Aurith

What is held, and what is not.

Short, because there is very little. Aurith is a financial news service. It holds an email address to reply to, and — if you open an account — the settings and keys that account needs to work. Nothing else, and none of it is sold. Last revised 10 October 2026.

Who else handles it

Stripe, and Supabase.

Payment is taken by Stripe, on Stripe's own pages. Your card number, billing address and payment method are given to Stripe and are never held by Aurith — there is no card data anywhere in this system to lose. Stripe acts as a processor and has its own privacy notice, which governs what it does with what you give it.

Your card is kept, and it is charged again. This is a subscription, so when you pay, Stripe stores your payment method and charges it automatically at the start of each period — every month, or every year — until you cancel. Nobody asks you again each time, and that is the point of it. The card is held by Stripe, not by Aurith; what Aurith holds is a Stripe identifier for you, which is useless to anyone else.

Cancelling is immediate, from your side. Send GET /v1/portal with your API key and it hands back a link to Stripe's own page, where you can change the card, read every invoice, or cancel. There is no notice period, nothing to email, and no telephone call. When you cancel, Stripe stops charging, and your key keeps working to the end of the period you have paid for — then stops.

Aurith is told only that a subscription started, changed or ended, and the email address on it. That is what turns a key on and off.

Supabase holds the sign-in. The email address and password behind an account live with Supabase, which acts as a processor for Aurith just as Stripe does, under its own privacy notice. Aurith never sees the password. Everything else about an account — the plan or packs bought, your feed settings, your API keys (kept only as a one-way hash, so a key is shown once and never again) and how many calls each key has made — is kept on Aurith’s own server.

There is no analytics, no advertising network, no content delivery network and no third-party font. The public pages make no request to anyone but Aurith. The account pages talk to Supabase to sign you in — that is the only other place a request goes.

The short version
Held

What is held, and why.

WhatWhyHow long
Your account: the email address you sign in with, and your password To sign you in. The password is stored by Supabase as a hash and is never seen by Aurith Until you delete the account
Your feed settings — regions, categories, topics, sources, languages and the three release times To build the feed you asked for Until you change or delete them
Your plan and packs, and Stripe's customer and subscription identifiers. Not your card — Stripe keeps the card and charges it each period; Aurith never receives it To know what you are entitled to, and to bill you For as long as the subscription exists, and while tax law requires the record afterwards
A hash of each API key, when it was last used, and how many calls it has made To check the key and enforce the published rate. The key itself is never stored — it is shown once and only a SHA-256 hash is kept Until the key is revoked
The address you write to us from, and emails you send to hello@ or api@ To answer you Until the question is answered; otherwise kept as ordinary correspondence and deleted on request

The web host keeps standard server logs, including IP addresses, as every web host does. Those are the host's, are used to keep the server running and to stop abuse, and are not read by Aurith for any other purpose. No IP address is recorded against your account.

Accounts

An email, a password, and your settings.

Accounts are held by Supabase, which runs the sign-in and the database behind the account pages. Your email address and password are stored there. Aurith never sees the password — it is sent straight to Supabase, which keeps only a hash of it — and nobody at Aurith can read it or recover it for you.

Your settings are what you told Aurith to send: the regions, categories, topics, sources and languages you chose, and the three release times in Toronto time. That is the whole of it, and it exists only so the feed can be built for you.

Plans and packs are recorded so an account knows what it is entitled to. API keys are shown once, when they are made, and only a hash is kept afterwards — the key itself is never stored and cannot be shown again. What is kept per key is how many calls it has made and when it was last used, so the published rate can be enforced and a stray key noticed.

Aurith's own server holds the email address on the account, the plan and packs, the hashed keys, the feed settings and the per-key usage counts above. Nothing else — the news itself carries nothing about you, and reading the feed tells Aurith no more than that a key made a request.

Leaving

Deleting an account.

Email hello@aurith.ca and it is done: the account and its settings are deleted, and every key on it is revoked at once. One thing stays behind — Stripe keeps the invoices and payment records for the periods you paid, as tax and accounting law requires. That record is Stripe's, holds no card number Aurith can read, and is the only part of a closed account that remains.

A single key can be revoked, and any setting changed, at any time from the account pages, without asking anyone.

Your rights

Canadian law, used worldwide.

Aurith operates from Canada and is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). The site is reachable from anywhere, and the rights below are offered to everyone who uses it regardless of where they are.

Asking

One address.

hello@aurith.ca — it reaches the person who runs Aurith, who is also the person who would action the request. There is no privacy department to be forwarded to.

If this page changes materially, the date at the top changes and anyone holding a key is told what moved.