Privacy Policy
Last Updated: August 19, 2026
NITROVENTUS - Unipessoal Lda ("Nitroventus," "we," or "us") provides the Nooko app and nookoapp.com and is responsible for the processing described in this policy. This policy explains what data we process, why we process it, the service providers involved, and the choices available to you.
The Short Version
- Nooko processes the information needed to provide pregnancy tracking, private sync, partner sharing, subscriptions, notifications, support, reliability, and product improvement.
- Your pregnancy content is not public. Approved family members receive only the access allowed by Nooko's family permissions.
- We do not show third-party ads, sell personal information, or use your data for cross-app advertising.
- Nooko's Product analytics is enabled by default in analytics-configured production builds after it checks local Settings. You can turn it off at any time.
- An explicit opt-out leaves analytics off, and all core features work either way.
- Settings can export a JSON snapshot of the structured records you are currently authorized to read, plus photo and attachment metadata. It does not embed the binary photo or attachment files.
For disclosures and rights specific to consumer health data, see our separate Consumer Health Data Privacy Policy.
Information Nooko Processes
App Account and Content
Nooko uses anonymous authentication, so an email address and password are not required to create the app account. The app and its service providers process an anonymous account identifier and, depending on the features you use:
- Pregnancy profile: Last menstrual period or dating-scan due date, pregnancy week, scheduled delivery or birth date, and optional baby name and gender.
- Journal and planning: Journal notes, moods and selected symptoms, attachments, checklists, reminders, and appointment information.
- Tracking: Bump photos, weight entries, kick-counting sessions, and contraction timing.
- Partner sharing: Family membership, role, permissions, invite status, and the content shared with approved family members.
Subscriptions, Notifications, Diagnostics, and Support
- Purchases: Apple and RevenueCat process product, purchase, subscription, and entitlement information. RevenueCat also receives the anonymous Nooko account identifier used to provide and share Nooko+ access.
- Notifications: If you enable notifications, Nooko, Expo, and Apple process a push token and the title, body, and routing data needed to deliver remote notifications. Partner notifications use generic feature-level messages and do not include journal text, photos, kick counts, contraction measurements, or appointment details.
- Error and performance diagnostics: Sentry receives technical error information, app release and device/runtime context, and limited performance traces. Earlier Nooko 1.1 builds configured Session Replay for 10% of sessions and sessions with errors; those replays could include on-screen app content. The August 12, 2026 production update disabled replay, console diagnostic logs, screenshots and view hierarchy, and reduced trace sampling to 10%. The update applies when Nooko launches or reloads, so an older installed or not-yet-updated app process may retain the earlier configuration until the update takes effect. Default collection of personally identifiable information is disabled.
- Feedback and support: We receive the message and attachments you choose to submit. Email support also provides your email address and normal message metadata. In-app feedback is delivered through Sentry.
Product Analytics
In analytics-configured production builds, Nooko enables Product analytics by default after checking its local Settings records so an existing opt-out cannot be bypassed. The app does not read your App Store storefront, locale country, IP address, account data, or a country code to decide whether analytics is enabled. Settings → Your Data → Product analytics lets you turn it off at any time; that stops future capture. Core app features do not depend on the setting.
When enabled, the EU-hosted PostHog project counts only coarse, allowlisted events describing a fixed feature, screen, action, placement, result, app variant, release, or build. Events do not include pregnancy dates or weeks, symptoms, journal text, photos, measurements, appointment details, notification times, invite codes, names, email addresses, account or family identifiers, advertising identifiers, or persistent device or session identifiers.
Every permitted event uses the same shared non-user identifier and is sent in its own request. The analytics transport uses memory-only storage and does not identify people, build user profiles, record sessions, replay screens, autocapture interactions, capture console or performance data, or use feature flags, surveys, or advertising tracking. PostHog necessarily receives transient network metadata to accept an HTTPS request. Each event disables GeoIP enrichment. These controls are intended for aggregate event counts, not individual journeys, retention, or unique-user analysis.
Website and Newsletter
- Vercel: Hosts nookoapp.com and provides Web Analytics and Speed Insights. These services process aggregate page-view and performance data such as the visited path, referrer, coarse region, browser, operating system, device type, and web-performance measurements. Vercel Web Analytics does not use cookies and does not create a persistent cross-site visitor profile.
- Buttondown: If you subscribe to Nooko Updates, Buttondown processes your email address, subscription status, and sign-up metadata such as IP address and referrer to deliver and manage the newsletter. You can unsubscribe using the link in any newsletter.
- Direct contact: If you email us, we process your address, message, attachments, and normal delivery metadata so we can respond.
How We Use Information
- Provide the app features you request and keep supported data available locally and through private cloud sync.
- Apply family roles and permissions when you share Nooko with a partner.
- Provide, verify, share, and restore Nooko+ entitlements.
- Deliver enabled reminders and partner notifications.
- Secure Nooko, diagnose failures, respond to support, and improve important product flows.
- Operate the website and send newsletters you requested.
- Meet legal obligations and protect users, Nitroventus, and the service.
