← All policies

Privacy Policy

Version 2.0 · Effective July 16, 2026 · Consumer Health Data Privacy Policy

Nuro exists to support eating-disorder recovery. That only works if you can trust us with some of the most sensitive information there is. This policy explains exactly what we collect, why, who can see it, how long we keep it, and the controls you have. The short version: your health data is used only to run the service, is shared only with clinicians you approve, is never sold, is never used for advertising, and is never used to train AI models.

Because nearly everything Nuro handles relates to your health, we also publish a separate Consumer Health Data Privacy Policy that describes our handling of consumer health data in the form some state laws (such as Washington's My Health My Data Act and Nevada's consumer health data law) require. The two documents are consistent; if they ever conflict, the one giving you stronger protection controls.

1. What We Collect

DataWhat it includesWhy
Account Email address, sign-in method (email, Sign in with Apple, or Google), date of birth (from the age screen) Creating and securing your account; age-appropriate consent flow
Profile Weight, height, birthday, gender; optional blind weight check-ins on the cadence your clinician sets Personalizing your daily eating rhythm and the chart your care team sees
Meal logs Meal photos, the food name and calorie estimate generated from them, the meal time (which you can edit), and your answers to post-meal check-in questions, including any questions your clinician configures The core of the service: logging meals and tracking consistency
Meal plan & grocery list The meal plan you or your clinician set up, and your shared grocery list Planning support you and your care team edit together
Mood & check-ins Mood entries and notes, daily check-in answers, and responses to any questionnaires your clinician assigns Mood support features and, with your consent, care-team visibility
Chat with Nuro Your recent chat messages, a rolling summary the app keeps so Nuro remembers context, and automated safety flags when a message suggests a crisis Making the chat useful across sessions and keeping you safe; see the Safety page
Care-team messages Messages between you and clinicians you've approved, including messages they send you Direct communication with your care team
Consent records Terms acceptance (who signed, when, version), guardian consent for teen accounts, data-sharing agreements with clinicians Legal records of the permissions you've granted
Progress counters Simple counts of the days you have shown up, used to restore your progress Keeping your progress in sync across your devices
Subscription status Whether your account has an active premium subscription, verified through Apple Unlocking premium features. Apple processes payment; we never see your card details
Device & usage Device identifier, push notification token, time zone, app-open times, app settings Sync, notifications delivered at times that make sense where you are, and timing reminders when they actually help

What stays on your device only

Your journal is private to your device. Journal entries are stored locally and are never uploaded, synced, or visible to anyone, including your care team and us. If you ask Nuro to reflect on a journal entry, the text is processed once to generate the reflection and is not stored on our servers. Keepsakes such as your memory book also stay local.

Photos and metadata

Meal photos are re-encoded on your device before upload, which removes embedded metadata including location (EXIF/GPS). When you import a photo from your library, the app reads the photo's capture date on your device to suggest the meal time; that metadata itself is not uploaded. We perform no facial recognition or biometric processing on any image, ever. We do not collect your precise location.

2. What We Never Do

  • We never sell your data, health data or otherwise.
  • We never show you ads or share your data with advertisers or data brokers.
  • We put no third-party advertising or analytics trackers in the app. Our Cookie Policy covers what our websites store in your browser.
  • We never use your data to train AI models. Our AI provider processes your content only to generate responses and, under our API agreement, does not use it for training. We never use children's or teens' data for AI training, and would never use anyone's data for AI training without a separate, optional opt-in.
  • We never make your weight or trends visible to anyone except you and the care team you approved.
  • We never change this policy retroactively: a new use of already-collected data requires your fresh consent, not just an updated document.

3. Who Can See Your Data

  • You.
  • Clinicians you approve. A clinician sees your detailed data only after a data-sharing agreement is signed, and you can sever it anytime in Settings; access stops immediately. Every clinician read of your data is written to an audit log. When you're enrolled through a treatment provider, Nuro acts as a service provider (HIPAA business associate) to that provider.
  • Safety escalation. If the app detects signs of a crisis (for example in chat), it may alert the clinician you've consented to share with. If you haven't approved a clinician, no one is alerted; the app shows you crisis resources directly. See the Safety page.
  • Legal requirements. We disclose data if validly required by law, and we limit any such disclosure to what is required.

