Last updated: 27 September 2026 · Maison Bear · Gold Coast, Australia
Ura Panic (Ura) is operated by Maison Bear, based in Gold Coast, Australia. This policy explains how we handle information in our apps, website and support services. Features and permissions vary by device and app version.
Some Ura features involve sensitive information about health, emotions or recovery. Reading this notice or using Ura does not replace the separate choices required for optional Health access, AI processing or clinical sharing.
Depending on the features you use, this includes account and sign-in details; your chosen name, profile image or avatar; age group, goals and onboarding answers; check-ins, panic/support sessions, Journey progress and Playbook reflections; AI messages and preferences; Circle messages, support requests and bookings; Community Outpost contributions; purchase and redemption records; and feedback or support correspondence.
Information about anxiety, cravings, sleep, emotional state or recovery may be sensitive health information. You choose what to write or share. Avoid including another person's private information without their permission.
We collect information such as device and app version, language, feature use, interaction times, errors and subscription status to operate Ura, understand how features are used and improve reliability. PostHog provides product analytics. Events may include onboarding steps, selected recovery pathway, use of support tools and purchase-related activity.
These analytics are not all anonymous: a signed-in user's events can be linked to their Ura account identifier. Pathway and support-tool events may reveal sensitive interests or recovery context. Analytics are separate from optional Apple Health and Screen Time data, which are handled as described below. We do not use your data for advertising tracking or sell it to advertisers. You can contact us about analytics access or deletion.
Ura does not request precise device location. A Journey planet or environment is part of the app experience, not your physical location.
Your Playbook, check-ins and AI conversations are not automatically published to the Community Outpost or made visible to everyone in a Circle. Specific information may be used for personalisation or shared with a care team when you enable the relevant feature and permissions. Publishing a post or sending a Circle message is a separate action.
When you publish in the Community Outpost, your post or comment, stable public alias, publication date and reaction/comment counts are visible to other signed-in Ura members. The alias links your contributions. A post may include an optional snapshot of the Journey planet and broad environment shown for your account at publication. Ura validates recognised identifiers but does not independently confirm your progress.
Environment names may indirectly suggest your recovery pathway. The snapshot does not include your exact checkpoint, progress percentage, streak, onboarding answers, email or internal account identifier. It is omitted if the app has no complete account-matched snapshot.
Reports, block lists, automated safety signals and moderation records are not public. Systems and authorised people may access them to protect the community and operate the service.
Personal Circles: other members can see the profile information and content made available within that Circle, including messages and support signals you send. Additional presence, achievement or progress information depends on the feature and your sharing settings.
Clinic Circles: authorised clinic staff can access the client information permitted by their role and assignment. Optional sharing categories include mood trends, Panic Flow usage, trigger patterns, check-ins, AI summaries and AI-conversation summaries. These sharing categories start off and require your choices; clinical AI processing and conversation-summary sharing have additional consent controls. A generated summary is not the full chat transcript.
Organisation Circles: profile, community participation, requests and booking information are made available to the members or authorised staff needed for that feature. Private booking or care information is not intended for the general community feed.
We store membership, roles, permissions and relevant messages, resources, requests and booking records to provide these services. You can change supported sharing choices or leave a Circle. Revoking access stops future sharing under that permission; it cannot recall information already viewed, copied or retained independently by a recipient. A clinic or organisation may have its own privacy notice and legal recordkeeping duties. Contact that provider about its own records.
“For my next session” lets you keep up to three talking points, select recent check-ins and Ura support records, and save your own after-session takeaways and agreed next steps. You can review and copy a saved reflection or chat message into a talking point. The card and up to 12 past session notes are stored for your account in protected, device-only storage on that iPhone. They do not sync as session cards to your Ura account or automatically go to a therapist, Circle or the Community Outpost.
Writing, selecting or saving these notes does not itself send them to AI. If you request an AI summary, Ura asks you to approve sending the card’s talking points and selected entries through its backend to OpenAI. “Help me say this” instead sends the selected talking point to suggest an opening sentence. General AI consent and processing terms also apply. The card does not automatically attach your full chat history or Apple Health records. You decide whether to use the draft or show the card to someone.
Starting the next card carries forward topics you have not marked as covered. Use Session card options → Delete session cards to remove the current card and saved takeaways from that device. This does not delete the original check-ins, chats or reflections, or recall information already processed by a provider. Deleting your account in the app also clears the local session-card store on that device.
