Privacy Policy

Last updated: September 7, 2026

Application Scope and Developer Identity

This Privacy Policy applies solely and exclusively to the mobile software application designated as Aurion (hereinafter referred to as the "App"), which is made available for download through the Google Play platform.

The App is developed, held, and administered by Perawat 24 (hereinafter referred to as the "Developer," "we," "our," or "us"). Any and all references to "we," "our," or "us" within this Privacy Policy shall be construed as referring to Perawat 24, being the legal entity that bears responsibility for the operation, maintenance, and management of Aurion.

In the event that you have obtained Aurion via Google Play, this Privacy Policy shall serve as the governing instrument with respect to the collection, utilization, retention, and sharing of your personal data and related information during your engagement with the App.

Operational Workflow Overview

The following steps outline the sequential process by which our Service operates:

  1. Users are required to upload photographic images to the application and subsequently select a preferred template configuration from the available options.
  2. A dedicated instance of the underlying stable diffusion model is subjected to fine-tuning procedures, utilizing the submitted imagery as the training corpus for the purpose of delivering a customized user experience.
  3. Upon successful completion of the fine-tuning phase, the system proceeds to generate a personalized avatar output that reflects the characteristics derived from the user-specific model.
  4. Following the generation and delivery of the avatar, both the original uploaded photographs and the fine-tuned model instance are subjected to permanent deletion from our server infrastructure. Users are hereby reminded that certain usage restrictions apply to the generated avatars---specifically, the creation of nude or sexually explicit imagery is strictly forbidden, as is the unauthorized use of photographs belonging to other individuals.
  5. Under no circumstances shall your personal data be repurposed for the training of general-purpose models or for the development of any other independent artificial intelligence products or services.

On-Demand Cloud-Based Processing

Aurion offers a selection of artificial intelligence-driven functionalities---including but not limited to image editing, visual enhancement, and graphical rendering---that are executed via secure remote server infrastructure. Such cloud-based processing is activated solely in response to your deliberate engagement with a feature that necessitates computational resources beyond the capabilities of your local device, and only when you have explicitly initiated such an action within the application.

Upload Initiation Conditions

Media files---including images, video recordings, and other forms of digital content---are transmitted to our protected server environment solely upon your affirmative and deliberate selection of a cloud-reliant feature, followed by your explicit action to commence the processing workflow. Aurion does not engage in any automatic, background, or unattended uploading of your personal media assets at any time. Prior to the commencement of any data transmission, the App provides clear and conspicuous notification that the selected function requires remote cloud-based computation.

Data Storage Period and Disposal Protocol

Uploaded media assets are retained exclusively for the duration required to fulfil the specific processing request you have initiated. Upon completion of the processing operation, both the original source files and any resultant output are subject to automatic and permanent deletion within a period not exceeding 72 hours. Perawat 24 does not maintain archival copies, backup versions, or redundant storage of your uploaded content, nor is your content utilized for promotional campaigns, algorithmic training, behavioral analysis, or any purpose unrelated to the immediate service request.

Security Measures

All data transmissions to and from our servers are safeguarded through industry-standard TLS encryption protocols. Access privileges to uploaded content are stringently limited to automated processing pipelines and authorized system components that are essential for the delivery of the requested functionality.

Content Notice

We strive to configure the AI model as appropriately as possible. However, you may still encounter content that feels unsuitable for you. If you see anything offensive or inappropriate, please report it to us at perawat.247@gmail.com. We will take prompt action, and your feedback also helps us improve the algorithm over time.

