Back to Aura

Aura Privacy Policy

Last updated: July 20, 2026

Aura helps patients find participating hospitals, doctors, and clinics, view appointment availability, and request visit bookings online.

Google user data

Google sign-in is used to identify the patient account by email and keep booking access tied to the signed-in user. When a patient allows Google Drive access, booking receipts may be saved to the patient's private Google Drive app data folder so booking history can be restored across devices.

For provider and doctor accounts, Aura uses Google Calendar access only to support appointment scheduling. With the doctor's consent, Aura may read free/busy availability, list appointment-related calendar events for the selected schedule window, and create, update, or delete appointment or availability-block events in the doctor's Google Calendar.

The Google user data we may process includes the signed-in Google account email address, Google account identifier, Google Drive app data files created by Aura for booking receipts, Google Calendar availability information, Google Calendar event identifiers, and appointment event details needed to create, update, cancel, or display bookings.

Patient and booking data

Patient name, phone, and local receipts are stored in the browser using encrypted local storage. Appointment details needed for a booking may be shared with the selected participating hospital, clinic, or doctor.

Sharing and disclosure of Google user data

We do not sell Google user data. We do not use Google user data for advertising, generalized analytics, or training AI or machine learning models. We disclose Google user data only as needed to provide the scheduling service, comply with law, protect users, or maintain the service.

Appointment details may be shared with the selected participating hospital, clinic, doctor, or helper so they can manage the requested booking. Calendar invitations may disclose the patient's signed-in email address to the selected doctor and other event attendees selected by the user or provider. Google user data is processed by Google services such as Google Sign-In, Google Drive, Google Calendar, Firebase, Google Cloud Functions, Firestore, and Firebase Storage to operate the app.

Data protection

Aura uses Firebase Authentication, server-side Cloud Functions, Firestore Security Rules, Firebase Storage Rules, role-based access checks, rate limits, and HTTPS encryption in transit to protect account, booking, and scheduling data. Data stored in Google Cloud services is protected by Google Cloud's infrastructure security controls, including encryption at rest.

Patient profile details and booking receipts stored in the browser are encrypted locally before storage. Google Calendar refresh tokens for provider accounts are stored server-side and are used only by Cloud Functions for authorized scheduling operations. Access is limited to the minimum application components and authorized users needed to provide the service.

Retention and deletion

Google user data is retained only for as long as needed to provide booking history, appointment management, security, legal compliance, and operational support. Patient booking receipts saved to Google Drive app data remain in the user's own Google Drive app data folder until the user deletes them, disconnects the app, deletes the app's Drive app data, or requests deletion from Aura where supported.

Doctor Google Calendar refresh tokens and Calendar connection metadata are retained until the doctor or provider disconnects Google Calendar, revokes Aura access from the Google Account permissions page, removes the doctor account from the practice, or requests deletion. Appointment records and Calendar event identifiers are retained while needed for active bookings, booking history, cancellation handling, dispute resolution, security, legal compliance, and audit purposes. When a booking is cancelled through Aura, Aura attempts to cancel or remove the corresponding Google Calendar event where it has permission to do so.

Users can revoke Google access at any time from their Google Account permissions page. Patients may delete local browser data and Drive app data from their own account. Providers may remove or deactivate doctor and helper accounts in the provider app. Deletion requests can also be sent through the app support channel or to the operator of the hospital or clinic using Aura.

Service limits

This service is for appointment discovery and booking requests only. It does not provide medical advice, diagnosis, treatment, emergency support, or guaranteed appointment acceptance.