Privacy Policy
How Aura Software collects, uses, and protects information when you use Bright.
Effective Date: June 12, 2026
1. Introduction
Aura Software (“we,” “us,” or “our”) provides Bright, a middleware integration service for SCORM Cloud. This Privacy Policy explains how we collect, use, and protect information when you use our services. By using Bright, you agree to the terms outlined here.
2. Information We Collect
As a middleware provider, we collect data in two primary categories:
Customer Account Data
Information you provide to create an account, such as your name, business email, billing information, and API keys for SCORM Cloud.
Learner Data (Service Data)
When your end-users interact with SCORM content via Bright, we may process:
- User identifiers (typically anonymized IDs or email addresses).
- Course progress, completion status, and scores.
- Technical logs (IP addresses, browser types, and timestamps).
3. How We Use Data
We use the collected information strictly for the following purposes:
- Service Provision: To facilitate the communication between your host application and SCORM Cloud.
- Synchronization: To ensure learner progress is accurately reported back to your primary system.
- Troubleshooting: To diagnose technical issues and improve the performance of the middleware.
- Security: To detect and prevent fraudulent or unauthorized activity.
4. Data Sharing and Disclosure
We do not sell learner or customer data. Data is only shared in the following contexts:
- Rustici Software (SCORM Cloud): As middleware, Bright passes data directly to SCORM Cloud to execute its core function.
- Service Providers: We may use third-party hosting (e.g., AWS, Azure) to run our infrastructure.
- Legal Requirements: If required by law, we may disclose information to comply with legal obligations or protect our rights.
5. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption: Data is encrypted in transit via TLS/SSL and at rest where applicable.
- Access Control: Access to our backend systems is restricted to authorized personnel only.
- API Integrity: We utilize secure authentication methods to handle your SCORM Cloud credentials.
6. Your Responsibilities
As the Customer, you are the Data Controller regarding your learners’ information. You are responsible for:
- Ensuring you have the legal right (and learner consent, if applicable) to process their data through Bright.
- Complying with regional privacy laws, such as GDPR (EU) or CCPA (California).
7. Data Retention
- Account Data: Retained as long as your account is active.
- Learner Data: We typically act as a pass-through. Any data cached for performance is purged according to our data retention schedule or upon your request.
8. Contact Us
If you have questions about this policy or our data practices, please contact us at:
support@aura-software.com