Privacy Policy

Version v4.1 | Effective 2026-09-07 | Last Reviewed 2026-09-07

Operator note: Nourai is currently operated by its individual developer. This policy is maintained from the actual product and infrastructure behavior. It is not a claim of HIPAA compliance or legal-counsel review.
v4.0 release notice: This version adds the optional private outdoor-workout route feature and its precise-location disclosure. The operator confirms there were no existing external users before v4.0 took effect. The current mobile build therefore does not present a versioned in-app update notice or send a notification email for this change; this public policy provides the release disclosure.
v4.1 release notice: This version replaces the backend cache processor (Google Cloud Memorystore → Upstash, Inc. on AWS us-east-1), in production since 2026-09-06. The processed data class is unchanged (short-TTL cache entries only), and Upstash's DPA, EU SCCs, and EU-U.S. Data Privacy Framework provide safeguards equivalent to the previous Google Cloud processing terms; this public policy provides the release disclosure.

English is the governing language. Any translation into another language is provided solely for convenience. In case of any discrepancy or conflict between the English version and any translation, the English version shall prevail and govern.

1. Overview

Nourai ("we," "us," or "our") is an AI-powered food and nutrition tracking application operated by its developer, Huibin Wu. We are committed to the principle of data minimization — collecting only what is necessary to provide our services.

This Privacy Policy explains what information we collect, how we use that information, who we share it with, how we protect it, and what rights you have.

By using Nourai, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, please do not use the App.

Nourai is not a medical device. It does not provide medical diagnosis, treatment, or prescription advice. If you have diabetes, kidney disease, eating disorders, pregnancy-related nutritional needs, or other medical conditions, please consult a physician or registered dietitian.

2. Information We Collect

2.1 Account Information (Required)

  • Email address — used for login, password recovery, and essential service notifications
  • Password hash — stored using Argon2id; we never store plaintext passwords
  • Display name — optional; used to personalize your experience
  • Account creation timestamp and last login timestamp
  • Authentication method (email/password, Apple Sign-In, or Google Sign-In)
  • Passkey credential identifiers — if you choose to register a Passkey
  • Email verification status

2.2 Profile & Goals (Optional)

  • Physiological data: height, weight, age, gender
  • Activity level: sedentary, lightly active, moderately active, very active
  • Health goal: lose weight, gain weight, maintain, build muscle
  • Timezone — used for daily summary calculations

From this information, we calculate your BMR, TDEE, daily calorie budget, and macronutrient targets. You may update or delete this profile data at any time in the App.

2.3 Food & Nutrition Records

  • Food name, weight in grams, meal type (breakfast, lunch, dinner, snack), and timestamp
  • Nutritional data per entry: calories, carbohydrates, protein, fat, fiber, sugar, sodium
  • Food photos — uploaded by you, stored in Google Cloud Storage
  • Nutrition label photos — uploaded by you for OCR processing
  • Weight source — how the weight was determined (visual estimate, 3D depth, reference object)
  • Search queries, barcode scans, and manual entry inputs

2.4 AI Recognition, Voice & Conversational Data

Food Photos & Nutrition Labels

  • Food photos are uploaded to our servers and forwarded to the recognition provider selected by the active reviewed configuration. The current primary is DeepSeek V4 Flash Vision Exp; Google Vertex AI / Gemini 3.8 Flash remains a controlled candidate. We do not send the same recognition request to multiple providers in parallel.
  • Nutrition-label and package-front photos use DeepSeek V4 Flash Vision Exp as the primary OCR/extraction provider. Google Vertex AI / Gemini 3.8 Flash remains an operator-selected candidate. We do not send or replay the same image to both providers.
  • Recognition results: candidate foods, confidence scores, estimated weights, and explanatory text

Voice Recordings

  • Audio recorded via the "Speak to Log" feature
  • Audio is temporarily uploaded to our servers and transcribed by Google Vertex AI (Gemini). For meal logging, the resulting transcript text is parsed into a draft food list by DeepSeek V4 Flash; the audio itself is not sent to DeepSeek. Resulting text that you submit to Nour Chat follows the Chat provider path described below.
  • Audio files are deleted immediately after processing, typically within seconds; if a transient technical failure requires a retry, temporary audio retention must not exceed 24 hours
  • Only the transcribed text is retained in your food records or chat history if you save it

