Skip to content
Nelora

Legal

Privacy Policy

Last updated: August 5, 2026

1. Scope, controller, and interpretation

This Privacy Policy ("Policy") governs the collection, use, disclosure, transfer, retention, and protection of personal data in connection with the Nelora mobile application (the "App"), the website published at https://nelora.app (the "Site"), and all related features, interfaces, and back-end services operated by us (together, the "Service"). This Policy applies to all users of the Service, wherever situated, subject to the jurisdiction-specific provisions at section 18.

The controller of the processing described in this Policy (and, where applicable, the "business" within the meaning of the California Consumer Privacy Act as amended) is Line 19 LLC, a limited liability company organised under the law of the State of Wyoming, United States, of 30 N Gould St Ste N, Sheridan, WY 82801, United States, trading as Nelora ("Nelora", "we", "us", "our"). Enquiries, rights requests, and complaints may be addressed through the contact page or to privacy at nelora dot app .

In this Policy: "personal data" (equivalently, "personal information") means any information relating to an identified or identifiable natural person; "processing" means any operation performed upon personal data, whether or not by automated means; "health data" means the health-adjacent and wellbeing data enumerated at section 2.2, which constitutes special-category personal data under Article 9 of the UK GDPR, sensitive information under the Privacy Act 1988 (Cth), and sensitive personal information under applicable United States state privacy legislation, and which is subject throughout to the heightened handling described in this Policy; "processor" means a person or entity processing personal data on our documented instructions; and "anonymised data" means data which has been irreversibly stripped of identifiers and aggregated or otherwise transformed such that neither we nor any recipient can, by any means reasonably likely to be used, re-identify a natural person from it, and which accordingly does not constitute personal data.

Headings are for convenience and do not affect construction. This Policy describes our practices as at its date; it is a notice given for the purposes of applicable data-protection law and does not form part of any contract, create any warranty, or confer any contractual right. Descriptions of technical design describe how the Service is built rather than guaranteeing a result in every circumstance.

2. Categories of personal data processed

2.1 Account and identity data

Your email address, the display name you choose, the authentication provider used (email and password, Sign in with Apple, or Sign in with Google), the authentication identifier assigned by our identity provider, an internal account identifier generated by us, your device timezone, and account lifecycle timestamps. Authentication is performed by a third-party identity provider; where you authenticate with a password, that password is processed by that provider and is neither transmitted to nor stored by us. Where you authenticate by way of a platform sign-in service, we receive only the identifiers and, where you permit it, the email address that the platform discloses to us, including any private relay address you elect to use.

2.2 Health and wellbeing data

Data you elect to record in the App, comprising: menopause stage; selected symptoms and their severity, timing, and recurrence; suspected triggers; the goal you identify at onboarding; mood, sleep, and energy ratings; daily context flags; menstrual-cycle context and recorded period days; timestamped symptom events recorded through in-app or widget logging; medication-related context you enter; and free-text notes. Recording is at all times voluntary and item-by-item; the Service functions on whatever subset you choose to provide.

2.3 Health data imported from Apple Health (iOS only)

Where you expressly grant the corresponding iOS permission, the App reads a fixed, read-only set of Apple Health types, being sleep analysis, step count, exercise time, workout duration, resting heart rate, and menstrual flow. The App requests no write access and reads no other type. Samples so read are reduced on your device to a daily summary row and the underlying samples are not retained; the retained fields are limited to date, sleep minutes, awake minutes, steps, exercise minutes, total workout minutes, average resting heart rate, and a single daily menstrual-flow label. Apple Health summaries are held in device storage, are held separately from data you record manually, and are not transmitted to our servers, to analytics, or to any AI service. Apple does not disclose to applications whether a read permission has been refused or restricted to a limited history, and the App accordingly makes no representation as to what has in fact been shared. You may vary or withdraw the permission at any time in iOS Settings, Privacy & Security, Health, Nelora.