Connecting Apple Health is optional. With your permission, the iPhone patterns feature reads sleep and step records to show changes in your routine. It requests read access, not permission to write Health records. Ura reduces these records on your device; raw Health samples are not uploaded to Ura's account storage, analytics or Circles.
Sharing a Health summary with AI is a separate, optional choice. Only with both AI consent and Health-summary sharing enabled can a dated summary of recorded sleep and steps, including available comparisons, be sent through Ura's backend to OpenAI with a chat request. It does not contain raw Health samples or Screen Time app identities. These summaries are not saved as automatic AI memory or shared with Circles.
You can stop future AI-summary sharing or disconnect Health through the controls in Your patterns, and change read permissions in Apple's settings. Disconnecting clears Ura's current patterns; it does not delete your Apple Health records or recall information already sent for processing. Missing readings are not treated as zero or as a diagnosis.
Gentle check-ins are optional. If enabled, permitted background sleep/step updates and a daily usage threshold for apps or groups you select in Apple's Screen Time picker can be evaluated on your device to offer an invitation to pause or talk. Comparisons use available recorded history; Ura does not read what you type in other apps or monitor their content.
Screen Time selections use Apple's opaque tokens stored locally. Actual app identities and usage are displayed within Apple's private report extension, not sent to Ura's servers, OpenAI, analytics or Circles.
The invitation explains the routine change and can appear in your conversation with Ura. Generating or opening that invitation does not itself send an AI request. If you reply, the normal AI consent and sharing controls apply. Notification delivery depends on your permissions and iOS; this is not continuous monitoring or detection of anxiety, addiction or a crisis.
For this feature, Ura temporarily stores a protected local summary of the relevant routine comparison, threshold event, notification preferences and random session identifiers. It keeps the latest invitation and optional Helpful/Not helpful feedback for up to seven days, removing expired copies when that storage is next accessed. Invitation feedback stays on your device and is not sent to AI or analytics or used to train an external model. This local evidence is cleared when you disconnect Health, turn off gentle check-ins or sign out. Screen Time can also be disconnected separately.
Where you use Ura's Watch feature, optional gentle nudges request read access to heart rate, heart-rate variability, steps, sleep and workouts. The Watch uses available records to learn its local baseline and consider movement and recent exercise before offering support. It does not write Health records or run a continuous diagnostic sensor session.
These Health readings and the Watch's learned patterns stay on that Watch. They are not sent by this feature to your Ura account, OpenAI, analytics or Circles. Local settings, recent invitation decisions and optional session feedback help manage nudges and preferred exercises. The protected learning file is excluded from backup.
Watch permissions and learning are separate from your iPhone account and AI settings. Turning off Watch nudges stops monitoring; use Delete learned patterns in the Watch settings to clear its learning. Deleting your phone account does not remotely clear this independent Watch storage. None of these actions deletes the original Apple Health records. Watch support and notifications are not an emergency monitoring service.
With your consent, Ura sends relevant messages, session context, onboarding preferences, recorded app activity, conversation context and selected memories through its backend to OpenAI to generate replies or insights. Optional Health summaries and clinical summaries use the additional controls described above. Declining or withdrawing AI consent blocks AI chat and insight requests; it does not remove access to non-AI guided support.
Voice input uses the microphone when you start a voice feature. Speech recognition can run on-device when supported; otherwise Apple's speech service may process the audio. The resulting transcript can be used like typed text. For spoken AI replies, Ura sends reply text through its backend to OpenAI for speech generation. The chat speech player holds generated audio in memory for playback rather than writing it to disk. Ura does not collect ambient microphone recordings for Health or gentle check-ins.
Provider processing can involve temporary storage and security or abuse-prevention records; no-training does not mean zero retention. OpenAI's applicable API data controls and service terms govern its processing. You can withdraw consent in AI Settings, but withdrawal cannot recall a request already processed.
After AI consent, memory is on automatically unless you previously turned it off. It can keep concise useful details such as goals, preferences and what helped; onboarding provides starting context. Full conversations are not saved as memory. You can review, edit, forget or pause memory through AI Settings and What Ura understands about me.
