Nora ("we," "us," or "our") is operated by Axiom One LLC. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Nora mobile application ("App").
Nora helps families check in on a Loved One using quiet phone activity and home/away context, so Guardians can know when something seems off without intrusive check-ins.
01Information We Collect
1.1 Account Information
- Email address — used for authentication (magic link sign-in)
- First name — used to personalize the app experience
- Phone number — used for passwordless sign-in codes via text, check-in nudges (Loved Ones), and wellness alerts (Guardians). Also collected on our website beta signup form with your consent.
- Role — whether you are a Guardian or Loved One
1.2 Household Information
- Household name — a label for your family group
- Member relationships — which Guardians are connected to which Loved Ones
1.3 Phone Activity and Location (Loved Ones Only)
If you are set up as a Loved One, Nora checks in from the phone about every 15 minutes and may use the following information:
- Screen unlock count — how many times the phone was unlocked
- Step count — from the phone pedometer
- Phone motion activity — Core Motion activity type classification such as stationary, walking, running, automotive, cycling, or unknown. Nora does not derive route, speed, or location from motion.
- Battery level and charging state
- Home/away and location relaunch — Nora asks for Always location on iOS so it can tell whether the Loved One is home or away and resume check-ins after the phone dies or restarts. Exact coordinates are used only for home/away and short-lived server checks that help the app recover; Guardians and family members never see exact position, addresses, route history, or a live map.
This information is used only to understand whether the Loved One's phone shows ordinary daily use and whether they are home or away.
1.4 Phone and App Information
- Phone model and operating system version — collected periodically (every 4th check-in) for troubleshooting
- App version — for compatibility and debugging
- Push token — to send Nora messages to your phone
1.5 Backup Contact Information
Guardians may add backup contacts:
- Name and phone number — used only to send a text if something seems off and the Home is set up for that option
1.6 Error and Diagnostic Information
- App crash reports — error messages, stack traces, phone model, OS version
- Collected automatically to help us fix bugs
- Automatically deleted after 30 days
1.7 Audit Logs
We maintain internal logs of system actions (concern events, concern resolutions, account changes) for security and debugging purposes. These do not contain message content or personal communications.
1.8 Website Visitors and Beta Signup
When you visit hellonora.io or join our beta waitlist, we collect:
- Information you provide: first name, email address, phone number (optional), your role, distance from your loved one, their phone type, and anything you share about your concerns.
- Automatic technical information: IP address and the approximate location it corresponds to (country, region, city — never precise location), device type, browser and operating system, preferred language, time zone, screen size, the page that referred you, and campaign tags (UTM parameters).
- Site usage: we use PostHog, a privacy-focused analytics tool, in cookieless mode to understand how visitors use our site (such as which sections are read and where forms are abandoned). It does not use tracking cookies and does not follow you across other websites.
We use this information to operate and improve our website, understand our beta community, and prevent spam. We never use it for advertising or sell it to anyone.
02Information We Do NOT Collect
- Phone call logs, text messages, or contacts
- Photos, videos, or files
- Health records or medical data
- Browsing history
- Microphone or camera data
- Information from other apps on the phone
2.1 Information We Do NOT Share or Display
- Exact position, address, or route history shown to Guardians, family members, or other users
- Live location feed or map of where a Loved One has been
03How We Use Your Information
| Purpose | Data Used |
|---|---|
| Authenticate your account | Email address |
| Check in on a Loved One's phone activity | Phone activity and location information (Section 1.3) |
| Let Guardians know if something seems off | Push tokens, phone numbers |
| Text backup contacts when that option is on | Backup contact phone numbers |
| Personalize the app | First name, role, household membership |
| Fix bugs and improve the app | Error reports, phone and app info |
| Manage your subscription | Subscription plan and status |
04SMS / Text Messaging
If you provide your phone number and opt in, Nora sends three kinds of text messages: one-time sign-in codes, check-in nudges (for Loved Ones), and wellness alerts (for Guardians). Message frequency varies with account activity. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for assistance. Opting out of SMS does not affect push notifications or your account.
Phone numbers and SMS opt-in consent are never sold, shared, or transferred to third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data is not shared with any third party, except as required to deliver the messages themselves (Twilio, our SMS provider).
