Effective 30 August 2026
Privacy Policy
PARTYPETE.COM PTY LTD (ABN 30 653 453 215) operates AuraPic. Its address is 38 Nelson St, Stepney SA 5069, South Australia. This policy explains how it handles information submitted to and generated by AuraPic.
Information AuraPic collects
- Your first name or chosen display name and a normalised mobile number, which is required to create a result.
- Your ten selected trait IDs, all nine options shown in each round, favorite color, computed scores, and generated animal, fruit, symbol, descriptors, reasons, title, and summary.
- Client timing, timezone, locale, and viewport details supplied with the submission.
- A two-value US or Australian spelling preference. AuraPic checks the server-observed IP address against a GeoLite2 Country database installed locally, then uses browser language only when that lookup has no result. The request does not send the IP address to MaxMind. AuraPic saves the spelling preference with the result but not the detected country.
- Your sequential public result number and creation time.
- Operational and security data such as IP address, user agent, referrer, request ID, method, content type and size, protocol, route, response status, and timestamps.
- Generation records such as the text and image model names, processing time, provider request IDs and status codes, usage or token metadata returned by the provider, final poster size and integrity hash, the exact successful text-profile JSON request and response bodies, the exact text-only image prompt sent to the Image API, the final sanitized output PNG after the fixed local badge is applied, and database save outcome.
- Result interaction events when a result is viewed or a visitor uses an image share, page share, download, copy-link, named social-network, or Create Yours control. These records include the result number, action name and timestamp, and may include a packed IP address, bounded user agent, and query-free same-origin referrer path. The default no-referrer policy means the referrer path is normally absent.
Why AuraPic uses it
The profile information is used to generate, save, display, and share the result. Operational records are used to prevent abuse, diagnose errors, protect the profile-generation endpoint, understand service reliability, and measure which result-sharing controls are useful. Authorised operators can review submitted result data, IP addresses, generation records, and successful provider exchanges through a protected administration page for support, security, and service operations. A share-control event records an attempted interaction, not proof that an external platform completed the share.
A mobile number is required to create a result. The operator may use it for one personal follow-up about that AuraPic. It will not be used for marketing without separate permission, and you may withdraw the follow-up request at any time.
Public and enumerable results
Your public result page and completed share poster show your name, selected traits, and generated profile, and use your favorite color as a visual palette. AuraPic sends a text-only prompt to its AI image service to create a photographic poster with your displayed name, match names, descriptors, category labels and selected color. The prompt requires three columns and the exact text, while leaving the scene and camera choices to the model. No sketch or subject image is uploaded. After the image service returns its result, AuraPic applies its fixed local badge once in the bottom-right corner, then stores and shares the completed image without any other redraw. The badge is not sent to the AI service. AI generation may produce inaccurate wording or artwork, or unexpectedly introduce branding despite the prompt safeguard. The image does not show your mobile number. Result numbers are sequential, so anyone can try nearby numbers without receiving your link. Do not treat a result URL as private or as a password.
