Last updated 2026-04-30

Summary in plain English

What we collect

1. Anonymous activation token (AURA_TOKEN)

When you install Aura through the official Homebrew tap, the binary ships with an activation token embedded at compile time. The token is HMAC-signed by our Cloudflare Worker and lets your Aura process call the language model through our proxy. The token does not contain your name, email, or any personal data — it is an opaque string scoped to a release.

2. Voice / text payloads in transit

When you speak, Aura streams encoded audio to xAI through codexini.com. The Cloudflare Worker forwards the stream and attaches the upstream API key server-side. We do not retain the audio, the transcript, or the assistant response. Cloudflare's standard edge logs (request count, status code, IP-derived region, user agent) are retained for up to 30 days for abuse prevention and then discarded.

3. Optional orb account

If you choose to associate an email with the Aura orb (the menu-bar app), that email is stored on our Cloudflare KV store alongside your activation token. It is used to identify your account if you reach out for support, recover access, or upgrade plans. You can request deletion at any time by emailing georgiyxo@protonmail.com.

4. Aggregate diagnostics

The orb periodically pings codexini.com to check for new releases. The ping carries the current Aura version so we can prioritize the rollout. It does not include your microphone audio, project paths, or any code.

What we don't collect

Third parties

Data location

Cloudflare Workers run at the edge near you. Cloudflare KV storage (used for orb accounts and activation tokens) is hosted in Cloudflare's global infrastructure. We do not maintain our own servers.

Security

All network requests use TLS. Activation tokens are HMAC-signed and verified server-side. The upstream xAI key never leaves the Cloudflare Worker — it is not bundled with the Aura binary, not available to your local process, and not exposed in any client response. If the embedded activation token leaks, we can invalidate every outstanding token by rotating the Cloudflare signing key.

Your choices

Children

Aura is not directed at and not intended for children under 13. We do not knowingly collect data from children.

Changes

If we materially change how we handle data, we update this page and bump the date above. Material changes that affect existing users are also called out in the release notes.

Contact

Questions, requests, or anything else: georgiyxo@protonmail.com.