2.4 Chat data

The content of messages you submit to, and responses you receive from, the Service's chat feature (the "Chat"), together with routing and quota-enforcement metadata. The storage of message content differs by plan and is described at section 6. Where you use dictation to compose a message, the transcription is performed by your operating system's speech-recognition service under permissions you grant to it; we neither record, store, nor transmit audio, and only the resulting text enters the Service, where it is treated as though you had typed it. Your device operating system may transmit audio to its vendor's speech services under that vendor's own terms and privacy policy, over which we have no control.

2.5 Consent records

Three separately recorded consent values, being consent to the processing of health data (mandatory, and a precondition to the existence of an account), consent to marketing email, and consent to the personalisation of marketing email using data you record (each optional), together with the timestamp at which each value last changed, retained so that the state and history of your consent remain auditable.

2.6 Billing and entitlement data

Where you purchase a subscription or a one-time item, we process the signed transaction records issued by the app marketplace, the marketplace transaction and product identifiers, an opaque purchase token generated by us to associate a marketplace transaction with your account, the derived plan and billing period, and the derived entitlement state and its expiry or renewal status. Payment is taken by the app marketplace and not by us: we do not receive, process, or store your payment card number, bank details, or billing address. Billing records are held in a storage boundary separate from health data.

2.7 Notification delivery data

Where you enable notifications, the push token issued by the platform push service and the identity of that service. The push token is treated as a sensitive delivery credential, is held in a dedicated registration store separate from your profile and health data, is never returned by our profile endpoints, and is excluded from logs, analytics, tracing attributes, metrics labels, and AI inputs.

2.8 Technical, diagnostic, and usage data

Device model, operating-system version, App version and build, language, locale, and timezone; uncaught application exceptions, unhandled rejections, native crash reports, exception stack traces, and developer-authored diagnostic breadcrumbs; application lifecycle events (install, update, open, foreground, background); and a closed, pre-registered allow-list of product-analytics events describing feature use. Allow-listed analytics events are constrained by design to carry counts, booleans, fixed enumerated values, and — in respect of purchases only — product identifier, price, and currency. They are designed not to carry symptom, trigger, stage, goal, note, chat content, or other free-text values, and events outside the allow-list are filtered before transmission. Diagnostic and analytics records are keyed to an internal account identifier; neither your email address nor your authentication identifier is used as an analytics identity. Server logs record error classes and identifiers and do not record request bodies, authorisation headers, tokens, health payloads, notes, or AI prompts.

2.9 Site data

The Site is a static publication served through a content-delivery network and uses a cookieless, privacy-preserving traffic measurement service which reports aggregate page-level metrics and does not set cookies, assign persistent identifiers, or construct individual profiles. Our content-delivery and security provider processes connection metadata, including IP address, transiently for the purposes of routing, transport security, and abuse mitigation. No advertising or cross-site tracking technology is deployed on the Site.

2.10 Communications data

Where you contact us, the content of your message and the address required to reply. Contact-form submissions are transmitted by email to us through an email-delivery provider and are not otherwise retained by the Site.

2.11 Data we do not collect

We do not collect precise geolocation, contact lists, photographs, camera or microphone recordings, biometric identifiers other than the Apple Health metrics enumerated at section 2.3, advertising identifiers, or cross-application tracking data. We do not deploy session-replay, screen-recording, or touch-recording instrumentation. We do not operate advertising cookies on the Site.

2.12 Advertising attribution data

To measure whether our own advertising results in installations of the App, the App participates in Apple's privacy-preserving attribution frameworks (SKAdNetwork and AdAttributionKit). The App updates an on-device conversion value that encodes a single coarse milestone: installation, completion of onboarding, or a purchase category. Attribution postbacks are assembled, anonymised, subjected to crowd-size thresholds, and transmitted by Apple, not by us; they contain no identifier of you or your device, and neither we nor any advertising network receives user-level attribution data. The App embeds no advertising network's software, collects no advertising identifier, and does not present the App Tracking Transparency prompt, because it does not track. The milestone code is stored on the device only and carries none of the data described elsewhere in this section.