Nour Chat Conversations

  • Messages you send to Nour and responses generated by Nour
  • Conversation IDs for context continuity
  • Long-term memory extracted from conversations (dietary preferences, allergies, goals)
  • Weekly report context derived from your nutrition data and conversation history
  • Authenticated Nour Chat currently uses DeepSeek V4 Pro as its primary provider. The intent-specific Google Vertex AI / Gemini 3.8 Flash model is used once as a sequential fallback only when a typed transient failure occurs before any DeepSeek output is received. The fallback is not a parallel copy and is not used after output starts.
  • DeepSeek context is selected by Chat intent. Ordinary small talk and food-recording replies do not receive database-derived profile, memory, or daily-nutrition context. Nutrition-advice requests may include relevant profile/goals, saved dietary memories, and an aggregate daily nutrition summary. If you explicitly ask to review today's foods, the necessary daily context may include itemized food names, meal/time, grams, calories, and macronutrients. The prompt may also contain your current message and necessary recent user-authored messages. When a request can reach DeepSeek, we omit prior assistant replies and synthetic conversation summaries, and do not automatically attach your account email, internal user ID, cohort bucket, display_name, photo URL, or raw HealthKit / Health Connect sample. Text you choose to type in Chat may itself contain identifying information and is sent as part of that Chat message.
  • For food recognition, nutrition-label OCR, and package-front extraction, DeepSeek receives only the current request's corresponding photo(s), recognition prompt/schema, and necessary capture metadata — not your account email, user/entry ID, storage pointer, historical photos, audio, or raw HealthKit / Health Connect samples.
  • Registered DeepSeek text services receive only their bounded task input: a meal transcript after Google audio transcription; a food name and target language for translation; food name, total weight, and meal type for a clearly labeled low-trust nutrition estimate; the persisted user/assistant turn pair for memory derivation, where facts may be extracted only from user text; the oldest bounded conversation window for background compaction; the current user-authored Chat turn for opt-in emotion classification; an existing pattern/evidence payload, display name, and locale for proactive wording; current/previous weekly aggregates, streak, high-confidence goal memories, locale, and opt-in emotion distribution for weekly-report generation; or a masked sender plus bounded inbound support-email recipient, subject, and body for classification and draft generation. Conversation or email text may itself contain identifying or health-related information.
  • The DeepSeek Open Platform Terms confirms that the API model processes end-user Inputs and requires Nourai to disclose delegated personal-information processing. Section 5.5 says the linked DeepSeek Privacy Policy does not cover processing rules for downstream end users. Nourai therefore has not obtained provider-specific confirmation of the API input processing/storage location, training/improvement use, retention/deletion, processor-only handling, or sensitive-health-data acceptance.

Our commitments:

  • Photos and audio are used only for your current logging session
  • Nourai does not use your content to train Nourai-owned AI models. Current DeepSeek Open Platform evidence does not confirm whether downstream API Inputs, including recognition images, are used for provider model training or improvement.
  • We do not share your content with other users
  • High-trust nutrition values come from databases, product labels, controlled providers, or your explicit input. When no verified source matches and you request or review an AI Nutrition Estimate, DeepSeek may produce a clearly labeled low-trust estimate from food name, weight, and meal type. Server sanity checks apply, you must confirm it before saving, provenance is retained, and it never updates Nourai's authoritative food tables.

2.5 Emotional Insights (Opt-In, Default: OFF)

Emotional Insights is disabled by default. If you enable it in Settings:

  • Nourai infers emotional states (joy, stress, fatigue, motivation, frustration, neutral) from your conversations with Nour
  • Emotional signals are stored as high-level tags and numerical confidence scores, not as original biometric emotion templates or face/fingerprint recognition templates
  • Purpose only: Personalized insights in your weekly reports and mood charts
  • Not used for: advertising, push notifications, cross-user aggregation, or third-party sharing
  • Retention: Controlled by you. Disabling stops new observations but does not delete historical data. You may hard-delete all emotional observations at any time via Settings or by calling DELETE /api/v1/users/me/emotions

2.6 Health Platform Data (HealthKit / Health Connect)

Health Sync is disabled by default and requires your explicit authorization. Read and write permissions are managed independently.

If you authorize Read access, Nourai may read:

  • Steps
  • Active energy burned
  • Weight

If you authorize Write access, Nourai may write:

  • Nutrition records: energy (kcal), protein, carbohydrates, fat

Through HealthKit / Health Connect, we do NOT read: heart rate, sleep data, blood glucose, location, contacts, call logs, or messages.

