Privacy Policy
Effective date: August 29, 2026
Version: 1.1
Nuuar is provided by Dobleu Studio LLC, a Puerto Rico limited liability company (“Dobleu Studio,” “we,” “us,” or “our”). This Privacy Policy explains how Nuuar collects, uses, stores, shares, and deletes information when you use the Nuuar mobile application and related web or server services.
For privacy questions or requests, contact contact@dobleu.studio.
1. Scope
This Policy applies to the Nuuar mobile application, Nuuar’s public website and launch landing page, the launch waitlist, Nuuar-operated API/server routes, and Nuuar’s public Legal pages. It does not replace the privacy policies of Apple, Google, your email provider, or other third-party services you choose to use.
2. Information Nuuar processes
Account and authentication information
If you create or use a permanent account, Nuuar may process:
- your email address;
- your Supabase user identifier;
- the authentication provider you use, such as Apple, Google, or email;
- provider identifiers needed to associate the sign-in method with your account; and
- authentication session data required to keep you signed in securely.
When you use Sign in with Apple, Nuuar may store an encrypted Apple refresh token on the server solely so Nuuar can attempt to revoke its Apple authorization when you delete your account. The token is stored in a private server-side database area and is not returned to the mobile app.
Nuuar may also create a temporary anonymous Supabase session when an unauthenticated user first uses an AI feature. That session is used for authentication, quota, security, and abuse-prevention purposes.
Reminders and user content
Depending on how you use Nuuar, we may process content such as:
- reminder titles and notes;
- dates, times, recurrence settings, tags, completion state, and urgency settings;
- text you enter for AI-assisted reminder creation;
- voice transcripts;
- optional information you enter in About You for personalization; and
- shopping or context-search queries generated from a reminder request.
Reminders are local-first. For permanent authenticated users, reminder data may also be synchronized with Supabase when remote synchronization is enabled.
Voice audio
When you use voice capture, Nuuar processes the audio recording so it can be transcribed and converted into a reminder. Audio is sent through Nuuar’s authenticated server route to OpenAI for transcription. Nuuar does not intentionally store the audio file in its own server database after the request, and temporary local recording files are cleaned up by the app flow.
Location information
For supported context-search features, Nuuar may request foreground location permission.
- Precise device coordinates are used locally for reverse geocoding.
- Nuuar does not intentionally send the exact latitude and longitude in the context-search request.
- Approximate location information, such as city or district, region, country code, and timezone, may be sent with the relevant search or reminder context.
Context search is currently available only to registered/permanent users when the feature is enabled.
Operational and security metadata
Nuuar may process limited operational metadata, including:
- user or anonymous-session identifier;
- AI feature name;
- internal request and idempotency identifiers;
- credit or quota units;
- request status;
- HTTP status or sanitized error code;
- provider request identifiers; and
- request timestamps.
Nuuar’s AI operational-events table does not intentionally store reminder text, prompt text, transcripts, audio, or About You content.
Support communications
If you contact support, we receive the information you choose to include in the message. The app may also prefill technical details such as app version, platform, and operating-system version in a support email that you choose whether to send.
Transactional email information
When Nuuar sends a sign-in or authentication email, Supabase Auth and Postmark process information required to deliver that message, including the recipient email address, message content, delivery status, and related mail metadata.
Launch waitlist information
If you join the Nuuar launch waitlist, Nuuar may process:
- your email address;
- your language or locale;
- your subscription or waitlist status;
- optional campaign attribution, such as source, medium, campaign, term, or content;
- an optional referrer;
- the consent version and consent timestamp;
- the signup or creation timestamp; and
- a launch notification timestamp if and when launch notification is used.
We use this information to administer the launch waitlist, understand signup attribution, and communicate when Nuuar becomes available. Joining the waitlist does not currently mean that Nuuar sends a signup confirmation email.
Website analytics
The public Nuuar website uses Google Analytics through Google Tag Manager to understand website usage and performance. Nuuar’s custom website events currently include waitlist_cta_click, waitlist_form_start, generate_lead, waitlist_error, and language_change. Allowed custom event properties are locale, placement, and error_kind.
Nuuar does not intentionally include a waitlist email address in these custom analytics events. Depending on its configuration and practices, Google Analytics may also process standard technical and web information such as page views, browser and device information, traffic and referral information, interaction information, and cookies or similar technologies where applicable.
3. Information that stays on your device
Some information is designed to remain on your device and is not intentionally uploaded by the relevant feature, including:
- device contact records and phone numbers used by local contact search;
- precise coordinates used only for local reverse geocoding;
- local notification and AlarmKit identifiers;
- local progress, streak, reward, and theme data; and
- certain local app preferences.
A person’s name can still be transmitted if you independently include that name in reminder text sent for AI processing.
4. How we use information
We use information to:
- provide reminders, routines, notifications, and urgent alarms;
- authenticate users and protect accounts;
- synchronize reminder data for eligible users;
- transcribe voice recordings and interpret reminder requests;
- personalize supported AI features;
- provide nearby or contextual shopping assistance;
- enforce quotas and prevent abuse;
- diagnose errors and maintain service reliability;
- process account deletion and provider-revocation requests;
- operate and administer the launch waitlist;
- communicate when Nuuar becomes available;
- understand website usage and performance;
- protect forms and the website against abuse and bots; and
- respond to support requests.
We do not sell personal information. We do not use Nuuar data for third-party advertising or cross-app behavioral advertising or tracking.
5. AI processing and OpenAI
Nuuar uses OpenAI APIs for supported AI features, including voice transcription and structured reminder interpretation. Information sent to OpenAI may include reminder text, transcripts, approximate location/context information, and optional About You information when relevant to the feature being used.
