Aurora privacy policy
Last updated 25 September 2026.
Aurora is a media player for the playlists and media servers you add to it. This page explains what the app stores and where it sends it. The short version: what you add and what you watch stays on your device, and the only servers Aurora talks to for your content are the ones you enter. We have no servers of our own. Two things leave the device that are not for your source: if the app crashes, it sends a report of the crash — built so that it cannot identify you — to an error-reporting service so that we can fix it; and the free version pays its way with ad breaks, and on a phone or tablet the ads in them come from Google, which collects data of its own as described below. Aurora Premium has no ads and never starts the ad software at all.
Who is responsible
Aurora is made by Rhythmcode, Unipessoal Lda, which is the controller, under the General Data Protection Regulation, for the little personal data Aurora's maker has any part in: the crash reports the app sends, the decision to include Google's advertising software in the free version, and the emails you send us.
Rhythmcode, Unipessoal Lda — NIPC 516661493 — Portugal.
Contact: support@rhythmcode.pt.
What Aurora stores on your device
- Playlists and logins. The addresses, usernames and passwords of the playlists and media servers you add. They are stored on the device so the app can sign in on your behalf. On Apple TV a copy is kept in the system's own settings store so it survives the system clearing caches.
- Catalog. A local copy of the channel, film and series listings your source publishes, so browsing and search work offline and quickly.
- Favourites and watch history, including how far into a film or episode you got, so the app can carry on where you left off.
- Settings, such as subtitle size, stream buffer and whether adult categories are hidden.
- Whether you have Premium, and how much you have watched since the last ad break. Neither is sent to us or to the ad software.
None of this is ever sent to us: it never leaves your device through Aurora, except as described in the next section. You can delete any of it at any time under Settings ▸ Clear stored data, and everything is deleted when you uninstall the app.
Device backups. On an iPhone or iPad, a backup of the device that you have switched on — to iCloud or to a computer — includes Aurora's stored data as it does other apps', under your own Apple Account. On Android, Aurora opts out of the system's backup. On a Windows PC or a Mac the data sits in your user profile, and is in whatever backups you make of it.
Where your data goes
- The source you added. To sign in, load listings and play streams, Aurora sends your credentials and requests directly to the server address you entered. Many such servers use plain HTTP, which is not encrypted; what they do with your data is governed by their terms, not this policy.
- Your Chromecast or AirPlay device. When you cast, the stream address is sent to the device you chose on your own network. Google's Cast framework on iPhone and iPad may collect device information under Google's privacy policy. When Aurora starts on an iPhone or iPad, that framework also asks a public service, ipify (api.ipify.org), for the device's public IP address, which that service necessarily sees; Aurora does not use or keep the answer.
- The App Store or Google Play, if you buy Premium. The purchase is made with the store, not with Aurora: the app never sees your payment details. It asks the store whether your store account owns Premium, and remembers the answer on the device.
- Google, for the ads in the free version's breaks — phones and tablets only. When a break offers an ad, it is loaded and shown by Google's advertising software (AdMob). Google receives your IP address, which shows roughly where you are; identifiers for the device, including its advertising identifier where you allow that; and which ads you were shown or tapped, along with diagnostics about the ad software itself. It uses these to choose, measure and guard ads against fraud, under Google's privacy policy and its page on how it uses data from apps that use its services. Aurora tells Google nothing about your playlists, your sources or what you watch, and the ad software is given no access to them.
- Sentry, for crash reports — every version. If Aurora crashes, or an error inside it is caught, it sends a report to Sentry, an error-reporting service, so that we can see what went wrong and fix it. A report says what failed and where in the app's code, the device model and system version, the app's version, whether it is the phone, TV or desktop version, and the app's last few steps before the failure — screens opened, buttons pressed. On an iPhone or iPad it can also carry Apple's own diagnostics of why the system stopped the app — running out of memory, say, or no longer responding — which Apple hands to the app on its next launch. It is built not to identify you: it carries no account, no name, no advertising or device identifier, no screenshot, and before a report the app assembles is sent, every address in it has the username and password blanked out, so a source's login never leaves the device in one. (A report of the app being killed outright, or of a crash below the app's own code, is written by the reporting library rather than by the app, and is set up to record no addresses and no identifier at all.) Your playlists, history and what you were watching are not in it. Sentry receives your IP address in delivering the report, as any server does, and we have set the reports up not to keep it. The legal detail is under Crash reports.
