Adarna Inc. is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, store, share, and protect the information you provide when you use our website, mobile applications, the Aura Clarus wearable device, and any other services we offer.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use our Services.
1. Information We Collect
1.1 Personal Information You Provide
When you create an account, place a pre-order, sign up for beta access, or contact us, we may collect:
- Full name, email address, phone number, and postal address
- Account credentials (username and password, stored in encrypted form)
- Payment and billing information (processed securely through third-party payment processors; we do not store full card numbers)
- Communication preferences and correspondence with our support team
1.2 Health and Biometric Data
When you use the Aura Clarus wearable device and associated applications, we may collect sensitive health and biometric data, including but not limited to:
- Heart rate, heart rate variability (HRV), and ECG readings
- Blood oxygen saturation (SpO2) and respiratory rate
- Body temperature and electrodermal activity (EDA)
- Sleep patterns, sleep stages, and sleep quality metrics
- Physical activity data, step counts, and movement patterns
- Stress levels, recovery scores, and wellness indicators
Health and biometric data is classified as sensitive personal data and is processed with significantly enhanced safeguards and protections as described in this policy.
1.3 Automatically Collected Information
When you use our website or applications, we may automatically collect:
- Device information (device type, operating system, browser type)
- Usage data (pages visited, features used, time spent)
- IP address and approximate geographic location (city/region level)
- Cookies and similar tracking technologies (see Section 7)
2. How We Use Your Information
We use the information we collect for the following purposes:
- Delivering our Services: To operate, maintain, and improve the Aura Clarus device, mobile applications, and website functionality
- Health insights: To process your health data and provide personalised health metrics, trends, alerts, and recommendations through the Aura Clarus application
- Account management: To create and manage your account, process orders, and provide customer support
- Communication: To send service-related notices, updates, security alerts, and promotional materials (with your consent)
- Research and improvement: To analyse aggregated, de-identified data to improve our algorithms, products, and services
- Legal compliance: To comply with applicable laws, regulations, and legal processes
- Safety and security: To detect, prevent, and address fraud, security issues, and technical problems
3. Legal Basis for Processing
We process your personal data on the following legal bases under applicable United States federal and state data-protection law and, where relevant, international data-protection frameworks:
- Consent: For processing health and biometric data, marketing communications, and cookies. You may withdraw consent at any time.
- Contractual necessity: To fulfil our obligations under the terms of service and deliver the Services you have requested.
- Legitimate interest: For product improvement, security, and fraud prevention, where such interests are not overridden by your rights.
- Legal obligation: To comply with applicable laws and regulations, including applicable United States federal and state data-protection and privacy laws.
4. How We Protect Your Data
We implement industry-standard technical and organisational measures to protect your personal and health data:
- End-to-end encryption for data transmitted between your device, our applications, and our servers
- AES-256 encryption for data at rest
- Secure, access-controlled cloud infrastructure hosted within certified data centres
- Regular security audits, vulnerability assessments, and penetration testing
- Strict access controls and role-based permissions for employees and contractors
- Mandatory data protection training for all personnel who handle personal data
While we take all reasonable precautions, no method of transmission or storage is completely secure. We cannot guarantee absolute security but are committed to promptly addressing any breach in accordance with applicable laws.
5. Data Sharing and Disclosure
IBT Aura does not sell, rent, trade, or otherwise commercially exploit your personal data. We may share your information only in the following limited circumstances:
- Service providers: With trusted third-party vendors who assist us in operating our Services (cloud hosting, payment processing, analytics), subject to strict contractual obligations of confidentiality and data protection
- Legal requirements: When required by law, regulation, legal process, or governmental request
- Safety: To protect the rights, property, or safety of IBT Aura, our users, or the public
- Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate notice to affected users
- With your consent: When you explicitly authorise sharing with a specific third party (such as a healthcare provider)
Health and biometric data is never shared with advertisers, data brokers, or any third party for marketing purposes.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
- Account data: Retained for the duration of your account and for a reasonable period thereafter for legal and administrative purposes
- Health data: Retained for as long as your account is active. You may request deletion at any time.