Nuuar uses a pseudonymous safety identifier rather than sending the raw Supabase user ID as the OpenAI safety identifier.
OpenAI states that API data is not used to train its models by default unless the API customer opts in. Under OpenAI’s default API data controls, abuse-monitoring logs may be retained for up to 30 days unless a longer period is legally required or different approved data controls apply.
6. Service providers and third parties
We use service providers to operate Nuuar. Depending on the feature and release configuration, these include:
- Supabase — authentication, database, account management, synchronization, launch waitlist storage, and server-side data services;
- OpenAI — voice transcription and AI processing;
- Expo / EAS — application build, delivery, and server hosting services; Expo uses infrastructure subprocessors, including Cloudflare, for parts of its services;
- Cloudflare — public website and Worker hosting, network and security infrastructure, and Turnstile bot protection;
- Postmark — transactional and authentication email delivery;
- Apple — Sign in with Apple, App Store/TestFlight distribution, notifications, AlarmKit, and related platform services; and
- Google — Google authentication when that sign-in method is enabled, Google Analytics, and Google Tag Manager for website measurement.
These providers process information under their own terms, privacy notices, and service agreements.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
7. Hosting and network logs
Nuuar’s hosting and infrastructure providers may automatically process standard network and request information needed to operate and secure the service. This can include IP address, request time, route, HTTP status, browser or user-agent information, approximate region, request duration, and similar technical diagnostics.
Nuuar does not intentionally write IP addresses into its private AI usage-events table. Hosting-platform logs are retained and made available according to the applicable provider’s operational, security, and retention practices.
8. Retention
We keep information only for as long as reasonably needed for the purposes described in this Policy, subject to the following current practices:
- AI operational metadata: automatically deleted after approximately 30 days for active accounts, and also removed through account-deletion cascades.
- Reminder/account data in Supabase: kept while needed to provide the account and synchronization features, until you delete the relevant data or delete your account, subject to limited provider backup or disaster-recovery copies.
- Local app data: kept on the device until it is edited, deleted, reset, removed with the app, or cleared during account deletion as applicable.
- Support communications: generally retained for up to 12 months after the last interaction, unless longer retention is reasonably necessary to resolve a request, address security or abuse, or comply with a legal obligation.
- Postmark transactional email records: under Postmark’s default settings, message content and activity data are generally retained for 45 days. Postmark may separately retain aggregated statistics or suppression information under its own practices.
- OpenAI API data: subject to OpenAI’s applicable API data controls, including default abuse-monitoring retention described above.
- Hosting and infrastructure logs: retained according to the relevant provider’s operational and security practices where Nuuar does not control a fixed retention period.
- Launch waitlist information: retained while reasonably needed to administer the launch waitlist and related launch communications, subject to applicable deletion requests, operational needs, and legal requirements. The launch waitlist database does not implement automatic expiration.
- Google Analytics information: retained according to its configuration and Google’s applicable provider practices; Nuuar does not state a fixed retention period here.
Deletion from active systems may not immediately remove limited copies held in backups, security logs, legal records, or provider systems where retention is required or technically necessary.
9. Account deletion
Permanent users can request account deletion from Nuuar’s Settings.
After successful remote deletion, Nuuar deletes the Supabase Auth user and associated server records that are configured to cascade with that user. The app then clears applicable local reminders, tags, progress, preferences, scheduled notifications, AlarmKit state, caches, and local session data.
For Apple accounts, Nuuar attempts to revoke stored Apple authorization before deleting the Nuuar account. Legacy Apple accounts may be asked to reauthenticate so Nuuar can attempt an immediate revocation. Provider revocation is best-effort: if it cannot be completed, Nuuar still allows the authenticated user to continue deleting the Nuuar account.
Deleting a Nuuar account does not delete your separate Apple, Google, email-provider, or other third-party account, and those providers may retain information under their own policies.
A launch waitlist signup is independent of a permanent Nuuar app account. Deleting a Nuuar account does not automatically delete a separate launch waitlist signup. To request deletion of a waitlist signup or other applicable information, contact contact@dobleu.studio.
10. Security
We use technical and organizational safeguards designed to protect information appropriate to the nature of the service. These include authenticated server routes, private database permissions, encrypted storage of Apple revocation credentials, and server-side protection of privileged credentials.
No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
11. Your privacy choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, or a copy of personal information, or to object to or restrict certain processing.
Nuuar already provides in-app account deletion for permanent accounts. For other privacy requests, contact contact@dobleu.studio. We may need to verify your identity before completing a request.
Nuuar does not offer an opt-out of sale or targeted advertising because Nuuar does not sell personal information or use it for cross-context behavioral advertising.
12. Children
Nuuar is a general-audience productivity service and is not intended for children under 13. You must be at least 13 years old to use Nuuar.
We do not knowingly collect personal information from a child under 13. If we learn that we have collected personal information from a child under 13, we will take reasonable steps to delete it. A parent or guardian who believes a child under 13 has provided personal information to Nuuar may contact contact@dobleu.studio.
13. International processing
Nuuar and its service providers may process information in Puerto Rico, the United States, and other locations where the providers operate. Where required, transfers are handled under applicable legal safeguards and provider contractual terms.
14. Changes to this Policy
We may update this Privacy Policy when Nuuar’s features, providers, or legal obligations change. We will post the updated version at Nuuar’s stable Privacy Policy URL and update the effective date. Material changes may also be communicated in the app or through another appropriate method.
15. Contact
Dobleu Studio LLC
Puerto Rico, United States
contact@dobleu.studio