05How We Store and Protect Your Information
Storage
- All data is stored in Supabase (PostgreSQL database) with encryption at rest
- Authentication tokens are stored on-device using iOS Keychain (Secure Store), not in plain storage
- Data is isolated per household using Row Level Security — one family cannot access another family's data at the database level
Retention
- Phone activity check-ins (heartbeats): Retained for 90 days, then automatically deleted via monthly partition cleanup
- Short-lived location-push reports: Retained for 7 days, then automatically deleted
- Error reports: Automatically deleted after 30 days
- Account data: Retained until you delete your account
- Audit logs: Retained for security and debugging purposes
Security Measures
- PKCE authentication flow (no passwords stored)
- Row Level Security on all database tables
- Service-level API keys isolated to backend functions (never in the app bundle)
- TLS 1.3 encryption for all data in transit
- Heartbeat submission idempotency (prevents duplicate data)
06Third-Party Services
We use the following third-party services to operate Nora:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, backend functions | All app data (encrypted at rest) |
| Twilio | SMS delivery for Nora messages | Phone numbers + message text |
| Expo | Push messages | Push tokens + message content |
| Apple | App distribution, push infrastructure | Push certificate tokens |
| Cloudflare | Turnstile bot protection on our forms | Client signals (IP address, TLS fingerprint, User-Agent) |
| PostHog | Privacy-focused website analytics (cookieless) | Site usage events, device/browser info |
| Resend | Sending transactional email (e.g., beta confirmations) | Email address, first name |
| Cloudflare | Website hosting, security, and email routing | Website request data (IP, headers) |
07Your Rights
You have the right to:
Access Your Data
You can request a copy of all data we hold about you by contacting us at the email below.
Correct Your Data
You can update your name, email, and backup contacts directly in the App.
Delete Your Data
You can delete your entire account from within the App (Settings → Delete Account). This permanently removes:
- Your profile and account
- All heartbeat data associated with you
- Your phone registrations
- Your household membership
- If you are the last member, the entire household is also deleted
Account deletion is immediate and irreversible.
Data Portability
You can request an export of your data in a machine-readable format by contacting us.
Withdraw Consent
You can pause check-ins at any time by pausing or removing the Loved One from the Home. You can delete your account at any time.
08Children's Privacy
Nora is designed for adults who use Nora to check in on elderly family members. We do not knowingly collect information from children under 13. If we learn that we have collected information from a child under 13, we will delete it promptly.
09International Users
Nora is primarily operated in the United States. If you are located in the European Union or other regions with data protection laws:
- Your data is processed and stored in the United States (via Supabase's infrastructure)
- By using Nora, you consent to the transfer and processing of your data in the United States
- You retain all rights under applicable data protection laws (including GDPR), as described in Section 7
10Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will update the "Last Updated" date at the top
- We will let you know via the App or email for significant changes
- Continued use of the App after changes constitutes acceptance
11Cloudflare Turnstile (Bot Protection)
Nora uses Cloudflare Turnstile — a privacy-first bot-protection tool from Cloudflare, Inc. — to protect our sign-up and contact forms from automated abuse by distinguishing human visitors from bots and blocking bot traffic. This section is supplemental to the rest of this Privacy Policy; where it provides more specific information about Turnstile, that information applies instead. It also covers Cloudflare's Challenge Platform, and any reference to “Turnstile” here applies equally to the Challenge Platform.
Information Turnstile processes
Turnstile processes a limited set of client-side signals (“Signals”) such as your IP address, TLS fingerprint, User-Agent header, and the sitekey and its associated origin. Cloudflare cannot directly identify any individual from these Signals, including IP addresses.
How these Signals are used
Bot detection and blocking. Turnstile evaluates these Signals — specific to both the visitor and the site being visited — solely to detect and block bots, not to identify, profile, or target individuals. These Signals are strictly necessary for that purpose. For this processing Cloudflare acts as our data processor, handling Signals on our behalf and under our instructions; Nora (Axiom One LLC) is the data controller. If you have questions or wish to exercise data-protection rights regarding this processing, contact us using Section 12 below.
Improving Turnstile. Cloudflare also processes these Signals to refine and improve its bot-detection algorithms in response to evolving threats. For this purpose Cloudflare acts as the data controller, governed by its own Turnstile Privacy Notice and Cloudflare's main Privacy Policy.
Notice to EU and UK residents
To the extent this data qualifies as personal data: when Cloudflare processes it as a processor to protect our forms, we (as controller) determine the lawful basis and Cloudflare processes it under our instruction and on our behalf; when Cloudflare processes it as a controller to improve Turnstile, it relies on its legitimate interest in improving Turnstile's bot-detection capabilities.
Cookies
The Signals collected by Turnstile are strictly necessary to detect and block bots so visitors can enjoy a safe, secure experience on sites that use it. For more on the cookies Cloudflare uses, see Cloudflare's Cookie Policy and the Turnstile Developer Docs.
12Contact Us
If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about how your information is handled: