Privacy Policy

Last updated: February 28, 2026

Ora ("we," "our," or "us") operates the Ora mobile application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our app. Please read this policy carefully. By using Ora, you consent to the practices described in this policy.

Account Information

When you create an account, we collect your email address and password. This information is used to authenticate your account and provide personalized services.

Skin Profile Data

During onboarding and through app usage, we collect information you provide about your skin type, skin concerns, allergies and sensitivities, age range, and budget preferences. This data is used exclusively to personalize your skincare recommendations.

Product & Routine Data

When you scan products or build routines, we store product names, brands, ingredients, and your routine configurations. This enables features like ingredient conflict detection and routine management.

Skin Tracking Data

If you use the daily tracker, we store your skin ratings, notes, and streaks to help you monitor your skincare progress over time.

Chat Data

Conversations with the Ora AI assistant are stored to provide context-aware responses and improve your experience. Chat history is retained for 7 days and then summarized.

Images

When you use the product scanner or skin analysis features, images you capture or upload are processed by our AI systems for analysis. Images are processed in real-time and are not permanently stored on our servers after analysis is complete.

  • Provide personalized skincare recommendations and AI chat responses
  • Analyze product ingredients and detect potential conflicts or allergens
  • Build and manage your skincare routines
  • Track your skin health progress over time
  • Send push notifications for routine reminders and check-ins (with your permission)
  • Process subscription payments through our payment partners
  • Improve and optimize our services

We use the following third-party services to operate Ora:

  • Supabase — Database hosting, authentication, and file storage
  • xAI (Grok) — AI-powered skincare analysis and chat responses
  • RevenueCat — Subscription management and payment processing
  • Apple App Store / Google Play Store — App distribution and payment processing
  • Expo — Push notification delivery

Each third-party service has its own privacy policy governing how they handle your data. We do not sell your personal information to any third party.

We implement industry-standard security measures to protect your data, including row-level security on all database tables, encrypted data transmission (HTTPS/TLS), server-side API key storage, and secure authentication practices. However, no method of electronic storage is 100% secure, and we cannot guarantee absolute security.

Your data is retained for as long as your account is active. Chat messages are retained for 7 days before being summarized. You may request deletion of your data at any time through the app settings or by contacting us.

You have the right to:

  • Access — Request a copy of the personal data we hold about you
  • Rectification — Request correction of inaccurate personal data
  • Erasure — Request deletion of your personal data ("right to be forgotten")
  • Portability — Request a machine-readable copy of your data
  • Withdraw consent — Opt out of data processing at any time

You can delete your account and all associated data directly from the app's Settings screen. This action is irreversible and removes all your data from our servers.

Ora is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete it promptly.

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last updated" date at the top of this page and, where appropriate, through in-app notifications.

If you have questions about this Privacy Policy or your data, please contact us at:

hello@ora-ai.co