Legal

Privacy Notice

Effective and last updated: August 28, 2026

This notice explains what information Digital Aura handles, why it is used, when it can become public, and the choices available to users.

1. Scope

This notice describes information practices for Digital Aura, a service offered through 10K Dre Digital. It applies to account setup, Aura creation and publication, lead capture, networking, community features, analytics, transactional email, and optional wallet passes.

An Aura owner controls the content they publish. Visitors should also review the privacy practices of any social network, booking service, website, email client, or other destination reached from an Aura.

2. Information we collect

  • Account information: name, email address, authentication information, session data, and optional multi-factor authentication status.
  • Aura content: names, public links, headlines, biographies, locations, photos, videos, documents, social links, booking details, custom sections, and visual preferences.
  • Private communications settings: a verified business or personal email attached to an Aura. This address is used operationally and is not intended for display on the public Aura.
  • Lead, network, and community information: contact details and messages submitted by visitors, connection invitations, relationship notes, community memberships and messages, and voice or video room participation.
  • Usage and security information: profile views, QR visits, link clicks, contact saves, lead submissions, timestamps, limited request and device information, security events, and URL reputation results.

3. How we use information

  • Authenticate users and protect accounts.
  • Create, publish, display, and manage Auras.
  • Deliver leads, invitations, confirmations, and other requested communications.
  • Provide Aura-owner analytics, networking, community, and wallet features.
  • Detect malicious links, limit abuse, troubleshoot failures, and secure the service.
  • Comply with legal obligations and enforce applicable service rules.

4. Public information and user-directed sharing

An Aura becomes publicly accessible only after it is published. Its visible profile fields, links, sections, assets, and media can then be viewed without signing in. Draft Auras remain limited to authorized preview and owner access.

Downloads, QR codes, vCards, wallet passes, and links can create copies or send visitors to services outside our control. Removing or changing content in Digital Aura may not remove copies already saved to a device, wallet, inbox, or third-party service.

5. Service providers and other recipients

We use providers to operate specific parts of the service:

  • Supabase for authentication, database, realtime features, and file storage.
  • Vercel for application hosting, request processing, and runtime logs.
  • Resend and the configured Supabase email provider for transactional email.
  • Daily.co when a user joins an available community voice or video room.
  • Google Web Risk and IPQualityScore to evaluate URLs for security threats.
  • Google Wallet and Apple Wallet when a user chooses to create or save a wallet pass.

We may also disclose information when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards. We do not currently use Stripe payments inDigital Aura; this notice will be updated before payment processing is activated.

6. Tracking signals and analytics

Digital Aura records first-party Aura interactions such as profile views, QR visits, link clicks, contact saves, and lead submissions. We did not identify a third-party advertising analytics SDK in the current application.

Because there is no uniform browser standard for interpreting legacy “Do Not Track” signals, the service does not currently respond to those signals. We will update this notice if our tracking practices or supported preference mechanisms change.

7. Retention

We retain information while an account or feature is active and as reasonably needed to provide the service, protect the platform, resolve disputes, and meet legal obligations. Different records may require different retention periods.

Automated retention controls are still being implemented. Account Settings provides guarded account-wide deletion; privacy requests may still require identity verification and limited legal or security exceptions may apply.

8. Your choices and requests

Account holders can edit Aura content, change publication status, remove content, and change or remove an Aura communications email from the dashboard. A private JSON account export is available from Account Settings after a recent sign-in. Account Settings also provides permanent account deletion with recent-sign-in and typed confirmation safeguards. Deletion pauses when an owned community has other members so their content is not erased without a transfer or closure decision. You may also request access, correction, export, or deletion of account-related information. Applicable rights depend on where you live and may be subject to legal exceptions.

To make a privacy request, email flysouthfilms1@gmail.com using your account email when possible, with “Digital Aura Privacy Request” in the subject. We may ask you to verify your identity and authority before disclosing or deleting information.

9. Security and sensitive information

We use access controls, row-level database security, server-side secrets, input validation, and other safeguards designed to protect information. No service can guarantee absolute security.

Do not place passwords, government identifiers, financial account numbers, health records, precise private locations, or information about a child in public Aura fields, generic notes, links, or uploads.

10. Changes and contact

We may update this notice as the service changes. The effective date above identifies the current version. Material changes will be presented through an appropriate in-product or email notice when required.

Questions about this notice can be sent to flysouthfilms1@gmail.com.