← Back to NURA AI
Privacy Policy

Your life is personal. We treat it that way.

NURA is being designed around a local-first private vault, strong encryption, explicit permissions, and data minimization. This policy explains the privacy model we intend the NURA mobile application and connected services to follow.

Last updated: August 11, 2026

Your private vault stays on your device

Files, photos, videos, health records, documents, notes, reminders, and personal history stored in the NURA private vault are designed to remain on your device by default.

Sensitive data is encrypted

NURA is designed to protect private-vault content in encrypted form at rest and to use secure transport for any transfer you explicitly authorize.

No advertising profile and no data sale

NURA does not sell private-vault information to advertisers, data brokers, or third parties for cross-app advertising or behavioral profiling.

Permission before optional sharing

If a feature requires information to leave the device, NURA must clearly identify what will be shared and why before that transfer can occur. Optional integrations are user-controlled.

1. Information stored in your private vault

Depending on the features you use, NURA may let you store documents, images, videos, voice notes, reminders, calendar information, health information, vehicle information, travel information, financial organization data, and other content you choose to add. Private-vault content is intended to stay on your device unless you deliberately use a feature that requires a transfer.

2. No silent background upload of your private vault

NURA is designed not to silently copy your private-vault files, photos, videos, documents, or records to NURA servers merely because they exist in the app. A feature that needs external processing or an external integration must be permission-gated and should tell you what data is involved before you proceed.

3. Encryption and access controls

Private-vault content is designed to be protected using encryption at rest, operating-system security controls, and NURA access controls. Where a user authorizes data to be transmitted, secure encrypted transport should be used. You are responsible for maintaining the security of your device, passcode, biometric access, backups, and operating-system account.

4. Photos, videos, camera, microphone, and files

NURA should request access only when a feature needs it. Camera, photo library, microphone, file, calendar, health, location, notification, and similar device permissions remain governed by the permissions you grant through your device. You can revoke operating-system permissions at any time through device settings.

5. Connected services and optional integrations

You may choose to connect services such as calendars, email, cloud drives, maps, health platforms, or other applications. Each integration should be optional and limited to the permissions required for the feature you enable. Disconnecting an integration stops future access through that connection, subject to the third party’s own systems and retention rules.

6. AI processing

NURA’s goal is to perform as much private processing on-device as practical. If a specific AI feature cannot run fully on-device and requires external processing, the product should disclose that fact before private-vault content is sent. NURA should not use private-vault content to train advertising models or build third-party marketing profiles.

7. Data sale, advertising, and profiling

NURA does not sell private-vault information. NURA is not designed to share private-vault content with data brokers or advertising networks for targeted advertising based on your private life, documents, health information, or activity stored in the vault.

8. User control, export, and deletion

NURA is designed to give you clear controls to remove stored items, disconnect integrations, revoke permissions, and delete local private-vault information. Where optional cloud services are introduced, their export and deletion tools should be documented separately and made accessible from account or privacy settings.

9. Children

NURA should not knowingly collect personal information from children in a way that conflicts with applicable law. Age requirements and parental-consent rules may vary by country and by the services a user connects.

10. Changes to this policy

Privacy behavior must match this policy and the actual product. If NURA’s data flows materially change, this policy should be updated before or alongside the change, and important changes should be clearly communicated to users.

Product promise

Privacy claims must match the shipping application. Before release, NURA’s mobile architecture, analytics SDKs, AI providers, backup behavior, and every connected integration should be audited against this policy.