Privacy policy
Your data.
Your choices.
This notice covers this informational website and the private Aura1v1 dance-battle beta. Browsing this website does not start a call, create an account or request camera access.
Effective 2026-09-09
Who is responsible
Maximilian Huang, Germany, operates Aura1v1 and is responsible for the processing described here.
Maxfeldhof 2
85716 Unterschleissheim
Germany
Contact for privacy requests: support@aura1v1.com.
Visiting this website
This informational site has no sign-in form, analytics scripts, advertising trackers, external fonts, camera access or application cookies. Its pages and styles are delivered through Cloudflare. Delivery and security infrastructure can process your IP address, requested URL, request time and browser/network information. The proposed legal basis is our legitimate interest in delivering and protecting the website (Article 6(1)(f) GDPR).
Accounts and Google sign-in
The beta uses Supabase for email/password and Google sign-in. Account information includes your email address, account identifier, confirmation status and profile. Passwords entered for email sign-in are sent securely through the application to Supabase for authentication. Choose a separate battle name during setup; the application does not use editable Google profile metadata as your battle name or permissions.
With Google sign-in, Google provides identity information to Supabase, which may include your Google identifier, email and verification status, name and profile image. Aura1v1 uses the account identifier and email for authentication and account management. Supabase may retain the Google profile information with the linked identity. The application does not request access to Gmail messages, contacts, Drive files or YouTube, and has no feature that sells Google user data, uses it for advertising or trains AI with it.
The intended purpose and legal basis for account processing is providing the beta service you request (Article 6(1)(b) GDPR). Google also handles information under its own privacy policy. You can remove the Google connection in your Google Account; that does not itself delete your Aura1v1 account.
During a battle
Your camera and microphone streams are sent to your opponent using WebRTC, directly or through a Cloudflare TURN relay when needed. Direct peer connections can reveal network addresses to the other participant. The application server coordinates the connection and receives your player name, match membership, permission choices, scores and temporary body-joint positions for recognition. Recognition processes camera frames in your browser and sends body landmarks, excluding facial landmarks, for server scoring. It does not perform identity recognition.
Normal calls are not continuously recorded by the application server, and the scoring code does not persist the body-landmark stream. Match results and permission records are stored. Your player name, identifier and game totals can appear in the beta leaderboard for other beta users. Scores are automated game results and can be wrong; this scoring feature does not make decisions with legal or similarly significant effects. Processing necessary to run the match is proposed under Article 6(1)(b) GDPR. Camera and microphone permission in the browser remains under your control.
Optional recordings and submitted clips
In-app recording is off unless both players allow it. It records both video feeds and voices in the browser for replay and download. Unsaved replays disappear when you leave or reload. Both players can keep downloaded copies; Aura1v1 cannot recall those files or prevent independent screen recording.
Separate social permission from both players, followed by an explicit submission, allows a completed clip to be uploaded for private operator review. Approval and export do not automatically post it. Social permission covers editing and posting the submitted video, names, images and voices on Aura1v1’s own social accounts; it does not cover paid advertising, resale or AI training. No public broadcast feature is offered by this site.
The proposed basis for these optional uses is consent (Article 6(1)(a) GDPR). You can play without giving either permission. Turn off recording or social permission in Video options, or use My videos to remove a submission or withdraw permissions. Withdrawal stops the relevant in-app use and invalidates applicable server-held submissions for your player identity. Clip files are removed; metadata about status and consent can remain. Withdrawal does not undo processing that was lawful before withdrawal or recall copies already downloaded or posted elsewhere. Contact the operator about removal of any externally published copy.
Safety, reports and service limits
Reports can contain a reason, time, match and participant identifiers. Block lists, ban decisions and operator review records support moderation. Usage counters include hashed player and IP identifiers; hashing does not make them anonymous. The proposed legal basis is the legitimate interest in investigating abuse, protecting participants and keeping the service available (Article 6(1)(f) GDPR). Do not include unnecessary sensitive information in a report.
The private beta uses Cloudflare Access for invited testers and Cloudflare Turnstile for protected account actions. These services process authentication or challenge information and network/device signals. This is separate from the public informational website.
