AppsServicesStudioUpdatesSupport Talk to the studio

Privacy · WebAura · Effective 4 August 2026

WebAura privacy policy.

WebAura keeps core browser information on your device. Websites you visit, optional account features, ads, analytics and store services can still process information as described below. This page explains what is processed, by whom, why, for how long, and the choices you have.

1. Scope, developer and controller

This policy covers the WebAura app on Android, Huawei/AppGallery, iPhone, iPad, Mac and Windows, in every distribution (Google Play, App Store, Mac App Store, Microsoft Store, AppGallery and the direct installers on this site). WebAura is an original product operated and published by CreedStack Motions Limited, commonly known as CreedMotions. The lead developer and AppGallery account holder is Mike Swimming (the account may display the name as “Swimming Mike”). Ovian Nassuna is the assistant developer. The data controller is CreedStack Motions Limited. Contact: info@creedmotions.store. This policy should be read with the company privacy policy.

2. At a glance

Browsing history, tabs, bookmarks, downloads, your media library and your settings live on your device, not on our servers. WebAura does not sell personal data. Network activity goes to the websites and services you choose to open, the search engine you select, and — for specific features — the providers listed in section 8. An account is optional and currently anonymous. Where ads are enabled, Google Mobile Ads processes advertising data under its own policy, and Premium removes in-app ads where they exist.

3. Data stored on your device

WebAura stores locally: open tabs and tab groups; browsing history and bookmarks; site data such as cookies, cache and local storage held by the system web engine; your settings, themes and toolbar layout; the download queue, download history and files you save; your audio library, playlists and play history used for on-device recommendations; locked-folder contents; extension and userscript files plus the small storage those scripts keep; and cached balances such as Aura Points. Uninstalling the app removes app-managed data, but files you exported to shared storage or Photos remain until you delete them.

4. What websites receive

Like any browser, when you open a page WebAura sends that site your request, IP address, standard browser headers, cookies previously set by the site and anything you type into it. Sites you visit are independent controllers under their own privacy policies. Built-in ad and tracker filtering can reduce, but never completely prevent, third-party requests made by pages.

5. Search and page tools

Searches and address-bar suggestions are sent to the search engine you have selected in Settings. Optional page tools — translation, reader mode, page summaries and lyrics translation — only send the relevant page text or query to the supporting service when you actively invoke that tool, and only to fulfil that request.

6. Downloads and media features

The Quick Downloader and browser download tools detect media and process supported downloads on your device wherever possible. For some sources, a public link you provide is sent to a supported extraction or processing service operated for the app so the file, formats or subtitles can be resolved; those requests carry the link and technical request data, not your browsing history. Only save media you own, public downloads, or content you have permission or another lawful right to keep.

7. Accounts, restore codes and sync

No email address is required. WebAura currently offers anonymous sign-in only: the app creates a random account identifier through Firebase Authentication, and the restore code shown in the app lets you reopen the same anonymous identity later. Keep the code private — anyone holding it can restore that identity. If you use an account, we associate with it only what the feature needs, such as entitlement status and synced media-library metadata stored in Google Cloud Firestore. Google and Apple federated sign-in are temporarily unavailable while the account experience is being refined; if they return, the provider will process your account identifiers under its own policy.

8. Service providers

Depending on platform, build and your choices, WebAura uses: Google Firebase (Authentication for anonymous accounts, Cloud Firestore for synced data, Cloud Messaging for notifications, and Analytics for aggregate usage measurement) under the Google privacy policy; Google Mobile Ads (AdMob) for advertising in builds where ads are enabled; Apple, Google Play, Huawei AppGallery and Microsoft Store for distribution, updates, in-app purchases and platform sign-in services on their platforms; and supported media extraction and knowledge services for the specific features described in sections 5 and 6. These providers act under their own policies for the parts they control. We do not give providers access to your local browsing data.

9. Advertising and consent

Some builds show ads in limited places, for example around Quick Downloader activity. Where ads are enabled, Google Mobile Ads may process device identifiers, IP address, approximate location inferred from IP, ad interactions and your consent choices. Where consent rules apply, you are asked before personalised ads are shown, and you can decline personalisation. WebAura Premium removes in-app ads where they exist. Websites you visit may show their own advertising independent of the app.

