Privacy

AuraDrive Privacy Policy

Version 2026.08.24 · Effective 2026-08-24

AuraDrive Privacy Policy

Effective: August 24, 2026
Last updated: August 24, 2026

This Privacy Policy explains how Wisheda, Inc., a Delaware corporation, doing business as AuraDrive (“AuraDrive,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information through the AuraDrive applications, websites, driving-session features, Parent Watch, AuraVisor marketplace, subscriptions, communications, and related services (the “Services”).

Privacy and legal requests may be sent to dev0@auradrive.co.

1. Key commitments

  • AuraDrive is intended for people age 13 and older. A known child under 13 may not create an account or provide personal information.
  • A parent or legal guardian must approve a 13–17-year-old's use of driving sessions, precise location, Parent Watch, AuraVisor booking or chat, and identity-related features.
  • We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.
  • We do not disclose raw driving, precise-location, or inferred-risk information to insurers or data brokers or use it to determine insurance eligibility or price.
  • Parent Watch is limited to disclosed scopes and active-session windows. It is not hidden or continuous background surveillance.
  • We do not receive facial templates from Apple Face ID, fingerprints from Apple Touch ID, or device passcodes.
  • Optional third-party AI processing is off until the user authorizes it. We do not send names, government-ID images, or raw precise-location traces to the generative-AI model.
  • AuraDrive records are user records, not official government records, and acceptance is not guaranteed.

2. Information we collect

Account, profile, and eligibility information

We collect name, username, email, telephone number, date of birth or age range, mailing address, account role, settings, communication preferences, account status, authentication tokens, password hash, policy and consent versions, permit or license information, instructor credentials, insurance and vehicle information, and Guardian relationship and linked-account identifiers.

Identity and credential verification

For eligible adults, Stripe Identity may collect a government-ID image, selfie, date of birth, address, document details, and fraud or device signals. AuraDrive receives the verification outcome, provider reference, reason codes, and limited extracted fields needed for the disclosed purpose rather than the underlying image.

AuraDrive does not offer Stripe Identity verification to a Minor User, a person Stripe treats as a minor, or anyone under 16. The applicable Minor User workflow uses Guardian attestations or other lawful, proportionate documentation.

Driving sessions, location, and device signals

When you activate an applicable feature and grant permission, we may collect:

  • precise or approximate location, route, start and end points, timestamps, distance, and duration;
  • estimated speed, acceleration, deceleration, turns, motion, orientation, and device-placement signals;
  • proximity or Bluetooth signals between approved devices;
  • session status, daylight or weather context, supervisor information, notes, and edits;
  • device-authentication success, failure, interruption, and risk or anomaly indicators; and
  • network availability, offline queue, synchronization, app state, and relevant battery or permission status.

We collect high-frequency location and sensor information only during setup for, operation of, or completion of an active driving session. A limited setup or last-known location may persist briefly to finish synchronization. Parent Watch does not authorize unrelated continuous location collection outside the disclosed feature window.

Transactions and subscriptions

We may receive subscription status, product, price, currency, purchase date, renewal or expiration, refund status, transaction and payment-provider identifiers, billing name or address, and limited card details such as brand and last four digits. Apple, Stripe, or another payment provider processes payment credentials. AuraDrive does not store full card numbers or security codes.

Marketplace, communications, and user content

We collect booking requests, availability, service area, lesson details, pricing, cancellation status, booking-linked messages, attachments, reports, blocks, reviews, ratings, support requests, moderation actions, logbook notes and corrections, exports, incident descriptions, and AI narrative inputs and edits.

App, web, security, and diagnostics

We collect IP address, device and app identifiers, browser, operating system, language, time zone, device model, sign-in and session events, consent and audit records, feature use, crash and performance information, and signals associated with suspected fraud, account takeover, tampering, or abuse.

AuraDrive does not use third-party advertising cookies or SDKs for cross-context behavioral advertising.

Information from others

We may receive information from a Guardian, linked learner or supervisor, AuraVisor, Apple, identity or payment provider, communications provider, licensing authority, public record, security provider, mapping or weather provider, support interaction, or another user who reports an incident.

