Security & privacy
The strongest privacy feature is the data we never take.
Health apps usually ask you to trust them. Nolara tries to need less trust: collect the minimum, protect what remains, and put the receipts where you can check them.
- What is collected
- Your name, email, role, and timezone; the medicines, doses, and vitals you enter; and whatever optional profile detail you choose to add — date of birth, conditions, an emergency contact. Optional fields left blank are simply never collected. Messages and notes in your care space are stored so the people in it can read them. Signup phone numbers used to be required. They had no purpose, so we stopped collecting them and deleted the stored ones. An emergency contact you add yourself is different — that is your data, entered by choice.
- What is never collected
- No advertising identifiers, no analytics events, no tracking pixels, no location, no contacts, no photos. The Android app requests no camera, storage, or location permission at all — the permission list is the audit, and anyone can read it.
- Consent, asked plainly
- Before any health data is stored, the app asks in its own words, on its own screen, with a checkbox that starts empty. The consent is versioned: if the policy materially changes, everyone is asked again — agreement to an old promise does not cover a new one.
- In transit and at rest
- Every connection is HTTPS; the domain is HSTS-preloaded, so browsers refuse plain HTTP outright. Passwords are stored only as bcrypt hashes — we cannot read them. Your sign-in token lives in the phone's own keystore, not in app storage.
- The database
- Not reachable from the public internet, and backed up nightly — with each backup restore-tested automatically, because a backup nobody has ever restored is a belief, not a backup. Backups age out on a fixed schedule within about a month, and a deleted account is never restored from them.
- Who processes what
- Amazon Web Services hosts the server and database in the United States. Google delivers sign-in and push notifications. Resend delivers email. Each is a processor working for Nolara — none may use your data for its own purposes, and none receives more than its job requires. If you are in the UK or EU: your data is stored in the US, under standard contractual clauses. We say this plainly because it should be part of your decision.
- Alerts without exposure
- A caregiver alert carries a first name and the fact that a dose was not recorded — never a medication name, never a diagnosis. Emails carry no tracking pixels and no rewritten links, on purpose.
- Your rights
- See, correct, export, or erase everything — deletion is built into the app and completes immediately. UK/EU residents have the full set of GDPR rights; California residents, the CCPA set. There is nothing to opt out of selling, because nothing is sold.
The full policy is a ten-minute read.
Written in plain language, because a policy you cannot read protects the company, not you.
Read the privacy policy