Privacy Policy
Last updated: 2 September 2026
Who We Are
aurate is a trading name of AURATE AI LTD, a company registered in England and Wales (Company No. 17131159), with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Throughout this policy, "aurate", "we" and "us" refer to AURATE AI LTD.
We are the data controller for your personal data.
Contact for data protection queries: hello@aurateai.com
ICO Registration: ZC109790
Privacy-First Design
aurate is designed to keep your personal data tight to what's actually needed to run the service. We don't record audio. We don't sell your data. We don't use your sessions to train AI models. What we do keep is described below — and you can delete almost all of it by deleting your account.
What we retain:
- Account data: your email and encrypted password.
- Payment data: managed entirely by our payment processor. We never see or store your card details.
- Session telemetry: scores, session duration, persona choice, interaction counts. No transcript content.
- Your marked card content: the report shown on your marked card and
/cardpage — your overall score, feedback bullets, metric evidence, phase summaries, Biggest Gap, Silver Lining, and Next Step. This is text generated by our scoring engine that quotes and paraphrases what you said in the session. - Module summaries: the "strongest response" and "weakest response" the scoring engine extracts from each phase of your session. Also paraphrases of what you said.
- Action plan: the action plan you talk through near the end of the session, extracted by the scoring engine.
- Session transcript: we retain the text transcript of your session to generate and verify your performance feedback and to resolve disputes. Transcripts are tied to your account and are deleted when you delete it, or after 18 months, whichever comes first.
- CV text and CV summary: when you start a session, we store your CV text and a short summary of it on the session record so the AI can stay coherent across reconnects and grade you accurately. Tied to your account and deleted when you delete it.
- Marked CV review: when you buy a marked review in the CV Studio, we store the CV text and the job ad you gave us, and the marked review we produced, so you can come back to it. Tied to your account and deleted when you delete it, or after 18 months, whichever comes first.
- Application drafts: when you use the Application Studio on a paid plan, we store the question you pasted, the answer you wrote, the job advert if you provided one, and the marking we returned — so you can come back to a draft and see how it changed. Tied to your account and deleted when you delete it, or after 18 months from your last edit, whichever comes first. If you are not on a paid plan, nothing you paste into the studio is stored at all — it is marked and discarded.
- Pitch cases: before confirmation, a Pitch Room draft stays in that browser tab. When you confirm it, we store the structured case, typed or pasted notes, evidence and source labels, audience context, exact decision, Decision Case, and each later accepted version so you can rehearse and compare changes. A bounded refinement conversation is not stored; only changes you explicitly accept are kept. Pitch is currently deferred. Existing cases and accepted versions remain stored privately; account deletion still removes them. Individual case controls will return when Pitch is available.
- Pitch Room briefs: when you set up a Pitch Room rehearsal, we store the brief you enter — the presentation task, the time limit and the panel type — so you can rehearse it and come back to it. If you add slides, they are read in your browser and their text is sent to our AI provider once to write a short summary for the panel; we store only that summary, never the slides or their full text. You can delete a brief at any time; it is deleted when you delete your account, or 18 months after you last used it, whichever comes first.
- Pitch case-survival cards: after a Pitch Room rehearsal, we store the private, numberless marked card, its short transcript references, and the internal claim and concern evidence used to prepare it. It assesses this rehearsal only and does not predict approval.
- Direction state: when you use Career Map or a 30-60-90 Plan, we store the structured Direction state and the changes you accept so you can return to them. Structured drafts and unapplied proposals are short-lived; see Sections 3.6 and 6.
- Saved 30-60-90 plans and presentation decodes: the free 30-60-90 Plan and Presentation Decoder tools do not store what you paste (a job ad, your CV or a presentation brief). If you are signed in and choose to save a result, we store that result — the plan or decode we produced, which may reflect the CV you pasted — so you can return to it. Tied to your account; you can delete it at any time, and it is deleted when you delete your account, or after 18 months, whichever comes first.
What we never retain:
- Audio recordings of your sessions. Your voice is transcribed in real time by our AI provider so the interviewer can respond. The audio stream goes directly from your browser to that provider via an ephemeral token. It never passes through our servers and is never stored anywhere we control.
