Privacy
NELUA is built with privacy in mind: cycle and wellbeing data are especially sensitive. Below is an honest description of what the app does today — in plain language, without legal fog.
1. Who we are and what this policy covers
NELUA (bundle ID: app.aura.app) is a mobile app for tracking the menstrual cycle and gentle wellbeing support: calendar, day log, phase tips, food, movement, meditation, and chat.
This policy explains what data is processed, why, where it is stored, and what control you have. It should match how the app actually works.
2. Data you enter
The following data you enter may be stored on your device:
• cycle settings: period start date, average cycle length and period length;
• marked period days;
• day log entries: flow intensity, symptoms, mood, intimacy and protection notes;
• activity diaries: meals (name, macros, portions, optional photo and/or packaging barcode), workouts and meditations; nutrition and minute goals;
• local Open Food Facts barcode response cache (to avoid repeat network calls);
• chat history with the assistant (text; chat photos are not written to permanent storage);
• app settings: notifications, theme, language, onboarding completion flag.
We do not ask for a name, email, account, or profile to use core features. There are no user accounts in the current version.
3. Where data is stored
Cycle data, wellbeing logs, activity diaries, and chat history are stored locally on your device (expo-sqlite). Manual meal photos are files in the app directory (not in a NELUA cloud). Barcode product cache is also local.
By default, cycle health data and local diaries are not synced to our servers. On-device privacy is a core NELUA principle.
Exceptions are features that, by your action, call third-party services: AI (chat and meal-photo nutrition estimate) and Open Food Facts barcode lookup (see section 6). Raw period dates and the full cycle diary are not sent there.
If you delete the app or clear its data, local records are usually removed with them (depending on the OS and device backup settings).
4. Why we need the data
We use the data you enter only to:
• show cycle day, phases, and predictions;
• help you keep a calendar and wellbeing diary;
• keep food, workout, and meditation diaries and show progress toward goals;
• fill packaged product name and macros from a barcode (with your review before saving);
• suggest local content (recipes, workouts, practices) with phase awareness;
• reply in chat and (by your action) estimate grams/macros from a meal photo;
• schedule reminders if you enable notifications;
• save your interface settings.
Health and wellbeing data are not used for advertising, sale to data brokers, or profile mining.
5. Notifications
If you enable notifications, the system may request an OS permission. Reminders are scheduled locally on the device (via the system notification service). You can turn them off in NELUA settings or in system settings.
6. Third-party services and updates
The app may use technical services needed for reliable operation:
• Sentry (optional) — crash and error reports if a DSN is configured in the build. Sending personally identifying information is disabled by default (sendDefaultPii: false). Reports must not include your cycle diary contents, API keys, or base64 images.
• Expo Updates (OTA) — checking and downloading JS bundle updates from Expo/EAS servers so you get fixes faster.
• RevenueCat — Premium subscription status and purchase validation via App Store / Google Play (purchase tokens and technical subscription info). Cycle and diary data are not sent there.
• Ollama Cloud (chat and meal-photo nutrition) — when you send a chat message or add a meal photo for auto macros. In production builds the request may go through our Cloudflare Worker proxy (Premium subscription check) and then to Ollama. Only what is needed for the response is sent:
— chat: a short context pack (cycle phase, cycle day, today’s symptoms/mood) + message text and/or photo;
— meal estimate: a compressed JPEG of the food and optionally meal time (breakfast/lunch/dinner/snack). Raw period dates, the full cycle diary, and chat history are not linked to the meal estimate.
Photos and text are processed by the provider to generate a response and are not intended for advertising or training third-party models on NELUA’s side. Without your action (send in chat / choose a photo for analysis), this data does not go to Ollama.
• Open Food Facts (barcode lookup) — when you scan a barcode or enter a code on the scan screen. Only the barcode number (and technical request headers, including the app identifier) is sent to Open Food Facts. Cycle data, wellbeing diary, meal photos, and chat history are not sent. The response (name, macros, optional packaging photo URL) can be edited before saving to the diary; packaging photos are copied locally on save. Open Food Facts is open data (ODbL); the UI shows source attribution. Without your action (scan / manual code entry), no Open Food Facts requests are made.
These services process technical or user-requested data as described above. Third-party SDKs and APIs must protect data no less carefully than stated here — within their policies and settings we control.
7. Sharing and sale of data
We do not sell cycle or wellbeing data.
We do not share local diary or period contents with third parties for marketing or advertising.
Data may be shared only as needed for the listed services (crashes, OTA, subscription billing, AI requests and barcode lookups you initiated), or if required by law.
8. Your rights and control
You can view and edit cycle and diary data in the app at any time.
You can delete individual diary entries or adjust cycle settings; meal-photo estimates and Open Food Facts data can be edited manually before saving.
You can choose not to use chat, photo analysis, or barcode scanning — then the related data is not sent to third parties.
Full deletion of local data is via uninstalling the app / clearing app data in the system.
Where GDPR, CCPA/CPRA, or similar laws apply, you may request information about processing practices. Because cycle health data is stored locally and there is no account, the main control path is on-device. For questions write to hi@nelua.app or via the app page on the App Store / Google Play.
9. Children
NELUA is not intended for children under 16 and is not designed to collect children’s data. If you are under 16, use the app only with a parent or legal guardian’s consent.
10. Policy changes
If data practices change (for example, cloud backup or accounts appear), we will update this policy and the “Updated” date. We will try to reflect material changes clearly and in advance — in the spirit of transparency expected by app stores and regulators.
11. Contact
Privacy questions: hi@nelua.app or the NELUA page on the App Store / Google Play (developer support).
Important: this describes current product practices. It is not legal advice; store listings also need a public URL for this policy aligned with App Privacy / Data Safety.