Categories of Information Collected

  1. Platform Interaction Data
    We may gather information pertaining to your engagement with our Platforms, including but not limited to browsing patterns, click activity, content downloads, shared materials, video manipulation actions, and any other inputs you supply during your use of our services. Such data enables us to provide and maintain the core functionalities of the Platform.
  2. Device and Operational Log Data
    In order to ensure system stability, safeguard security, enhance user experience, facilitate advertising and notification delivery, and protect the integrity of your account, we collect certain device-related and log-based information when you access our services. This includes: device identifiers (including unique device ID and GAID), hardware model, system language settings, geographic country, advertising ID, operating system version, IP address, software build number, network connection type, connection quality indicators, and service logs.
  3. Customer Support and Feedback Data
    When you contact us for technical assistance or to submit feedback, we collect the content of your communications and any accompanying materials, along with your contact information (including telephone number and email address). This allows us to respond effectively to your concerns and provide appropriate support.
  4. Facial Feature Processing Data
    When utilizing our facial editing or compositing functionalities, we automatically detect the spatial positioning and morphological characteristics of your facial features to derive the necessary analytical inputs for image manipulation. The resulting output renderings are then delivered back to you. We do not permanently store these photographs, videos, facial geometry data, or output renderings, nor are they shared with any external parties. This processing is executed solely for the purpose of enabling face-related features and refining the quality of your final outputs. Should your editing involve facial representations of other individuals, you bear sole responsibility for notifying them and securing their explicit consent.
  5. Temporary Cloud-Based Processing
    To deliver prompt and precise processing of images or video content, we may provisionally transfer your materials or associated metadata to a cloud environment for the generation of requested effects. Such uploads are strictly confined to the specific operation you have initiated. We neither retain these materials, labels, or related data beyond the duration required for the task, nor do we repurpose them for any other objective or disclose them to any third party.

Device Authorization Requirements

In order to deliver enhanced product functionality, efficient service delivery, and an optimized user experience, we may seek certain permissions from your device when activating supplementary features. Subject to your explicit consent and in accordance with the principle of data minimization---whereby we collect only the least amount of information necessary---we may access the following permissions and the associated data types:

  1. Read/Write External Storage Permission -- Used to read from and write to your device's external memory card for video editing purposes.
  2. Camera Permission -- Allows you to take photos and record videos within the app.
  3. Network Access Permission -- Enables various online services, such as accessing and downloading materials.

Permission Sensitivity and User Control

The information associated with these permissions is classified as sensitive in nature. Should you choose to decline any specific permission, such action will merely restrict your access to the particular feature that depends on that permission; your continued use of all other application functionalities will remain unaffected. You may at any time review the current status of your granted permissions via the system settings interface on your device. The decision to enable or disable any or all of these permissions rests entirely within your discretion.

It is important to understand that by granting a permission, you thereby authorize us to collect and process the corresponding personal data exclusively for the purpose of delivering the associated service. If you subsequently revoke a permission, such revocation shall operate as a cancellation of your prior consent, and we will cease any further collection or usage of personal information predicated on that permission from that moment onward. Nevertheless, the deactivation of a permission shall not retroactively affect any data acquisition or processing activities that occurred during the period when the permission remained active.

Third-Party SDKs and Service Providers

To deliver core features, process analytics, and support in-app purchases, Aurion integrates with the following third-party software development kits (SDKs). Each SDK may collect and process certain device and usage data as described below. All such processing occurs only after you have consented to this Privacy Policy.

  1. AppsFlyer (provided by AppsFlyer Ltd.)
    Purpose: Mobile attribution, marketing analytics, and campaign performance tracking.
    Data collected: Device identifiers (Android ID, Google Advertising ID), IP address, app install source (referrer), conversion events, and in-app user actions. This data helps us understand how you discovered our app and improve our promotional activities.
  2. Google Play Billing (provided by Google LLC)
    Purpose: Processing in-app purchases and subscription transactions.
    Data collected: Purchase details, transaction history, and order identifiers. We do not store or have access to your full payment card information; all payment data is handled directly by Google Play.
  3. Google Install Referrer (provided by Google LLC)
    Purpose: Identifying the source (channel) that led to your app installation.
    Data collected: Referrer information (e.g., which campaign or ad led to the install) and installation timestamp. This data is used exclusively for attribution analysis.
  4. Google Ads Identifier & AppSet ID (provided by Google LLC)
    Purpose: Providing anonymized identifiers for analytics and ad performance measurement.
    Data collected: Google Advertising ID (AAID) and AppSet ID. You may reset or limit these identifiers at any time via your device settings.
  5. Google Sign-In (provided by Google LLC)
    Purpose: Enabling Google account-based login and authentication.
    Data collected: Only when you actively choose to sign in, we receive your basic profile information (name and email address) as provided by your Google account. No data is collected passively.
  6. Functional Libraries (No Data Collection)
    The following tools are used solely for technical operations such as networking, image loading, media playback, local storage, and background scheduling. They do not collect, transmit, or process any personal data: Retrofit & OkHttp (networking), Glide (image loading), ExoPlayer (media playback), DataStore (local preferences), WorkManager (background tasks), and Hilt (dependency injection).

