Privacy & your data
This notice covers AuraMatrix discovery, visitor submissions and account records. It describes the data handling currently implemented by this service.
AuraMatrix supports existing invited password accounts and ordinary accounts through configured Google or GitHub sign-in. Passwords are hashed by Better Auth. Email addresses are account identifiers; password-account email verification and email recovery are not enabled. The sign-in page shows which social providers are configured.
Private by default
Only structured drafts you choose to save are stored. Search and AI conversation history are not copied into your workspace. Your account email, private notes and application review comments are excluded from public records. Authorized reviewers can read submitted listings, their private reviewer notes and the submitting account’s name and email, including after a decision. They can read requests explicitly submitted for review and their private contact details; unsent account drafts and login credentials remain inaccessible.
What becomes public
New requests become public only after you confirm the preview and a separate reviewer approves it. Previously published requests remain public under their existing approved snapshot. Saving later changes does not replace that public snapshot. A listing becomes public after you submit a specific version and an authorized reviewer approves it. A link, login or review does not establish project ownership.
Visitor submissions
You may submit a request or recommend a GitHub project without an account. Private contact details are shared only with the review team, never public readers or anonymous AI tools. Keep the private management link: it controls only that submission, and anyone you share it with can manage it. The server stores a digest of its key and uses a secure browser session after an explicit restore action. Public share links carry no management permission. Visitor records do not automatically move into an account when you sign in. There is no verified recovery channel or email notification service for visitor submissions.
Submitted material, source observations, decisions and prior approved versions are retained for review. Withdrawal stops public display; it does not delete the private record or audit. Explicit synthetic test records are excluded from public lists, details and anonymous MCP.
Unsent drafts in this browser
Unsent visitor public form fields and comparison selections can be restored in this tab for up to one hour after editing so you can return without retyping. The local project draft includes its public source details and a temporary GitHub source-check ticket, valid on the server for about an hour. That ticket cannot manage a submission or establish ownership. Private contacts and confirmation are not saved in that draft storage. Expired copies are removed when you return to the page or it checks the saved draft. Clear the saved draft or close the tab to remove it; you must preview and confirm again before anything is submitted.
Persistence and connections
Accounts, drafts, published snapshots, operation receipts, review history and grants are stored in the service database and private backups. There is no scheduled expiry or automatic data deletion. Archiving or closing a request does not erase published history. For an export or removal request, contact the AuraMatrix team at hello@auramatrix.ai. No automatic deletion or account-recovery service is promised.
Revoke an AI connection in Connections to stop its access without deleting your records. Signing out of the website or removing a local MCP configuration alone does not revoke the grant. Never paste passwords or access tokens into an AI chat.
Records marked “candidate acceptance” are synthetic test records. They are not real procurement, author participation, completed tasks or human acceptance.