Privacy Policy

Last updated: August 17, 2026

This policy describes the data flows in the current Nuro mobile and web products, including the server-owned account deletion process and its 30-day recovery window. It states current behavior rather than promising a future implementation.

What Nuro collects

  • Account data: email address, authentication identifiers, profile fields, consent status, and account timestamps.
  • Journal content: recordings, transcripts, written entries, attachments, titles, summaries, actions, categories, embeddings, and other generated results.
  • Product events: coarse events such as screens opened, recording duration, processing status, feature use, subscription events, and non-content error codes.
  • Device and service data: app version, operating system, language, connection class, provider request metadata, and subscription status.

How Nuro uses data

  • Record, transcribe, store, organize, search, and display your entries.
  • Generate optional summaries, actions, connections, recaps, and answers.
  • Authenticate accounts, manage subscriptions, prevent abuse, diagnose failures, and support users.
  • Measure coarse product use and conversion so we can improve reliability and onboarding.

Nuro does not sell your recordings or transcripts. Nuro does not use your recordings or transcripts to train its own AI models. Service providers process data as described below.

Service providers and data flows

Deepgram — mobile transcription

Mobile audio is sent to Deepgram for streaming or batch speech-to-text. Nuro includes Deepgram's mip_opt_out=true option on these requests so they are excluded from Deepgram's voluntary Model Improvement Partnership program. Processing and operational metadata remain subject to Deepgram's agreement and policies.

OpenAI — web transcription and AI features

Audio recorded in the web app may be sent to OpenAI for transcription. Transcripts and related account context may be sent through OpenAI APIs for analysis and Ask Nuro. OpenAI states that API/business data is not used to train its models by default. Some endpoints may retain abuse-monitoring logs for up to 30 days. Assistant threads and messages are application state that can remain until explicitly deleted.

Supabase — authentication, database, functions, and storage

Nuro stores account data, recordings, transcripts, attachments, embeddings, generated results, and operational records with Supabase. Connections use TLS, and Supabase provides encryption at rest. Database and storage access also depend on Nuro's row-level and bucket policies.

PostHog — pseudonymous product analytics

Nuro identifies in-app analytics records with an internal account ID and sends coarse product events. The marketing website records privacy-minimized page and call-to-action events without cookies or persistent browser identifiers. Email, first name, raw journal content, raw question content, local file paths, database record IDs, full query-string URLs, and raw error messages are not intentionally included. Session replay is disabled.

Meta — limited conversion events

Nuro may send explicit events for registration, a saved recording, trial start, or purchase. Automatic event logging and advertiser-ID collection are disabled. Recordings, transcripts, titles, and generated journal content are not included in these events.

RevenueCat and Apple — subscriptions

RevenueCat processes app-user and subscription status information. Apple processes App Store purchases and payment details. Nuro does not receive your full payment-card details from Apple.

Apple and Google — optional authentication

If you use an Apple or Google sign-in method, that provider processes the authentication information needed to sign you in.

AI training and retention

“Training” and “retention” are different. Nuro opts Deepgram transcription requests out of its model-improvement program, and OpenAI says API data is not used for training by default. That does not mean every provider copy is deleted in 30 days. In particular, OpenAI Assistant application state can remain until Nuro explicitly deletes it.

Nuro keeps account and journal data while an account is active unless you delete an entry or request deletion. Provider logs, application state, and backups follow different retention schedules. Contact privacy@nuro.so for a deletion request or confirmation covering those systems.

Deletion and export controls

  • Individual entry deletion: deleting an entry removes its database record, everything Nuro derived from it, and its stored recording and attachments.
  • Account deletion, in the app: “Delete everything” schedules your account for deletion and signs you out. You have 30 days to change your mind, and signing back in cancels it. After that a scheduled job deletes every database row belonging to you, your stored recordings, and your sign-in identity itself. No email is required and nothing is kept behind a flag.
  • Backups: deletion removes your data from the live systems. Encrypted database backups held by our hosting provider expire on that provider’s own retention schedule and are not individually edited.
  • Export: in the app, under your data. One text file containing every entry you have recorded, readable without Nuro, and it does not require a subscription. Exporting changes nothing.
  • Questions: deletion and export both work without contacting us, but privacy@nuro.so is there if something has not worked.

Security

Nuro uses encrypted network connections, private storage buckets, and database access policies intended to limit records to the owning account. Entries are not end-to-end encrypted: Nuro's service providers must be able to process audio and text to provide transcription and AI features. No system is perfectly secure, and implementation defects can occur.

Children

Nuro is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact privacy@nuro.so if you believe a child has submitted information.

International processing

Nuro is operated from the United States. Data may be processed in the United States and other regions where our providers operate, subject to their agreements and applicable law.

Changes and contact

We may update this policy as the product and its providers change. Material changes may be communicated in the app or by email. Questions and privacy requests can be sent to privacy@nuro.so.