Memory is stored locally for your account. Optional account sync stores a private copy in Firebase so enabled devices can share memories and changes. That copy is encrypted in transit and on the server, but is not end-to-end encrypted. Turning sync off leaves the account copy in place; clear memories with sync enabled to clear that copy. Account deletion also removes the account copy. Relevant memories can be included in subsequent AI requests while the applicable permissions are enabled.
We use information to provide accounts, guided support, personalisation, Journey and progress tools; operate Circles, bookings and community moderation; process purchases and permitted promotions; deliver optional notifications; respond to support requests; maintain security; and understand app usage and reliability.
Health and Screen Time permissions serve the specific optional purposes described in section 3. We do not use Health data for advertising, sell it, or send raw Health samples to analytics.
If you send app feedback, its text, optional reply email and relevant app/version information can be delivered to Ura support using an email provider. Do not include sensitive details that are unnecessary for your request.
Ura uses device storage and services including Firebase Authentication, Firestore and cloud storage. Network requests use encrypted HTTPS/TLS and access controls help restrict account and Circle information. Cloud storage is not the same as end-to-end encryption: authorised service systems and personnel may process information to provide, secure and support the service.
Community content is visible as explained above. Local Health summaries and Watch learning have separate device protections. No storage or transmission method can be guaranteed completely secure.
Retention depends on the information and its purpose. Account content is generally kept to provide your account and features until you remove it or request account deletion. Outpost submissions have no automatic expiry, but you can review and delete your submissions, including those in review, hidden or removed. Account deletion removes associated Outpost content within 30 days, except where limited retention is legally required.
Use Settings to request account deletion or follow our account-deletion instructions. The process removes account records and associated content from Ura's active systems, including the synced memory copy and relevant Circle records. Clinic or Organisation owners need to transfer or close their managed Circle first; contact support if this prevents you from completing deletion.
Deletion from Ura's active systems does not instantly erase every processor log, backup, billing record, support email or copy held by another recipient. Account-linked analytics and provider records may remain after the in-app deletion action. Contact us to request deletion of these records as well. We assess remaining retention against the purpose, applicable law and security needs rather than treating account closure as permission for indefinite retention.
Limited records may need to be retained for transactions, legal obligations, disputes, fraud prevention or security. Backup removal follows the relevant backup lifecycle. Independently held clinic records are subject to that provider's obligations. We can explain applicable retention or an exception when handling your request.
Local iPhone invitation evidence has the seven-day limit described above. Independent Watch learning must be cleared on the Watch. Disconnecting Ura or deleting an account does not erase Apple Health records. Deleting an account or uninstalling Ura does not cancel a subscription with Apple, Google or another payment provider.
Depending on the feature and platform, recipients include:
Providers process information needed for their service under applicable arrangements. Stores and independent care providers also have their own privacy notices. Information you enter into a browser tool described as local-only stays in that browser; this does not prevent ordinary website hosting requests and server logs.
We may disclose information where required or permitted by applicable law, to respond to valid legal process, protect rights or address a serious threat to safety. This does not mean Ura or Circle members continuously monitor your activity or can guarantee intervention.
You can use available controls to change Health and notification permissions, stop AI-summary sharing, manage AI memory, change clinical sharing, remove your submissions or delete your account. You may also request access to, a copy of, correction of or deletion of personal information by emailing support@uraapp.com. We may need to verify your identity before disclosing or changing account information.
To make a privacy complaint, describe your concern and how we can contact you at the same address. We aim to respond within 30 days; if more time is needed, we will explain why. If you remain dissatisfied, you may contact the Office of the Australian Information Commissioner or another relevant regulator. Available rights and exceptions depend on applicable law.
Ura is intended for people aged 16 or older. We do not knowingly collect personal information from children under 16. Contact us if you believe a child has provided information so we can investigate and take appropriate action.
Ura operates from Australia and uses international providers. Processing can occur outside Australia, including in the United States, where Ura uses backend and analytics services and where several providers operate. Other processing locations depend on the provider, service and configuration, including their support and subprocessors.
Relevant provider information is available from Firebase, OpenAI, PostHog and Vercel. You can contact us about the recipients and locations relevant to your information. Overseas processing does not remove protections required by applicable Australian law.
We update this notice as Ura's features and data handling change. The current version and date are published here and linked from the app. Where a change requires a new permission or consent, updating this page alone does not provide that consent.
Operator: Maison Bear, operating Ura
Location: Gold Coast, Australia
Privacy and support: support@uraapp.com