Privacy Policy
Effective Date: May 24, 2026
This Privacy Policy explains how Vinova Tech Ltd ("we," "us," or "our"), operating as Aruma, collects, uses, and shares information about you when you use the Aruma app and related services. By using our Services, you agree to this policy. If you are in the EEA, UK, or Switzerland, see Section 12 for additional provisions.
We are committed to protecting your privacy and handling your personal information with transparency and care.
1. Information We Collect
1.1 Information You Provide Directly
- Account registration: your name, email address, phone number, and password.
- Profile details: profile photo, date of birth, gender, and health or fitness goals you choose to share.
- Views, opinions, and wellness data: meditation ratings, mood check-ins, reflections, sleep notes, and other responses you record.
- Payment and subscription information: processed securely by Apple App Store or Google Play; we do not store full card details.
- Communications: support requests, survey responses, and feedback you send us.
1.2 Information Collected Automatically
- Device information: device model, operating system version, unique device identifiers, and mobile network information.
- Usage information: sessions, content you listen to or view, features you access, session duration, and in-app interactions.
- Transactional information: product description, price, subscription expiration date, and transaction time/date.
- Log information: app version, access times, pages viewed, IP address, and referring pages.
- Location data: country or region derived from IP address; more precise location if you grant permission.
- Communications: messages you send us via support channels.
1.3 Information We Infer or Generate
We may derive information about you based on what we collect — for example, using your IP address to infer approximate location, or making educated guesses about your interests based on your usage — to improve personalisation.
1.4 Cookies and Tracking Technologies
We and our third-party partners use cookies, web beacons, device identifiers, pixels, and similar tracking technologies to authenticate you, remember your preferences, analyse usage, and deliver and measure advertising. You can control cookies through your device and browser settings, though disabling certain cookies may affect App functionality.
We do not currently respond to Do Not Track (DNT) browser signals. If an industry-wide standard is adopted, we will review our approach.
1.5 Information from Third Parties
- Social sign-in providers (Google, Apple): your name and email when you choose to sign in through those services.
- Health app data: if you grant permission, data from Apple HealthKit or Google Health Connect such as sleep hours and activity goals. We do not infer health characteristics from this data and only use it for the purpose provided.
- Analytics and advertising partners: aggregated information about your use of our Services.
- App store transaction data: details from Apple or Google when you purchase a subscription.
2. How We Use Your Information
We use the information we collect for the following purposes (legal basis in brackets where relevant):
- Provide the Services: create and manage your account and deliver the app experience. (Contract performance)
- Personalise your experience: content recommendations, activity plans, and UI customisation. (Legitimate interest / consent)
- Process transactions: manage subscriptions and fulfil purchases. (Contract performance)
- Transactional communications: account confirmations, subscription receipts, and service messages. (Legitimate interest; contract)
- Promotional communications: news, offers, and content about Aruma — you may opt out at any time. (Legitimate interest / consent)
- Analytics and improvement: analyse usage to improve features and build new ones. (Legitimate interest)
- Security and fraud prevention: detect and prevent fraud, abuse, and illegal activity. (Legitimate interest; legal obligation)
- Legal compliance: fulfil tax, legal, and regulatory obligations. (Legal obligation)
- Anonymised data: create anonymised or aggregated data that no longer identifies you, which we may use and share freely. (Legitimate interest)
- Personalised advertising: tailor ads you see on other platforms based on your preferences and behaviour. (Legitimate interest / consent)
3. Cookies and Advertising by Third Parties
We allow third-party advertising and analytics companies to collect information about your use of the Services through cookies, device identifiers, and similar technologies. They may use this to display Aruma advertisements on other sites, measure ad effectiveness, and understand your online activity.
You can opt out of interest-based advertising through your device settings:
- iOS: Settings > Privacy & Security > Tracking
- Android: Settings > Google > Ads > Opt out of Ads Personalisation
You may also contact us at admin@aruma.app to opt out of certain data uses.
4. Sharing of Information
We do not sell your personal information. We may share your information in the following circumstances:
- Service providers and contractors: cloud hosting, analytics, payment processing, email delivery, fraud prevention, advertising measurement, and customer support — all bound by confidentiality and data protection obligations.
- Analytics and advertising partners: as described in Section 3.
- Professional advisors: accountants, auditors, lawyers — subject to confidentiality obligations.