Usage Analytics and Aggregated Insights

We engage in the collection and examination of data for the ongoing enhancement of our Service and the optimization of user experience. Such information is processed in a consolidated and aggregated format, enabling us to gain a more comprehensive understanding of utilization trends and to refine our product offerings accordingly. These summarized analytical findings may be disseminated to our affiliated entities, authorized agents, and commercial partners for purposes related to research initiatives, product development efforts, and strategic business planning. We confirm that all such data is rendered fully anonymized prior to any disclosure and does not contain any information that could identify you individually or your end users personally.

Purposes of Information Utilization

We may process the data you supply to us, in a manner consistent with the provisions of this Privacy Policy, for the purpose of rendering our services or maintaining communication with you. The principal applications of your information include, but are not limited to, the following:

  1. Service Optimization and Product Development
    Your data contributes to the creation, deployment, operation, and ongoing refinement of our product portfolio. By way of illustration, analyzing user interaction patterns with our platform enables us to verify that the interface remains accessible and user-friendly.
  2. Security and Protective Functions
    We employ your information to uphold the integrity of user accounts and the security of our network infrastructure, thereby safeguarding our services for the entire user community. This may encompass preliminary content filtering or automated scanning of uploaded materials to detect potentially unlawful content. Furthermore, your data may be utilized for risk mitigation, user security assistance, and other associated protective measures.
  3. Delivery of Essential Notifications
    Your information serves as the basis for transmitting critical communications to you, including alerts concerning your account status and notifications regarding updates to our terms, conditions, or policies.
  4. Legal Compliance and Record-Keeping
    We preserve and administer your information to the extent necessary for fulfilling our statutory and regulatory obligations. This includes the recording, auditing, analysis, and processing of your data in accordance with applicable legal requirements, which may extend to emergency situations as warranted by law.

Your Choices

You may limit data collection by:

Your Right to Delete Data

While using our app, you retain full control over your information and may delete saved records at any time. We are committed to protecting your privacy and ensuring that data removal is possible. You can clear your history and other stored information through the app's settings menu. Additionally, uninstalling the app will automatically erase any data stored locally on your device. Please be aware that once data is deleted, it cannot be restored. If you have any questions regarding your deletion rights, feel free to reach out to our support team for help.

Cookies and Related Data Technologies

In common with the majority of online service providers, we employ cookies, web beacons, and analogous technologies. Cookies are compact text files that are stored on your hard drive or within your device's memory, retaining information concerning your usage of our services. These facilitate functions including user authentication, preservation of your preferences and configuration settings, analysis of traffic patterns and usage behavior, evaluation of advertising campaign performance, and support for social media integration. Web beacons are embedded software elements placed within web pages or email communications that enable us to gain insight into your engagement with that content.

By default, most web browsers are configured to accept cookies. Should you prefer otherwise, you may typically modify your browser settings to restrict or delete cookie storage. We wish to advise, however, that such adjustments may impact the accessibility and full functionality of our services.

To measure traffic volume and usage patterns across our services, we utilize third-party analytics solutions. These tools collect data transmitted from your device or through our services, including the pages you view, the extensions you employ, and other usage metrics that assist us in enhancing our product offerings. The information gathered through these analytics is aggregated with comparable data from other users and does not reasonably permit identification of any specific individual.

Our collaboration with third-party advertising agencies involves the delivery of promotional content across internet platforms and other media. In order to evaluate campaign effectiveness and determine compensation to these agencies, we incorporate third-party modules into our applications. We may also integrate such modules to better comprehend user interaction patterns with our services.