3. How we use information

We use personal information to:

  1. create, authenticate, secure, and administer accounts;
  2. determine age-appropriate feature access and document Guardian approval;
  3. record and synchronize driving sessions, create summaries and exports, and display verification status;
  4. operate the Parent Watch scopes selected by linked users;
  5. list, discover, book, communicate with, review, and support AuraVisors;
  6. process subscriptions, transaction records, refunds, taxes, and entitlements;
  7. send operational, safety, legal, and support communications;
  8. prevent, detect, investigate, and respond to fraud, tampering, abuse, misconduct, and security incidents;
  9. moderate content and operate reporting, blocking, and appeals;
  10. generate an AI-assisted draft only when the user selects the feature and authorizes the disclosed fields;
  11. debug, maintain, analyze, and improve performance and accessibility;
  12. comply with law, respond to valid legal process, establish or defend claims, enforce agreements, and protect people and rights; and
  13. create aggregated or deidentified information that we do not attempt to reidentify except to test the deidentification process.

We do not use precise location, identity artifacts, teen communications, or raw driving telemetry for advertising, data-broker products, insurance decisions, or general-purpose AI training.

4. Sensitive information and consent

Precise geolocation, government identifiers, account credentials, information about a known child, biometric identifiers, and certain identity or driving information may be sensitive under applicable law. We process sensitive information only for disclosed purposes that are reasonably necessary and proportionate to provide or secure the requested feature, comply with law, or act with required express consent.

Just-in-time in-app permissions describe separate choices for precise location, driving and device signals, electronic records, and Parent Watch. You may withdraw optional consent in settings or by contacting us. Withdrawal does not affect prior lawful processing and may disable the affected feature.

Apple LocalAuthentication does not give AuraDrive a user's face, fingerprint, or passcode. If AuraDrive introduces direct capture of a biometric identifier, it will provide a dedicated biometric notice, retention schedule, and any required written consent before collection.

5. Location, sensors, Parent Watch, and verification

When you activate an applicable feature and grant permission (including just-in-time in-app authorization), AuraDrive may collect and process precise location, route, timestamps, distance, duration, estimated speed, motion, proximity or Bluetooth signals between approved devices, session state, offline and sync status, weather or daylight context, device-authentication success or interruption indicators, and supervising-adult information, notes, corrections, and audit history.

Purposes

We use these data to create Session Records and summaries, operate selected Parent Watch scopes, identify possible errors or tampering, support exports, troubleshoot the Services, handle disputes, and protect accounts and users. High-frequency raw telemetry is subject to the shorter retention period in Section 9.

Limits

AuraDrive does not guarantee that the account holder was driving, the phone was in the vehicle, a sensor was accurate, no fraud occurred, or a record satisfies a government or school requirement. Device authentication is one signal. Apple Face ID, Touch ID, or device-passcode authentication does not give AuraDrive the user's face, fingerprint, or passcode and may authenticate any person enrolled on the device.

AuraDrive is not a DMV, insurer, driving school, emergency service, or safety monitor. A Session Record is a user record, not an official government certification. Requirements and acceptance vary.

Safety rule

Never respond to a phone prompt while driving. Begin setup only when lawfully parked. If verification is interrupted while the vehicle is moving, continue driving safely. AuraDrive may mark the session and permit review only after the vehicle is lawfully parked.

Parent Watch

Parent Watch shares only the scopes displayed at setup (for example session status, live location during an active session, selected alerts, summaries, and booking-linked communications where enabled). Parent Watch is not continuous background tracking. Live location is available only during an active session and ends when the session ends. Both linked accounts can see the relationship and its permissions. Revocation ends future access promptly but does not retrieve information already viewed.

Third-party identity verification

Where offered to eligible adults, Stripe Identity may collect a government-ID image, selfie, document details, and fraud or device signals under its own notice. AuraDrive receives the verification outcome, provider reference, and limited eligibility fields. AuraDrive does not offer Stripe Identity verification to a Minor User, a person Stripe treats as a minor, or anyone under 16.

Withdrawal

You may withdraw optional session, Parent Watch, or AI authorizations in AuraDrive settings or by contacting us and may separately disable device permissions. Withdrawal stops future processing after a reasonable implementation period but does not invalidate prior processing or require deletion of a record AuraDrive lawfully retains. Affected features may stop working.

6. Optional AI processing

AuraDrive can turn selected session facts or user notes into an editable narrative using Google Cloud/Vertex AI. Before the first transfer, we identify the processor, show the information sent, and request optional permission. Declining does not prevent use of core non-AI functions.

The feature sends the session date, duration, distance, daylight and weather context, supervisor role, and notes selected by the user. It does not send names, contact details, government identifiers, identity images, raw GPS traces, or unrelated chat. We do not authorize the provider to use identifiable AuraDrive content to train general-purpose models. AI drafts may be inaccurate and must be reviewed by the user.

