Privacy Policy
Last updated: 12 July 2026.
At Aurio we take your privacy seriously. We process the least personal information possible and apply data minimisation and data protection by design. This policy explains what data we process, for what purpose and what rights you have, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Data controller
- Data controller: Jesús Badía Closa
- NIF: 39390530V
- Registered address: Ronda de Ponent, 2, 1.º B — 08201 Sabadell (Barcelona), Spain
- Privacy contact: privacidad@aurioapp.com
We are not required to appoint a Data Protection Officer; you may address any query about your data to the address above.
2. Who is responsible for which data
For the operation of the service (your account, your analyses, your calculations) Aurio acts as the data controller. That said:
- You decide what data goes in. It is you who chooses to import a file or upload a document and, when bank connectivity becomes available, whether to enable it to connect a bank. You are responsible for the accuracy of that data.
- Third-party data that you provide. If you upload invoices or receipts containing data of suppliers, customers or counterparties, it is you who determines that processing: with respect to that data you act as the controller and Aurio merely as a data processor handling it on your behalf. You must have a legitimate basis to provide it.
- Your decisions are yours. Aurio is informative; financial or tax decisions and any formality before the Administration are your responsibility.
In any case you are in charge of your data: you can export and delete it whenever you want (section 8).
3. What data we process
- Account data: name, email and credentials (the password is stored hashed; the 2FA secret is stored encrypted).
- Financial data: transactions, categories, accounts and net worth. They are kept encrypted and with minimisation: of the IBAN, only the last 4 digits plus a token; merchants, counterparties and tax IDs (NIF) are tokenised; the raw bank description is ephemeral.
- Tax data: tax bases, VAT and amounts for the calculations (VAT, estimated personal income tax, depreciation). They are informative estimates.
- Documents (OCR, optional premium feature): when you upload an invoice or receipt the data is extracted; the tax ID (NIF) and the supplier are tokenised and the image is discarded by default (it is only kept, encrypted, if you so decide).
- Google Drive folders (automatic sync, optional): if you enable this feature, you share one specific Drive folder, read-only, with an Aurio service account. We only access that folder you share (never the rest of your Drive) to import documents into OCR, with the same guarantees as above. You can revoke access at any time by unsharing the folder or turning the sync off. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements (we do not use this data to train generalised AI models).
- Payment and subscription data: on the web, Stripe processes the payment. On iOS, Apple processes the purchase and RevenueCat manages pseudonymous identifiers for subscription status and Premium access. We do not store your card or payment method details.
- Minimal technical and usage data: only what is essential for security, diagnostics and improving the service. Product analytics uses a pseudonymous internal workspace identifier and usage events with a closed set of properties; it never includes amounts, balances, merchants, descriptions, document content or AI question content.
4. Protection by design
Aurio is built so that not even we can normally read your sensitive data in the clear: encryption at rest of sensitive information, tokenisation of identifiers (merchants, counterparties, NIF, IBAN), strict per-user isolation and minimisation of identifying information. It is the best guarantee of your privacy and reduces the scope of any incident.
5. Purposes and legal basis
- Providing the service and managing your account — performance of the contract.
- Read-only PSD2 bank aggregation, when it becomes available and you choose to enable it — explicit and revocable consent.
- Analysis, insights and tax calculations on your data — performance of the contract and legitimate interest in offering you a useful service.
- Processing of the documents you upload to OCR — consent (an optional feature that you activate).
- Security, fraud prevention and compliance with legal obligations — legal obligation and legitimate interest.
- Pseudonymous usage analytics and technical diagnostics — legitimate interest in improving the security, reliability and usefulness of the service, using minimised data without financial content.
- Optional communications (for example, a periodic summary) — consent, revocable at any time.
6. Artificial intelligence
The AI features operate on aggregated and tokenised data: as a general rule personal information in the clear is never sent to the AI provider. Processing is carried out through model providers —currently Google (Gemini models)— acting as processors; in production, processing in the European Union (Vertex AI) is prioritised and your data is not used to train their models.
The only exception: in document OCR, the image you upload necessarily contains its data (supplier, NIF, amounts), because reading it is precisely the objective. That processing is carried out on an ephemeral basis, the identifiers are tokenised before anything is stored and the image is discarded by default. The AI features do not make decisions with legal effects on you: they are indicative and always reviewable by you.
7. Recipients and data processors
We rely on a small number of providers. Depending on the service and their role, they act as processors or process data under their own terms, with the applicable safeguards and, where appropriate, Standard Contractual Clauses. We prioritise providers that process data in the EU:
- Web hosting and aggregate traffic analytics: Vercel (without analytics cookies).
- Database (encrypted, in the EU): Neon.
- Queues and rate limiting: Upstash.
- Payments and subscriptions: Stripe (web); Apple and RevenueCat (iOS purchases and Premium access management). We do not store payment method details.
- Transactional email: Resend.
- PSD2 bank aggregation (when it becomes available and you choose to enable it): Tink (authorised provider), read-only.
- Artificial intelligence: Google (Gemini models / Vertex AI).
- Product analytics: PostHog Cloud EU, when enabled after completing the governance controls (pseudonymous events, no personal profile and no financial content).
- Error diagnostics: Sentry (technical information needed to detect failures).
We do not sell your data or transfer it to third parties for advertising purposes.
8. Your rights
You can exercise the rights of access, rectification, erasure, objection, restriction of processing, portability and to withdraw your consent at any time. From Settings you can, immediately and on your own, export all your data and delete your account. You can also write to us at privacidad@aurioapp.com. Product analytics events do not create a personal profile; deleting your account removes the internal link that allowed them to be associated with your workspace. You can also request any additional erasure at the same address. If you consider that we have not handled your request, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) (aepd.es).
9. Retention
We keep your data for as long as you have an active account. After cancellation, we delete it without undue delay, except for data we must retain due to a legal obligation (for example, billing and payment records, in accordance with tax and commercial regulations, usually between 4 and 6 years) or data that is blocked to address possible liabilities during the applicable limitation period. The audit log is kept without personal data in the clear. When product analytics is enabled, its events are limited to a maximum retention period of 12 months.
10. International transfers
We prioritise providers that process data in the EU. Where a provider entails a transfer outside the European Economic Area, it is covered by an adequacy decision or by European Commission Standard Contractual Clauses, together with any additional measures that may apply.
11. Minors
Aurio is not directed at minors. To create an account you must be over 18 years old.
12. Security
We apply encryption at rest of sensitive information, tokenisation of identifiers, per-user isolation, strengthened authentication (two-factor verification) and audit logging. No system is infallible, but we design Aurio to minimise both the data we process and the impact of any incident.
13. Changes
We may update this policy; we will publish the current version with its date and, when the change is significant, we will notify you.