- Nowhere else. Aurora has no account system and no analytics, and no servers of its own. It does not send your playlists, credentials, history or viewing habits to the developer or to anyone else.
Ads: the legal detail
- Who decides what. We decide that the free version carries Google's ad software; Google decides, as a controller in its own right, what it does with the data that software collects. For people in the European Economic Area and Switzerland that is Google Ireland Limited; elsewhere, Google LLC. We never receive this data ourselves.
- Legal basis. In the European Economic Area, the United Kingdom and Switzerland, the ad software is started, and reads or stores anything on your device, only with your consent, given in Google's consent form. You are free to refuse: Aurora works the same, and you may see less tailored ads, or Aurora's own message in place of one. You can withdraw consent at any time under Settings ▸ About ▸ Ad privacy choices; withdrawing does not undo what was lawfully done before. Elsewhere, the same form offers the choices your local law requires.
- Transfers outside Europe. Google may process this data in the United States and other countries. Google states that it relies on the EU–US Data Privacy Framework and on standard contractual clauses for this; see its page on data transfer frameworks.
- How long. Google keeps ad data for the periods in its retention policy. We keep none.
Your choices about ads
- Nothing is loaded before you answer. In the European Economic Area, the United Kingdom and Switzerland, Aurora shows Google's consent form before the ad software is started, and starts it only once you have answered. You can change your answer at any time under Settings ▸ About ▸ Ad privacy choices.
- On iPhone and iPad, Apple's own prompt decides whether ads may use the device's advertising identifier. Saying no keeps the ads but makes them less tailored; you can change it under the system's Settings ▸ Privacy & Security ▸ Tracking.
- An ad is only ever shown when you ask for one, from Aurora's own break screen. Aurora never opens one by itself.
- On an Apple TV or an Android TV, the breaks show only Aurora's own message about Premium. The ad software is never started on a TV, no consent is asked for, and none of the above applies. The desktop app has no breaks and no ad software at all.
- Premium removes the breaks, and with them every ad. On a device where Premium is active the ad software is never started.
Crash reports: the legal detail
- What and why. A crash report is the only data about the app's use that reaches us, and it exists so that a fault found on one device can be fixed for everyone. Reports are looked at by the developer to find and fix faults, and for nothing else: not to measure how the app is used, and never to advertise.
- Legal basis. Our legitimate interest in keeping the app working (Article 6(1)(f) of the GDPR), weighed against a report that has been stripped of anything that would name you. No consent is asked for, as none is needed for a diagnostic report of this kind; the app reads or stores nothing on your device for it beyond the report waiting to be sent.
- Who processes it. Functional Software, Inc., trading as Sentry, San Francisco, as our processor under its data processing addendum. Reports are stored in Sentry's European Union region, in Frankfurt, and do not leave it.
- How long. Sentry deletes a report ninety days after it arrives. We keep no copy.
- Your choices. Because a report carries nothing that identifies you, we cannot pick yours out to show you or delete it; the ninety days do that. You have the right to object to this processing, and can do so by writing to us; there is no switch for it in the app in this version.
If you write to us
If you email us, we use your address and what you wrote to answer you and to deal with the matter — our legitimate interest in replying to people who contact us, or a legal obligation where your message is a complaint or a legal request. We keep the correspondence no longer than that needs, and share it with no one except the company that hosts our email, or where the law requires.
Your rights
Under the General Data Protection Regulation you have the right to ask for access to your personal data, to have it corrected or erased, to restrict or object to its use, to receive it in a portable form, and to withdraw a consent you gave. Because Aurora keeps your data on your own device and we hold none of it, most of this is in your own hands: Settings ▸ Clear stored data erases it. For the data Google's ad software collected, Google's own tools — linked from its privacy policy — are the direct route, and we will help if you write to us. The only data we hold ourselves is any email you sent us, and the crash reports, which are not tied to you.
You also have the right to complain to a data protection authority: in Portugal the Comissão Nacional de Proteção de Dados (cnpd.pt), or the authority of the country where you live.
Aurora makes no automated decisions about you, and does not sell your data.
Children
Aurora is rated for adults because it plays whatever a source you add carries, and is not meant for anyone under 18. It hides categories labelled as adult by default. It is not directed at children, and Aurora itself collects nothing about anyone beyond the crash reports described above, which name no one; what the ad software collects in the free version is described above.
Changes and contact
If this policy changes, the date above changes with it and the new text is published here. Questions go to support@rhythmcode.pt.