42
Grade C

Aura Privacy Policy

All-in-one digital security | Last reviewed: January 2026

Privacy Summary

Aura's privacy policy is clearer than many competitors, but the all-in-one nature of their service means they collect an extensive range of data across identity, devices, passwords, and browsing. They also own IdentityGuard and share data across their service portfolio. Family plans raise additional concerns about monitoring family members' data.

Data Collection Overview

Data Type Collected Shared Sold
Social Security Number Yes Credit Bureaus No
Financial Account Info Yes Monitoring Services No
Device/Browser Data Yes Analytics Partners No (claimed)
VPN Traffic Metadata Yes (connection data) Internal Use No
Password Vault Data Yes (encrypted) Not Shared No
Family Member Data Yes (family plans) Same as Primary No

Key Privacy Concerns

Family Plan Data Aggregation

Family plans require submitting SSNs and personal information for all covered family members. The account holder has access to alerts for all family members, creating potential privacy issues within families.

VPN Connection Logging

While Aura claims not to log VPN traffic content, they do collect connection timestamps, bandwidth usage, and server selections. This metadata can reveal browsing patterns even without content inspection.

IdentityGuard Data Sharing

Aura owns IdentityGuard and shares data between the services. If you've used both services, your data may be combined for "improved service" and analytics purposes.

Marketing Opt-Out Available

Unlike some competitors, Aura provides clear opt-out mechanisms for marketing communications and some data sharing. However, opting out doesn't affect core service data collection.

Device Monitoring Scope

Aura's device security features require extensive device access:

  • Antivirus scans read file metadata across your device
  • Safe browsing monitors all web traffic
  • Password manager has clipboard access
  • Parental controls can log app usage and location (family plans)
  • WiFi security scanner detects network configurations

Data Retention

Aura's retention policy is vague on specific timeframes but better than some competitors:

  • Active account data: Retained during subscription
  • After cancellation: "Reasonable period" (undefined)
  • Legal holds: May retain indefinitely for legal compliance
  • Aggregated/anonymized data: Retained indefinitely

Comparison Note

Aura scores 42 on privacy - the best in the identity protection category, though still a C grade. Their clearer policy and opt-out mechanisms help, but the breadth of data collection for an "all-in-one" service remains a concern.

Read our Aura Terms of Service Review →