3. Legal bases for processing

Where the UK GDPR or an equivalent regime applies, we rely upon the following bases:

  • Explicit consent (Article 6(1)(a) and Article 9(2)(a)) for all processing of health data. That consent is obtained through a dedicated, unticked control presented during onboarding, which links to this Policy and describes the processing before the control is offered. Consent to the processing of health data is a precondition to the creation of an account and to the operation of the Chat, which is gated upon it at the server. The two marketing consents are separately and independently obtained through controls presented pre-selected during onboarding, which you can deselect before completing sign-up; they gate no feature of the Service, and may be withdrawn without consequence to your use of the Service.
  • Performance of a contract (Article 6(1)(b)) for account administration, provision of the features you request, synchronisation of your records to your account, and administration of purchases and entitlements.
  • Legitimate interests (Article 6(1)(f)) for security, fraud and abuse prevention, service integrity, defect diagnosis, and product improvement by reference to the content-free diagnostic and allow-listed analytics data described at section 2.8, in each case balanced against your interests, rights, and reasonable expectations.
  • Legal obligation (Article 6(1)(c)) where retention, disclosure, or restriction is required by applicable law.
  • Vital interests or substantial public interest (Article 6(1)(d) and, as applicable, Article 9(2)(c) or 9(2)(g)) only where necessary to address a risk to life or a serious safety matter.

Withdrawal of consent operates prospectively and does not affect the lawfulness of processing carried out in reliance upon it before withdrawal. Withdrawal of consent to the processing of health data is effected by deletion of your account, that consent being constitutive of the account.

4. Purposes of processing

  • Provision of the Service – recording, storing, and returning to you the data you enter; synchronising your records between your device, your account, and the home-screen widget; and restoring your records upon sign-in to a device.
  • Analysis presented to you – computing, from data you have recorded and, on iOS, from Apple Health summaries held on your device, derived day-level values and possible associations between recorded factors, solely for presentation to you within the App. Such analysis is computed for display and yields observations, not clinical findings, and is not used to evaluate, score, profile, or make any decision about you producing legal or similarly significant effects.
  • Chat – generating responses to the messages you send, subject to section 6.
  • Doctor report – assembling, on your device, a summary document of your own records for you to save, print, or share at your discretion. The resulting document is generated locally and passed to your operating system's share interface; we do not receive it and do not know to whom you send it.
  • Reminders and notifications – where enabled. Notification payloads are constructed so as to contain no symptom name, log content, or other health data, in order that sensitive information does not appear upon a lock screen or traverse third-party notification infrastructure. The same constraint applies to email subject lines and preview text.
  • Marketing email – where you have consented. Segmentation, targeting, or personalisation of marketing by reference to health data requires the second, separate consent; absent that consent, audience selection uses only non-health signals such as plan status, engagement, and account tenure. Every marketing email carries a functioning unsubscribe mechanism.
  • Purchases and entitlement – verifying transactions with the app marketplace, deriving and maintaining plan entitlement, processing marketplace lifecycle notifications including renewal, cancellation, refund, and revocation, and responding to billing enquiries and disputes.
  • Security, integrity, and improvement – diagnosing faults, protecting the Service and its users against abuse, and understanding aggregate feature use by reference to content-free events.
  • Research – producing anonymised data for the research purpose described at section 8.
  • Support and compliance – responding to your enquiries and rights requests and discharging legal obligations.

We do not sell personal data; we do not share personal data for cross-context behavioural advertising; we do not disclose personal data to advertising networks or data brokers; we do not use health data for advertising of any kind; and we do not subject you to automated decision-making producing legal or similarly significant effects. Nelora is a consumer wellbeing product and not a covered entity or business associate; no representation of HIPAA coverage is made, and the protections described in this Policy are applied to health data uniformly and irrespective of that fact. Where we advertise Nelora, campaign measurement relies solely on the aggregate, anonymised attribution postbacks described at section 2.12 and on aggregate campaign reporting from the App Store; no personal data is disclosed to any advertising platform for that purpose.

5. Storage architecture and separation

Your device is the primary record of the data you enter. Check-in entries and timestamped symptom moments are additionally mirrored to your authenticated account as a background synchronisation, so that your history is restored when you sign in on a device; the mirrored copy is stored opaquely, scoped to your account, and excluded from logs, analytics, tracing attributes, metrics labels, email targeting, and AI inputs. We do not represent that data recorded in the App remains solely on your device.

