AuraDrive Privacy Policy
Effective: August 24, 2026
Last updated: August 24, 2026
This Privacy Policy explains how Wisheda, Inc., a Delaware corporation, doing business as AuraDrive (“AuraDrive,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information through the AuraDrive applications, websites, driving-session features, Parent Watch, AuraVisor marketplace, subscriptions, communications, and related services (the “Services”).
Privacy and legal requests may be sent to dev0@auradrive.co.
1. Key commitments
- AuraDrive is intended for people age 13 and older. A known child under 13 may not create an account or provide personal information.
- A parent or legal guardian must approve a 13–17-year-old's use of driving sessions, precise location, Parent Watch, AuraVisor booking or chat, and identity-related features.
- We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.
- We do not disclose raw driving, precise-location, or inferred-risk information to insurers or data brokers or use it to determine insurance eligibility or price.
- Parent Watch is limited to disclosed scopes and active-session windows. It is not hidden or continuous background surveillance.
- We do not receive facial templates from Apple Face ID, fingerprints from Apple Touch ID, or device passcodes.
- Optional third-party AI processing is off until the user authorizes it. We do not send names, government-ID images, or raw precise-location traces to the generative-AI model.
- AuraDrive records are user records, not official government records, and acceptance is not guaranteed.
2. Information we collect
Account, profile, and eligibility information
We collect name, username, email, telephone number, date of birth or age range, mailing address, account role, settings, communication preferences, account status, authentication tokens, password hash, policy and consent versions, permit or license information, instructor credentials, insurance and vehicle information, and Guardian relationship and linked-account identifiers.
Identity and credential verification
For eligible adults, Stripe Identity may collect a government-ID image, selfie, date of birth, address, document details, and fraud or device signals. AuraDrive receives the verification outcome, provider reference, reason codes, and limited extracted fields needed for the disclosed purpose rather than the underlying image.
AuraDrive does not offer Stripe Identity verification to a Minor User, a person Stripe treats as a minor, or anyone under 16. The applicable Minor User workflow uses Guardian attestations or other lawful, proportionate documentation.
Driving sessions, location, and device signals
When you activate an applicable feature and grant permission, we may collect:
- precise or approximate location, route, start and end points, timestamps, distance, and duration;
- estimated speed, acceleration, deceleration, turns, motion, orientation, and device-placement signals;
- proximity or Bluetooth signals between approved devices;
- session status, daylight or weather context, supervisor information, notes, and edits;
- device-authentication success, failure, interruption, and risk or anomaly indicators; and
- network availability, offline queue, synchronization, app state, and relevant battery or permission status.
We collect high-frequency location and sensor information only during setup for, operation of, or completion of an active driving session. A limited setup or last-known location may persist briefly to finish synchronization. Parent Watch does not authorize unrelated continuous location collection outside the disclosed feature window.
Transactions and subscriptions
We may receive subscription status, product, price, currency, purchase date, renewal or expiration, refund status, transaction and payment-provider identifiers, billing name or address, and limited card details such as brand and last four digits. Apple, Stripe, or another payment provider processes payment credentials. AuraDrive does not store full card numbers or security codes.
Marketplace, communications, and user content
We collect booking requests, availability, service area, lesson details, pricing, cancellation status, booking-linked messages, attachments, reports, blocks, reviews, ratings, support requests, moderation actions, logbook notes and corrections, exports, incident descriptions, and AI narrative inputs and edits.
App, web, security, and diagnostics
We collect IP address, device and app identifiers, browser, operating system, language, time zone, device model, sign-in and session events, consent and audit records, feature use, crash and performance information, and signals associated with suspected fraud, account takeover, tampering, or abuse.
AuraDrive does not use third-party advertising cookies or SDKs for cross-context behavioral advertising.
Information from others
We may receive information from a Guardian, linked learner or supervisor, AuraVisor, Apple, identity or payment provider, communications provider, licensing authority, public record, security provider, mapping or weather provider, support interaction, or another user who reports an incident.
3. How we use information
We use personal information to:
- create, authenticate, secure, and administer accounts;
- determine age-appropriate feature access and document Guardian approval;
- record and synchronize driving sessions, create summaries and exports, and display verification status;
- operate the Parent Watch scopes selected by linked users;
- list, discover, book, communicate with, review, and support AuraVisors;
- process subscriptions, transaction records, refunds, taxes, and entitlements;
- send operational, safety, legal, and support communications;
- prevent, detect, investigate, and respond to fraud, tampering, abuse, misconduct, and security incidents;
- moderate content and operate reporting, blocking, and appeals;
- generate an AI-assisted draft only when the user selects the feature and authorizes the disclosed fields;
- debug, maintain, analyze, and improve performance and accessibility;
- comply with law, respond to valid legal process, establish or defend claims, enforce agreements, and protect people and rights; and
- create aggregated or deidentified information that we do not attempt to reidentify except to test the deidentification process.
We do not use precise location, identity artifacts, teen communications, or raw driving telemetry for advertising, data-broker products, insurance decisions, or general-purpose AI training.
4. Sensitive information and consent
Precise geolocation, government identifiers, account credentials, information about a known child, biometric identifiers, and certain identity or driving information may be sensitive under applicable law. We process sensitive information only for disclosed purposes that are reasonably necessary and proportionate to provide or secure the requested feature, comply with law, or act with required express consent.
Just-in-time in-app permissions describe separate choices for precise location, driving and device signals, electronic records, and Parent Watch. You may withdraw optional consent in settings or by contacting us. Withdrawal does not affect prior lawful processing and may disable the affected feature.
Apple LocalAuthentication does not give AuraDrive a user's face, fingerprint, or passcode. If AuraDrive introduces direct capture of a biometric identifier, it will provide a dedicated biometric notice, retention schedule, and any required written consent before collection.
5. Location, sensors, Parent Watch, and verification
When you activate an applicable feature and grant permission (including just-in-time in-app authorization), AuraDrive may collect and process precise location, route, timestamps, distance, duration, estimated speed, motion, proximity or Bluetooth signals between approved devices, session state, offline and sync status, weather or daylight context, device-authentication success or interruption indicators, and supervising-adult information, notes, corrections, and audit history.
Purposes
We use these data to create Session Records and summaries, operate selected Parent Watch scopes, identify possible errors or tampering, support exports, troubleshoot the Services, handle disputes, and protect accounts and users. High-frequency raw telemetry is subject to the shorter retention period in Section 9.
Limits
AuraDrive does not guarantee that the account holder was driving, the phone was in the vehicle, a sensor was accurate, no fraud occurred, or a record satisfies a government or school requirement. Device authentication is one signal. Apple Face ID, Touch ID, or device-passcode authentication does not give AuraDrive the user's face, fingerprint, or passcode and may authenticate any person enrolled on the device.
AuraDrive is not a DMV, insurer, driving school, emergency service, or safety monitor. A Session Record is a user record, not an official government certification. Requirements and acceptance vary.
Safety rule
Never respond to a phone prompt while driving. Begin setup only when lawfully parked. If verification is interrupted while the vehicle is moving, continue driving safely. AuraDrive may mark the session and permit review only after the vehicle is lawfully parked.
Parent Watch
Parent Watch shares only the scopes displayed at setup (for example session status, live location during an active session, selected alerts, summaries, and booking-linked communications where enabled). Parent Watch is not continuous background tracking. Live location is available only during an active session and ends when the session ends. Both linked accounts can see the relationship and its permissions. Revocation ends future access promptly but does not retrieve information already viewed.
Third-party identity verification
Where offered to eligible adults, Stripe Identity may collect a government-ID image, selfie, document details, and fraud or device signals under its own notice. AuraDrive receives the verification outcome, provider reference, and limited eligibility fields. AuraDrive does not offer Stripe Identity verification to a Minor User, a person Stripe treats as a minor, or anyone under 16.
Withdrawal
You may withdraw optional session, Parent Watch, or AI authorizations in AuraDrive settings or by contacting us and may separately disable device permissions. Withdrawal stops future processing after a reasonable implementation period but does not invalidate prior processing or require deletion of a record AuraDrive lawfully retains. Affected features may stop working.
6. Optional AI processing
AuraDrive can turn selected session facts or user notes into an editable narrative using Google Cloud/Vertex AI. Before the first transfer, we identify the processor, show the information sent, and request optional permission. Declining does not prevent use of core non-AI functions.
The feature sends the session date, duration, distance, daylight and weather context, supervisor role, and notes selected by the user. It does not send names, contact details, government identifiers, identity images, raw GPS traces, or unrelated chat. We do not authorize the provider to use identifiable AuraDrive content to train general-purpose models. AI drafts may be inaccurate and must be reviewed by the user.
