Acora Privacy Policy
Effective date: 12 August 2026
Last updated: 12 August 2026
This Privacy Policy explains how Acora Ltd ("we", "us", or "Acora") handles personal information when you use the Acora iPhone application, website, support channels, and related services (collectively, the "Service").
Controller/contact: Acora Ltd, trading as Acora, established in Hong Kong. Email: info@acora.app.
Summary
- Apple Health sleep records are read and processed only on your device. Acora does not upload HealthKit data to its servers or send it to AI providers.
- Acora asks for explicit, versioned permission before a goal or desire can be used for new third-party AI processing. Declining leaves bundled starter content available.
- Acora does not sell personal information, use it for third-party advertising, or track you across other companies' apps or websites.
- You can stop future AI data sharing in the app and can delete your Acora account in the app.
Information we handle
Account and authentication
If you sign in with Apple, we receive an Apple-linked user identifier and, depending on your Apple choice, your name and email address or private relay address. Acora stores its session credential in the iOS Keychain. Acora sends Apple's single-use authorization code to its server, validates that the resulting Apple identity belongs to the signed-in Acora account, and stores the Apple refresh token in encrypted form solely so the authorization can be revoked when the account is deleted. Apple provides the authentication service. Acora also receives signed Apple account events, such as email forwarding changes, revoked consent, or deletion of an Apple Account.
Goals, desires, and generated content
Acora stores goals or desires you create, along with the stories, manifestation cards, narration, and cover artwork generated for your account. This content may reveal interests, plans, relationships, financial aspirations, or other information you choose to enter. Do not submit information you do not want processed as described below.
Profile content
Optional personalization details you enter—such as name, age, city, career, work situation, gender, sexuality, and free-form context—are stored for your account so Acora can create and update personalized manifestation aids. You can review, change, or clear these details in Profile > Settings > Personalisation. Favorites and playback/activity history are stored on the device. A profile photo selected by a signed-in user is resized on the device and stored in private cloud storage so it is available for that account. Acora accesses only the photo you select; it does not upload the rest of your photo library.
Purchases and subscription status
Apple processes payments. Acora receives transaction and subscription identifiers, product, entitlement status, storefront-related subscription information, and dates needed to provide paid access, restore purchases, prevent abuse, and handle billing events. We do not receive your full payment-card details.
Feedback and support
If you rate content, report an issue, or contact support, we process the rating, reason, optional message, relevant content identifier, account/contact information, and the communications you send. An in-app bug report also includes the selected issue category and limited technical context: Acora version and build, iOS version, device type, and locale. Please do not include passwords, payment details, health information, or other sensitive data in a bug report.
Bug-report text is stored privately with the Acora account. If Acora enables its optional Discord support alert, Discord receives only an opaque report identifier, issue category, and that limited technical context so the team knows a report is waiting. The alert does not include the free-form report, account identifier, or email address.
Notifications
If you enable notifications, Acora processes an Apple Push Notification service device token, notification preferences, time zone, content-window identifiers, and whether the latest content has already been viewed. This is used to send content-ready and subscription-status notifications and to suppress stale or duplicate messages. Acora may show a short manifestation-card preview on the Lock Screen. You can disable notifications in Acora or iOS Settings.
Apple Health sleep information
With your permission, Acora reads sleep duration and stage samples from HealthKit to calculate private sleep-pattern insights on the device. HealthKit information is not uploaded to Acora, included in AI prompts, used for advertising, or shared with third parties. Removing Health access in iOS Settings prevents future reads.
Technical information
Our hosting and security systems may process IP address, request time, response status, and limited security/operational logs when your device communicates with the Service. Acora does not include a third-party advertising SDK or a cross-app tracking SDK in the audited release.
Third-party AI processing and your choice
Before new personalized generation, Acora presents a disclosure and asks you to allow or decline the following processing:
- DeepSeek receives the selected manifestations, relevant optional personalization details you chose to provide, and bounded content instructions to generate personalized weekly goal suggestions, English story and manifestation-card text.
- Fish Audio receives the generated story script to create narration.
- OpenAI receives a generated visual description to create story cover artwork.
Acora's servers coordinate these requests. HealthKit sleep records are never included. These providers are used for the stated creation purposes; Acora does not disclose this information to them for advertising or cross-service tracking. Their infrastructure may process and retain information in countries different from yours under their service terms and Acora's applicable agreements with them.
