Privacy Policy
We built Aurus on the principle that your data is yours. This policy explains what we collect, why, and what we never do with it. Written to be read.
1. Who We Are
Aurus is an API infrastructure and data control platform operated by Lunixify Studio. When we say “Aurus”, “we”, “us”, or “our” in this document, we mean Lunixify Studio as the data controller for personal data collected through the Aurus platform and website.
For privacy-related questions, contact us at privacy@aurus.io.
2. What We Collect and Why
Account data: When you create an Aurus account, we collect your name, work email address, company name, and billing information. This is necessary to provide the Service and process payments.
API usage data: We collect metadata about requests routed through your Aurus gateways — including request counts, latency, error rates, and API identifiers. This is used to power your dashboard analytics and enforce your plan quota. We do not inspect the content of API request bodies or responses.
Technical data: When you access the Aurus dashboard or website, we collect standard server log data including your IP address, browser type, operating system, and referring URL. This is used for security monitoring and platform reliability.
Communications: If you contact us via email, a contact form, or support channels, we retain that correspondence to respond to your inquiry and improve our support.
Workspace and configuration data: Your API gateway rules, API configurations, access policies, team member records, and workspace settings are stored and processed to provide the Service.
3. What We Do Not Collect
We do not read or store the content of API request or response bodies passing through your Aurus gateways. We do not sell your data. We do not use your data to train machine learning models. We do not serve advertising.
4. How We Use Your Data
We use the data we collect to:
Provide, operate, and improve the Aurus platform
Authenticate your identity and enforce access controls
Calculate and enforce your plan quota and billing
Send transactional emails (account confirmation, invoice receipts, quota alerts, security notifications)
Respond to support requests and inquiries
Monitor for abuse, security threats, and platform reliability issues
Comply with applicable legal obligations
We will not use your data for purposes materially different from those listed above without notifying you and obtaining consent where required.
5. Data Sharing
We share your data only with the following categories of third parties, and only to the extent necessary to provide the Service:
Infrastructure providers: Cloud hosting and database services that store and process platform data on our behalf (under data processing agreements)
Payment processors: Billing providers that process subscription payments (they receive only the data necessary to complete transactions)
Email providers: Transactional email services used to send account and billing notifications
Analytics tools: Aggregated, anonymized usage analytics to understand how the platform is used
We do not share personally identifiable information with advertising networks, data brokers, or any party for commercial purposes.
We may disclose your data if required by law, court order, or regulatory authority, or to protect the rights, property, or safety of Aurus, our customers, or the public.
6. Data Residency and Transfers
Aurus infrastructure is hosted in [Region]. Enterprise customers may request VPC deployment in specific geographic regions to meet data residency requirements. Contact enterprise@aurus.io for details.
If you are located in the European Economic Area, United Kingdom, or Switzerland, your data may be transferred to and processed in countries outside those regions. Where this occurs, we rely on Standard Contractual Clauses or equivalent transfer mechanisms.
7. Data Retention
We retain your account and configuration data for as long as your account is active. After account termination, we retain data for up to 30 days to allow export, then delete it from production systems within 90 days.
Audit logs are retained for 12 months to support SOC II compliance obligations. Anonymized, aggregated usage statistics may be retained indefinitely.
8. Security
Aurus is SOC II Type 2 certified. We implement encryption in transit (TLS 1.2+) and at rest, role-based access controls, audit logging for all configuration changes, and regular security reviews.
Despite these measures, no system is perfectly secure. We will notify affected customers promptly in the event of a data breach that affects their personal data, as required by applicable law.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you
Correction: Request correction of inaccurate or incomplete data
Deletion: Request deletion of your personal data (subject to legal retention obligations)
Portability: Receive your data in a machine-readable format
Restriction: Request that we limit processing of your data in certain circumstances
Objection: Object to processing based on legitimate interests
To exercise any of these rights, email privacy@aurus.io. We will respond within 30 days.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or the platform. We will notify you of material changes by email at least 14 days before they take effect.
11. Contact
For privacy-related questions or to exercise your rights: privacy@aurus.io