How Long We Keep Your Personal Information

We retain your personal data for a period of 48 months. We may keep and use your information as necessary to fulfill legal obligations (for example, complying with applicable laws), resolve disputes, and enforce our agreements and policies.

We also retain Usage Data for internal analytical purposes. This type of data is generally kept for a shorter duration unless it is needed to enhance security, improve our Service functionality, or we are legally required to retain it for a longer period.

Disclosure of Personal Data

We do not engage in the sale, lease, or rental of your personal information to any external parties. The third-party software development kits (SDKs) integrated into our platform transmit data solely to their respective providers, strictly for the purposes expressly stated in their documentation. We impose contractual obligations upon these providers to ensure that all data processing activities are conducted in full compliance with applicable privacy legislation.

Conditions Under Which Information Is Disclosed

Perawat 24 does not sell, lease, or otherwise trade your personal data to any third-party organization. We disclose personal information only under the following circumstances: when such disclosure is essential to deliver the services you have requested, to operate and maintain the functionality of Aurion, to process transactions you have initiated, to fulfill legal obligations to which we are subject, or to defend our legal interests and the integrity of our service infrastructure.

Third-Party Service Providers

In order to deliver the core functionality of Aurion, we engage a limited number of carefully vetted third-party service providers. These entities furnish essential services including user authentication, payment transaction processing, analytics and usage measurement, installation source attribution, cloud-based hosting infrastructure, fraud mitigation, and application performance oversight.

Depending on the feature you use, these providers may process limited categories of information, including:

Each third-party provider processes personal information solely for the purpose of delivering the services they perform on our behalf and in accordance with their own privacy policies and applicable data protection laws. We do not authorize our service providers to use your personal information for their own independent advertising or marketing purposes.

AI-Mediated Content Processing

Any photos, video files, or other media that you voluntarily submit for AI-assisted processing are employed exclusively for the purpose of producing the outputs you have explicitly requested. Under no circumstances is your uploaded content sold, licensed, or otherwise made available to third parties for advertising initiatives, user profiling, or the training of foundational artificial intelligence systems. All submitted media are processed strictly in connection with the specific service you have invoked and are automatically expunged in accordance with the data retention schedule set forth in this Privacy Policy.

Legal Disclosure

We may disclose your personal information only when we believe such disclosure is necessary to:

Business Transfers

If Aurion or Perawat 24 becomes involved in a merger, acquisition, corporate reorganization, financing, sale of assets, or similar business transaction, your personal information may be transferred as part of that transaction.

In such cases, the receiving entity will be required to protect your personal information under privacy protections that are substantially equivalent to those described in this Privacy Policy and in accordance with applicable data protection laws.

Data Security and Protective Safeguards

We take the protection of your personal information with the utmost seriousness. In order to mitigate risks associated with unauthorized access, inadvertent disclosure, or other potential threats, we have instituted reasonable physical, technical, and administrative controls over the data collected through your use of our Platform services. We are steadfast in our commitment to applying all reasonable efforts to safeguard your information.

Our security protocols are subject to periodic review and are updated as circumstances warrant, in response to evolving business operations, advances in technology, and changes in applicable legal standards. These protective measures encompass, but are not limited to, the implementation of technical and organizational security frameworks, role-based access restrictions, and ongoing employee awareness and training initiatives.

Although we place significant emphasis on the protection of your data, it is important to recognize that no transmission method over the internet or electronic storage system can be guaranteed as completely invulnerable. While we endeavor to secure your personal information through measures consistent with industry standards, we cannot offer an absolute assurance of security.

Should we become aware of a security incident that has compromised your personal information, we will provide notification to you in accordance with applicable legal requirements. By utilizing the Platform, you consent to receive such notifications through electronic means.

Your Privacy Entitlements

Should you wish to obtain further information regarding your statutory rights under applicable data protection laws, or if you intend to exercise any such rights, you are invited to contact us through the channels specified in the "How to Contact Us" section of this document. Subject to the provisions of your local legal framework, you may be entitled to request that we undertake the following actions:

  1. Provide access to, or a copy of, certain personal information we hold about you.
  2. Stop using your information for direct marketing purposes, including any marketing activities based on profiling.
  3. Correct any outdated or inaccurate information we have about you.
  4. Erase specific information we maintain on you.
  5. Limit how we process or share certain information related to you.
  6. Transfer your information to another third-party service provider.
  7. Withdraw any consent you previously gave regarding the processing of your information.

