Acceptance
These terms apply to anyone who creates an Aura identity or otherwise uses the Aura apps or services. Aura ships on four surfaces today: the hosted web app, macOS, Linux and Android. There is no Windows build published and no iOS app; iOS has never been built or released. If either ever ships, these terms will cover it too.
If you're using Aura on behalf of an organization, you're confirming you have authority to bind that organization, and "you" includes that organization.
Creating a new Aura identity, on any surface, requires confirming you're at least 16 and agreeing to these terms and the Privacy Policy before the account is created — that acceptance, with its date and the version of these terms you agreed to, is recorded against your identity server-side. If you created your identity before this requirement shipped, you were not retroactively asked; nothing here is being enforced against you on the strength of a consent you were never asked for.
The service
Aura is a closed-inbox-by-default communication platform: one identity, revocable Reach Contracts, and end-to-end protected messages, calls, notes, and files. Instead of an open phone number or email address, people reach you only through a scoped, revocable permission you grant. We provide the client apps and the routing infrastructure that moves encrypted envelopes between devices; we do not provide, and this isn't, an open messaging address book.
Account & identity
You must be at least 16 years old to create an Aura identity, consistent with the age you confirm during account setup. That confirmation is self-attested; we do not verify age, because we deliberately collect nothing that would let us.
Where your keys live depends on which Aura you use, and it changes what we can see:
- Android and desktop (macOS, Linux): your identity and device private keys are generated and held on your own hardware. We never receive them and we cannot read your message content.
- The hosted web app at app.auratt.com: your device private keys are held by an Aura process running on our servers, which encrypts and decrypts on your behalf. On that surface we are technically able to access your keys and your message plaintext. This is set out in full on the security page, and it is the honest answer wherever else on this site a shorter phrase might suggest otherwise.
We do not read hosted-web message content as a matter of practice or policy, and we do not scan or mine it. But "we choose not to" and "we cannot" are different promises, and only Android and desktop earn the second one.
On every surface we cannot reset or recover your account for you, because we do not hold your recovery material. Depending on your setup, recovery may rely on a single recovery key or a threshold of recovery shares held across your own devices and trusted contacts. If you lose the device(s) or material needed to meet that threshold — without ever having backed up or distributed your recovery key or shares — your account and everything in it is unrecoverable. This isn't a limitation we're choosing to leave unfixed; it's the direct consequence of not holding your keys in the first place, and we tell you this during setup for exactly that reason.
You're responsible for keeping your recovery key, your recovery shares, and your devices secure, and for revoking any device you lose or no longer trust.
Acceptable use
You agree not to use Aura to:
- Send spam, or otherwise attempt to reach people without an active, honestly-obtained Reach Contract.
- Engage in phishing, fraud, harassment, or send illegal content.
- Circumvent the Reach Contract permission model — including attempting to message, call, or discover a recipient who has not granted you an active contract.
- Attempt to break, bypass, or reverse-engineer Aura's end-to-end encryption, or interfere with the integrity of the client or routing infrastructure.
- Use Aura to violate the rights of others or applicable law.
If someone violates these terms against you, you can report or block them. Reports go through categories like spam, phishing, harassment, fraud, or other; the account you report is never told who reported it. Blocking takes effect immediately whether or not you also report, and stops the blocked party's messages and contact-discovery visibility toward you. Report and block are available on every surface:
- Android, one-to-one chats: from the conversation's message and contact menus, and from the Safety Center.
- Android, group threads: from a message's long-press menu, and from the Safety Center.
- Hosted web and desktop: from a message's action menu, from a contact's "Block or report" action, and from Settings → Safety Center.
Appeals against a moderation decision are handled server-side and are available on every surface where a decision was made.
Content & encryption
On Android and desktop: message plaintext, attachment keys, device private keys and local Vault contents stay outside our servers. We handle encrypted envelopes and the metadata required to deliver them, not readable content. A direct consequence: for content created and read on those surfaces we cannot moderate it, cannot retrieve it on your behalf, and cannot produce it in response to a request — including a valid legal request — because we do not have it.
On the hosted web app: encryption and decryption are performed by an Aura process on our servers using your device keys, so plaintext exists on our infrastructure while a message is being sealed or opened. We do not retain it, log it, scan it or mine it. But we will not tell you we are incapable of seeing it, because on that surface we are capable of it, and a compelled request or a compromise of that server is therefore a different risk from the same request aimed at Android or desktop.
Server-side abuse handling is limited to what is reportable or observable at the account and metadata level (user reports, delivery metadata, contract activity). We do not scan message content on any surface.
We will comply with valid legal process to the extent we are technically able to. That means we can produce what we actually hold — account metadata, routing metadata, and the limited signals described on our security and privacy pages — plus, for hosted-web users, whatever a lawful order could compel from a server that holds their device keys. We cannot produce plaintext from devices whose keys we never had.
Business & verified accounts
Organizations using Aura's business platform features — campaigns, webhooks, verified domains, and related tooling — are covered by these general terms, the same as everyone else. There is no separate business terms addendum. None has been written, and an earlier version of this page referred to one that does not exist. If a business addendum is ever published it will be linked from here; until then, nothing else governs these features.
Termination
You can delete your account at any time from the Android app, in Settings → Delete my account: it requires typing a confirmation phrase and re-entering your passphrase (and MFA, if enabled), and it is irreversible. The hosted web app and the desktop app have no delete control today. If you only use web or desktop, the account deletion page is the route to use — it also covers what deletion does and does not erase, which is not "everything".
We may suspend or terminate your access for violating the acceptable use section above, or where required by law. Because we don't hold your message content, termination on our side means cutting off routing and account access, not deleting content we never had.
Disclaimers & limitation of liability
Aura is provided "as is," without warranties of any kind, express or implied. We work to keep the service reliable and secure, but we don't guarantee uninterrupted availability, that the service will be error-free, or that it will meet every use case. Encryption reduces what we can see, not what can go wrong on your own device or through your own account practices.
To the extent permitted by law, Aura is not liable for indirect, incidental, or consequential damages arising from your use of the service, including loss of access to an account due to lost recovery material — since, by design, we have no way to recover it for you.
This is the same honest-limitations approach we take on the security page: knowing what we can't do is part of understanding what Aura actually protects.
Changes to these terms
We may update these terms as the product changes. Material changes will be reflected here with an updated date, and where practical, surfaced in-app before they take effect. Continuing to use Aura after a change takes effect means you accept the updated terms.
Governing law & contact
The governing-law clause below reflects the operator's country of incorporation. It has not been separately reviewed by outside counsel — get that review before treating a specific dispute as governed by it, particularly for users outside Nepal where a local consumer-protection law may override a chosen jurisdiction regardless of what this clause says.
Governing law: the laws of Nepal, without regard to conflict-of-law principles. Aura is operated by Orgware Construct Pvt. Ltd., a company registered in Nepal.
Legal contact: [email protected], or by post to Orgware Construct Pvt. Ltd., Prachin Marg-10, Old Baneshwor Height, Kathmandu, Nepal. The support page lists every other channel that is actually live.
AURA