- CV text submitted for a free CV read. If you use the CV Studio's free read without an account, the CV text and the job ad you paste are used to write the read you see and are then discarded. We write nothing to a database, a log, or our analytics, and nothing is tied to you — there is no account, and therefore nothing to delete afterwards. If you upload a file, the file itself is opened in your browser and never sent to us; only the text is.
- Raw Direction conversation transcripts, audio, model reasoning or full prompts. Direction stores structured accepted state and bounded proposals, not a raw conversation history.
Clearing or replacing your inputs:
- You can clear or replace your CV, the job description, and your other inputs on the context page at any time. Clearing an input resets the form so you can build a new interview plan from the edited inputs — it does not erase data we have already stored. A plan you previously generated stays on your account until you delete it. To remove stored data, delete your account (which erases it) or email us to ask us to delete it.
Progression tracking and benchmarking
At the end of each session we store your performance scores alongside a one-way hash of your account identifier. Because that hash is derived from your account, it stays linked to you — so this is pseudonymised data, and we treat it as personal data. It is not anonymised. We use it to give you progression insight across sessions and to maintain aggregate performance benchmarks. It never includes your name, email, or IP address. See Section 3.3 for the detail, and Section 6 for how long we keep it — including that, because these rows carry no name, email, or IP, they are not removed when you delete your account.
What Data We Collect
3.1 Data You Provide
| Data | When Collected | Purpose |
|---|---|---|
| Email address | Account creation | Authentication, account management, transactional communications |
| CV text | Session configuration (uploaded, extracted in-browser, or pasted) | Personalising the interview and grading your performance. See Sections 3.2 and 6 for storage and retention. |
| Session configuration choices | Session setup | Calibrating the AI interviewer (role level, industry, persona) |
| Payment information | Checkout | Processing payments. We do not store card details — handled entirely by our payment processor. |
| CV text and job ad (free CV read) | The CV Studio, without an account (pasted, or extracted from a file in your browser) | Producing the read shown on screen. Not stored — used for the request and discarded. See Sections 4 and 6. |
| CV text and job ad (marked CV review) | The CV Studio, on a paid plan | Producing your marked review and storing it with the review so you can return to it. See Sections 2 and 6 for storage and retention. |
| Application question, answer and job advert | Typed or pasted by you in the Application Studio | Marking your draft and, on a paid plan, showing what changed between versions. See Sections 2 and 6 for storage and retention. |
| Pitch case, notes, evidence/source labels, audience context and requested decision | Typed or pasted by you in Pitch Room; stored only when you confirm the Decision Case | Building a grounded Decision Case, rehearsing one internal approval decision, and preserving user-confirmed versions. See Sections 2 and 6. |
| Direction career and role context | Entered when you request a Career Map or 30-60-90 Plan, including your current role, goals, employer, start date, role expectations, constraints and evidence you select | Creating the Direction map or plan you request. See Sections 3.6 and 6. |
3.2 Data We Generate During Your Session
| Data | How Generated | Retention |
|---|---|---|
| Audio (voice) | Real-time conversation with the AI interviewer | Never stored. Streams directly from your browser to our AI provider via ephemeral token. Never passes through our servers. |
| Session transcript | Transcribed in real time during the session | Retained on our servers to generate and verify your performance feedback and to resolve disputes. Tied to your account; deleted when you delete it, or after 18 months, whichever comes first. |
| AI responses | Generated by our AI provider during the session | Stored as part of the session transcript (same row as above) — same retention and deletion behaviour. |
| overall score, marked card payload, and feedback bullets | Generated at session end by our results pipeline | Retained as the report shown on your marked card and /card page — includes your overall score, metric evidence, phase summaries, Biggest Gap, Silver Lining, Next Step, and feedback bullets. This is AI-generated text that quotes and paraphrases what you said. Tied to your account; deleted when you delete it. |
| Module summaries | Generated at phase transitions | Retained as the “strongest response” and “weakest response” the scoring engine extracts from each phase. These quote and paraphrase what you said. Tied to your account; deleted when you delete it. |
| Action plan | Extracted at the end of the session | Stored on your session record. Tied to your account; deleted when you delete it. |
| Heartbeat telemetry | Sent periodically during active sessions | Stored as a timestamp update used for crash detection and session recovery. No transcript content. |
| Marked CV review | Generated by our AI provider when you buy a marked review | Stored on your account with the CV text and job ad it was written from. Deleted when you delete your account, or after 18 months, whichever comes first. |
