This page is maintained by the AURA Quest team to answer common security, privacy and safety questions. It describes our own practices — it is not a certification or an independent audit.
Sign-in is optional — you can play every quest without an account. If you do sign in, it uses email or Google through our hosting platform's managed authentication. We never see or store your password.
Only what the game needs: your display name, chosen role (student / parent / teacher), XP, streak and which quests you finished. Progress also saves in your browser so offline play works.
Every progress and profile row is protected by row-level security rules, so an account can only read and write its own data. Role assignment lives in a separate table that the app cannot edit from the browser.
AURA Quest runs on Lovable Cloud with a managed Postgres database and edge-served app code over HTTPS. AI replies and voice come from hosted model APIs called from the server, never with keys in your browser.
No ads, no ad networks, and no selling of data — ever. Chat messages are sent to the AI model to generate an answer and are not used to build a profile of your child.
Found a bug or a security issue? Please report it before sharing it publicly, and include the steps to reproduce it. We review reports and fix confirmed issues as a priority.
Last reviewed by the AURA Quest team. We update this page when our practices change.