- Business transfers: if we merge with or are acquired by another company, your information may be transferred. We will notify you of such changes.
- Legal and safety requirements: when required by law, court order, or governmental authority; or to protect the rights, property, or safety of Aruma, our users, or the public.
- With your consent or direction: for example, when you use social sharing features or link third-party accounts.
We may share anonymised or aggregated data that cannot reasonably identify you with third parties for business or research purposes.
5. Data Security
We implement industry-standard technical and organisational safeguards, including:
- Encrypted data transmission (TLS/HTTPS)
- Encrypted storage of sensitive data
- Access controls limited to authorised personnel
- Regular security assessments and monitoring
In the event of a personal data breach that is likely to put your rights and freedoms at high risk, we will notify you without undue delay as required by applicable law.
No electronic storage or transmission method is 100% secure. Please notify us immediately at admin@aruma.app if you suspect any unauthorised access to your account.
6. Data Retention
We retain your personal information for as long as your account is active or as necessary to fulfil the purposes described in this policy. When you delete your account, we will delete or anonymise your information within 90 days, except where legal, tax, accounting, or regulatory obligations require longer retention.
Anonymised data that can no longer identify you may be retained indefinitely.
7. Your Privacy Rights
Depending on your location, you may have the right to:
- Access: know what personal information we hold about you.
- Rectification: correct inaccurate or incomplete information.
- Erasure: request deletion of your personal information (subject to legal retention obligations).
- Restriction: limit how we process your information in certain circumstances.
- Portability: receive a copy of your information in a structured, machine-readable format.
- Object: object to processing based on legitimate interests or for direct marketing.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.
- Opt out of targeted advertising: opt out of the use of your data for targeted advertising or profiling.
Exercising Your Rights
Contact us at admin@aruma.app. We may verify your identity before processing your request. We will respond within 30 days (or as required by applicable law). You may also designate an authorised agent to submit requests on your behalf.
Appeals
If we deny your request, we will explain why. You may appeal by emailing admin@aruma.app with the subject line "Privacy Rights Appeal."
8. Your Choices
Promotional Communications
Opt out of promotional emails by clicking the unsubscribe link in any email, or by contacting admin@aruma.app. You will still receive transactional messages related to your account.
Push Notifications
With your consent, we send push notifications. Deactivate them at any time in your device settings (iOS: Settings > Notifications; Android: Settings > Apps > Aruma). Disabling notifications may affect certain App features.
Account Information
Update your profile at any time within the App. To delete your account, go to Profile > Settings > Delete Account, or email admin@aruma.app.
Health App Data
If you connected Aruma to Apple HealthKit or Google Health Connect, you can disconnect at any time through your device's Health or Fit settings. We will not collect further health data after disconnection.
9. Children's Privacy
The App is not directed at children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If we learn we have done so, we will delete it promptly. Please contact us at admin@aruma.app if you believe a child has provided us with personal information.
10. International Data Transfers
Aruma is operated from Iran. Your information may be transferred to and processed in countries with different data protection standards. Where required by applicable law, we implement appropriate safeguards — which may include standard contractual clauses or other legally recognised transfer mechanisms. You may request details by contacting admin@aruma.app.
11. Important Notice — Not Medical Advice
The content in the App — including meditations, breathing exercises, sleep programmes, and music — is for informational and educational purposes only. It is not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider before beginning any new fitness or wellness programme.
We do not infer health-related characteristics or medical conditions from information you share with us.
12. Information for EEA, UK, and Switzerland Residents
If you use the Services while in the European Economic Area, United Kingdom, or Switzerland, Vinova Tech Ltd is the data controller for personal information processed under this policy. The legal bases for our processing activities are described in Section 2. Where we rely on legitimate interests, you have the right to object.
You also have the right to lodge a complaint with your local data protection authority.
13. Third-Party Links and Services
The App may contain links to or integrations with third-party websites, apps, or services. We are not responsible for their privacy practices. Please review their policies before providing personal information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective Date" above and provide notice through the App or by email. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
15. Governing Law
This Privacy Policy is governed by the laws of the Islamic Republic of Iran. Any disputes shall be subject to the exclusive jurisdiction of the competent courts of Iran.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
Vinova Tech Ltd (operating as Aruma)
Email: admin@aruma.app
Website: www.aruma.app