Privacy Policy

How Aurora collects, uses, and protects your data

Last updated: 1 October 2026

Data We Collect

Account data: your email address, first and last name, and a hashed password when you create an account.

Submission data: uploaded H&E images, any paired spatial and molecular data (such as training pairs or data for model adaptation), and generated results, associated with your email. When you submit images, we record the version of the Terms you accepted and when.

Website analytics: Google Analytics page views, session duration and approximate geographic region, collected only after consent. Our own page counts and result usage logging are described below.

Demo enquiries: your email address and any optional institution, company or industry details you provide when downloading a demo dataset or report. We use these to deliver the file. Product updates require a separate opt-in confirmed by email (double opt-in).

We do not ask for patient identifiers or clinical records. You must fully anonymise uploaded data before submission.

Use of Uploaded Data for Model Development

Under the academic terms, Aurora uses uploaded data and generated results to develop, train, validate, and improve its models and services, including those it offers commercially. These uses and your permission for them are described in our Terms under Use of Data for Model Development. Commercial access is governed by a separate written agreement, under which a customer's data is not used for model development without the customer's written permission.

Read the data-use terms

When You View or Download Results

When someone opens a result link, Aurora records events such as opening the spatial map, loading a slide image, viewing a gene symbol or downloading a result. Events are linked to the submission and, where relevant, its image. Downloads record an artefact category rather than a filename. We use these events to understand result usage and improve the service.

To identify repeat requests from the same network, the server derives a daily, submission-specific hash from the request IP address. Event records do not store the raw IP address, browser user agent or referrer. This first-party logging uses no analytics cookies or third-party analytics service.

Cookies & Tracking

Cookies are small text files placed on your device to operate the website. Aurora does not use targeting, advertising or profiling cookies. Analytics cookies are set only after you accept them in the cookie banner.

Rejecting or withdrawing consent stops analytics collection and deletes existing analytics cookies. You can change your choice through "Cookie Settings" in the footer at any time.

Essential Cookies (no consent required)

CookiePurposeLifetime
__Secure-next-auth.session-tokenAuthenticated session (JWT)Session / 30 days
__Host-next-auth.csrf-tokenNextAuth CSRF protectionSession
__Secure-next-auth.callback-urlRedirect after loginSession
XSRF-TOKENApplication-level CSRF protection1 hour

Non-essential Cookies (consent required)

CookiePurposeLifetime
_gaGoogle Analytics: distinguishes unique visitors2 years
_ga_G-6CJGEC0G6HGoogle Analytics: maintains session state2 years

Page View Counts

Aurora counts how many times each public page of this website is viewed. Your browser sends the page address without any query string, and we add one to its daily count. The counter sets no cookie, uses no browser storage and stores no IP address, browser details or other identifier: only the page, the date and the number of views. To prevent duplicate counts and flooding, the server keeps hashes of your IP address, browser user agent and page for about 30 minutes, in memory only, using a random key that is replaced every day and never stored. Nothing is counted on admin or sign-in pages, or when your browser sends Global Privacy Control or Do Not Track. Counts stay with Aurora and are shared with no one.

Newsletter and Updates

If you subscribe to updates, we send occasional emails about Aurora's models and features. You can subscribe on this website, where we ask you to confirm by email first, or by opting in to news when you request access to one of our repositories.

We record your email address, where you subscribed, the wording you agreed to and when. We send these emails on the basis of your consent (GDPR Article 6(1)(a)).

Every update includes an unsubscribe link, and you can unsubscribe at any time. Unsubscribing also stops our reminder emails. Emails about your submissions and your account are not affected.

We keep your subscription record until you unsubscribe or ask us to delete it. After you unsubscribe, we keep your email address only to make sure we do not email you again.

Data Storage & Security

Uploaded images, generated results and account information are stored on infrastructure in Switzerland, where analyses also run. Aurora's administrators may access these data when needed to operate the service, provide support or investigate a problem. Cloudflare may process website traffic outside Switzerland, including decrypting and inspecting requests for security; see International Data Transfers below.

Aurora applies technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction, including encryption in transit, access controls and security monitoring. No electronic storage or transmission method is fully secure; we cannot guarantee absolute security.

Data Retention

We retain personal data for as long as needed to provide the service and meet legal obligations. Uploaded data, generated results and account data remain accessible while your account is active.

Result usage events have no separate time limit. They remain linked to their submission and are deleted with it. Records of interactions with links in our emails have no separate time limit and are deleted when you request deletion of your data. Demo enquiry details, including your email and any institution, company or industry information, are kept until you request deletion or withdraw consent.

You can request deletion of your account and associated data through the contact form. Deleting uploaded data does not withdraw models already developed with it. Deletion does not remove copies already held in backups.

Your Statutory Rights

Under the GDPR and Swiss nDSG, you may request access to and a copy of your personal data, or ask us to correct inaccurate or incomplete data. Depending on the circumstances, you may also object to processing, request restrictions, erasure or data portability.

You can withdraw consent at any time without affecting processing carried out before withdrawal. Use "Cookie Settings" in the footer to change analytics consent. To exercise other rights, use the contact form. You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC).

Third-Party Services

Google Analytics measures website usage after explicit consent. Cloudflare provides TLS termination, web application firewalling and Zero Trust access controls for the admin panel.

Aurora does not sell personal data. We share it with these providers as needed to deliver their services and otherwise only where required by law.

International Data Transfers

Google Analytics data may be processed by Google LLC in the United States. Google states that it has certified its adherence to the EU-U.S. Data Privacy Framework (DPF). The European Commission's adequacy decision covers transfers to participating organisations.

Cloudflare may process requests outside Switzerland through its global edge network, including decrypting and inspecting traffic for security. Its Data Processing Addendum describes the applicable transfer safeguards, including DPF certifications and standard contractual clauses where relevant.

Contact

For privacy questions or to exercise your rights, use the contact form. We respond to requests under GDPR Articles 15–22 within one month of receipt. Where necessary, Article 12(3) allows up to two further months; we will notify you of an extension within the first month.

Contact Aurora