| Draft marking (Application Studio) | Generated by our AI provider when you ask for a mark | On a paid plan, stored with the draft it belongs to — same retention and deletion behaviour. On the free mark, not stored. |
| Pitch Decision Case and refinement proposals | Generated from the Pitch context you supplied | A confirmed Decision Case and accepted structured changes are stored with the Pitch case. The free-form refinement exchange is not retained. |
| Pitch Room marked card (brief-based) | Generated after a Pitch Room rehearsal from your brief, any slide summary and the rehearsal transcript | Stored privately with the Room result. It shows your timing, the panel's questions and short quotes of your answers; it has no score. Deleted with your account. |
| Pitch case-survival marked card | Generated after a Pitch rehearsal from the confirmed case and transcript evidence | Stored privately with the Room result. It may contain short transcript quotes and case references; deleted with your account. |
| Direction Career Map, 30-60-90 Plan and accepted changes | Generated from the bounded career, role and evidence context you choose to provide | Stored so you can review, accept and return to your Direction state. Structured drafts and unapplied proposals are deleted after 30 days; archived or closed artefacts after 18 months; active state remains while active. |
| Saved 30-60-90 plan or presentation decode | Generated by our AI provider when you use the free tool | Stored only if you are signed in and choose to save it. Deleted when you delete it or your account, or after 18 months, whichever comes first. |
3.3 Benchmarking and Progression Data (Pseudonymised)
At the end of each session we store performance metrics from your results: your overall score and sub-scores (logic, specificity, resilience, synthesis), filler-word frequency, persona, tier, role/sector category, session length, and a per-session counter that lets us see your trend over time. We store these alongside a cohort_id — a one-way SHA-256 hash of your account identifier. Because that hash is derived from your account, these rows stay linked to you: this is pseudonymised data and we treat it as personal data. It is not anonymised, and we do not claim it cannot be traced back to you.
We do not include your name, email address, IP address, or any transcript content in this data. Our lawful basis is legitimate interest (Article 6(1)(f)) — giving you progression insight across sessions and maintaining aggregate performance benchmarks. You can object to this processing at any time (see Section 7).
Because these rows carry only the hashed identifier and your performance numbers — no name, email, or IP — they are not removed when you delete your account. We keep them so our aggregate benchmarks and trend statistics stay intact. If you would like your existing benchmarking rows removed, contact us before deleting your account and we will delete them — after your account is gone we can no longer tell which rows are yours.
3.4 Data Collected Automatically
| Data | Purpose | Retention |
|---|---|---|
| IP address (session) | Dispute resolution, fraud prevention, session validation | Retained for 90 days, then automatically deleted. Lawful basis: legitimate interest. |
| IP address (account creation) | Sign-up fraud and abuse prevention | Logged for fraud and abuse prevention. Retained for 90 days, then automatically deleted (or earlier on request); not linked to your account. Lawful basis: legitimate interest. |
| Browser/device information | Session compatibility and debugging | Not stored persistently. Used transiently during session establishment. |
| Consent timestamps | Proving you consented to session terms | Stored on your account record; deleted when you delete your account. |
3.5 Website Analytics
We use Vercel Web Analytics to understand how visitors use aurate (for example, which pages are viewed and how visitors arrive). It is privacy-first and cookieless — it does not use cookies or other persistent identifiers, does not track you across other websites, and does not collect personally identifiable information. It records only aggregated, non-identifying data such as page views, referring sites, approximate country-level location, and device or browser type. Vercel Inc. acts as a processor for this purpose.
We also count a small number of aggregated product events — for example that a free session was started, an account was created, or a purchase was completed — so we can see where people get stuck. These events record that something happened, not who did it, and carry no personal data.
3.6 Direction
Direction. When you use Career Map or a 30-60-90 Plan, we send the career information you enter — such as your current role, goals, employer, start date, role expectations, constraints and selected evidence — to our AI providers to create the map or plan you request. If you explicitly select an eligible aurate CV Studio review or Interview Room result, Direction uses only the bounded findings shown to you, not the raw CV or Room transcript. OpenAI currently normalises 30-60-90 role context; Google currently generates the map or plan. We store the Direction state and changes you accept so you can return to them. Structured drafts and unapplied proposals are deleted after 30 days; archived or closed Direction artefacts are deleted after 18 months; active state remains while active. Deleting a Direction artefact removes its dependent Direction data, and deleting your account removes all Direction data. We do not store raw Direction conversation transcripts, audio, model reasoning or full prompts.