- Transaction records: Retained for the period required under applicable tax and financial regulations (typically as required under applicable United States federal and state law)
- Usage data: Retained in anonymised or aggregated form for analytics and product improvement
7. Cookies and Tracking Technologies
This section is our cookie policy. It explains what we store on your device, why, and how you can change or withdraw your choice at any time.
7.1 Your choice comes first
When you first visit our website we show a cookie banner. No analytics or marketing cookies are set, and no analytics script is even downloaded, until you choose to allow them. Until you make a choice, only essential cookies are used. You can accept all, reject everything that is not essential, or open Manage preferences to decide category by category.
7.2 The categories we use
- Essential (always on): Required for the website to work and to remember the cookie choice you made. These do not track you and cannot be switched off. This includes our own consent cookie,
aura_cookie_consent, which stores only your preference and the date you gave it, and expires after 180 days. - Analytics (off until you allow it): Google Analytics 4, used to understand which pages are read, how visitors move through the site, and what we should improve. This sets Google's
_gacookies. If you do not consent, the Google Analytics script is never loaded and these cookies are never created. - Marketing (off until you allow it): Reserved for measuring the performance of campaigns. We do not currently run any advertising or marketing cookies. The category exists so that, if we ever do, it stays under your control and off by default.
7.3 What analytics collects, and what it does not
If you allow analytics, we collect only aggregated, non-identifying usage information: pages viewed, approximate location at country or city level, referring site, device and browser type, and interactions such as clicking a call-to-action, downloading a document, starting an enquiry, or signing up for the beta.
We have deliberately limited what is sent. IP addresses are anonymised, advertising and personalisation signals are disabled unless you separately allow marketing, and we never send personal data to Google Analytics — no names, no email addresses, no message contents, and no health or wearable data. Where an interaction involves an email address, we record only that contact was initiated, never the address itself. Health data from the Aura Clarus device is never part of website analytics.
7.4 Who receives this information
Analytics data is processed by Google as our analytics provider. It is used only to produce reports for us and is not sold. Marketing cookies, should we introduce them, would be disclosed here before being switched on.
7.5 How to change or withdraw your consent
You can change your mind at any time, for any reason:
- Select Cookie Settings at the bottom of any page on this website to reopen your preferences and turn any category on or off.
- When you withdraw analytics consent, we stop analytics immediately and delete the Google Analytics cookies already stored in your browser.
- You can also block or delete cookies in your browser settings. Blocking essential cookies may stop parts of the site working, including our ability to remember that you declined.
Withdrawing consent does not affect the lawfulness of anything done before you withdrew it. If you clear your browser storage, your choice is forgotten and the banner will appear again on your next visit.
8. Your Rights
Under applicable United States federal and state data-protection laws, you have the following rights:
- Right to access: Request a copy of the personal data we hold about you
- Right to correction: Request correction of inaccurate or incomplete personal data
- Right to erasure: Request deletion of your personal data, subject to legal retention obligations
- Right to withdraw consent: Withdraw your consent for data processing at any time
- Right to grievance redressal: Lodge a complaint with us or with the relevant data protection authority
To exercise any of these rights, please contact us at contact@adarna.us. We will respond to your request within 30 days.
9. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without verified parental consent, we will take steps to delete such information promptly. If you believe a child has provided us with personal data, please contact us immediately.
10. International Data Transfers
Your data is primarily stored and processed in the United States. If we transfer data outside the United States for any purpose (such as cloud processing), we ensure that appropriate safeguards are in place, including contractual protections and compliance with applicable cross-border data-transfer regulations.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you through the Services or by other appropriate means. The "Last updated" date at the top of this policy indicates when it was most recently revised.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Adarna Inc.
28 Geary Street, Suite 650 #366,
San Francisco, CA 94108, United States
Email: contact@adarna.us