Cookies and browser storage
In the beta, a secure HttpOnly cookie identifies a signed-in account session, and a short-lived cookie links the Google sign-in flow. The application session lasts at most one hour, or less if the provider token expires; the pending Google flow expires after ten minutes. Browser session storage remembers setup and pending actions. Private guest testing also uses a player token in local storage, which remains until removed. Clearing it can lose access to guest submissions. Cloudflare protection can set its own security cookies.
These functions support service or security actions you request. The intended terminal-access exemption is § 25(2) TDDDG where strictly necessary; consent must be assessed separately for any optional device storage or future tracking.
Who receives information and where
Your opponent receives the live call and gameplay information. The operator and the small moderation team helping him can review reports and submitted clips. Supabase provides accounts and profile storage, Google supplies Google sign-in, Fly.io hosts the beta application and local data volume, and Cloudflare provides public-site delivery, beta access protection, account challenges, email services and TURN relay services. No social platform receives a clip automatically from this implementation.
The beta application and attached volume run in Fly.io’s Frankfurt region. The configured Supabase database pooler is in AWS eu-west-1 (Ireland). Cloudflare, Fly.io, Supabase and Google can use subprocessors and process service, support or security data in other countries. Their published terms describe transfer safeguards such as adequacy decisions and Standard Contractual Clauses where applicable; this does not mean all processing stays in Germany or the EEA. Ask support@aura1v1.com for information about the safeguards relevant to a request. Cloudflare Email Routing and Email Sending support the project’s addresses; the public site itself sends no email.
How long information stays
Temporary scoring landmarks are used during the match without persistent storage by the scoring code. Unsaved browser replays last only while retained in the current page. Application session and Google-flow lifetimes are described above. Daily usage counters roll over on subsequent activity; this is not a guaranteed midnight disk-deletion job.
Uploaded clip files and detailed completed-match records are deleted or reduced to a minimal consent record after 30 days; an earlier withdrawal or valid erasure request can remove them sooner. Active accounts and setup records remain while the account is used and are removed through account deletion or a valid request, subject to the limits below. Reports, block lists and ban/audit records are kept while needed to investigate safety issues, enforce an active restriction, handle a dispute or meet legal obligations, and are reviewed manually because there is no automatic expiry for every safety record. Fly.io automatic volume snapshots expire after five days. Encrypted daily Supabase exports in private backup storage are pruned after seven days only after a newer export has passed its restore check. Separate manual recovery copies do not yet have a fixed automatic expiry and must be removed manually when replaced or no longer needed. Provider security and delivery logs follow the providers’ own settings and retention rules.
Requests and account deletion
You can request access, correction, erasure, restriction and, where applicable, portability, and object to processing based on legitimate interests. You can withdraw consent at any time. Send requests to support@aura1v1.com; only information reasonably needed to verify the request should be requested. You may complain to a data protection supervisory authority, including one where you live, work or believe an infringement occurred.
Email/password and Google accounts can be deleted in the beta. Deletion removes the authentication account and profile, related local match history and stored clip files, and revokes active Aura1v1 sessions. It replaces structured account identifiers in reports, but free-text report content can still identify someone. Ban/audit records, Paddle sandbox links and backup copies are not comprehensively erased by that flow, so deletion is not a promise of complete anonymization. The current beta has no live subscriptions; if live billing is introduced later, account deletion will not by itself cancel an active Paddle subscription unless that behavior is changed and verified.
The operator monitors incoming mail at support@aura1v1.com and handles privacy and moderation requests with help from a small team. The operator records the request, verifies account ownership proportionately, locates the relevant provider and application data, and replies. Never send a password. Requests are normally answered within one month; if the law permits more time, the reason and extension will be explained within that month. Account deletion and consent withdrawal are applied to active data first. Safety-report text, ban audit entries, Paddle sandbox links and backup copies can require separate review or remain until their applicable purpose or retention period ends.
What you need to provide
Account details and an 18+ confirmation are needed for managed-account play. Live battles need camera/microphone access and gameplay processing. Without those inputs the relevant feature cannot work. Recording and social permission are optional. No date-of-birth document check is implemented; the 18+ confirmation is a self-declaration.
Changes to this notice
Material changes to data use require an updated notice and, where necessary, a new choice before the new use begins. The date above identifies this version.