Withdrawing authorization: You may disable Health Sync in Settings at any time. Data already written to Apple Health or Health Connect must be managed separately in those apps.

2.7 Outdoor Workout Routes (Optional)

Nourai collects precise location only if you choose route recording for an outdoor workout and grant the iOS location permission. You may record the workout without GPS.

While that workout is active, Nourai may collect:

  • Precise latitude and longitude, timestamp, and horizontal accuracy
  • Optional altitude, vertical accuracy, speed, and course reported by the device
  • A private route and server-derived distance and ascent
  • An optional destination and route-planning geometry when you request guided navigation

Nourai requests only iOS When In Use location access. During an explicitly active workout, iOS may continue location updates while the screen is locked or the App is in the background and shows the system location indicator. Nourai does not request Always location permission, continuously track you outside an active workout, or make a route public.

Raw route data is owner-scoped health and location data. It is encrypted in transit and at rest. An unfinished route may also be stored in an AES-GCM encrypted, owner-scoped recovery file on your iPhone. Coordinates, timestamps, destination, and route geometry are excluded from ordinary logs, analytics, Sentry, advertising, and AI or LLM prompts.

If you request guided navigation, Apple MapKit receives the origin, destination, and necessary route-planning geometry for that request. Nourai does not send saved raw routes to AI providers. Only you can access a saved route through your authenticated account; public route sharing is not available.

You can delete the raw route while retaining the workout summary, delete the workout, include route records in your account export, revoke location permission in iOS Settings, or delete your account. Route-only deletion removes raw samples but may retain the coordinate-free workout summary and a deletion tombstone needed to prevent accidental recreation.

2.8 Subscription & Billing Data

  • Subscription status, plan type, and platform (Apple App Store or Google Play)
  • Purchase receipts and verification results
  • Daily quota usage (recognition, chat, voice calls)
  • Trial progress and billing dates

We do not store your payment card details. All payments are processed by Apple App Store or Google Play.

2.9 Diagnostics & Stability (Optional)

We use Sentry to collect crash reports and diagnostic information:

  • Crash stack traces
  • Device model, OS version, and App version
  • Limited user context (user ID, for error correlation)

Sentry is opt-out: You may disable crash reporting in Settings. If disabled, Sentry is not initialized on the next App launch.

We do NOT collect: your food records, chat messages, photos, or profile data in crash reports.

Current Sentry project evidence shows server-side data scrubbing enabled, default scrubbers enabled, IP address storage disabled, and additional sensitive field names configured for email, food_record, chat_content, audio_filename, HealthKit, and HealthConnect. Project-level Advanced Data Scrubbing rules were not shown in the evidence screenshot and should be added separately if Nourai needs pattern-based redaction beyond field-name scrubbing.

Current Sentry evidence supports a signed Data Processing Amendment. Current evidence does not show a Sentry Business Associate Agreement. For this reason, Nourai must keep Sentry free of PHI and sensitive user content.

2.10 What We Do NOT Collect

  • Contacts, calendar, or photo gallery (except photos you explicitly upload)
  • Call logs, SMS, or other App data
  • Third-party advertising tracking (no Facebook Pixel, no Google Analytics for Firebase Ads, no AppsFlyer, no Branch.io)
  • Biometric data

We do not sell your personal data.

Nourai does not collect, share, or sell consumer health data, including consumer health data that may be covered by Washington's My Health My Data Act, except as reasonably necessary to provide features requested by you, comply with law, protect security, or otherwise as described in this Policy.

3. How We Use Your Information

We use your data solely for the following purposes:

  • Core functionality: Food and water logging, nutrition calculation, workout recording, optional private outdoor routes, history, trends, achievements
  • AI assistance: Food recognition, OCR, voice parsing, Nour chat responses, weekly reports
  • Nutrition matching: Querying our nutrition database (USDA + Open Food Facts)
  • Personalization: TDEE, calorie budget, and macronutrient targets based on your profile
  • Subscription management: Access control, quota enforcement, purchase verification, restoration
  • Health sync: Reading/writing health platform data (with your authorization)
  • Diagnostics: Fixing bugs and improving stability (via Sentry)
  • Account security: Email verification, Passkey management, password resets
  • Legal compliance: Responding to data subject requests, fraud prevention, legal obligations

Zero LLM-Hallucination Commitment: Our AI identifies food, estimates weight, parses labels or voice, and provides explanations. All nutritional values come from our database or your explicit input. The AI never generates nutritional data.

