1. Introduction
This Privacy Policy (“Policy”) describes how Calming Aura Studios LLC (“we,” “us,” or “our”) collects, uses, and shares information when you use the Asset Recovery family of mobile applications (the “Apps”), including Asset Recovery: Missing Cash, Law Payouts, Tax Refund, Lost 401k, and Cash Audit.
By downloading, accessing, or using any Asset Recovery app, you agree to this Privacy Policy. If you do not agree, do not use the Apps.
2. Information we collect
We collect information in the categories below, depending on how you use the Apps.
2.1 Account and authentication (optional)
You may use the Apps without an account. If you create an account, we collect:
- Identifiers: Email address, user ID issued by our authentication provider, and (if you use them) identifiers from Apple or Google when you sign in with those services.
- Credentials: Password (stored securely by our provider; we do not store your password in plain text).
- Profile: Display name or similar profile fields you choose to provide.
2.2 App content and usage data
When you use core features, we process information you enter, such as:
- Wizard and checklist responses (e.g., state, name, employer, years, check types)
- Search results you log (found / none / pending, amounts, notes, claim status)
- Reminder preferences and scheduled reminder metadata
- Checklist completion state
This data is stored locally on your device and, if you are signed in, synced to our backend so you can access it across devices.
2.3 Payments and subscriptions
The Apps are currently free. If we add paid features in the future:
- Subscription status: We may store your subscription tier and related metadata as needed to enforce plan limits.
- Payment details: Purchases would be processed by Apple (App Store) or Google (Google Play). We would not receive or store your full payment card number.
2.4 Device, technical, and usage data
- Device and app info: Device type, operating system version, app version, and similar technical data.
- Analytics: We use PostHog to collect usage events (e.g., screen views, wizard steps, link opens, cross-app promotions) to improve the Apps. Analytics payloads are designed to avoid sensitive identifiers such as Social Security numbers, full street addresses, or complete financial account numbers.
- Advertising: When ads are enabled, Google AdMob may collect device and ad interaction data per Google’s policies.
- Affiliate and monetization metadata: We may log affiliate link clicks (app identifier, link key, timestamp) locally and in our backend when configured.
- Push notifications: If you enable reminders, we process tokens and preferences needed to deliver local notifications you configure.
2.5 Communications
- Support: If you contact us, we process your email address and message content to respond.
- Transactional email: If you request a password reset, we process your email address to send a one-time verification code via our email provider (Resend).
2.6 Sensitive information
The Apps may ask you to enter information (e.g., name, state, employer) to build links to official government or third-party search tools. Do not enter your Social Security number, bank account numbers, or other highly sensitive identifiers in the Apps unless a specific official site requires it—and then only on that official site, not in our Apps.
We do not intentionally collect health information, precise geolocation for tracking, or government ID numbers through the Apps.
3. How we use your information
We use the information above to:
- Provide, operate, and improve the Apps (personalized links, claim guidance, reminders, checklists)
- Create and maintain your account and authenticate you when you sign in
- Sync your data across devices for signed-in users
- Send local push notifications for reminders you configure
- Analyze usage in aggregate to improve reliability and features
- Measure affiliate and cross-promotion effectiveness
- Deliver transactional messages (e.g., password reset codes)
- Protect security, detect abuse, and comply with law
We do not sell your personal information as that term is commonly defined under applicable privacy laws (including CCPA).
4. How we share your information
4.1 Service providers (processors)
We use third-party services that process data on our behalf under contractual safeguards, including:
| Category | Examples of use |
|---|---|
| Backend, database, authentication | Supabase (hosted infrastructure, authentication, database, cloud sync) |
| Email delivery | Resend (transactional email such as password reset codes) |
| Analytics | PostHog (product analytics and usage measurement) |
| Advertising | Google AdMob (in-app banner ads when enabled) |
| Mobile platform services | Apple, Google (sign-in when enabled, in-app purchases if added, push notification infrastructure) |
| App builds and updates | Expo / EAS (build and delivery infrastructure) |
We may add or change subprocessors for similar purposes; we will update this Policy when we do so in a material way.
4.2 Legal and safety
We may disclose information if required by law, legal process, or government request, or when we believe disclosure is necessary to protect rights, safety, and security.
4.3 Business transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you as required by law.
5. Data security
We use industry-standard measures including encryption in transit (HTTPS/TLS) and access controls on our backend. No method of transmission or storage is 100% secure.
6. Your data rights
Depending on where you live, you may have the right to:
- Access personal information we hold about you
- Correct inaccurate information
- Delete your account or certain data, subject to legal exceptions
- Opt out of certain processing (e.g., non-essential marketing, where applicable)
- Limit use of sensitive personal information (where applicable under CCPA)
To exercise these rights, email support@calmingaura.net. We aim to respond within 30 days.
If you are in the EEA/UK, you may lodge a complaint with your local supervisory authority. Nothing in this Policy limits mandatory statutory rights that apply to you as a consumer.
7. Children’s privacy
The Apps are not intended for children under 13 (or under 16 in the EU/UK where applicable). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
8. Data retention
Local data remains on your device until you uninstall the App or clear app data. Account data is retained while your account is active. When you delete your account, we delete or anonymize associated cloud data within a reasonable period, except where retention is required by law or for legitimate security purposes.
9. International transfers
Your information may be processed in the United States or other countries where our service providers operate. We use appropriate safeguards where required by law (e.g., standard contractual clauses).
10. Third-party links
The Apps link to official government and third-party websites (e.g., IRS, state unclaimed property offices, class action administrators). We are not responsible for the privacy practices of those sites. Please read their policies before submitting information.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version and update the “Last updated” date. For material changes, we may provide additional notice (e.g., in-app message or email). Continued use of the Apps after the effective date means you accept the updated policy.
12. Contact
Calming Aura Studios LLC
Email: support@calmingaura.net
We aim to respond to privacy inquiries within 30 days.
13. Consent
By using the Apps, you acknowledge that you have read this Privacy Policy and agree to the collection, use, and sharing of your information as described herein.
14. Legal compliance (summary)
This Policy is intended to comply with applicable laws and platform requirements, including CCPA (where applicable), GDPR (where applicable), Google Play data safety disclosures, and Apple App Store privacy requirements.