7. When we disclose information

Service providers and processors

Vendors process information under contracts and AuraDrive's instructions.

Provider or categoryFunctionInformation processed
SupabaseAuthentication, database, storage, server functionsAccounts, consents, app content, session summaries, permissions, support records
AppleApp distribution, In-App Purchase, push/device services, device authenticationEntitlement and transaction IDs, device token, authentication result
StripeWeb subscriptions, direct AuraVisor-payment processing where selected, and eligible-adult identity verificationTransaction/customer records; identity artifacts and verification outcome where permitted
TomTomMaps, routing, geocoding, and location contextCoordinates, route queries, and required technical data
TwilioOperational text and phone communicationsPhone number, message content, delivery metadata
ResendOperational emailEmail address, message content, delivery metadata
Google Cloud, including Vertex AICloud processing and optional AI narrative generationAuthorized AI fields and technical/security records
Managed cache and queue infrastructurePerformance, queues, short-lived session stateMinimized tokens and task data
Security, diagnostics, and customer-support providersFraud prevention, crash diagnosis, incident and support handlingDevice/security events, crash records, support content

These providers may process information in the United States and other locations where they or their subprocessors operate, subject to contracts and applicable law.

Linked users and marketplace participants

  • We disclose selected Parent Watch scopes to the specifically linked adult or learner.
  • We disclose booking and communication information to the AuraVisor and customer or Guardian as needed for Provider Services.
  • Public profiles and submitted reviews are visible as indicated at submission.
  • Session exports are sent to recipients selected by the user. AuraDrive does not control a recipient's downstream use.

Legal, safety, and rights-protection disclosures

We may preserve or disclose information to comply with valid legal process; respond to a documented emergency involving imminent danger; investigate fraud, security, or misconduct; enforce agreements; or protect rights and safety. We review government demands for legal validity and scope, seek to narrow overbroad demands, and notify affected users where permitted. We do not provide voluntary bulk access to driving or location data.

Corporate transactions

Information may be disclosed in diligence for, or transferred as part of, a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets. A recipient must use information consistently with this Policy unless it provides required notice and obtains required consent for a new purpose.

At your direction

We disclose information when you direct us to do so or provide a separate valid consent.

8. No sale, targeted advertising, or insurance-data use

AuraDrive does not sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising as those terms are defined by state privacy laws. We have not done so for personal information of known users under 16.

We do not disclose raw driving telemetry, precise-location history, or inferred driving-risk information to insurers or data brokers and do not use it to determine insurance eligibility or price. We do not offer a financial incentive in exchange for personal information unless a separate legally compliant notice is presented.

9. Parent Watch and Minor Users

Guardian approval does not provide unlimited access to a teenager's information. The app displays the scopes requested and active. The learner may approve or revoke optional sharing where applicable, while a Guardian may stop the Minor User's participation.

Parent Watch shares information during an active driving session and related summaries, not continuous background location. Both linked accounts can see the relationship and its permissions. AuraDrive records link creation, changes, access, and revocation for security and disputes. At age 18, the prior link is suspended and sharing continues only if the adult user creates a new link.

If we learn that we collected personal information from a child under 13, we take reasonable steps to delete it. Contact dev0@auradrive.co if you believe this occurred.

10. Retention

We retain information only as long as reasonably necessary for its disclosed purpose, security, contracts, law, disputes, and documented legal holds.

InformationRetention period
High-frequency raw GPS, speed, motion, proximity, and sensor events90 days after the session, then deletion or irreversible aggregation
Pre-session or last-known setup location24 hours
Session summaries and logbookAccount life plus 3 years, subject to valid deletion and legal exceptions
Account profile and Parent Watch link recordAccount life plus 30 days; access ends promptly upon revocation
AuraDrive-held permit or license imageCurrent verification need, no later than 1 year after expiry or account closure
Identity verification outcome and provider reference3 years after verification
Terms, consent, authorization, and audit evidence7 years after account closure
Payment, tax, refund, and financial booking records7 years
Booking chat, reviews, and support content3 years after last activity
Misconduct or emergency reports3 years after final resolution
Crash, performance, and security logs90 days; deidentified aggregate metrics up to 2 years
Marketing preference or suppression proofUntil changed, plus the minimum period needed to honor the opt-out

We may retain a narrowly limited record longer for an open dispute, fraud or safety investigation, tax duty, valid legal request, or litigation hold. Backups are isolated from normal use and age out within 90 days. If restored for disaster recovery, applicable deletion requests are re-applied.