Processing Activity Legal Basis
Account creation & loginContract (Art. 6(1)(b))
Food logging & nutrition trackingContract (Art. 6(1)(b))
AI recognition & Nour chatContract (Art. 6(1)(b))
Profile & health goalsConsent (Art. 6(1)(a))
HealthKit / Health Connect syncConsent (Art. 6(1)(a))
Optional precise-location route recordingConsent (Art. 6(1)(a), and Art. 9(2)(a) where applicable) — explicit feature choice and separate OS permission; workout logging remains available without GPS
Emotional InsightsConsent (Art. 6(1)(a)) — explicit opt-in, default OFF
Sentry crash reportingConsent (Art. 6(1)(a)) — opt-out available
Subscription managementContract (Art. 6(1)(b))
Data export / deletion requestLegal obligation (Art. 6(1)(c))
Fraud prevention & securityLegitimate interest (Art. 6(1)(f))

5. Third-Party Services & Processors

We engage the following service providers. DPAs or standard contractual clauses (SCCs) apply where available and verified; the table and notes disclose known exceptions.

Service Provider Purpose Data Processed
Vertex AI / Gemini Google Cloud Controlled food-recognition, nutrition-label OCR, and package-front candidate; audio transcription, memory embedding, Google Search grounding, and authenticated Nour Chat pre-output fallback The corresponding vision photo only when the Gemini candidate is selected; temporary audio, fallback Chat context, embedding/search input, or bounded memory/proactive input only for the selected capability
DeepSeek V4 Flash / V4 Flash Vision Exp / V4 Pro Hangzhou DeepSeek Artificial Intelligence Co., Ltd. Current food-recognition, nutrition-label OCR, package-front, authenticated Nour Chat, registered text-service, Deep Insight, planner, proactive-insight, and weekly-report primary Vision routes receive only current-request corresponding photo(s), prompt/schema and necessary capture metadata. Text routes receive only the bounded task input disclosed above. No route automatically attaches account email, internal user/entry ID, storage pointer, historical photo, audio or raw health-platform sample; user-authored conversation or email text may itself contain identifiers.
Cloud Storage Google Cloud Storage of food photos, nutrition label photos, avatars User-uploaded images
Cloud SQL / Cloud Run Google Cloud Backend infrastructure & data storage All app data
Upstash (Redis) Upstash, Inc. Backend cache & sessions (idempotency markers, App Attest nonces, quota counters, translation / food-search cache) — in production since 2026-09-06 Short-TTL cache entries only, which may include internal user IDs and bounded user-typed food or search text; no photos, audio, chat content, health-platform samples, or other special-category data
Sentry Functional Software Crash reporting & diagnostics Device info, stack traces, limited user context
Apple Sign-In / App Store Apple Inc. Social login, in-app purchases, subscription management Login tokens, purchase receipts
Google Sign-In / Play Store Google LLC Social login, in-app purchases, subscription management Login tokens, purchase receipts
HealthKit Apple Inc. Health platform integration (iOS) Health data (with authorization)
Health Connect Google LLC Health platform integration (Android) Health data (with authorization)
MapKit Apple Inc. User-requested outdoor route planning and guided navigation Current origin, destination, and necessary route-planning geometry for the request
FoodData Central USDA Nutrition database source No user data transmitted
Open Food Facts Open Food Facts Association Nutrition database source No user data transmitted

Data Residency for Vertex AI: We use Google Vertex AI's global endpoint region. Your data may be processed in Google Cloud data centers worldwide.

DeepSeek vision / Chat / registered text / Insight processing: The Open Platform Terms confirms processing of end-user Inputs but says the consumer DeepSeek Privacy Policy does not cover downstream end-user processing rules. Current evidence does not confirm the API processing/storage location and does not include a Nourai-specific DeepSeek DPA, fixed deletion SLA, processor-only instruction, training-use commitment, or sensitive-health-data acceptance.

5.1 Open Database License (ODbL) Notice

Nourai uses nutritional data from Open Food Facts, which is licensed under ODbL v1.0. Any derivative nutritional database based on Nourai remains subject to ODbL. Attribution to original contributors is available at openfoodfacts.org.