7. When we disclose information
Service providers and processors
Vendors process information under contracts and AuraDrive's instructions.
| Provider or category | Function | Information processed |
|---|---|---|
| Supabase | Authentication, database, storage, server functions | Accounts, consents, app content, session summaries, permissions, support records |
| Apple | App distribution, In-App Purchase, push/device services, device authentication | Entitlement and transaction IDs, device token, authentication result |
| Stripe | Web subscriptions, direct AuraVisor-payment processing where selected, and eligible-adult identity verification | Transaction/customer records; identity artifacts and verification outcome where permitted |
| TomTom | Maps, routing, geocoding, and location context | Coordinates, route queries, and required technical data |
| Twilio | Operational text and phone communications | Phone number, message content, delivery metadata |
| Resend | Operational email | Email address, message content, delivery metadata |
| Google Cloud, including Vertex AI | Cloud processing and optional AI narrative generation | Authorized AI fields and technical/security records |
| Managed cache and queue infrastructure | Performance, queues, short-lived session state | Minimized tokens and task data |
| Security, diagnostics, and customer-support providers | Fraud prevention, crash diagnosis, incident and support handling | Device/security events, crash records, support content |
These providers may process information in the United States and other locations where they or their subprocessors operate, subject to contracts and applicable law.
Linked users and marketplace participants
- We disclose selected Parent Watch scopes to the specifically linked adult or learner.
- We disclose booking and communication information to the AuraVisor and customer or Guardian as needed for Provider Services.
- Public profiles and submitted reviews are visible as indicated at submission.
- Session exports are sent to recipients selected by the user. AuraDrive does not control a recipient's downstream use.
Legal, safety, and rights-protection disclosures
We may preserve or disclose information to comply with valid legal process; respond to a documented emergency involving imminent danger; investigate fraud, security, or misconduct; enforce agreements; or protect rights and safety. We review government demands for legal validity and scope, seek to narrow overbroad demands, and notify affected users where permitted. We do not provide voluntary bulk access to driving or location data.
Corporate transactions
Information may be disclosed in diligence for, or transferred as part of, a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets. A recipient must use information consistently with this Policy unless it provides required notice and obtains required consent for a new purpose.
At your direction
We disclose information when you direct us to do so or provide a separate valid consent.
8. No sale, targeted advertising, or insurance-data use
AuraDrive does not sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising as those terms are defined by state privacy laws. We have not done so for personal information of known users under 16.
We do not disclose raw driving telemetry, precise-location history, or inferred driving-risk information to insurers or data brokers and do not use it to determine insurance eligibility or price. We do not offer a financial incentive in exchange for personal information unless a separate legally compliant notice is presented.
9. Parent Watch and Minor Users
Guardian approval does not provide unlimited access to a teenager's information. The app displays the scopes requested and active. The learner may approve or revoke optional sharing where applicable, while a Guardian may stop the Minor User's participation.
Parent Watch shares information during an active driving session and related summaries, not continuous background location. Both linked accounts can see the relationship and its permissions. AuraDrive records link creation, changes, access, and revocation for security and disputes. At age 18, the prior link is suspended and sharing continues only if the adult user creates a new link.
If we learn that we collected personal information from a child under 13, we take reasonable steps to delete it. Contact dev0@auradrive.co if you believe this occurred.
10. Retention
We retain information only as long as reasonably necessary for its disclosed purpose, security, contracts, law, disputes, and documented legal holds.
| Information | Retention period |
|---|---|
| High-frequency raw GPS, speed, motion, proximity, and sensor events | 90 days after the session, then deletion or irreversible aggregation |
| Pre-session or last-known setup location | 24 hours |
| Session summaries and logbook | Account life plus 3 years, subject to valid deletion and legal exceptions |
| Account profile and Parent Watch link record | Account life plus 30 days; access ends promptly upon revocation |
| AuraDrive-held permit or license image | Current verification need, no later than 1 year after expiry or account closure |
| Identity verification outcome and provider reference | 3 years after verification |
| Terms, consent, authorization, and audit evidence | 7 years after account closure |
| Payment, tax, refund, and financial booking records | 7 years |
| Booking chat, reviews, and support content | 3 years after last activity |
| Misconduct or emergency reports | 3 years after final resolution |
| Crash, performance, and security logs | 90 days; deidentified aggregate metrics up to 2 years |
| Marketing preference or suppression proof | Until changed, plus the minimum period needed to honor the opt-out |
We may retain a narrowly limited record longer for an open dispute, fraud or safety investigation, tax duty, valid legal request, or litigation hold. Backups are isolated from normal use and age out within 90 days. If restored for disaster recovery, applicable deletion requests are re-applied.
