Last updated 26 September 2026
Nolara holds health information — what medication you take, when you took it, readings you record. This page says exactly what is stored, who can see it, where it lives, and how to remove it.
Nolara is built and operated by CLOUD ARMORS (SMC-PRIVATE) LIMITED, a company registered in Pakistan under company number 0358201. Its registered office is Old Shujabad Road, Bilal Chowk, Gulshan-e-Palace Colony, Street No 2A, House Number 55, Khan Manzil, Multan Cantt., Punjab, Pakistan. Responsibility for your data rests with the company, and it is also who answers you: for anything about it, write to support@nolara.app.
| Category | What exactly | Why |
|---|---|---|
| Account | Name and email address. Your role (patient or caregiver) and your timezone. No phone number — it used to be asked for and never had a purpose, so it is no longer collected and the ones already stored were deleted. | To create the account and to build your dose times in your own local day. |
| Sign-in | If you use Google, we receive your Google account identifier, name and email address from Google. If you use a password, we store a one-way hash of it — never the password itself. | So you can sign back in. |
| Health information | The medicines you add, their doses and times, whether each scheduled dose was taken, skipped or missed, and any vitals you choose to record. | This is the service. Without it there is nothing to remind you about. |
| Care relationships | Which caregivers you invited, which invitations were accepted, notes a caregiver writes, and messages between you. | To show your caregiver what you agreed they may see. |
| Device token | An identifier for this installation of the app, issued by Google, so alerts can reach your phone. | To notify you — or, if you are a caregiver, to tell you someone missed a dose. Deleted when you sign out. |
| Profile (optional) | Date of birth, gender, address, emergency contact — only if you fill them in. | Left blank, they are simply never collected. |
| Profile picture (optional) | A photograph, only if you choose one from your gallery. It is re-encoded on arrival, which removes the location and camera details a phone writes into a photo — so the copy stored is the picture and nothing else. Stored privately; shown to you and to caregivers you have invited, through links that expire within the hour. | So a caregiver looking after several people can tell whose record they are reading. Choose none and nothing is stored. |
No advertising identifiers, no tracking pixels, no third-party analytics, no location, no contacts, and no camera access. Choosing a profile picture uses the phone's own photo picker, which hands the app the one image you pick and nothing else — the app is never granted access to your gallery, and taking a new photo inside Nolara is deliberately not offered because that would require the camera permission.
The app itself asks for internet access and the permissions a reminder needs — to post a notification, to schedule it at an exact minute, and to restore your schedule after the phone restarts. A few more appear in the installed app because the libraries it uses declare them: vibration and wake-lock so an alert can actually wake the screen, network-state, and the biometric permissions that come with the secure storage your sign-in token is kept in. None of them reach the camera, your photos, your location or your contacts. Firebase is included for delivering notifications only; Google Analytics for Firebase is deliberately not part of the app.
| Service | What it receives |
|---|---|
| Amazon Web Services | Hosts the server and database, in the United States (Northern Virginia). All of the above is stored there. |
| Google Sign-In | If you choose it, Google tells us your account identifier, name and email. Google does not receive your health information from Nolara. |
| Resend | Delivers verification codes, password-reset codes, and — unless a caregiver turns them off — missed-dose alert emails. An alert email carries a first name and the fact that a dose was not recorded: that is health information, which is why it never includes a medication name, a diagnosis, or anything more. Resend is contractually a processor and does not use any of it for its own purposes. Tracking is off: the emails carry no pixels and no rewritten links. |
| RxNorm (U.S. National Library of Medicine) | When you type a medicine name, Nolara asks this public drug dictionary how it is usually spelled, so it can offer suggestions. The request is made by our server, never by your phone, and it contains the letters you typed and nothing else — no account, no name, no device, no address, nothing that ties a lookup to you. It is a spelling check: it does not decide whether a medicine is right for you, and a name it has never heard of is saved exactly as you wrote it. You can ignore every suggestion. |
| Firebase Cloud Messaging | Delivers alerts to your phone. Google receives a device token — an identifier for your installation — and the text of the alert, which never names a medication. If you turn notifications off, no token is registered. |
The server and database are in the United States. If you are in the United Kingdom or the European Economic Area, your information is therefore transferred outside your country, to a jurisdiction whose data protection laws differ from yours. We rely on Amazon's Standard Contractual Clauses for that transfer. If this matters to you, it should factor into whether you use Nolara.
Until you delete it. There is no automatic expiry — a medication history is only useful if it goes back far enough to be worth looking at.
When you delete your account, everything above is removed from the live system immediately and permanently — no grace period, no soft-delete. Backups age out on a fixed schedule within about a month, and a deleted account is never restored from them. One exception, stated plainly: if you are a caregiver, vitals you recorded on a patient's chart stay on their record — a measurement of their body is their health data, whoever typed it. Notes you wrote are deleted with you.
Wherever you live, you can ask us to show you what we hold, correct it, export it, or delete it. Deleting is built into the app — Profile → Delete my account — and there is also a web route if you no longer have the app installed.
If you are in the UK or EEA, the GDPR additionally gives you the right to restrict or object to processing, to withdraw consent, and to complain to your national data protection authority. Our legal bases are: performing our contract with you (running the account), your explicit consent (the health information you enter), and our legitimate interest in keeping the service secure.
If you are in California, the CCPA gives you the right to know, delete, correct and opt out of sale or sharing. Nolara does not sell or share personal information, so there is nothing to opt out of.
No system is perfectly secure. If we ever discover a breach affecting your information, we will tell you and the relevant regulator as the law requires.
Nolara is for adults. It is not intended for anyone under 18, and accounts should not be created for children — the target age group declared on Google Play says the same. A parent or guardian managing an adult's medication is a different thing and is fine.
Nolara does not give medical advice and is not for emergencies. It records what you enter and shows it back to you. It does not interpret readings, warn about thresholds, advise on doses, or check drug interactions. Never change how you take a medicine because of anything in this app — talk to your doctor or pharmacist.
If what we collect or who we share it with changes, this page changes with it and the date at the top moves. Material changes will be shown in the app before they take effect.