How We Use Your Data
| Purpose | Lawful Basis (UK GDPR) |
|---|---|
| Providing the interview simulation service | Performance of contract (Article 6(1)(b)) |
| Processing payments | Performance of contract (Article 6(1)(b)) |
| Generating your results and performance analysis | Performance of contract (Article 6(1)(b)) |
| Storing consent timestamps | Legal obligation (Article 6(1)(c)) |
| Retaining IP addresses for dispute resolution and fraud prevention | Legitimate interest (Article 6(1)(f)) |
| Storing pseudonymised benchmarking and progression data | Legitimate interest (Article 6(1)(f)) — see Section 3.3 |
| Crash detection and session recovery | Legitimate interest (Article 6(1)(f)) |
| Website analytics — understanding how visitors use the site | Legitimate interest (Article 6(1)(f)) |
| Sending transactional emails | Performance of contract (Article 6(1)(b)) |
| Producing a free CV read for a visitor without an account | Legitimate interest (Article 6(1)(f)) — you asked for the read, you receive it immediately, and we retain none of it |
| Marking a single application answer on a free account | Performance of contract (Article 6(1)(b)) — the free mark is part of the service your account entitles you to, and you asked for it |
| Producing and storing your marked CV review | Performance of contract (Article 6(1)(b)) |
| Creating and storing the Direction maps and plans you request | Performance of contract (Article 6(1)(b)) |
We do not use your data for marketing purposes unless you explicitly opt in. We do not sell your data to third parties. We do not use your session content (audio, transcripts) for AI model training.
A note on voice data
Your voice is processed by our AI provider during your session for real-time transcription so the interviewer can respond. We've architected the audio path so that audio never transits our servers — it goes directly from your browser to the provider via an ephemeral token, and we never store any audio recording or voiceprint. We retain only the resulting text transcript and the scores derived from it.
We use your interview audio only to transcribe your answers and generate your feedback — never to recognise or identify you by your voice. For that reason we treat this as ordinary personal data under UK GDPR, not as special category 'biometric' data under Article 9.
Who We Share Your Data With
We share personal data only with service providers acting as data processors on our behalf, in the following categories:
| Category | Data Shared | Purpose |
|---|---|---|
| Cloud database and authentication | Email, user profile, session metadata, telemetry, IP | Database, authentication, session state |
| AI interview provider | Audio (in-transit), CV context (in system prompt) | AI interview simulation |
| Payment processor | Email, payment information | Payment processing |
| Application hosting | Transient request data during function execution | Application hosting, results processing |
| Website analytics | Cookieless, aggregated usage data — page views, referring site, approximate country, device/browser type (no cookies, no personal identifiers) | Understanding how visitors use the site |
| Rate limiting and abuse prevention | IP addresses, user identifiers | Protecting the service from abuse, fraud, and excessive requests |
| Transactional email | Email address | Transactional email delivery |
| Error monitoring | Error data (user identifiers, email, request metadata) | Error tracking and monitoring |
| Email and productivity | Email correspondence (support and data-protection requests) | Receiving and handling your support and privacy emails |
| AI provider (CV Studio — free read) | CV text and job ad — in transit only | Producing your free CV read. Not retained by aurate; not used to train models. |
| AI provider (30-60-90 Plan and Presentation Decoder) | Job ad and optional CV, or presentation brief — in transit only | Producing the plan or decode you asked for. The text you paste is not retained by aurate; not used to train models. |
| AI provider (CV Studio — marked review) | CV text and job ad — sent for processing | Producing your marked review. aurate stores your CV text, job ad and marked review as described in Sections 2, 3 and 6. Not used to train models. |
| AI provider (Application Studio) | Application question, answer and job ad — sent for processing | Marking your application answers. Paid drafts and markings are stored as described in Sections 2, 3 and 6; free marks are not retained. Not used to train models. |
| AI provider (Pitch Room rehearsal) | Your brief, any slide summary, and session audio and text — in transit | Running the rehearsal panel and preparing your marked card. Not used to train models. |
| AI provider (Pitch Room slides) | The text of slides you add to a Pitch Room brief — in transit only | Writing a short summary of your slides for the rehearsal panel. The slide text is not retained by aurate; not used to train models. |
| AI provider (Pitch Room) | Confirmed Pitch case, source labels, audience context, requested decision and session audio/text in transit | Preparing the Decision Case and audience plan, running the rehearsal, proposing bounded refinements, and producing the case-survival card. |
| AI provider (Direction — OpenAI) | The user-supplied role context for a 30-60-90 Plan, including role, employer, start date, expectations, constraints and selected source references | Normalising that bounded role context before plan generation. |
| AI provider (Direction — Google) | The bounded career state, role context and selected evidence needed for the requested Career Map or 30-60-90 Plan | Generating the Direction map or plan requested by you. |
When a job description is uploaded, as part of the parsing process, Gemini extracts the Role and company name to increase accuracy ahead of the interview.