11. Security
We use administrative, technical, and physical safeguards appropriate to the information, including access controls, encryption in transit and at rest where appropriate, segregated permissions, audit logging, secrets management, secure development, incident response, and deletion controls. No method is completely secure, and we cannot guarantee absolute security.
Use a unique password, protect your device and email, review active Parent Watch links, and report suspected misuse to dev0@auradrive.co.
12. Your privacy rights and choices
Subject to identity verification and legal exceptions, AuraDrive provides U.S. users the ability to:
- confirm whether we process their personal information and access it;
- correct inaccurate information;
- delete personal information;
- obtain a portable copy of information they provided and certain account data;
- withdraw consent for optional processing;
- revoke a Parent Watch link or reduce its scopes;
- manage device permissions, notifications, AI features, and marketing preferences; and
- appeal a denied privacy request.
Submit a request through in-app privacy settings or email dev0@auradrive.co. Describe the right and account involved. We verify requests in a manner proportionate to the information's sensitivity and do not discriminate against a user for exercising a privacy right. Authorized agents may submit requests where law permits, subject to proof of authority and direct verification.
We respond within the time required by applicable law. If we deny a request, we explain the basis and appeal process. Send appeals to dev0@auradrive.co with “Privacy Appeal” in the subject. You may also contact your state attorney general or privacy regulator.
We may retain information where an exception applies, including to complete a transaction, protect security, prevent fraud, exercise legal rights, comply with law, or protect another person's privacy.
Device and account controls
- Location, motion, and Bluetooth: Change permissions in device settings. An affected feature may stop or become unverified.
- Parent Watch: View and revoke links and scopes in account settings.
- AI narratives: Turn off optional AI processing in settings.
- Communications: Use unsubscribe controls for marketing. Operational and legal notices continue while the account is active.
- Account deletion: Use the in-app deletion control or email us. Deleting the app does not delete the account or cancel an App Store subscription.
13. State-specific disclosures
California notice at collection
| CCPA category | AuraDrive examples | Retention |
|---|---|---|
| Identifiers | Name, email, phone, address, IP, device/account/provider IDs | Account and security purpose under Section 10 |
| Customer records | Contact, permit/license, billing, Guardian relationship | Section 10 |
| Protected characteristics | Age or birth date used for eligibility | Account life plus 30 days, except consent evidence |
| Commercial information | Product, subscription, lesson, transaction, refund | Financial records up to 7 years |
| Internet/electronic activity | App use, authentication, crash, security, communications metadata | Logs generally 90 days; account records as stated |
| Geolocation | Precise route, start/end, setup location | Raw session data 90 days; setup location 24 hours |
| Sensory/device data | Motion, speed, orientation, proximity, submitted media | Raw session data 90 days; submitted content as stated |
| Professional information | AuraVisor licenses, credentials, insurance, services | Active listing plus applicable record period |
| Education-related information | User-entered training and logbook context | Session/logbook period |
| Inferences | Fraud, verification interruption, anomaly flags | No longer than the related record |
| Sensitive personal information | Government ID, account credentials, precise location, Minor User and verification data | Shortest applicable period in Section 10 |
California residents may have rights to know, access, correct, and delete information and rights relating to sale, sharing, and sensitive information. AuraDrive does not sell or share for cross-context behavioral advertising and uses sensitive information only for disclosed service and security purposes.
Residents of Virginia, Colorado, Connecticut, Delaware, Maryland, Montana, New Jersey, Oregon, Texas, and other states may have additional access, correction, deletion, portability, consent, opt-out, and appeal rights. AuraDrive's nationwide choices provide a consistent baseline; additional nonwaivable rights also apply.
14. Cookies and similar technologies {#cookies}
AuraDrive uses first-party and service-provider cookies, local storage, and SDK storage needed to sign in, secure sessions, remember settings, process purchases, prevent fraud, and understand core performance. We do not use them for cross-context behavioral advertising. Blocking essential storage may prevent web functions from working.
15. External links
The Services may link to government sites, AuraVisor services, Apple, and other third parties. Their privacy practices govern information you provide directly to them. Review their notices before submitting information.
16. Changes to this Policy
We may update this Policy as the Services or law changes. We post the updated version and date and provide advance notice of material changes. If a new purpose requires consent, we request it rather than treating continued use as consent.
17. Contact us
Wisheda, Inc. (d/b/a AuraDrive)
Attn: Privacy
Email: dev0@auradrive.co