AI service provider processing
To select the three matches, AuraPic sends its AI service provider the server-resolved trait labels, five-axis scores and leanings, type context, selected color, derived color mood, two-value spelling preference, and allowed match catalogues. That text-profile request does not send your name, mobile number, visitor IP address, user agent, referrer, browser telemetry, raw form, or exact round history in its model prompt. To generate the shareable picture, AuraPic sends the same AI service provider a text-only prompt containing your displayed first name or chosen name, the three selected match names, their descriptors and category labels, and your selected six-digit color code. No sketch, source PNG, animal image, fruit image, symbol image, logo, or badge is uploaded for new generations. The prompt asks the model to create the photograph and all ten text occurrences in three columns, with Personal Symbol on the left, Signature Fruit in the centre, and Spirit Animal on the right. It specifies exact spelling, punctuation and casing. The color code and any color label are not intended to appear as visible text. The image prompt requests photorealistic photography with a gentle spiritual atmosphere and gives the model freedom to choose the scene and camera view. It requests bright daytime light mode across the whole picture, with your favorite color accenting roughly one third of the background and environment. Natural subject colors, subtle aura wisps and sparse background bokeh keep the scene clear. Only the Spirit Animal may have facial features. The headline is compact and centred, with Bauhaus-style typography. Visible text uses white or soft-white letter fills with a subtle, close dark shadow and optional fine dark outline for legibility; the three category labels use 50% opacity, while other text stays fully opaque. The image remains AI-generated, and lettering or layout can vary. The model receives the displayed name as text for image generation, while personality matching does not receive it. The image prompt does not include your mobile number, visitor IP address, user agent, referrer, browser telemetry, raw form, or exact round history. A random internal request ID is sent as an API transport header for tracing. AuraPic stores the exact successful text-profile JSON request and response under the result retention period. For each new completed image generation, it also stores two token-derived files in protected server-side storage for verification: the exact prompt text sent to the Image API and the final sanitized 1024 x 1024 output PNG after the fixed local badge is applied. Older results may retain their previously stored private input PNG for inspection. The badge is never sent to the AI service, and AuraPic does not retain a separate undecorated provider PNG. AuraPic does not retain transport headers, the API credential, or the provider's base64 JSON response. It also stores bounded image-provider operational metadata. Provider bodies do not contain AuraPic's API credential or transport authorisation header. Depending on provider routing and configuration, the AI service provider and infrastructure providers may process this content outside Australia, including in the United States.
Storage, logs, and secrets
Profile, successful text-profile exchange, image-provider metadata, and operational data are stored in MySQL. Each new completed image generation stores its prompt text and final output PNG in protected server-side image storage. Older input PNGs remain private when retained for inspection. Only the completed output PNG can be served through AuraPic's verified public image handler. The stored prompt text and any older input PNG remain private and are not exposed by result or card routes. Share interaction records do not copy your name, mobile number, selected traits, generated profile, request body, cookies, or form-security token. The protected administration page is not public, is excluded from indexing and caching, and requires an authenticated operator session. Application audit logs must not copy your mobile number, full generated profile, generated image bytes, database password, API credential for the AI service provider, session token, or other secrets. Hosting and infrastructure providers may process technical data as necessary to deliver and secure the service.
Cookies
AuraPic uses a short-lived, first-party visitor session cookie for form security and per-session share-event rate limiting. An administrator who signs in receives a separate first-party Strict session cookie for the protected administration page. The base installation does not include advertising or third-party analytics cookies.
Retention and deletion
This installation has a target retention period of 90 days. The operator must schedule the supplied cleanup process for that period to be enforced. That process removes completed result records, their stored successful AI service provider exchanges, the corresponding prompt text file, output PNG, any older input PNG, and operational audit records after the configured period. Share interaction records are linked to their result and are deleted automatically when that result is deleted. Admin login-attempt security records are removed after 30 days. Shorter retention may apply after a verified deletion request. Hosting providers, the AI service provider, and legally required records may have separate retention periods under their applicable terms.
Your choices and rights
Subject to applicable law, you may request access, correction, deletion, or restriction, object to certain uses, ask the operator to stop a requested mobile follow-up, and complain about the handling of your information. Contact hey@partypete.com and include the public result URL where relevant. General support details are on the Contact page.
Security and children
AuraPic uses HTTPS in production, limited database permissions, input validation, prepared queries, security headers, and server-side API credentials. No online service is completely secure. If you are under 15, use AuraPic only with a parent or guardian who understands that the name and result will be public.
Changes and complaints
Material changes will be published on this page with an updated effective date. Send privacy questions or complaints to hey@partypete.com. The operator aims to respond to a privacy complaint within 30 days. If it remains unresolved, you may be able to complain to the Office of the Australian Information Commissioner.