Some of these providers process personal data outside the United Kingdom, including in the United States. Where they do, the transfer is protected by an approved safeguard — the UK Extension to the EU-US Data Privacy Framework ("UK-US Data Bridge") or the UK International Data Transfer Agreement. We make the names of our current processors available on request.
We do not share personal data with any other third parties.
Speech input. Where you can speak instead of typing, the recognition is done by your own browser's provider — Google in Chrome, Apple in Safari. The audio goes from your browser to that provider and never to us; we receive the text, as if you had typed it. We make no recording, and we never store, upload or play back any audio. What that provider does with the audio is governed by their terms, not ours.
Data Retention Schedule
| Data Category | Retention Period | Deletion Trigger |
|---|---|---|
| Audio | Not retained. Never stored. | N/A — streams directly from browser to AI provider |
| Session transcript and AI responses | Account lifetime, or 18 months, whichever is shorter | Account deletion (cascade) or scheduled 18-month purge |
| marked card payload, module summaries, action plan | Account lifetime | Account deletion (cascade) |
| CV text and CV summary | Lifetime of your session record | Account deletion (cascade) plus session cleanup |
| Account data (email, tier, credits) | Lifetime of account | Account deletion |
| Session telemetry (scores, metadata) | Lifetime of account | Account deletion (cascade) |
| IP address (session) | 90 days | Automatic scheduled purge |
| IP address (account-creation logs) | 90 days, then automatically deleted (or earlier on request) | Automatic scheduled purge (not linked to your account) |
| Consent timestamps | Account lifetime | Account deletion (cascade) |
| Pseudonymised benchmarking & progression data | Indefinite | Not removed on account deletion — rows carry only a one-way hash plus performance scores (no name, email, or IP), retained to keep aggregate statistics intact. See Section 3.3 |
| Historical public marked-card share records | Account lifetime, or 18 months from the session, whichever is shorter | Account deletion (cascade) or the scheduled 18-month expiry. New public share links are no longer created. |
| Admin audit logs | Retained for compliance | Not deleted — required for compliance |
| Payment records (transaction IDs, amounts, tier — no card data) | Retained; your user identifier is removed on account deletion | Anonymised on account deletion (financial record retained) |
| Waitlist sign-up email (if you joined the waitlist) | Until removal on request | On request |
| CV text and job ad submitted for a free CV read | Not retained. Never stored. | N/A — used for the request and discarded |
| Job ad, CV or brief pasted into the 30-60-90 Plan or Presentation Decoder | Not retained. Never stored. | N/A — used for the request and discarded |
| Saved 30-60-90 plan or presentation decode | Until you delete it, or 18 months, whichever is shorter | Your deletion, account deletion (cascade) or scheduled 18-month purge |
| Marked CV review (paid) | Account lifetime, or 18 months, whichever is shorter | Account deletion (cascade) or the scheduled 18-month purge |
| Application drafts and their marking | Account lifetime, or 18 months from the last edit to that draft, whichever is shorter | Account deletion (explicit cascade), the scheduled 18-month purge, or when you delete the thread yourself |
| Pitch Room brief (task, time limit, panel type, slide summary) | Until you delete it, or 18 months after you last used it, whichever is shorter | Your deletion, account deletion (cascade) or the scheduled 18-month purge |
| Slide text added to a Pitch Room brief | Not retained. Never stored. | N/A — summarised once and discarded |
| Confirmed Pitch cases, notes and immutable Decision Case versions | Account lifetime | When you delete that Pitch case, or account deletion |
| Pitch case-survival card and internal evidence reconstruction | Account lifetime | Account deletion (cascade) |
| Pitch Room marked card (brief-based) | Account lifetime | Account deletion (cascade) |
| Direction structured drafts and unapplied proposals | 30 days from creation or last activity | Scheduled 30-day purge, Direction artefact deletion, or account deletion |
| Archived or closed Direction Career State, Career Maps and 30-60-90 Plans | 18 months after closure | Scheduled 18-month purge, Direction artefact deletion, or account deletion |
| Active Direction Career State, Career Maps and 30-60-90 Plans | While active | Direction artefact deletion or account deletion |
Your Rights
Under UK GDPR, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate personal data.