Health data, billing records, and notification-delivery credentials are held separately from one another. Apple Health summaries are not written into the records you enter manually, and the two meet only transiently at the point of analysis, as derived values recomputed for display; surfaces presenting both measured and self-recorded data distinguish between them.

6. Chat: processing, personalisation, and retention

Chat is a feature of the Service and is subject to the following terms in addition to the remainder of this Policy.

  • Eligibility and gating. Chat requires a valid account and the persisted health-data consent, which is enforced at the server and not merely in the App. There is no separate AI consent value; a request unaccompanied by the persisted consent is rejected.
  • Processing infrastructure. Responses are generated in part by deterministic, pre-authored routing and in part by a third-party generative model operated by our AI infrastructure provider acting as our processor under a written data-processing agreement. That agreement prohibits use of your data for the training or improvement of models and prohibits retention beyond that required to return a response. The App holds no model credentials and does not communicate with the model provider directly; all traffic is proxied through our own service, which enforces consent, quota, safety, and routing.
  • Data minimisation and personalisation. On the Free plan no personal health summary is transmitted with a message and answers remain general. On the Plus plan, and only where the conditions for it are met, a bounded, aggregate-only personalisation summary is computed on your device from recent recorded data and transmitted with the request. That summary comprises aggregate values only; it contains no note text, name, email address, or individual record; it is validated on receipt; and it is not persisted on our servers.
  • Retention of message content. Conversations created on the Plus plan, and their messages, are stored in your authenticated account and retained until you delete the individual conversation or your account. Conversations created on the Free plan are retained on your device; server-side we retain only routing and offer-enforcement metadata for such conversations, and not message content. Deleting a conversation deletes its stored messages. Deleting your account deletes all stored chat data. Conversations are scoped to their owner and are not accessible to any other user.
  • Human review. We do not routinely read your conversations. Access by our personnel occurs only where necessary for safety, security, abuse investigation, defect diagnosis at your request, or compliance with law, and is subject to access control and confidentiality obligations.
  • Limits by design. Chat is subject to per-day message quotas which differ by plan and which we may vary. It is designed to decline requests for diagnosis, dosage, or treatment decisions, to respond to indications of urgent risk with pre-authored guidance directing you to appropriate care, and to suppress commercial content in such circumstances.
  • Logging. Prompts, message bodies, responses, personalisation summaries, and tokens are excluded from logs and metrics; operational metrics are limited to content-free counters, route distribution, latency, and error rates.

7. Product suggestions, referrals, and affiliate links

Within Chat, and nowhere else in the Service, we may present a suggestion for a third-party product where it is relevant to the matter under discussion and, in the case of an unsolicited suggestion, where you have first been asked and have indicated interest. Suggestions are drawn exclusively from a curated catalogue fixed at build time; the model cannot originate a product, price, merchant, or link. The following applies:

  • No disclosure to partners. Selection occurs within the Service. Referral and affiliate partners receive neither your identity, nor your health data, nor the conversational context in which a suggestion arose. Attribution is carried within the catalogue link itself.
  • Disclosure of commercial interest. Referral and affiliate links are identified as such at the point at which they appear. We may earn a commission where you purchase through such a link.
  • No analytics on sensitive intent. Product intent and link engagement of a sensitive character are not recorded in analytics.
  • Third-party responsibility. Upon following a link to a partner's site or store, that partner's privacy policy and terms govern from that point.

8. Anonymised data and research use

We may produce anonymised data from data held in the Service and disclose that anonymised data to research institutions and academic or scientific research laboratories for the purpose of research into menopause, perimenopause, and women's health. The following conditions govern that activity and are cumulative:

  • Anonymisation before disclosure. Only anonymised data is disclosed. Direct and indirect identifiers – including name, email address, account and device identifiers, free-text notes, precise timestamps, and any value capable of singling out an individual – are removed or generalised before disclosure, and the data disclosed is aggregated or otherwise transformed such that re-identification is not reasonably possible. We do not disclose a key, and no recipient is placed in a position to reverse the process.
  • No identified or pseudonymised health data. We do not disclose your health data in identified or pseudonymised form to any research recipient. A dataset from which you could be singled out, directly or indirectly, is not anonymised data for the purposes of this section and falls outside this permission.
  • Contractual restriction. Disclosure is made only under a written agreement restricting use to the stated research purpose, prohibiting any attempt at re-identification, prohibiting onward disclosure otherwise than on equivalent terms, and prohibiting any advertising, marketing, insurance, employment, credit, or commercial-targeting use.
  • No sale of personal data. We do not sell personal data. Anonymised data is disclosed only to research recipients upon the restrictions set out in this section and is not made available to advertising networks, data brokers, insurers, or employers. We may recover the costs of preparing anonymised data, and may participate in funded or collaborative research, neither of which derogates from those restrictions.
  • Status of anonymised data. Anonymised data is not personal data. Consequently, and by operation of law rather than by our election, rights of access, correction, erasure, and portability do not attach to it once anonymisation is complete, and it may be retained and used after deletion of your account. The preparation of anonymised data from your personal data is itself processing to which this Policy and your rights apply up to the point of anonymisation.

Save as set out in this section and at section 9, we do not share your personal data with any third party for that party's own purposes.

9. Recipients of personal data

We do not sell personal data, and we do not disclose personal data to any third party for that party's own purposes save as set out in this section and at section 8. We engage a limited number of service providers which process personal data on our documented instructions and on our behalf, under written data-processing agreements imposing obligations of confidentiality, security, control of sub-processing, assistance with data-subject rights, and deletion or return upon termination. Those providers fall within the following categories:

  • cloud infrastructure, hosting, managed database, and storage providers, which process the account, onboarding, synchronised tracking, chat, consent, billing, and notification-registration data described at section 2;
  • identity and authentication providers, which process account identifiers and credentials;
  • AI infrastructure providers, which process chat content as described at section 6;
  • content-delivery, network-security, and cookieless traffic-measurement providers, which process connection metadata and aggregate site metrics;
  • diagnostics and product-analytics providers, which process the technical and allow-listed usage data described at section 2.8;
  • application-update and notification-delivery providers, which process application version metadata and notification tokens and payloads;
  • email-delivery providers, which process communications data; and
  • app marketplace and platform operators, which process purchase, subscription, and sign-in data under their own terms as described below.

App marketplace and platform operators — being the operator of the marketplace from which you obtained the App, and the provider of any platform sign-in service or operating-system speech recognition you elect to use — act as independent controllers in respect of the data they receive, and their own privacy policies govern that processing. We do not receive your payment card, bank, or billing address details.

We maintain an internal record of the providers we engage, assess the security and data-protection practices of each before and during engagement, and may add, replace, or retire a provider within the categories above without amending this Policy. A statement of the specific providers engaged at a given time, and of the safeguards applying to them, is available to you on request under section 14. Research recipients are addressed separately at section 8 and receive anonymised data only.

Beyond the foregoing, we may disclose personal data: (a) where required by law, regulation, legal process, or an enforceable governmental or regulatory request, and then only to the extent so required and, where lawful and practicable, upon notice to you; (b) where necessary to establish, exercise, or defend legal claims, or to protect the rights, safety, or property of you, other users, the public, or us; and (c) in connection with a merger, acquisition, financing, reorganisation, or sale of assets, in which case the transferee shall remain bound by commitments materially consistent with this Policy and we shall give notice before health data becomes subject to a materially different policy.

10. International transfers

The Service is offered to users in the United States, the United Kingdom, and Australia. Our primary infrastructure is located in the United States, and personal data is accordingly processed in a country other than that in which you may reside. Where applicable law regulates such transfers, we implement recognised safeguards, which may include the standard contractual clauses approved by the European Commission together with the United Kingdom International Data Transfer Addendum, or the United Kingdom International Data Transfer Agreement, supplemented by technical and organisational measures including encryption in transit and at rest and access control. For transfers of personal information of Australian users, we take steps reasonable in the circumstances to ensure the recipient handles it consistently with the Australian Privacy Principles as required by APP 8. Particulars of the safeguards applicable to a given transfer are available upon request.

