AURA MNGR← Home
Legal

Privacy Policy

Last updated 25 September 2026

AURA MNGR SUITE is the private platform AURA MNGR (“we”, “us”) uses to work with the creators it manages and the staff who support them. This policy explains what the platform collects, why, who processes it, and what you can ask us to do.

If you are a creator working with us, you also received and signed our Privacy Notice for Creators during onboarding. It covers your relationship with the agency in more detail, including identity records, access tiers and retention periods. Where it is more specific than this page, it governs.

Who can use the platform

The platform is not a public service. Accounts are either creators who sign up and are then approved by the agency, or staff invited by the agency. It is intended only for adults aged 18 or over, and we do not knowingly collect information from anyone younger.

Information we collect

Information you give us

  • Account details: your email address, the name you sign up with, and your password. Your password is handled by our authentication provider and is never visible to us.
  • Onboarding and profile information: the answers you give while setting up, such as your stage name, brand, audience, voice and texting style, content preferences, and goals.
  • Consent records: your content comfortability form, messaging and AI permissions, and the agreements you sign, including every earlier version of them, with the time each was signed.
  • Identity records: where the law requires age and identity records for the content you produce with us, the agency’s named compliance personnel record them. Only those people can see them.
  • Your work in the platform: content calendar plans and production status, ideas, time-off dates, custom requests and your responses to them, and messages exchanged with the agency inside the platform.
  • Files you upload: photos, videos and other content files you send to the agency through the platform.

Information collected automatically

  • Sign-in cookies: the cookies needed to keep you signed in. We do not use advertising or analytics cookies, and we do not run third-party trackers.
  • Activity status: the time you were last active, so your team can see who is online.
  • Server logs: our hosting and database providers keep standard technical logs, such as IP address, browser type and request time, to operate and secure their services.

How we use information

  • To create and secure your account and send you to the right area for your role.
  • To run the onboarding, calendar, custom-request, messaging and upload features you use.
  • To enforce your stated limits: requests are checked against your signed comfortability form before they can reach you.
  • To deliver the files you upload to the agency’s storage, described below.
  • To keep the records the law or your agreements require us to keep.
  • To send account emails such as sign-up confirmation and password reset.

We do not sell personal information, and we do not use it for advertising.

Google API data

The platform connects to one Google Drive account, belonging to the agency and authorised by the agency’s owner. Creators and staff never sign in with Google, and the platform never accesses anyone else’s Google account.

What access is requested

Only Google’s drive.file scope. Under that scope the platform can see and manage only the files and folders it creates itself or that are used through this integration. It cannot see, open, list or change anything else in that Drive. It requests no Google profile, contacts, email or other Google data.

How it is used

  • When a creator uploads a file, it is held briefly in our own temporary storage, then transferred into a folder the platform created in the agency’s Drive, named for that creator.
  • The platform reads back the transferred file’s identifier, size and checksum to confirm it arrived complete, and only then deletes the temporary copy.
  • The authorisation token Google issues is stored as server-side configuration. It is never shown to creators or staff, and is used for nothing except this transfer.

Limited Use

AURA MNGR SUITE’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, information received from Google APIs is used only to provide the file-transfer feature described above. It is not sold, not used for advertising, not used to develop, improve or train generalised AI or machine-learning models, and not transferred to anyone except as needed to provide that feature, to comply with the law, or as part of a merger or sale of the business with the same protections. No person reads it except with the agency’s consent, for security purposes, or where the law requires.

The agency can withdraw this access at any time from its Google Account permissions. Files already transferred stay in the agency’s Drive, and new uploads wait in temporary storage until access is restored.

Storage and security

  • All traffic to and from the platform is encrypted in transit (HTTPS).
  • Access is controlled by role and enforced in the database itself, not only in the app. A chatter sees only the creators assigned to them, and for each only a limits summary, never identity records or signed documents. Identity records are limited to the agency’s named compliance personnel.
  • A temporary upload copy cannot be deleted until Google Drive has confirmed receiving the whole file.

No system is perfectly secure, and we do not claim otherwise. If something goes wrong that affects your information, we will tell you.

Service providers

These companies process information on our behalf, only to run the platform:

  • Supabase: database, authentication, account emails and temporary file storage.
  • Vercel: hosting of the website and application.
  • Google: Google Drive, where uploaded files are stored for the agency.

The platform does not connect to OnlyFans or any other platform account, and shares no information with them.

Retention and deletion

  • Account and profile information is kept while your account is active.
  • Temporary upload copies are deleted as soon as Google Drive confirms the transfer. Transferred files are kept by the agency as your agreements provide.
  • Signed agreements and consent records are kept as records and are never edited after signing. For creators, how long each kind of information is kept is set out in the Privacy Notice for Creators.
  • Information the law requires us to keep is kept for as long as it requires, and no longer.

Your rights and choices

You can ask us to:

  • tell you what information we hold about you and give you a copy;
  • correct anything inaccurate;
  • delete information we are not legally required to keep; and
  • withdraw a consent you have given.

Many of these you can do yourself in the platform, including revising your comfortability form at any time. For anything else, email officialauramgr@gmail.com. Exercising these rights will not be held against you.

Changes to this policy

If we change this policy, we will update the date at the top of this page. If a change materially affects how your information is used, we will tell you in the platform before it takes effect.

Contact

Questions about this policy or your information: officialauramgr@gmail.com. See also our Terms of Service.

AURA MNGR SUITE·Privacy·Terms