Service providers that help us run Nuro

These companies process data only on our instructions to operate the service. None of them may use your data for their own purposes such as advertising or AI training:

ProviderWhat they do for us
OpenAIGenerates chat responses, meal-photo food and calorie estimates, and safety-moderation checks. Content is processed through their API, which is not used to train their models.
Amazon Web ServicesDatabase, sign-in infrastructure, and transactional email (for example guardian consent links and clinician alerts)
CloudflareApplication server and meal-photo storage
ApplePush notifications, Sign in with Apple, and App Store subscription billing
GooglePush notifications on Android and Google Sign-In
StripeBilling for clinics and institutions only; Stripe never receives patient health data

We have no affiliates, and we share consumer health data with no third parties other than the service providers above and the clinicians you approve. The complete, current list is on our subprocessors page.

4. How Long We Keep It (Retention Policy)

  • While your account is active: we keep your data so the service works. We keep only what the service needs; we don't warehouse data "just in case."
  • When you delete your account: your care team is notified immediately and loses access; the account can no longer sign in; all your data (photos, logs, moods, chats, messages, plans, profile) is permanently erased from our systems within 30 days. Backup copies age out on our standard rotation schedule.
  • What we must keep: a minimal record of consent grants/revocations, the deletion request itself, and clinician-access audit logs, retained approximately six years as required by law, keyed to an internal identifier rather than your name or email.
  • Children's and teens' data is kept only as long as reasonably necessary for the specific purpose it was collected for, never indefinitely.

5. Children and Teens

  • Under 13: Nuro does not accept accounts from children under 13, except through a participating treatment provider under a verifiable-parental-consent program (if and when offered). If we learn we have collected personal information from a child under 13 without verifiable parental consent, we delete it.
  • 13–17: a parent or legal guardian must agree to the Terms as the contracting party, and the teen confirms an age-appropriate assent. Guardian consent is recorded. Minor accounts default to the highest-privacy settings: no targeted advertising, no geolocation, no data sale, ever. In chat, minors also get periodic reminders that Nuro is an AI and prompts to take breaks during long sessions.
  • Parent/guardian rights: the consenting guardian may review the categories of information collected, revoke consent, and direct deletion of the minor's information at any time via pippa.app.general@gmail.com or the in-app deletion flow.

6. Security

We maintain reasonable administrative, technical, and physical safeguards: data is encrypted in transit, stored in access-controlled cloud infrastructure, and every clinician read of patient data is written to an append-only audit log. Access to production systems is limited and logged. No system is perfectly secure. If a breach affects your data, we will notify you without unreasonable delay, no later than 60 days after we discover it and sooner where the law requires, and we will notify regulators as required.

7. Your Rights and Controls

We offer these rights to every user, wherever you live, and we will never retaliate against you or degrade your service for using them:

  • Access & export: ask us to confirm what we have and get a copy of your data in a portable format, including which third parties it has been shared with.
  • Correction: most data can be edited directly in the app; for anything else, email us.
  • Deletion: delete your account in Settings (with the 30-day erasure timeline above), or ask us to delete specific data without closing your account. Deletion extends to backups as they rotate and is passed along to our service providers. See Delete Your Account.
  • Withdraw consent: sever a clinician's access in Settings, immediately. Guardians of teen accounts can revoke consent by email.
  • Notification control: manage notifications in your device settings or inside the app.

We respond to privacy requests within 45 days (extendable once by 45 days for complex requests, with notice). If we decline a request, we'll explain why and you can appeal by replying to our response; we answer appeals within 45 days, and if you're still unsatisfied you can contact your state Attorney General. Because we sell no data and do no targeted advertising, there is nothing to opt out of under state "do not sell or share" rules, and browser opt-out signals like Global Privacy Control have nothing to switch off; we honor the spirit of them by default.

8. Not for Emergencies

Nuro and your care team do not monitor the app 24/7. If you believe you are experiencing a medical emergency, call 911. If you are in suicidal crisis or emotional distress, call or text 988 (Suicide & Crisis Lifeline), available 24/7. Our full crisis protocol is published on the Safety page.

9. Changes to This Policy

If we make material changes, we'll notify you in the app and require re-acceptance before continued use. We will never apply a material change to previously collected data without your affirmative consent. The version and effective date at the top of this page always reflect the current policy.

10. Contact

Pippa LLC. Questions, requests, or concerns: pippa.app.general@gmail.com.