Privacy Policy — Aura
Last updated: 10 August 2026
Aura ("the Extension") is a Chrome extension that helps businesses detect and recover retailer deductions from their email inbox. This policy explains what data the Extension accesses, how it is used, and how it is protected.
What data we access
- Email content (Gmail / Outlook): when you connect your inbox, the Extension reads incoming emails to detect messages from known retailer domains and to identify emails containing remittance or deduction-related PDF attachments.
- PDF attachments: attachments identified as potential remittance or deduction documents are extracted and processed to identify deduction references, amounts, and reasons.
- Account identity: basic account information (email address) is used to authenticate your connection to Gmail/Outlook via OAuth, and to identify you within the Aura application.
How we use this data
- To detect and classify retailer deductions automatically, so you don't have to search for them manually.
- PDF content is sent securely to Anthropic's Claude API for classification (extracting reference numbers, amounts, and deduction types). Anthropic processes this data solely to return the classification result and does not use it to train models on our behalf beyond standard API terms.
- Extracted, structured dispute data (not raw email content) is stored securely in our backend database (Supabase) so you can review and act on it within the Aura application.
- If you choose to send a dispute letter through Aura, the letter content and recipient address you provide are sent via our email delivery provider (Resend).
What we do not do
- We do not sell or share your data with third parties for advertising or marketing purposes.
- We do not use your email content or data to determine creditworthiness or for lending decisions.
- We do not send, modify, or delete your emails. The Extension only reads emails to detect relevant content.
- We do not access emails unrelated to retailer deductions beyond what is necessary to identify them (e.g. sender domain and attachment checks).
Data storage and security
Extracted dispute data is stored in a secured database with access restricted to your own account (row-level security). Authentication tokens are stored locally in your browser and used only to maintain your connection to Gmail/Outlook.
Your choices
You can disconnect Gmail or Outlook at any time from the Extension's settings, which revokes the Extension's access to your inbox. You may also request deletion of your stored dispute data by contacting us at the email below.
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent revision.
Contact
Questions about this policy or your data can be sent to: sigrid.joon@gmail.com