10. Analytics and diagnostics

We use aggregate analytics to understand which features are used and to keep the app stable — for example feature usage counts, app version, device model, OS version, language and country. Crash and error reports include technical state at the time of the problem. We use this data to fix bugs and improve the product, not to build advertising profiles of your browsing.

11. Permissions, step by step

Network is required to browse. Photos/媒体 storage is requested only when you save, import or export files; on iOS the app uses add-only Photos access where possible. Notifications cover download progress and completion alerts you enable. Microphone is used for voice search only while you use it, and speech recognition is performed by your device’s system speech service. Biometrics or device PIN unlock the app lock and locked folder; the check is done by the operating system and we never receive your fingerprint or face data. You can revoke permissions in system settings at any time.

12. Cookies and site data

Cookies, cache and site storage created while you browse are held by the system web engine on your device. Settings → privacy controls let you clear browsing data by type — history, cookies, cache and more — for the ranges you choose, and per-site controls let you manage permissions granted to individual sites.

13. Private browsing and app lock

Private tabs are designed not to add visited pages to your normal history and to keep private downloads in the private area. Private browsing does not make you anonymous: websites, your network operator and your ISP can still see the traffic you send them. The app lock and locked folder protect access to the app and selected files on the device using your system authentication.

14. Extensions and userscripts

Extensions and userscripts are third-party code you choose to install. Within the access you grant, a script can read and change matching pages, and it may keep its own small storage on your device. Extensions obtained from third-party stores are governed by their developers’ own policies. Review requested site access before enabling anything — see the extension guide.

15. Purchases, Premium and Aura Points

Purchases are processed by Apple, Google or Huawei for the store your build came from; we receive transaction identifiers, the product purchased and entitlement status, never your full card number. Windows reads an eligible entitlement from an Apple or Google purchase after you sign in with the same WebAura account and has no separate billing store. Aura Points balances and redemptions are linked to your app identity so they can be honoured.

16. Retention

Local data stays until you delete it, clear it in Settings, or uninstall. Account records exist until you delete the account or ask us to. Synced data is kept while the account is active. Analytics and crash data are retained for the provider’s standard limited periods. Support emails are kept as long as needed to resolve the matter, then for a limited period for records. We keep transactional records only as long as accounting or legal duties require.

17. Security

Network traffic between the app and our providers uses transport encryption (HTTPS). Account access uses the platform’s authentication infrastructure. Locked-folder and app-lock features rely on your device’s security hardware where available. No product can promise perfect security, so we minimise what leaves the device in the first place.

18. International transfers

Our providers, including Google and the app-store platforms, may process data on servers outside your country, including in the United States, using the safeguards described in their own policies, such as standard contractual clauses where they apply.

19. Legal bases

Where GDPR-style laws apply, we process data to perform our contract with you (providing the app, accounts, purchases), with your consent (personalised ads, optional permissions — withdrawable at any time), and for legitimate interests (keeping the app secure and stable, preventing abuse, measuring aggregate feature use) balanced against your rights.

20. Your rights

Depending on where you live, you can request access to, correction of, deletion of, restriction of, objection to, or portability of personal data we hold, and you may complain to your local data-protection authority. Email info@creedmotions.store and we will respond within the period your law requires. Most WebAura data is local to your device, so many requests can be completed instantly with the in-app controls.

21. Children

WebAura is a general web browser and is not directed at children. We do not knowingly collect personal information from children outside the age and consent rules of their country. If you believe a child has provided personal data through the app, contact us and we will delete it.

22. Delete data or ask a question

Use the in-app privacy and account controls where available, follow the WebAura deletion guide, or email info@creedmotions.store. Include the app and account identifier involved, but never send a password, restore code or payment-card information by email.

23. Changes

We update this policy when app behaviour, providers or legal duties change, and the effective date above identifies the current version. Meaningful changes are reflected here before or when the corresponding app update ships. Store privacy disclosures use each store’s standard categories and should be read together with this fuller explanation.