Skip to content

Legal

Privacy Policy

Last updated: 22 September 2026

This is our launch privacy policy, kept in plain language. If anything is unclear, contact us at nuricare.co@gmail.com.

1. Who we are

Nuri Care is an eldercare app built to help older adults manage medications, appointments, and wellbeing, while keeping their family quietly in the loop. This policy covers both the Nuri mobile application and the Nuri website at nuricare.co (together, "the Service").

Nuri Care is the data controller for the information described here. You can reach us at nuricare.co@gmail.com.

2. Information we collect

We only collect what is needed to provide the Service.

Account information

Your name and email address, chosen when you create an account. The app distinguishes between three account types: For myself (the person receiving care), For someone I look after (a connected family member), and Both, for someone who is at the same time a person receiving care for their own connected family and a family member for someone else they look after. The sharing rules in this policy apply separately to each side of a Both account, and the app stores which type applies to your account.

Health and care information

Medications and dosing schedules, appointment dates and details, health-provider names and contact information, wellbeing check-in responses (mood, energy, sleep), and any health conditions or notes you choose to enter. It also includes the vital signs you record in the app: blood pressure, blood glucose, heart rate, blood oxygen (SpO2), body temperature and weight, each with the date and time it was logged. Nuri does not read any of this from a health platform or a wearable; every reading is one somebody typed in. This information is provided voluntarily by you and is used solely to run the Service.

Family-network connections

The names and email addresses of family members you invite, and which account they are connected to. The person receiving care controls what family members can see.

Limited device and usage data

Standard technical information such as device type, operating system version, app version, and crash reports (with identifying fields such as email and IP address removed). We do not build individual advertising profiles.

Location (only if you enable it)

If your parent switches location sharing on, the app collects their device location so family can see where they are against the places you've named, and records when they arrive at or leave one of those places. This feature is off unless they turn it on, and they can turn it off at any time from their own phone. We never use location for advertising.

Website: waitlist

If you sign up on the waitlist at nuricare.co, we store your email address to notify you when the app is available. Nothing else.

3. How we use your information

We use the information we collect to:

  • Provide the Service: medication reminders, appointment tracking, family-sharing summaries, wellbeing check-ins, and drug-interaction safety checks.
  • Send you push notifications and emails relevant to your care (reminders, alerts, account notices).
  • Improve the app: understanding how features are used in aggregate, diagnosing bugs, and making the experience better.
  • Respond to support enquiries and enforce our Terms of Service.
  • Comply with legal obligations where required.

We do not sell your personal data. We do not use it for advertising, and we do not share it with data brokers or marketing platforms.

Where GDPR applies, we rely on:

  • Contract: processing necessary to deliver the Service you signed up for.
  • Consent: for health and medication data, which you provide voluntarily, and for marketing emails (you may withdraw at any time).
  • Legitimate interests: security monitoring, fraud prevention, and aggregate product analytics, where these do not override your rights.
  • Legal obligation: where we are required to retain or disclose data by applicable law.

Under Singapore's PDPA, we collect, use, and disclose personal data only with your knowledge and consent, or where the PDPA permits without consent (e.g., investigations by public authorities).

5. Service providers (processors)

We use a small number of third-party services to operate Nuri. Each processes data only as instructed by us, and only for the purpose listed below. We choose providers that publish data-processing terms covering the services we use, we keep your account and care records in a single database hosted in the Asia-Pacific region, and we send each provider only the data its job needs. Access to production data is limited to the people who need it to run the Service.

  • Cloud hosting, database, and sign-in (Supabase, Asia-Pacific/Tokyo): stores your account data and care records and signs you in securely.
  • Push-notification delivery (Google Firebase Cloud Messaging, US): sends reminders and alerts to your device. Only a device token and the notification text are shared for routing.
  • AI safety checks (Anthropic, US): the medication-interaction and wellbeing-summary features send the relevant details you enter to Anthropic's Claude models to generate the result. That information is used only to produce your result and is never used to train AI models.
  • Medicine databases (US National Library of Medicine RxNorm/RxNav and US FDA openFDA): public reference databases queried to check drug names and interactions.
  • Address and place lookup (Google Places, US): when you search for a clinic, pharmacy, or address, the words you type are sent to Google so it can return matching suggestions.
  • Diagnostics and error monitoring (Sentry, EU): receives crash and error reports so we can fix bugs. We strip identifying fields such as your email address and IP address before reports are sent.
  • Aggregate product analytics (Google Firebase Analytics, US): records which parts of the app are used, in aggregate, so we can see what to improve.
  • Transactional email (Resend, US): sends account and billing emails, such as sign-in and account notices. Your email address and the contents of those messages pass through Resend so they can reach you.
  • Payments and subscriptions (RevenueCat and the app stores): if you upgrade to a paid plan, a payments provider records your subscription status. Your card details are handled by the app store, not by us.
  • Website hosting and security (Cloudflare): serves nuricare.co and protects it from attacks. Standard request metadata (IP address, headers) is processed in transit.

