Privacy
Last updated: September 26, 2026
AURA ENGINE (auraengine.io) is run by Psy-Opt-In. This page describes what the engine keeps today, where it goes, and for how long, as read from the engine's code. It describes how the engine works now; it is not a promise about tomorrow. When the code changes, this page changes with it and the date at the top moves.
The short version
- No accounts. No ad networks and no ad tracking: the only ads are the clearly labeled sponsor spaces, and they track nothing. No tracking across other sites. Nothing is sold.
- Your IP address is not stored. Where the engine needs to count "one connection" (to stop floods), it keeps a salted, one-way hash of it.
- Reading time: while a page is on screen and you are using it (you scrolled, tapped, typed or moved the pointer in the last 30 seconds), the page counts the seconds and sends only that number. It goes into one daily total. A tab left open counts nothing, and nothing about who you are is kept with it.
- Most of what the engine does is public on purpose (the log, the receipts, the book of deeds). What you write privately stays private.
Cookies and your browser
- aura_d and aura_b: a random number, no name attached, kept for up to 400 days. They let the button and the book of deeds count one device, so one person cannot flood them. Only a hash of the number is stored.
- Your callsign, if you enlist, is saved in your own browser (localStorage) so you do not have to retype it.
- aura:met: a yes/no in your browser (localStorage) so Soteira's welcome on the home page shows only on your first visit.
- The owner's own key, only on the owner's device, is kept for the browser session (sessionStorage).
- Nothing else is stored in your browser.
What the engine keeps, and for how long
- Button presses: what the engine did, what it acted on, and a hash of your connection and device. Kept as part of the public record, with nothing that names you.
- Signals ("I can offer" / "I need"): the kind, borough and tag are kept for the counts. Your text, handle and email are erased when the signal's 14 days end. An email is erased as soon as its one introduction is sent.
- Introductions: when two signals are paired and both left an email, one email goes to both of you together, so each of you sees the other's address and words. That is the point of an introduction.
- Enlisting: your division, borough, callsign, and the handle or email you chose to give. Kept until you ask for it to be deleted. The email is not used yet.
- Field reports: the outcome counts are public. A note you write goes only to a person at the desk and is not shown in public.
- Book of deeds: the line you file, its evidence link and borough are public. Hashes of your connection and device are kept to enforce the daily limit.
- Personal agents (the store): what one keeps is set out where it is sold.
- Payments: Stripe handles your card; the engine does not see it. We keep the amount, what it paid for, Stripe's reference, and a hash of the email to count repeat supporters. The company's books are private: no page shows who paid or how much.
- Attention spaces: the name, link and words a sponsor buys are public for the time bought, and kept in a history of the last 500.
- Messages the engine sends: everything the engine sends on its own (an answer on Bluesky, a notice to an organization that its help page broke) is kept in its sent record for three years: who it went to, what it said, why and when. The public page at /sent shortens email addresses to the organization. Reply STOP to any message and the engine stops writing to you.
- Contact messages and email: kept privately for 90 days, then deleted. When you buy an agent, the email from checkout is kept as a one-way hash on that agent so you can sign in later with a link (/login); the address itself is kept only if you asked for shift reports, and a sign-in link is sent only to an address that owns an agent. Mail to hello@psyoptin.com is sorted by fixed rules (no model reads it), gets at most one automated receipt a day, and is passed to a person when it needs one. Links you send may be checked once. Used only to reply.
- Talking to Soteira, the Voice or the letter helper: what you type is not stored by the engine. Only a count per hashed connection is kept, for 2 days, to enforce the daily limit.
Who else handles data
- Cloudflare hosts the engine, keeps short-lived request logs, runs its language and image models and Soteira's voice (text sent to make audio; the audio is cached for 30 days, keyed by the text), and sends the engine's email.
- Anthropic (Claude): when Soteira runs on Claude, what you type to her and the engine's public record go to Anthropic to produce the answer.
- Stripe processes payments and collects the email you give it at checkout.
- Google Fonts (the home page and Soteira's page) and jsDelivr (the code that draws Soteira) are loaded from their servers, so they see your IP address like any website you visit.
- Your browser's speech service: if you press Soteira's microphone, your browser (for example Chrome, which uses Google) turns your voice into text.
- Bluesky, Telegram, X and the Wayback Machine receive only the engine's own posts and the public pages it saves, not your data.
Public posts about the engine
The Anti-Slop Defense Division reads public Bluesky posts that mention the engine, slop or look-alike projects, and keeps the handle, link and text, with a label. They are public posts, shown at /sentiment. The engine does not reply. To have a post of yours removed from the list, use the contact page.
Public posts about New York (the mood readings)
To read how each borough feels, the engine reads public posts about the city: Bluesky search, public Mastodon hashtags, the public Lemmy NYC forum, and titles and descriptions of public YouTube videos. Each post is scored for mood in memory and then dropped. The engine keeps only a count and a mood per borough. It does not keep a post, a name, a handle, a photo or anyone's location, and it reads nothing private. The city's live traffic speeds are read the same way, as one number per borough. How it works, in full: /studies/how-the-vibes-are-measured.
The Watch
If you ask the engine to watch an address (at /watch or with /watch on the Telegram bot), it keeps that address, what you chose to watch, and where to send the alerts (an email address, or the Telegram chat you wrote from), for as long as the watch runs. It keeps the ids of the public records it has already told you about, so it does not repeat one. Alerts quote the city's public records (HPD, DOB, ECB/OATH, 311, permitted events, film permits, restaurant inspections) and link to them; they are not advice. Every message carries a stop link; /unwatch stops Telegram watches. When you stop, the contact is no longer used and the watch is not re-armed. Nothing about a watch is shown publicly, sold, or shared.
Children
The site is not meant for children under 13, and the engine does not knowingly keep data about them. If you think a child has left something here, say so through the contact page and it is removed.
Your choices
You can ask us to delete anything we can connect to you (a signal, an enlistment, a patron record, a message) through the contact page. Hashed counts cannot be traced back to anyone, so there is nothing in them to delete.
Changes and contact
When the code changes what it keeps, this page changes with it and the date at the top moves. Questions: the contact page.