5.2 USDA Public Domain Notice

USDA FoodData Central data is a U.S. Government work in the public domain, free of copyright restrictions.

6. Data Storage & Security

6.1 Local Storage

  • iOS: Authentication tokens stored in Apple Keychain (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly); local cache uses SwiftData; unfinished outdoor routes use a separate AES-GCM encrypted, owner-scoped recovery file with complete-until-first-unlock file protection
  • Android: Authentication tokens stored in EncryptedSharedPreferences (AES-256-GCM); local cache uses Room

6.2 Cloud Infrastructure

  • Database: PostgreSQL (with pgvector extension), hosted on Google Cloud SQL in us-east4
  • Cache & sessions: Upstash Redis on AWS us-east-1, TLS-enabled, in production since 2026-09-06; the previous Memorystore instance in us-east4-b is retained inactive during the post-cutover observation window and then decommissioned
  • Object storage: Google Cloud Storage bucket nourai-photos in US-EAST4
  • Application hosting: Google Cloud Run in us-east4
  • Google AI processing: Google Vertex AI (global endpoint) for the recognition candidate and other disclosed capabilities
  • DeepSeek AI processing: V4 Flash / V4 Flash Vision Exp / V4 Pro for recognition, Chat, registered text services, proactive reports, and insight (API processing/storage location not confirmed by the Open Platform Terms)
  • Diagnostics: Sentry (United States)

Encryption in Transit: All client-server communication uses HTTPS with TLS 1.3.

6.3 Security Measures

  • Passwords: Argon2id hashing with random salts
  • Authentication: Short-lived JWT access tokens + refresh token rotation
  • Refresh tokens: Stored as SHA-256 hashes in our database
  • API security: Rate limiting, JWT authentication, parameterized SQL queries
  • Image security: EXIF metadata is stripped from uploaded photos
  • Least privilege: Service accounts granted only necessary permissions

No system is 100% secure. Please keep your account password confidential.

7. Data Retention

Data Category Retention Period
Account data, food records, photosDuration of active account
Private workout routesDuration of active account unless you delete the route or workout earlier; route-only deletion removes raw samples while retaining the coordinate-free workout summary and deletion tombstone
Account-cleanup records after account deletionMinimum former-account identifiers, storage-object addresses, cache-namespace identifiers, or encrypted provider-revocation credentials only until deletion or revocation is acknowledged. Storage or provider outages can extend this beyond 30 days. These records cannot restore account or photo access; raw pointers and credentials are removed after acknowledgement.
Chat messages & emotional observationsUser-controlled 30, 90, or 365 days from creation; legacy accounts use the configured fallback or 90-day default
Password reset / refresh / email verification tokensExpire and purged automatically
Voice audio filesDeleted immediately after processing, typically within seconds; transient retry retention must not exceed 24 hours
Server access logs30 days
Crash reports (Sentry)90 days
Aggregate diagnostics (memory quality, proactive events)No user ID or content retained
Minimal external-service cleanup records after account deletionUntil Google Cloud Storage, Redis, or Apple acknowledges deletion; these records cannot restore the account or App access

Account Deletion

You may delete your account at any time via Settings → Delete Account.

Upon deletion request:

  1. We immediately remove the active account and user-facing production records such as the profile, entries, workouts and raw routes, photo records, chat history, achievements, and memories. The deleted account and its photos or routes cannot be accessed through Nourai after this point.
  2. A separate deletion queue may retain only the minimum technical records needed to finish cleanup, such as a former-account identifier, storage-object address, cache-namespace identifier, or encrypted provider-revocation credential. These records cannot restore account or photo access.
  3. We retry storage deletion and provider revocation until acknowledgement. Storage or provider outages can keep the minimum cleanup record for longer than 30 days; raw storage pointers and revocation credentials are removed after acknowledgement. Google Cloud Storage soft-delete protection may retain an already deleted object for up to 7 additional days.
  4. Backups: Deleted data remains in automated backups for up to 90 days, after which it is overwritten by backup rotation
  5. Legal holds: Certain minimal data may be retained longer if required by law, fraud prevention, or accounting obligations

