Trust, Security & Privacy
This page is maintained by the AuraScan team to answer common security and privacy questions about the platform. It describes current, app-visible practices and is not an independent certification or third-party audit.
Access & Authentication
Partner and admin areas require an authenticated account. Role-based access separates partner dashboards from administrative tools, and database row-level security restricts each partner to their own clients, scans, and catalog selections.
Public scan links use unguessable identifiers and only return the fields needed to render the report.
Data Storage & Photos
Client photos are stored in a private object storage bucket and are never served from a public URL. When a photo needs to be displayed or sent to the AI provider for analysis, the server issues a short-lived signed URL.
Database access uses row-level security policies; service-role access is restricted to server-side code and is never exposed to the browser.
Data We Collect
To produce a wellness report we collect: client name and contact details supplied by the partner or the client, the photos uploaded for the scan, the selected report language, and the AI-generated report. Partners may also store their own catalog and branding assets.
We use minimal product analytics to count scans, leads, and recommendation clicks for partner reporting.
Subprocessors & AI Providers
AuraScan runs on Lovable Cloud (hosting, database, authentication, and object storage) and uses the Lovable AI Gateway for image analysis and report generation. Photos sent to the AI provider are transmitted over signed, short-lived URLs.
Partners are responsible for ensuring they have the appropriate consent from their clients before uploading photos or personal data.
Retention & Deletion
Partners can delete test clients and individual scans from their dashboard. Deleting a scan also removes the associated photo files from storage. For full account deletion or data export requests, contact us using the address below.
Security & Privacy Contact
To report a security issue or make a privacy request, email security@ai-scaner.lovable.app. We aim to acknowledge reports within a few business days.
This page describes current practices and may change as the product evolves. It is not a legal agreement and does not replace our terms of service or any data processing agreement signed with a partner.