Acora Privacy Policy

Effective date: 12 August 2026

Last updated: 12 August 2026

This Privacy Policy explains how Acora Ltd ("we", "us", or "Acora") handles personal information when you use the Acora iPhone application, website, support channels, and related services (collectively, the "Service").

Controller/contact: Acora Ltd, trading as Acora, established in Hong Kong. Email: info@acora.app.

Summary

Information we handle

Account and authentication

If you sign in with Apple, we receive an Apple-linked user identifier and, depending on your Apple choice, your name and email address or private relay address. Acora stores its session credential in the iOS Keychain. Acora sends Apple's single-use authorization code to its server, validates that the resulting Apple identity belongs to the signed-in Acora account, and stores the Apple refresh token in encrypted form solely so the authorization can be revoked when the account is deleted. Apple provides the authentication service. Acora also receives signed Apple account events, such as email forwarding changes, revoked consent, or deletion of an Apple Account.

Goals, desires, and generated content

Acora stores goals or desires you create, along with the stories, manifestation cards, narration, and cover artwork generated for your account. This content may reveal interests, plans, relationships, financial aspirations, or other information you choose to enter. Do not submit information you do not want processed as described below.

Profile content

Optional personalization details you enter—such as name, age, city, career, work situation, gender, sexuality, and free-form context—are stored for your account so Acora can create and update personalized manifestation aids. You can review, change, or clear these details in Profile > Settings > Personalisation. Favorites and playback/activity history are stored on the device. A profile photo selected by a signed-in user is resized on the device and stored in private cloud storage so it is available for that account. Acora accesses only the photo you select; it does not upload the rest of your photo library.

Purchases and subscription status

Apple processes payments. Acora receives transaction and subscription identifiers, product, entitlement status, storefront-related subscription information, and dates needed to provide paid access, restore purchases, prevent abuse, and handle billing events. We do not receive your full payment-card details.

Feedback and support

If you rate content, report an issue, or contact support, we process the rating, reason, optional message, relevant content identifier, account/contact information, and the communications you send. An in-app bug report also includes the selected issue category and limited technical context: Acora version and build, iOS version, device type, and locale. Please do not include passwords, payment details, health information, or other sensitive data in a bug report.

Bug-report text is stored privately with the Acora account. If Acora enables its optional Discord support alert, Discord receives only an opaque report identifier, issue category, and that limited technical context so the team knows a report is waiting. The alert does not include the free-form report, account identifier, or email address.

Notifications

If you enable notifications, Acora processes an Apple Push Notification service device token, notification preferences, time zone, content-window identifiers, and whether the latest content has already been viewed. This is used to send content-ready and subscription-status notifications and to suppress stale or duplicate messages. Acora may show a short manifestation-card preview on the Lock Screen. You can disable notifications in Acora or iOS Settings.

Apple Health sleep information

With your permission, Acora reads sleep duration and stage samples from HealthKit to calculate private sleep-pattern insights on the device. HealthKit information is not uploaded to Acora, included in AI prompts, used for advertising, or shared with third parties. Removing Health access in iOS Settings prevents future reads.

Technical information

Our hosting and security systems may process IP address, request time, response status, and limited security/operational logs when your device communicates with the Service. Acora does not include a third-party advertising SDK or a cross-app tracking SDK in the audited release.

Third-party AI processing and your choice

Before new personalized generation, Acora presents a disclosure and asks you to allow or decline the following processing:

  1. DeepSeek receives the selected manifestations, relevant optional personalization details you chose to provide, and bounded content instructions to generate personalized weekly goal suggestions, English story and manifestation-card text.
  2. Fish Audio receives the generated story script to create narration.
  3. OpenAI receives a generated visual description to create story cover artwork.

Acora's servers coordinate these requests. HealthKit sleep records are never included. These providers are used for the stated creation purposes; Acora does not disclose this information to them for advertising or cross-service tracking. Their infrastructure may process and retain information in countries different from yours under their service terms and Acora's applicable agreements with them.

Acora may also use Discord as an operational notification processor for new support reports. As described above, that alert is limited to an opaque report identifier, issue category, and technical context; the report text and account identity remain in Acora's private backend.

You can decline and continue with bundled starter content. You can later allow or stop future AI sharing under Profile > Settings > AI Data Sharing. Stopping sharing prevents new provider work; it does not automatically erase already generated content. Delete your account to request deletion of account data and generated cloud content.

Why we use information

We use information to:

The legal bases applicable in some countries are performance of our contract, consent (including for third-party AI sharing and HealthKit access), legitimate interests in security and reliability, and compliance with law. Where processing relies on consent, you may withdraw it without affecting processing that occurred before withdrawal.

Sharing

We disclose information only as needed to:

We do not sell personal information or share it for cross-context behavioral advertising.

Storage and retention

Account information and generated cloud content are kept while your account is active. When you delete your account, Acora deletes your account, user-linked records from its active systems, and user-owned cloud media. Limited App Store and Sign in with Apple event records may remain after being separated from your account where needed for transaction reconciliation, security, fraud prevention, legal claims, or compliance. Apple and service providers may retain information under their own obligations and service terms.

Deleted database records may remain temporarily in restricted backups until the applicable backup cycle expires; they are not used to operate your account. Retention depends on the type of record, the purpose for which it is used, legal requirements, and the hosting backup schedule.

Device data remains until you remove it, delete your account through the app, or delete the app. After server deletion succeeds, Acora attempts to clear account-scoped preferences and downloaded profile, artwork, narration, and network caches from the device. If local cleanup fails, the app tells you to delete and reinstall Acora. Apple subscriptions are controlled by Apple and are not cancelled by deleting an Acora account.

An encrypted Apple refresh token is kept while the Acora account remains linked to Sign in with Apple and is removed when the authorization is revoked or the Acora account is deleted. Minimal notification identifiers, event type, pseudonymous Apple-subject digest, time, and processing outcome may be retained where necessary to prevent replay, reconcile account-security actions, resolve legal claims, or comply with law; raw Apple notification payloads are not retained.

Security

Acora uses transport encryption, iOS Keychain session storage, AES-GCM encryption for Apple refresh tokens, private cloud-storage buckets, account-based access controls, and default-deny AI consent checks. No security measure can guarantee absolute protection. Contact info@acora.app if you believe your account is at risk.

Your choices and rights

Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also complain to your local data-protection authority. Email info@acora.app to exercise a right. We may verify your identity before responding.

In the app you can:

Children

Acora is intended for people aged 16 and older. We do not knowingly collect personal information from anyone under 16. If we learn that an account belongs to someone under 16, we will suspend the account and delete the associated information unless applicable law requires or permits us to retain it. Contact info@acora.app if you believe a person under 16 submitted information.

International transfers

Service providers may process information outside your country. Where applicable law requires a transfer mechanism, Acora uses contractual or other legally recognized safeguards. You may contact info@acora.app for information about safeguards relevant to your data.

Changes

We may update this policy to reflect Service or legal changes. We will update the date above and, when required, provide additional notice or request renewed consent. A materially changed AI disclosure version requires a new in-app choice before new personalized provider work.

Contact