11. Security

We implement technical and organisational measures appropriate to the nature, scope, context, and purposes of processing and to the risk to individuals. Those measures include encryption of personal data in transit and at rest, access controls under which stored records are scoped to the owning account and internal access is restricted to personnel requiring it for the operation of the Service, and the design of operational logging and diagnostics so as to exclude health data content, free-text notes, chat content, credentials, and tokens. Measures are reviewed and may be varied from time to time, provided that we shall not materially reduce the overall level of security applied to health data. We do not publish further particulars of our security arrangements, disclosure of which would itself present a risk.

No method of transmission or storage is entirely secure, and we do not warrant absolute security. Where a personal data breach affecting your personal data occurs, we shall notify the competent supervisory or regulatory authority and, where required, you, within the periods and upon the thresholds prescribed by applicable law, including the UK GDPR and the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).

12. Retention and deletion

We retain personal data for so long as your account subsists, save as set out below. Deleting a conversation deletes its stored messages. Deleting your account causes, in sequence, the deletion of all stored chat data, the deletion of the mirrored check-in and moment records, the deletion of the push registration, the closure of the account, and the blocking of its authentication identifier, followed by the erasure of the App's data from the device on which deletion is performed. Access to the account cannot thereafter be restored.

Residual copies present in encrypted backup media at the time of deletion are not immediately individually addressable and are superseded in the ordinary course of backup rotation, during which period they remain encrypted, access-controlled, and used for no purpose other than restoration of the Service.

Two categories are expressly excepted from deletion. First, minimal records of billing ownership and linkage, and records of transactions and marketplace lifecycle events, are retained after account deletion for so long as necessary to establish who paid for what, to administer refunds, chargebacks, and disputes, and to comply with tax, accounting, and consumer-law record-keeping obligations. Second, anonymised data prepared in accordance with section 8, being no longer personal data, is unaffected by deletion of the account. Where applicable law requires longer retention of a specific record, we retain only that record, and only for so long as required.

Deletion of your Nelora account does not cancel any subscription purchased through an app marketplace, and does not of itself effect a refund. Cancellation is performed in the subscription settings of the marketplace through which the subscription was purchased.

13. Controls available to you within the Service

Without contacting us, you may at any time:

  • edit or delete the entries you have recorded, and edit the onboarding answers held in your profile;
  • delete an individual stored chat conversation;
  • grant or withdraw either optional marketing consent in the App's email preferences, and unsubscribe from any marketing email by the mechanism it carries;
  • enable or disable reminders and notifications, both in the App and in your operating-system settings;
  • on iOS, grant, restrict, or withdraw Apple Health read permission in iOS Settings, Privacy & Security, Health, Nelora;
  • sign out, which cancels reminders and erases the App's data from the device without deleting your account; and
  • delete your account and its associated data, from the You tab.

A self-service export of your data is not presently offered within the App. Until it is, requests for a copy of your data in a portable format are fulfilled by us upon request under section 14.

14. Your rights

Subject to and to the extent conferred by the law of your jurisdiction, you have the rights: to be informed of the processing of your personal data; to obtain access to it and a copy of it; to have inaccurate personal data rectified; to have personal data erased; to restrict processing; to object to processing carried out on the basis of legitimate interests; to receive personal data you have provided in a structured, commonly used, and machine-readable format and to have it transmitted to another controller where technically feasible; to withdraw consent at any time; and to lodge a complaint with a supervisory or regulatory authority.

Requests may be submitted through the contact page or to privacy at nelora dot app . We shall verify that a request emanates from the account holder before acting upon it, by reference to the address associated with the account, and may request further information for that purpose alone. We shall respond within the period prescribed by the applicable law conferring the right, and may extend that period where the applicable law permits, in which case we shall notify you of the extension within the initial period. Where a request is not verifiable, is not made by or on behalf of the account holder, or concerns data which is not personal data, we may decline to act, giving reasons. No fee is charged unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, giving reasons. You may nominate an authorised agent to act on your behalf where applicable law so provides. We do not subject you to detrimental treatment for exercising any right.

Rights of access, rectification, erasure, and portability do not attach to anonymised data, which is not personal data and from which you cannot be identified; see section 8.