- Right to erasure: Delete your account and your associated personal data using the "Delete my account" button in your profile settings (pseudonymised benchmarking rows are retained — see the note below).
- Right to restrict processing: Request that we limit how we use your data.
- Right to data portability: Request a copy of your data in a machine-readable format by emailing us.
- Right to object: Object to processing based on legitimate interest.
- Right to withdraw consent: Where processing is based on consent, you can withdraw at any time.
Account deletion: Use the "Delete my account" button in your profile settings. Deletion is immediate and irreversible. Your directly identifying data — profile, session history, telemetry, transcripts, CV, and Direction data — is permanently removed. Pseudonymised benchmarking and progression rows, which carry only a one-way hash of your account identifier plus performance scores (no name, email, or IP), are retained to keep our aggregate statistics intact (see Sections 3.3 and 6).
All other rights: Email hello@aurateai.com. We will respond within 30 days.
Complaints: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Security
We implement appropriate technical and organisational measures to protect your personal data, including: encryption in transit (TLS/HTTPS on all connections), database-level Row Level Security policies, API key isolation via ephemeral tokens (keys never exposed to client browsers), and immutable audit logging of all administrative actions.
Cookies
aurate uses cookies only where strictly necessary. We use authentication session cookies to keep you signed in — these are first-party, expire when your session ends or when you sign out, and cannot be disabled without breaking sign-in. We do not use advertising cookies, analytics cookies, or cross-site tracking cookies. Most of your client-side state (your tier and your session preferences) is held in your browser's localStorage rather than in cookies, and is cleared by signing out, clearing site data, or deleting your account.
Children
aurate is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that a user is under 18, we will delete their account and associated data.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of material changes by email or by a prominent notice in the application. The latest version will always be available at this page.
What changed on 12 August 2026. We added the CV Studio and the Application Studio to this policy: what each one collects, why, who it is shared with, and how long it is kept. The free CV read you can take without an account stores nothing at all. A marked CV review is stored on your account and is deleted when you delete your account, or after 18 months, whichever comes first. We have also set out that where you dictate instead of typing, the speech recognition is done by your browser's own provider and the audio never reaches us.
What changed on 17 August 2026. We added Pitch Room: tab-local drafts, confirmed cases and versions, bounded refinement, rehearsal transcripts, and private case-survival marked cards. We also describe the delete-this-case control and make clear that a Pitch result assesses a rehearsal rather than predicting a real approval.
What changed on 2 September 2026. We added Direction: the bounded career, role and selected-evidence context used to create Career Maps and 30-60-90 Plans; the OpenAI and Google provider roles; what structured state is stored; its 30-day and 18-month retention boundaries; and deletion behaviour.
Additional Disclosures for US Residents (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information. This section supplements the rest of our Privacy Policy for California residents.
Categories of personal information collected
In the preceding 12 months, we have collected the following categories of personal information as described in Section 3 above: identifiers (email address), commercial information (purchase history), internet activity information (session telemetry), and inferences drawn from session performance (overall scores).
We do not sell your personal information
aurate does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. We have not sold personal information in the preceding 12 months.
We do not share for cross-context behavioral advertising
aurate does not share your personal information for cross-context behavioral advertising as defined under the CPRA. We do not use tracking or advertising cookies.
Your CCPA rights
- Right to know: You may request the categories and specific pieces of personal information we have collected about you.
- Right to delete: You may request deletion of your personal information. Use the "Delete my account" button in your profile settings for immediate deletion, or email us.
- Right to correct: You may request correction of inaccurate personal information.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise any of these rights, email hello@aurateai.com. We will verify your identity and respond within 45 days.