8. Your Rights

8.1 GDPR Rights (EEA & UK Residents)

Right Article How to Exercise
Right to AccessArt. 15View in App; or email [email protected]
Right to RectificationArt. 16Edit your profile in the App
Right to ErasureArt. 17Delete account in Settings, or call DELETE /api/v1/users/me
Right to Restrict ProcessingArt. 18Email [email protected]
Right to Data PortabilityArt. 20Use GET /api/v1/users/me/export (JSON); excludes password hashes
Right to ObjectArt. 21Disable Sentry in Settings; or email [email protected]
Right to Withdraw ConsentArt. 7Disable Emotional Insights, Health Sync, or Sentry; revoke location permission or stop using GPS route recording at any time
Automated Decision-MakingArt. 22Nourai does not make legally significant automated decisions about you

Response Time: We will respond to verified requests within 30 days. We may extend this period by 60 days for complex requests, in which case we will notify you.

8.2 CCPA Rights (California Residents)

If you are a California resident, you have the following rights under CCPA / CPRA:

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information: Disable Health Sync and Emotional Insights
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

To exercise CCPA rights, email [email protected].

Do Not Sell or Share My Personal Information: Nourai does not sell personal information and does not share personal information for cross-context behavioral advertising. If you still want to submit a "Do Not Sell or Share My Personal Information" request, email [email protected] with that phrase in the subject line.

8.3 Other Jurisdictions

If you are located in a jurisdiction with additional privacy rights (e.g., Brazil LGPD, Canada PIPEDA, South Korea PIPA, China PIPL), please contact [email protected].

For Canadian users, Nourai aims to provide meaningful consent by describing optional AI photo, label, voice, Health Sync, and Emotional Insights processing before or at the time you choose those features. You can decline optional features and still use core manual logging features.

9. Children's Privacy

Nourai is not directed to children under 13. We do not knowingly collect personal information from children under 13.

Age Gate: During registration, users must confirm they are 13 years of age or older. If we learn that we have inadvertently collected personal information from a child under 13, we will delete that information promptly.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected].

10. Tracking, Advertising & Data Sales

  • No Cookies (App): The Nourai mobile App does not use cookies.
  • No Advertising Trackers: We do not use Facebook Pixel, Google Analytics for Firebase Ads, AppsFlyer, Branch.io, or any other cross-app advertising tracking SDK.
  • No Data Sales: We do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising.
  • AppTrackingTransparency: We do not use Apple's AppTrackingTransparency framework.

Our website (nourai.app) may use essential cookies for functionality. We do not use third-party analytics cookies on our website.

11. International Data Transfers

  • Primary Processing: Our backend, database, and object storage are hosted on Google Cloud in us-east4 / US-EAST4.
  • Google AI Processing: Google Vertex AI uses the global endpoint for the registered recognition candidate and other disclosed capabilities; your data may be processed in data centers worldwide.
  • DeepSeek Recognition / Chat / Registered Text / Insight Processing: DeepSeek is the current food-recognition, authenticated Nour Chat, registered text-service, proactive-report, and insight primary. The Open Platform Terms does not confirm the API processing/storage location and says the consumer Privacy Policy does not cover downstream end-user processing rules; Nourai has not verified provider-specific SCCs or a DPA for these paths.
  • Diagnostics: Sentry processes data in the United States.
  • Cache: Short-TTL cache entries are processed by Upstash, Inc. on AWS in us-east-1 (United States) under its Data Processing Addendum, with EU SCCs and the EU-U.S. Data Privacy Framework as transfer safeguards.
  • Cross-Border Safeguards: We rely on Standard Contractual Clauses (SCCs) and Google's GDPR-compliant data processing terms.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes may be communicated through:

  • A versioned in-App notification banner
  • The current public policy and the "Last Reviewed" date at the top of this document
  • Additional channels, including email, when required by law

Because there were no existing external users before v4.0 took effect, the current build does not present a versioned in-app update notice or send a notification email for this private-route disclosure.

Your continued use of Nourai after any changes constitutes acceptance of the updated Policy.

13. Contact Us

Contact Address
Privacy inquiries[email protected]
Legal inquiries[email protected]
Formal legal service / mailing address requestsContact [email protected]. If a public mailing address is required, use a real business mailbox, PO Box, or virtual office address rather than a private home address.
Support[email protected]
Data Protection Officer (DPO)Nourai has not appointed a DPO for the v1 solo-developer launch. Use [email protected] for privacy requests; we will appoint a DPO if legally required.
Websitehttps://nourai.app