We will evaluate all requests and respond within the timeframe required by applicable law. Please be aware that in some situations, certain information may not be subject to such requests --- for example, if we need to continue processing your data to protect our legitimate interests or to comply with legal obligations. Before processing your request, we may ask you to provide reasonable information to verify your identity.

Protection of Minor Users' Privacy

Our Services are not intended for individuals under the age of 18 (hereinafter "Minors"). We do not knowingly collect or solicit personally identifiable information from any person falling below this age threshold. Should you be a parent or legal guardian and become aware that your child has submitted Personal Data to us, we kindly request that you contact us without delay. Upon verification that such information has been collected absent verifiable parental consent, we will take prompt and appropriate measures to expunge it from our systems.

Rights Under CCPA, VCDPA, GDPR, and LGPD

We strictly comply with the privacy obligations prescribed by the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), the General Data Protection Regulation (GDPR) of the European Union, and Brazil's Lei Geral de Proteção de Dados (LGPD). For users resident in any of these jurisdictions, applicable law entitles you to certain rights, including the right to access, rectify, erase, or object to the processing of your personal information. To exercise any of these rights, please direct your request to our support team, who will assist you accordingly.

Legal Grounds for Processing Your Data

We process your personal information in compliance with relevant data protection laws, including the General Data Protection Regulation (GDPR). Depending on the specific purpose of processing, we rely on one or more of the following legal bases:

  1. Legitimate Interests
    We may process certain non-sensitive data to pursue our legitimate interests, which include:
    • Enhancing the performance and user experience of our applications.
    • Maintaining the security and reliability of our apps and services.
    • Studying app usage patterns to better inform future development.
    When relying on legitimate interests, we carefully weigh our interests against your rights and freedoms.
  2. Legal Obligations
    In certain situations, we are required to process your data to meet legal obligations, such as complying with applicable financial, tax, or regulatory requirements.
  3. Vital Interests
    In exceptional circumstances, we may process your data to protect your vital interests or those of another person --- for example, in response to a security incident affecting an application.

Right to Submit a Complaint

If you believe that our handling of your personal data contravenes applicable data protection legislation or otherwise infringes upon your rights under such laws, you are entitled to lodge a complaint with the competent supervisory authority. This right extends, for instance, to residents of the European Union under the General Data Protection Regulation (GDPR), as well as to individuals in other jurisdictions where local privacy laws confer similar entitlements.

Filing a Complaint

Should you wish to exercise your right to file a complaint, you may contact the data protection authority established in your country of residence. Contact details for such authorities are generally accessible through their respective official websites. Alternatively, you may reach out to us directly, and we will provide appropriate assistance to help direct your inquiry.

Prior Informal Resolution

Prior to elevating any concern to the level of a formal complaint, we respectfully request that you first get in touch with us so that we may make every reasonable effort to resolve your issues amicably. You may direct your inquiries to our Data Protection Officer (DPO) or reach us via email at perawat.247@gmail.com.

Data Controller Identification

For the purposes of applicable data protection regulations, the data controller responsible for the processing of personal information collected through Aurion is Perawat 24. Perawat 24 exercises authority over the purposes and methods of personal data processing and bears the responsibility for ensuring ongoing compliance with relevant privacy legislation. Should you have any privacy-related questions or concerns, please do not hesitate to contact us at perawat.247@gmail.com.

Data Protection Officer

We have appointed a Data Protection Officer to oversee our privacy practices. The DPO can be contacted as follows:

Amendments to This Privacy Policy

We reserve the right to update or modify this Privacy Policy as necessary from time to time. We recommend that you periodically revisit this page to remain informed of any changes. In the event of a revision, we will publish the updated version on this same page. All such modifications shall become effective immediately upon the date of publication.

Contact Us

Should you have any inquiries, reservations, or recommendations concerning our Privacy Policy, we welcome you to reach out to us at perawat.247@gmail.com.