Privacy Policy

Last updated: February 2026

1. Data Controller

Nala ("we", "us") is an AI wellness companion application. Contact: privacy@nala-meditation.com

2. Data We Collect

Account data: Email address, display name (via Firebase Authentication).

Usage data: Conversation transcripts with the AI, journal entries, wellness scores, mood selections, micro-actions. This data is used exclusively to personalize your experience.

Technical data: Device type, app version, crash reports. No IP addresses are stored permanently.

Payment data: Handled entirely by Google Play. We never see your card details.

3. How We Use Your Data

Your data is used to:

We never sell your data. We never share it with advertisers.

4. AI Conversations

Your conversations with Nala's AI are processed via the Anthropic API (Claude). Conversations are stored in our database to maintain continuity. Anthropic does not use your data to train models.

5. Data Storage & Security

Data is stored on Supabase (PostgreSQL, EU region) with encryption at rest and in transit. Authentication is handled by Firebase with industry-standard JWT tokens.

6. International Data Transfers

Your primary data is stored in the EU (Supabase, EU region). Some processing involves sub-processors located in the United States (see below). These transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) and each provider's data protection commitments.

7. Sub-processors

We use the following third-party services to operate Nala:

8. Your Rights (GDPR)

You have the right to:

To exercise your rights, use the in-app settings or email privacy@nala-meditation.com.

9. Data Retention

Account data is kept as long as your account is active. When you delete your account, all data is permanently erased within 30 days.

10. Cookies

The Nala website uses no third-party cookies and no tracking cookies. We use a minimal server-side analytics system that does not track individual users across sessions.

11. Children

Nala is designed for users aged 13 and above. For users under 16 in the EU, parental consent is required per GDPR Article 8.

12. Changes

We may update this policy. Significant changes will be communicated via the app. Continued use constitutes acceptance.