Legal Bases in the EEA and UK
Where applicable law requires a legal basis, the basis depends on the processing: providing the service you request; your consent for optional permissions and communications; our legitimate interests in securing, supporting, maintaining, and improving Nooko through the privacy-limited Product analytics described above; and compliance with legal obligations.
When Information Is Disclosed
We do not disclose personal information for third-party advertising. Information is disclosed only as needed to operate Nooko, follow your choices, comply with law, or protect the service:
- Approved family members: Content and capabilities allowed by the family permissions configured in Nooko.
- Supabase: Anonymous authentication, database, realtime sync, private file storage, and server-side app services.
- Sentry: Error and performance diagnostics, plus feedback you deliberately submit. Earlier Nooko 1.1 builds configured sampled and error-session replay. The August 12, 2026 production update disabled replay, console diagnostic logs, screenshots and view hierarchy, and reduced trace sampling to 10%; an older app process may retain its earlier configuration until the update applies on launch or reload.
- Apple and RevenueCat: App distribution, purchases, subscription status, entitlement delivery, and restoration.
- Expo and Apple Push Notification service: Delivery of remote notifications you enable.
- PostHog EU: Allowlisted coarse product-event counts under the shared non-user identifier when Product analytics is enabled; it is on by default in analytics-configured production builds unless you turn it off in Settings.
- Vercel: Website hosting, Web Analytics, and Speed Insights.
- Buttondown: Newsletter subscription management and email delivery.
- Authorities or transaction participants: Only when required by law or reasonably necessary to protect rights, safety, the service, or a legitimate corporate transaction.
Storage and Security
- On your device: Local-first app data is stored on the device so core features can work offline.
- Cloud sync: Nooko uses encrypted HTTPS connections, Supabase database access controls, row-level security, and private storage buckets.
- Family access: Joining with an invite does not by itself expose pregnancy content; the family administrator must approve the member, and permissions control available access.
No system can guarantee absolute security. Keep your device protected and contact us if you believe your Nooko data may have been accessed improperly.
Retention and International Processing
We retain information only for as long as needed for the purposes described above, the settings of the relevant service, dispute and security handling, or legal obligations. Synced app data remains associated with the anonymous account until it is deleted, subject to the non-atomic deletion sequence described below. The current PostHog plan reports a provider-set event-retention period of up to 84 months; we will use a shorter supported setting if one becomes available and periodically re-review the operational need. Diagnostics, support correspondence, and newsletter records follow the relevant provider settings and applicable retention requirements. Encrypted service backups and limited operational or security logs may retain copies for provider or legal retention periods. Apple and RevenueCat may separately retain purchase, subscription, and transaction records needed for accounting, fraud prevention, entitlement restoration, or legal compliance.
Some providers may process information outside your country. Where required, we use providers that offer contractual or other recognized safeguards for international transfers.
Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive personal information in a portable format and to complain to your local data-protection authority. The in-app export has the scope described below; email us for a broader access request. Nooko provides these practical controls:
- Edit: Update supported pregnancy and account content in the app, subject to family permissions.
- Export: Settings → Export my data creates a portable JSON snapshot of the structured records you are currently authorized to read. Depending on your permissions and available data, it can include pregnancy and prenatal records, journal and checklist records, kick-counting, contraction and weight records, reminders and notification settings, and photo or attachment metadata. It does not embed binary bump-photo or journal-attachment files or their local or provider file locations. Keep separate copies of those files. For a broader access request, email contact@nookoapp.com.
- Delete: Settings → Delete Account & Data starts with a warning and a link to Apple Subscriptions. Deleting Nooko data does not cancel an Apple subscription or stop Apple billing. If you own the family, deletion also removes the shared family space and its content, including contributions from approved members. The server removes applicable photo and attachment Storage objects first, then removes journal-attachment metadata whose file path has the authenticated uploader's account prefix, and only then deletes the account. This can remove a member's attachment metadata even when another member's parent journal entry survives. The sequence is not atomic: a retryable server failure can occur after some online media has already been removed. Nooko keeps the local app state and session until the server confirms account deletion; only then does it clear local data and sign out. If you cannot access the app or deletion remains pending, retry or email contact@nookoapp.com.
- Analytics: Product analytics is on by default in analytics-configured production builds after Nooko checks local Settings records. Settings → Your Data → Product analytics turns it off and stops future PostHog client, request, queue, and event activity. Product events contain no account identifier and are not attributed to your account.
- Notifications: Change Nooko notification settings in the app or iOS Settings.
- Newsletter: Unsubscribe using the link in any Nooko Updates email.
We do not sell personal information or share it for cross-context behavioral advertising. To exercise another applicable privacy right, email us with the subject “Privacy Request.” We may need enough information to verify and complete the request.
Children's Privacy
Nooko is designed for adults managing a pregnancy journey and is not directed to children. We do not knowingly create accounts for children under 16.
Changes to This Policy
We may update this policy as Nooko or legal requirements change. We will update the “Last Updated” date and provide additional notice when required.
Contact Us
Questions, support requests, or privacy-rights requests:
Email: contact@nookoapp.com
Controller: NITROVENTUS - Unipessoal Lda
App: Nooko (co.alexiron.nooko)
Formal privacy requests are handled within the deadline required by applicable law.