We do not use advertising trackers or any advertising SDK, and we do not sell your data to ad networks. The only analytics we run are aggregate, in-app product metrics that help us improve Nuri.

6. How we share your information

Your information is shared only in these circumstances:

  • With your connected family members: the account of the person receiving care controls which care information (medication status, appointment summaries, wellbeing check-ins) is visible to connected family members. Family members cannot access data that person has not shared.
  • With our service providers: as described in Section 5, for the purpose of running the Service.
  • When required by law: if we receive a valid legal request (court order, regulatory requirement), we will comply and, where permitted, notify the affected user.
  • In a business transfer: if Nuri is ever part of a merger, acquisition, or sale of assets, your data may pass to the new owner. They will be bound by privacy commitments no less protective than this policy, and we will notify you beforehand so you can export or delete your data first.

We never sell your data to data brokers, advertisers, or marketing platforms, and we never share it for advertising purposes.

7. Health data and the family-consent model

Medication lists, health conditions, appointment records, and wellbeing check-in responses are sensitive. We treat them with extra care:

  • Health data is stored encrypted at rest and transmitted over TLS.
  • Access within the app is gated by your account credentials, and family sharing further requires the person receiving care to have accepted a family-connection invitation.
  • The person receiving care can disconnect a family member at any time, immediately revoking that family member's access to shared care information.
  • No health data is used to train AI models, benchmarked against other users, or disclosed to third parties beyond the processors listed in Section 5.

Nuri is a personal care-management tool, not a regulated medical device or covered healthcare provider. We do not claim to diagnose, treat, or provide clinical advice.

8. Data retention, export, and deletion

We keep your data for as long as your account is active and for a reasonable period afterward to handle any support issues or legal obligations.

Export: You can export a copy of your data at any time from inside the app, under Settings, then Export my data, in machine-readable JSON. You can also request one by emailing nuricare.co@gmail.com, and we will provide it within 30 days.

Deletion: You may delete your account from within the app or by contacting us. Deletion takes effect immediately: your personal data and care records are removed from our live systems as the request is processed, not queued for later. Anonymised aggregate data (e.g., feature-usage counts) may be retained. Backup copies are purged within 90 days.

Waitlist email addresses collected on the website are deleted within 30 days of the app's general launch, or earlier on request.

9. Security

We take reasonable technical and organisational measures to protect your data:

  • All data in transit is encrypted with TLS 1.2 or higher.
  • Data at rest is encrypted using AES-256 at the storage layer.
  • Connections to our backend are made over HTTPS only; cleartext traffic is disabled at the platform level.
  • Access to production data is restricted to essential team members and is controlled by role-based permissions.
  • Row-level security policies in the database ensure each user can only access their own data (and data shared with them by the person they look after).
  • Profile photos are the one exception. They are served from a content delivery network at long, randomly generated web addresses, so they are not listed or searchable, but anyone holding the exact address can open the image. Please keep that in mind when choosing a profile photo.

No system is perfectly secure. If you discover a vulnerability, please report it responsibly to nuricare.co@gmail.com.

10. International data transfers

Nuri is operated from Singapore. Your account and care data are stored in our cloud provider's Asia-Pacific (Tokyo, Japan) region. Some features rely on service providers located outside Singapore, including in the United States and the European Union.

Where data is transferred internationally, we rely on the contractual safeguards each provider offers (standard contractual clauses or equivalent certifications) so your data receives a comparable level of protection, consistent with the PDPA's Transfer Limitation Obligation.

11. Your rights

Depending on where you are located, you have the following rights regarding your personal data. To exercise any of them, contact us at nuricare.co@gmail.com.

Access and correction (PDPA & GDPR)

You may ask us what personal data we hold about you and request that inaccurate or incomplete data be corrected. Most data is also viewable and editable directly in the app.

Deletion (PDPA & GDPR)

You may request deletion of your personal data (see Section 8). We will comply unless we are required to retain it by law or for legitimate business purposes such as resolving disputes.

Withdraw consent (PDPA & GDPR)

Where processing is based on consent (e.g., health data entry, marketing emails), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of prior processing.

Portability and restriction (GDPR)

If you are in the European Economic Area or United Kingdom, you additionally have the right to receive your data in a portable format, to object to certain processing, and to request that processing be restricted while a complaint is resolved.

Lodge a complaint

Singapore residents may complain to the Personal Data Protection Commission (PDPC). EEA/UK residents may complain to their local data-protection authority. We ask that you contact us first so we can try to resolve the issue directly.

We will respond to all valid requests within 30 days. Complex requests may take up to 60 days; we will let you know if that is the case.

12. Children

Nuri is not intended for anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, such as adding a new category of data we collect or a new sharing practice, we will notify you by email and display a notice in the app at least 14 days before the change takes effect.

The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact us

For any privacy-related questions, data requests, or concerns, please write to us at:

Nuri Care Data Protection Officer nuricare.co@gmail.com

We aim to respond within 5 business days. For formal data-subject requests under PDPA or GDPR, please include "Data Request" in your subject line.