Privacy Policy
Effective: 2026-05-27
This is what Nura collects, how it's used, and what control you have. If something is unclear, mail privacy@nura.day.
1. Information we collect
Identity: email, display name, avatar (optional) — for account login. Birth chart inputs: birth date, time, place (city + lat/lon + timezone) — for chart computation across five traditions. Optional profile: gender, sex at birth, MBTI, voice mode — for personalization. Usage: features visited, signals viewed, charts generated, chat messages with our agents — for product improvement and debugging. Device: platform, app version, IP-derived country, language — localization and abuse prevention. Payments: subscription tier, keys balance, purchase timestamps. We do NOT store credit card numbers — handled by Apple, Google, Stripe, or the platform processor. Push tokens: APNs/FCM token, your chosen notification rules + quiet hours — only for pushes you opted into. We do NOT collect contacts, photos beyond your avatar, microphone, fine location, or browsing history outside Nura.
2. How we use it
Compute your natal chart, transits, monthly forecast, compatibility charts; pass your chart + prompts to LLMs (Anthropic Claude, OpenAI) for interpretation; send the notifications you turned on (never marketing pushes you didn't opt into); investigate bugs and abuse; produce anonymized aggregates only.
3. Third parties we share with
Anthropic / OpenAI — prompt + chart context for each interpretation (LLM inference). Google FCM / Apple APNs — device push token (delivery). Apple / Google / Stripe / WeChat Pay / Alipay (whichever you used) — purchase intent only; card data stays with them. Cloudflare — request metadata for routing + DDoS protection. App Store / Play Store — OS-level crash reports if you opted in. We do NOT sell your data. We do NOT share with ad networks. There is no third-party tracking SDK in the app.
4. Where data lives & retention
Application data is stored on servers we operate. Primary China, mirror in Singapore for international users. Backups are encrypted at rest; retention 30 days.
5. Your rights
See: /me shows your profile + every chart we hold. Correct: /me/settings/birth-info. Export: email privacy@nura.day, we send a JSON dump within 30 days (free; PIPL/GDPR right of access). Delete account: /me/settings/delete-account. Your row is anonymized immediately (email replaced, password/birth/avatar cleared) and the account stops being usable. Aggregates that can no longer be tied to you are kept. Withdraw consent for push, optional analytics, or specific features in /me/settings. You may complain to your local data-protection authority (CN: 网信办; EU: your national DPA).
6. Children
Nura is not for users under 13 (EU: 16 where local law requires). If you believe a child has registered, mail privacy@nura.day and we will delete the account.
7. Security
HTTPS for every API call. Passwords hashed with bcrypt — we cannot read your password. We rotate signing keys and revoke leaked tokens. Any confirmed breach is disclosed to affected users within 72 hours.
8. Changes
If we materially change this policy we will notify you in-app and via email before the change takes effect.
General questions: support@nura.day Privacy or rights requests: privacy@nura.day