15. Children

The Service is intended for adults navigating the menopause transition. It is not directed to, and may not be used by, persons under the age of 18. We do not knowingly collect personal data from a person under 18. Where we become aware that we have done so, we shall delete the account and the associated data without undue delay. A parent or guardian who believes that a person under 18 has provided personal data to us should contact us at once.

16. Marketing communications

We send marketing email only where you have given the corresponding consent. During onboarding the marketing consent controls are presented pre-selected; you can decline them there with a single tap before completing sign-up, and no marketing email is sent unless you proceed with the consent selected. The consent is sought separately from the health-data consent, gates no feature of the Service, and may be withdrawn as easily as it was given. Personalisation of marketing by reference to data you have recorded requires the further, separate consent described at section 2.5. Transactional and service messages necessary to the operation of your account, including security, billing, and material changes to this Policy, are not marketing and are sent irrespective of marketing consent.

17. Cookies and similar technologies

The Site sets no advertising or tracking cookies and deploys no cross-site tracking technology; its traffic measurement is cookieless and aggregate. Strictly necessary technologies may be employed by our content-delivery and security provider for transport security and abuse mitigation. The App uses device storage to hold your records and preferences locally, which is necessary to its operation.

18. Jurisdiction-specific provisions

18.1 United Kingdom

Processing of the personal data of users in the United Kingdom is subject to the UK GDPR and the Data Protection Act 2018. Health data is processed upon the basis of explicit consent under Article 9(2)(a). You have the rights set out at section 14 and the right to lodge a complaint with the Information Commissioner's Office, whose contact particulars are published at ico.org.uk. We ask that you raise the matter with us first so that we may seek to resolve it.

18.2 United States

We do not sell personal information and we do not share personal information for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended by the California Privacy Rights Act and by comparable state legislation; there is accordingly no right to opt out of a sale or sharing to be exercised. We collect the categories of personal information described at section 2, from the sources and for the business purposes described at sections 2 and 4, and disclose them to the categories of recipient described at section 9. We treat health data as sensitive personal information and use and disclose it only for purposes permitted without a right to limit under applicable state law; we do not use or disclose sensitive personal information for the purpose of inferring characteristics about you. Residents of California and of other states conferring equivalent rights have the rights to know, access, correct, delete, and port personal information, to limit the use of sensitive personal information to the extent applicable law confers that right, and to be free from discrimination for exercising a right, exercisable as set out at section 14. Anonymised data disclosed under section 8 constitutes deidentified information: we have implemented measures designed to prevent re-identification, publicly commit by this Policy to maintain and use such information only in deidentified form and not to attempt to re-identify it save as permitted by law solely to test the adequacy of the deidentification, and contractually oblige every recipient to the same effect.

18.3 Australia

We handle the personal information of Australian users in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Health information is sensitive information for the purposes of APP 3 and is collected only with your consent and used and disclosed only for the purposes described in this Policy in accordance with APP 6. Cross-border disclosures are governed by APP 8 as described at section 10. You may seek access to and correction of your personal information under APP 12 and APP 13 as described at section 14. If you are dissatisfied with our handling of a complaint, you may complain to the Office of the Australian Information Commissioner, whose contact particulars are published at oaic.gov.au.

19. Third-party services and links

The Service contains links to third-party websites and services, including the referral links described at section 7 and the sources cited in Site articles. This Policy does not govern any third party, and we accept no responsibility for the privacy practices or content of any third party. Your use of an app marketplace, of a platform sign-in service, of your operating system's speech recognition, and of the Apple Health application is governed by the terms and privacy policy of the relevant provider.

20. Amendments

We may amend this Policy from time to time. Where an amendment is material – and in particular where it affects the processing of health data, the operation of Chat, or the research use described at section 8 – we shall give prominent notice within the App before the amendment takes effect and, where applicable law so requires, obtain fresh consent. The date stated at the head of this Policy is that of the current version. Continued use of the Service following the effective date of a non-material amendment constitutes acceptance of it.

21. Contact

Enquiries, rights requests, and complaints concerning this Policy may be directed to privacy at nelora dot app or submitted through the contact form.