Privacy policy

Last updated 15 August 2026

Nolara holds health information — what medication you take, when you took it, readings you record. This page says exactly what is stored, who can see it, where it lives, and how to remove it.

Who is responsible

Nolara is operated by [LEGAL ENTITY NAME], [COUNTRY]. For anything about your data, write to support@nolara.app.

What is collected

CategoryWhat exactlyWhy
Account Name, email address, and — if you sign up with a password rather than Google — a phone number. Your role (patient or caregiver) and your timezone. To create the account and to build your dose times in your own local day.
Sign-in If you use Google, we receive your Google account identifier, name and email address from Google. If you use a password, we store a one-way hash of it — never the password itself. So you can sign back in.
Health information The medicines you add, their doses and times, whether each scheduled dose was taken, skipped or missed, and any vitals you choose to record. This is the service. Without it there is nothing to remind you about.
Care relationships Which caregivers you invited, which invitations were accepted, notes a caregiver writes, and messages between you. To show your caregiver what you agreed they may see.
Device token An identifier for this installation of the app, issued by Google, so alerts can reach your phone. To notify you — or, if you are a caregiver, to tell you someone missed a dose. Deleted when you sign out.
Profile (optional) Date of birth, gender, address, emergency contact — only if you fill them in. Left blank, they are simply never collected.

What is not collected

No advertising identifiers, no tracking pixels, no third-party analytics, no location, no contacts, no camera or photo access. The Android app requests one permission for network access and the permissions needed to show you a reminder at the right time — nothing else. Firebase is included for delivering notifications only; Google Analytics for Firebase is deliberately not part of the app.

Who can see it

Services Nolara relies on

ServiceWhat it receives
Amazon Web ServicesHosts the server and database, in the United States (Northern Virginia). All of the above is stored there.
Google Sign-InIf you choose it, Google tells us your account identifier, name and email. Google does not receive your health information from Nolara.
ResendDelivers verification and password-reset emails. It receives your email address and the code — never your health information.
Firebase Cloud MessagingDelivers alerts to your phone. Google receives a device token — an identifier for your installation — and the text of the alert, which never names a medication. If you turn notifications off, no token is registered.

Where it is stored, and what that means for you

The server and database are in the United States. If you are in the United Kingdom or the European Economic Area, your information is therefore transferred outside your country, to a jurisdiction whose data protection laws differ from yours. We rely on Amazon's Standard Contractual Clauses for that transfer. If this matters to you, it should factor into whether you use Nolara.

How long it is kept

Until you delete it. There is no automatic expiry — a medication history is only useful if it goes back far enough to be worth looking at.

When you delete your account, everything above is removed immediately and permanently. There is no grace period and no backup we can restore you from. One exception, stated plainly: if you are a caregiver and recorded something on a patient's chart, that entry stays on their record after your account is gone. It is their health record, not yours.

Your rights

Wherever you live, you can ask us to show you what we hold, correct it, export it, or delete it. Deleting is built into the app — Profile → Delete my account — and there is also a web route if you no longer have the app installed.

If you are in the UK or EEA, the GDPR additionally gives you the right to restrict or object to processing, to withdraw consent, and to complain to your national data protection authority. Our legal bases are: performing our contract with you (running the account), your explicit consent (the health information you enter), and our legitimate interest in keeping the service secure.

If you are in California, the CCPA gives you the right to know, delete, correct and opt out of sale or sharing. Nolara does not sell or share personal information, so there is nothing to opt out of.

Security

No system is perfectly secure. If we ever discover a breach affecting your information, we will tell you and the relevant regulator as the law requires.

Children

Nolara is not intended for anyone under 16, and accounts should not be created for children. A parent or guardian managing an adult's medication is a different thing and is fine.

Nolara is not a medical device

Nolara does not give medical advice and is not for emergencies. It records what you enter and shows it back to you. It does not interpret readings, warn about thresholds, advise on doses, or check drug interactions. Never change how you take a medicine because of anything in this app — talk to your doctor or pharmacist.

Changes to this policy

If what we collect or who we share it with changes, this page changes with it and the date at the top moves. Material changes will be shown in the app before they take effect.