1. Information we collect
We collect the following information so the platform can work and stay secure:
- Account details — your name, username, email address, gender, and an optional profile picture. Gender is used to select your default 3D avatar.
- Google sign-in data — if you choose “Continue with Google”, we receive your name, email address, and profile picture from Google to create or link your account. We never receive your Google password.
- Session activity — sessions you host or attend, chat messages, quiz answers and scores, friend connections, and files you upload.
- Camera & microphone — when you join a live session you may share audio and video. If an instructor enables focus detection, your camera feed is analysed in your browser to estimate attention; see Section 3.
- Technical data — IP address, browser/device type, and approximate timing of requests, used for security, abuse prevention, and troubleshooting.
2. How we use your information
- To create and manage your account and authenticate you securely.
- To run live sessions: rendering avatars, delivering spatial audio/video, chat, and quizzes.
- To provide instructors with engagement and participation analytics for their own sessions.
- To protect the platform — detecting abuse, rate-limiting, and preventing unauthorised access.
- To respond to your requests and to improve the product.
3. Camera and focus detection
Some sessions use an optional focus-detection feature. When an instructor enables it, your device's camera is used to estimate whether you appear engaged. This analysis runs locally in your browser — your raw camera frames are notuploaded or stored by Aularis. Only derived signals (for example, a periodic “focused” or “distracted” status) may be shared with the instructor of that session and recorded as part of its analytics.
You remain in control of your camera and microphone through your browser's permissions and the in-session controls, and you can disable them at any time.
4. Cookies and local storage
We use a single secure, HTTP-only cookie to keep you signed in (your session refresh token). We also store a small amount of non-sensitive state in your browser's local storage, such as your display profile and preferences. We do not use advertising or third-party tracking cookies.
5. Third-party services
We rely on a few trusted providers to deliver core features:
- Google Sign-In — optional authentication.
- Media storage — uploaded images and files (e.g. profile pictures, slides) may be stored with a cloud storage provider.
- Real-time media — live audio and video are delivered through a real-time communication service.
- AI processing — features such as transcription, summaries, or quiz generation may process session content to produce those results.
These providers process data on our behalf and are not permitted to use it for their own purposes.
6. How we share information
We do not sell your personal information. Information is visible to others only as needed for the platform to function — for example, your name, username, and avatar are visible to other participants in sessions you join, and your chat messages are visible to that session. We may disclose information if required by law or to protect the rights, safety, and security of our users and the platform.
7. Data retention
We keep your information for as long as your account is active. When you delete your account, your profile is deactivated and your personal data is removed or anonymised, except where we must retain limited records for security or legal reasons.
8. Security
Passwords are hashed, authentication tokens are short-lived and rotated, and access to the platform is protected by rate-limiting and account-lockout safeguards. No system is perfectly secure, but we take reasonable measures to protect your information.
9. Your rights and choices
- Access and update your profile information from your account settings.
- Control camera and microphone access through your browser and in-session controls.
- Delete your account at any time, which removes or anonymises your personal data.
- Contact us to exercise any data-protection rights available to you under applicable law.
10. Children's privacy
Aularis is intended for use in educational settings by users old enough to consent to the processing of their data under their local laws. We do not knowingly collect personal information from children below that age without appropriate consent.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app.
12. Contact us
If you have questions about this policy or your data, contact us at amromsllam@gmail.com.
