and does not use it for its own purposes.
- Cloud storage provider: access-controlled storage of your photos and designs, linked to your account.
- Apple App Store and Google Play: subscription and payment verification.
- Email and error-reporting providers: delivery of verification codes and transactional emails, crash/error reports (personal fields are masked).
Separately from these recipients, a post you share in the community is open to every user of the app when your profile is public, and to your followers when your profile is private. That is not a transfer by us but a publication you initiate. The room photo you uploaded is never included in it under any circumstances; a design you choose to share is part of the publication.
These providers process data only on our behalf under written agreements. Your data is never sold to data brokers or advertising networks. Some providers operate servers abroad; such transfers rely on safeguards compliant with KVKK Article 9 and GDPR Chapter V (standard contractual clauses or equivalent measures).
5. Retention and Deletion
You can delete your account at any time from inside the app (Settings → Delete my account). On deletion your personal fields (email, name, username, bio, password hash) are permanently removed and all your sessions are signed out. Details on the account deletion page.
Retention periods:
- Account data: while the account exists; anonymized immediately on a deletion request.
- Room photos and designs: until you delete them; removed from storage within 30 days of account deletion.
- Community posts: until you remove them. When you delete your account your posts stop appearing anywhere in the app (feed, search, profiles, collection covers) and their images are removed from storage within 30 days along with the rest of your media.
- Likes, saves, collections and follows: removed together with your account.
- Moderation decisions, reports and block records: kept after account deletion, in a form that cannot be linked back to the deleted account, to prevent abuse and to answer app-store audits. Without them we could not stop a blocked or terminated account from deleting itself, signing up again and repeating the same violation; this is a necessary safety measure based on our legitimate interest. Report records are kept detached from the reporter’s identity.
- Financial records (subscriptions, purchases, room-allowance movements): for the statutory period, with personal identifiers masked.
- Error logs: purged automatically after 90 days.
6. Your Rights
Under GDPR Articles 15–22 and KVKK Article 11 you have the right to:
- Learn whether we process your data and request access to it
- Have incomplete or inaccurate data corrected
- Have your data erased
- Object to processing or request that it be restricted
- Receive your data in a portable format
- Have corrections and erasures communicated to third parties we shared data with
Send requests to support@aurahomeai.shop; we respond within 30 days. If you are not satisfied, you can lodge a complaint with the Turkish Personal Data Protection Authority or the supervisory authority in your country.
7. Security
Data is encrypted in transit (TLS) and protected with access controls at rest; passwords are hashed irreversibly (argon2). Session keys are kept in your device’s operating-system secure storage.
8. Children
AuraHome is not directed at children under 13. If you believe we have processed a child’s data, write to support@aurahomeai.shop and we will delete it promptly.
9. Cookies
Our website uses no marketing or analytics cookies; only the technical data needed to serve the pages is processed.
10. Changes
We may update this policy from time to time. Material changes are announced in the app; the current date is shown at the top of this page.
11. Contact
Email: support@aurahomeai.shop
Company: Miroğlu Bilişim Limited Şirketi