Legal

Privacy Policy

Last updated: August 22, 2026

🔒
On-device first Your daily insights never leave the device
☁️
Your iCloud, not ours Your logs sync under your Apple ID
🚫
Never sold Your data is never sold or shared
🗑
Delete anytime Full data deletion on request

Overview

Nora ("we", "our", "the app") is a personal health application for iOS. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data. We believe your health data is deeply personal and we take that responsibility seriously.

Nora does not sell or rent your personal health information, and never hands it to anyone for advertising, profiling, or model training. Ever. The one place your data is processed off your device is the weekly analysis, and this policy spells out exactly what it contains.

Nora is designed with your privacy rights in mind, in accordance with GDPR (EU), KVKK (Turkey), UK GDPR, and other applicable data protection regulations.

Data We Collect

Nora collects the following types of information:

How We Use Your Data

Apple Health (HealthKit)

Nora uses Apple's HealthKit framework to read HRV and related metrics, and to save your breathing sessions as Mindful Minutes. We request only the minimum data required. Your raw HealthKit samples are processed on-device and are never uploaded anywhere; the one exception is the weekly analysis described below, which sends a condensed weekly summary such as an average and a percentage change, never individual readings. You can revoke Health access at any time in Settings → Privacy & Security → Health → Nora.

If mood sync is on, each daily mood check-in is also saved to Apple Health as a State of Mind entry, and moods you log on Apple Watch or in the Health app are read back into Nora for days you left empty. Only the mood value goes to Health, plus a fitness tag when you ticked exercise on that check-in. Your notes, symptoms, medications, and the people you tag are never written to Health. You can turn this off at any time in Nora → Settings → Your Data → Sync mood with Apple Health.

iCloud Sync (CloudKit)

Your symptom and mood logs are stored in your personal iCloud account using Apple's CloudKit. Your data is encrypted in transit and at rest by Apple, and is accessible only through your Apple ID. Nora does not have access to the contents of your CloudKit database.

Analytics and Diagnostics (Firebase)

Nora uses Firebase Analytics and Firebase Crashlytics. Analytics records one event per day, that Nora was opened, plus the standard session and screen events the Firebase SDK collects on its own. Crashlytics records crash reports so we can fix what broke. Neither carries your health data: the events Nora sends have no place to put a mood, a symptom, a note, or a name. Both are tied to the same switch and stop completely when you turn it off, in Nora → Settings → Privacy → Anonymous Data Sharing.

AI Processing

Nora's everyday insight engine runs entirely on your device. Your nervous system score, trigger analysis, weekly patterns, correlations, and early-warning check-in are all computed locally, and on iOS 18.1+ with Apple Intelligence enabled the wording is refined locally too. None of that leaves your iPhone. The early-warning check-in can send you a reminder when you have not opened Nora, and that notification is written to reveal nothing: it names no symptom, score, or finding, so nothing sensitive is displayed on your lock screen.

Two features are different, and we want to be plain about them. Your weekly analysis and the insight that closes a meditation are generated by a large language model, Anthropic's Claude, reached through our own Firebase Cloud Function over an encrypted connection. For the weekly analysis, what is sent is a condensed summary of the previous week: counts and averages for your symptoms, mood, HRV, nervous system states and anger check-ins, plus up to four short excerpts, capped at 200 characters each, from notes you wrote yourself. For the meditation insight, what is sent is the gratitude list, intention, topic, and notes you just wrote in that session.

What is never sent: your safety plan, the names of the people you tag, your medications and doses, your cycle entries, your prediction journal, your appointments, and your raw HealthKit samples. Requests are authenticated with an anonymous Firebase sign-in that carries no name, email, or account of yours, the content is not used to train any model, and the result is stored on your device. A generated weekly analysis is also cached on our side for up to 14 days, as described under Data Retention and Deletion below. If you would rather not use these two features, simply do not open them; every other part of Nora keeps working on-device.

Data That Stays on Your Device

Your safety plan is the most sensitive thing in Nora, so it is handled differently from everything else. It is written to a protected file on the device that created it, excluded from iCloud backup, and never synced through CloudKit. It works with no network at all. Nothing about it is ever sent to us, and it is included in an export only when you explicitly ask for the sensitive sections.

Everything else you log, including the names of the people you tag and the small on-device index Nora builds from your own notes, is part of your private iCloud database like the rest of your entries. That means it syncs between your own devices under your Apple ID, and it means we cannot read it either.

App Lock

You can require Face ID, Touch ID, or your device passcode before Nora opens, in Settings → Privacy → App Lock. The check is performed by iOS; Nora never sees your face data, fingerprint, or passcode, and stores nothing about them. App Lock protects the app on your device and is separate from encryption, which Apple applies to your iCloud data regardless. Crisis support remains reachable from the lock screen on purpose.

Export and Restore

In Settings → Your Data → Export & Restore you can write everything Nora holds into a file you keep: a backup file Nora can read back, or an archive with a spreadsheet per section. You choose whether the sensitive sections, your people, medications, and safety plan, are included. Nora asks you to unlock before writing the file, and the file itself is not encrypted, so store it somewhere you trust. Once it leaves the app it is yours to look after; we never receive a copy of it.

Notes You Send Us

When you use Settings → Leave Nora a note, the message you write is sent to our servers, together with the category you picked, the app version, your iOS version, and the language the app was showing. If you choose to leave an email address, we store it so that we can reply to you, and we use it for nothing else. A note carries no identifier: no user id, no device id, and none of your entries, journal, mood, medications, people, or safety plan. We read these notes ourselves, and we do not share or sell them. Because a note is not tied to you, we can only find one again to delete it if you left an email address or can tell us roughly when you sent it.

Data Retention and Deletion

Your data is retained as long as you use Nora or until you request deletion. To delete all your data:

Children's Privacy

Nora is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided health data through Nora, please contact us so we can delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or by updating the "Last updated" date at the top of this page.

Contact Us

If you have questions or concerns about your privacy, or would like to request data deletion, please contact us at:

yusasarisoy@icloud.com