11. Security

We use administrative, technical, and physical safeguards appropriate to the information, including access controls, encryption in transit and at rest where appropriate, segregated permissions, audit logging, secrets management, secure development, incident response, and deletion controls. No method is completely secure, and we cannot guarantee absolute security.

Use a unique password, protect your device and email, review active Parent Watch links, and report suspected misuse to dev0@auradrive.co.

12. Your privacy rights and choices

Subject to identity verification and legal exceptions, AuraDrive provides U.S. users the ability to:

  • confirm whether we process their personal information and access it;
  • correct inaccurate information;
  • delete personal information;
  • obtain a portable copy of information they provided and certain account data;
  • withdraw consent for optional processing;
  • revoke a Parent Watch link or reduce its scopes;
  • manage device permissions, notifications, AI features, and marketing preferences; and
  • appeal a denied privacy request.

Submit a request through in-app privacy settings or email dev0@auradrive.co. Describe the right and account involved. We verify requests in a manner proportionate to the information's sensitivity and do not discriminate against a user for exercising a privacy right. Authorized agents may submit requests where law permits, subject to proof of authority and direct verification.

We respond within the time required by applicable law. If we deny a request, we explain the basis and appeal process. Send appeals to dev0@auradrive.co with “Privacy Appeal” in the subject. You may also contact your state attorney general or privacy regulator.

We may retain information where an exception applies, including to complete a transaction, protect security, prevent fraud, exercise legal rights, comply with law, or protect another person's privacy.

Device and account controls

  • Location, motion, and Bluetooth: Change permissions in device settings. An affected feature may stop or become unverified.
  • Parent Watch: View and revoke links and scopes in account settings.
  • AI narratives: Turn off optional AI processing in settings.
  • Communications: Use unsubscribe controls for marketing. Operational and legal notices continue while the account is active.
  • Account deletion: Use the in-app deletion control or email us. Deleting the app does not delete the account or cancel an App Store subscription.

13. State-specific disclosures

California notice at collection

CCPA categoryAuraDrive examplesRetention
IdentifiersName, email, phone, address, IP, device/account/provider IDsAccount and security purpose under Section 10
Customer recordsContact, permit/license, billing, Guardian relationshipSection 10
Protected characteristicsAge or birth date used for eligibilityAccount life plus 30 days, except consent evidence
Commercial informationProduct, subscription, lesson, transaction, refundFinancial records up to 7 years
Internet/electronic activityApp use, authentication, crash, security, communications metadataLogs generally 90 days; account records as stated
GeolocationPrecise route, start/end, setup locationRaw session data 90 days; setup location 24 hours
Sensory/device dataMotion, speed, orientation, proximity, submitted mediaRaw session data 90 days; submitted content as stated
Professional informationAuraVisor licenses, credentials, insurance, servicesActive listing plus applicable record period
Education-related informationUser-entered training and logbook contextSession/logbook period
InferencesFraud, verification interruption, anomaly flagsNo longer than the related record
Sensitive personal informationGovernment ID, account credentials, precise location, Minor User and verification dataShortest applicable period in Section 10

California residents may have rights to know, access, correct, and delete information and rights relating to sale, sharing, and sensitive information. AuraDrive does not sell or share for cross-context behavioral advertising and uses sensitive information only for disclosed service and security purposes.

Residents of Virginia, Colorado, Connecticut, Delaware, Maryland, Montana, New Jersey, Oregon, Texas, and other states may have additional access, correction, deletion, portability, consent, opt-out, and appeal rights. AuraDrive's nationwide choices provide a consistent baseline; additional nonwaivable rights also apply.

14. Cookies and similar technologies {#cookies}

AuraDrive uses first-party and service-provider cookies, local storage, and SDK storage needed to sign in, secure sessions, remember settings, process purchases, prevent fraud, and understand core performance. We do not use them for cross-context behavioral advertising. Blocking essential storage may prevent web functions from working.

15. External links

The Services may link to government sites, AuraVisor services, Apple, and other third parties. Their privacy practices govern information you provide directly to them. Review their notices before submitting information.

16. Changes to this Policy

We may update this Policy as the Services or law changes. We post the updated version and date and provide advance notice of material changes. If a new purpose requires consent, we request it rather than treating continued use as consent.

17. Contact us

Wisheda, Inc. (d/b/a AuraDrive)
Attn: Privacy
Email: dev0@auradrive.co