Privacy
NELUA is built with privacy in mind: cycle and wellbeing data are especially sensitive. Below is an honest description of what the app does today — in plain language, without legal fog.
1. Who we are and what this policy covers
NELUA (bundle ID: app.aura.app) is a mobile app for tracking the menstrual cycle and gentle wellbeing support: calendar, day log, phase tips, food, movement, meditation, and chat.
This policy explains what data is processed, why, where it is stored, and what control you have. It should match how the app actually works.
2. Data you enter
The following data you enter may be stored on your device:
• cycle settings: period start date, average cycle length and period length;
• marked period days;
• day log entries: flow intensity, symptoms, mood, intimacy and protection notes;
• activity diaries: meals (name, macros, portions, optional photo and/or packaging barcode), workouts and meditations; nutrition and minute goals;
• local Open Food Facts barcode response cache (to avoid repeat network calls);
• chat history with the assistant (text; chat photos are not written to permanent storage);
• app settings: notifications, theme, language, onboarding completion flag.
We do not ask for a name, email, account, or profile to use core features. There are no user accounts in the current version.
3. Where data is stored
Cycle data, wellbeing logs, activity diaries, and chat history are stored locally on your device (expo-sqlite). Manual meal photos are files in the app directory (not in a NELUA cloud). Barcode product cache is also local.
By default, cycle health data and local diaries are not synced to our servers. On-device privacy is a core NELUA principle.
Exceptions are features that, by your action, call third-party services: AI (chat, meal-photo and food-search text nutrition estimates), Open Food Facts barcode and text search, and USDA FoodData Central generic search (see section 6). Raw period dates and the full cycle diary are not sent there.
If you delete the app or clear its data, local records are usually removed with them (depending on the OS and device backup settings).
4. Why we need the data
We use the data you enter only to:
• show cycle day, phases, and predictions;
• help you keep a calendar and wellbeing diary;
• keep food, workout, and meditation diaries and show progress toward goals;
• fill product name and macros from barcode or food search (Open Food Facts / USDA / NELUA recipes), with your review before saving;
• suggest local content (recipes, workouts, practices) with phase awareness;
• reply in chat and (by your action) estimate grams/macros from a meal photo or from food-search text;
• schedule reminders if you enable notifications;
• save your interface settings.
Health and wellbeing data are not used for advertising, sale to data brokers, or profile mining.
5. Notifications
If you enable notifications, the system may request an OS permission. Reminders are scheduled locally on the device (via the system notification service). You can turn them off in NELUA settings or in system settings.
6. Third-party services and updates
The app may use technical services needed for reliable operation:
• Sentry (optional) — crash and error reports if a DSN is configured in the build. Sending personally identifying information is disabled by default (sendDefaultPii: false). Reports must not include your cycle diary contents, API keys, or base64 images.
• Expo Updates (OTA) — checking and downloading JS bundle updates from Expo/EAS servers so you get fixes faster.
• RevenueCat — Premium subscription status and purchase validation via App Store / Google Play (purchase tokens and technical subscription info). Cycle and diary data are not sent there.
• Ollama Cloud (chat and meal nutrition) — when you send a chat message, add a meal photo for auto macros, or tap “Estimate with AI” in food search (text estimate). In production builds the request may go through our Cloudflare Worker proxy (Premium subscription check) and then to Ollama. Only what is needed for the response is sent:
— chat: a short context pack (cycle phase, cycle day, today’s symptoms/mood) + message text and/or photo;
— meal estimate from photo: a compressed JPEG of the food and optionally meal time (breakfast/lunch/dinner/snack);
— meal estimate from text (food search): dish description and optionally meal time — no cycle context pack.
Raw period dates, the full cycle diary, and chat history are not linked to the meal estimate. Photos and text are processed by the provider to generate a response and are not intended for advertising or training third-party models on NELUA’s side. Without your action (send in chat / choose a photo / “Estimate with AI”), this data does not go to Ollama.
• Open Food Facts (barcode and text search) — when you scan/enter a barcode or search for a product on the food search screen. Only the barcode number or search query (and technical request headers, including the app identifier) is sent to Open Food Facts. Cycle data, wellbeing diary, meal photos, and chat history are not sent. The response (name, macros, optional packaging photo URL) can be edited before saving to the diary; packaging photos are copied locally on save. Open Food Facts is open data (ODbL); the UI shows source attribution. Without your action (scan / manual code entry / search), no Open Food Facts requests are made.
• USDA FoodData Central (generic product search) — when you search for food and the app queries USDA (directly with a key in a dev build, or via our Cloudflare Worker proxy). Only the search query text (often after a local RU→EN dictionary map) and technical headers are sent. Cycle and diary data are not sent. The response (name, macros per 100 g) can be edited before saving; the UI shows USDA attribution. Without your action (food search), no USDA requests are made.
These services process technical or user-requested data as described above. Third-party SDKs and APIs must protect data no less carefully than stated here — within their policies and settings we control.
7. Sharing and sale of data
We do not sell cycle or wellbeing data.
We do not share local diary or period contents with third parties for marketing or advertising.
Data may be shared only as needed for the listed services (crashes, OTA, subscription billing, AI requests, and Open Food Facts / USDA lookups you initiated), or if required by law.
8. Your rights and control
You can view and edit cycle and diary data in the app at any time.
You can delete individual diary entries or adjust cycle settings; meal-photo/text estimates and Open Food Facts / USDA data can be edited manually before saving.
You can choose not to use chat, photo analysis, food search, or barcode scanning — then the related data is not sent to third parties.
Full deletion of local data is via uninstalling the app / clearing app data in the system.
Where GDPR, CCPA/CPRA, or similar laws apply, you may request information about processing practices. Because cycle health data is stored locally and there is no account, the main control path is on-device. For questions write to hi@nelua.app or via the app page on the App Store / Google Play.
9. Children
NELUA is not intended for children under 16 and is not designed to collect children’s data. If you are under 16, use the app only with a parent or legal guardian’s consent.
10. Policy changes
If data practices change (for example, cloud backup or accounts appear), we will update this policy and the “Updated” date. We will try to reflect material changes clearly and in advance — in the spirit of transparency expected by app stores and regulators.
11. Contact
Privacy questions: hi@nelua.app or the NELUA page on the App Store / Google Play (developer support).
Important: this describes current product practices. It is not legal advice; store listings also need a public URL for this policy aligned with App Privacy / Data Safety.