Acora may also use Discord as an operational notification processor for new support reports. As described above, that alert is limited to an opaque report identifier, issue category, and technical context; the report text and account identity remain in Acora's private backend.
You can decline and continue with bundled starter content. You can later allow or stop future AI sharing under Profile > Settings > AI Data Sharing. Stopping sharing prevents new provider work; it does not automatically erase already generated content. Delete your account to request deletion of account data and generated cloud content.
Why we use information
We use information to:
- create, narrate, store, and deliver the content you request;
- save the optional profile details you provide and use them to personalize those aids;
- authenticate accounts and synchronize account features;
- provide and verify subscription access;
- deliver notifications you enable and suppress already-viewed content alerts;
- save selected profile photos and submitted feedback;
- provide support, protect the Service, prevent fraud or abuse, and meet legal obligations; and
- improve reliability using aggregated or de-identified operational information where lawful.
The legal bases applicable in some countries are performance of our contract, consent (including for third-party AI sharing and HealthKit access), legitimate interests in security and reliability, and compliance with law. Where processing relies on consent, you may withdraw it without affecting processing that occurred before withdrawal.
Sharing
We disclose information only as needed to:
- Apple (Sign in with Apple, StoreKit, APNs, HealthKit operating-system access, and App Store);
- Supabase and its infrastructure providers (authentication, database, Edge Functions, private object storage, and operational hosting);
- DeepSeek, Fish Audio, and OpenAI after the explicit AI-sharing choice described above;
- professional advisers and authorities when required by law; or
- a successor in a merger, financing, reorganization, or sale, subject to applicable law.
We do not sell personal information or share it for cross-context behavioral advertising.
Storage and retention
Account information and generated cloud content are kept while your account is active. When you delete your account, Acora deletes your account, user-linked records from its active systems, and user-owned cloud media. Limited App Store and Sign in with Apple event records may remain after being separated from your account where needed for transaction reconciliation, security, fraud prevention, legal claims, or compliance. Apple and service providers may retain information under their own obligations and service terms.
Deleted database records may remain temporarily in restricted backups until the applicable backup cycle expires; they are not used to operate your account. Retention depends on the type of record, the purpose for which it is used, legal requirements, and the hosting backup schedule.
Device data remains until you remove it, delete your account through the app, or delete the app. After server deletion succeeds, Acora attempts to clear account-scoped preferences and downloaded profile, artwork, narration, and network caches from the device. If local cleanup fails, the app tells you to delete and reinstall Acora. Apple subscriptions are controlled by Apple and are not cancelled by deleting an Acora account.
An encrypted Apple refresh token is kept while the Acora account remains linked to Sign in with Apple and is removed when the authorization is revoked or the Acora account is deleted. Minimal notification identifiers, event type, pseudonymous Apple-subject digest, time, and processing outcome may be retained where necessary to prevent replay, reconcile account-security actions, resolve legal claims, or comply with law; raw Apple notification payloads are not retained.
Security
Acora uses transport encryption, iOS Keychain session storage, AES-GCM encryption for Apple refresh tokens, private cloud-storage buckets, account-based access controls, and default-deny AI consent checks. No security measure can guarantee absolute protection. Contact info@acora.app if you believe your account is at risk.
Your choices and rights
Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also complain to your local data-protection authority. Email info@acora.app to exercise a right. We may verify your identity before responding.
In the app you can:
- stop or allow future AI data sharing;
- review, change, or clear optional personalization details;
- control notification permissions;
- remove Health access through iOS Settings;
- manage the App Store subscription through Apple's subscription settings; and
- delete the Acora account from Profile > Settings > Delete Account.
Children
Acora is intended for people aged 16 and older. We do not knowingly collect personal information from anyone under 16. If we learn that an account belongs to someone under 16, we will suspend the account and delete the associated information unless applicable law requires or permits us to retain it. Contact info@acora.app if you believe a person under 16 submitted information.
International transfers
Service providers may process information outside your country. Where applicable law requires a transfer mechanism, Acora uses contractual or other legally recognized safeguards. You may contact info@acora.app for information about safeguards relevant to your data.
Changes
We may update this policy to reflect Service or legal changes. We will update the date above and, when required, provide additional notice or request renewed consent. A materially changed AI disclosure version requires a new in-app choice before new personalized provider work.
Contact
- Privacy questions and rights requests: info@acora.app
- Support: info@acora.app
- Website: https://www.acora.app
- Establishment: Hong Kong