World map

Trust & Safety

This page is maintained by the AURA Quest team to answer common security, privacy and safety questions. It describes our own practices — it is not a certification or an independent audit.

Accounts & sign-in

Sign-in is optional — you can play every quest without an account. If you do sign in, it uses email or Google through our hosting platform's managed authentication. We never see or store your password.

What we store

Only what the game needs: your display name, chosen role (student / parent / teacher), XP, streak and which quests you finished. Progress also saves in your browser so offline play works.

Who can read it

Every progress and profile row is protected by row-level security rules, so an account can only read and write its own data. Role assignment lives in a separate table that the app cannot edit from the browser.

Platform & hosting

AURA Quest runs on Lovable Cloud with a managed Postgres database and edge-served app code over HTTPS. AI replies and voice come from hosted model APIs called from the server, never with keys in your browser.

Kids, ads & tracking

No ads, no ad networks, and no selling of data — ever. Chat messages are sent to the AI model to generate an answer and are not used to build a profile of your child.

Reporting a problem

Found a bug or a security issue? Please report it before sharing it publicly, and include the steps to reproduce it. We review reports and fix confirmed issues as a priority.

Shared responsibility

  • The platform provides managed authentication, an encrypted-in-transit database, and hosting.
  • We write and review the access rules, keep API keys server-side, and fix reported issues.
  • You keep your email account secure and supervise young players — a grown-up should set up the account for children.

Last reviewed by the AURA Quest team. We update this page when our practices change.