Legal
Privacy Policy
Effective Date: August 16, 2026 · Previous version: August 11, 2026
This Privacy Policy describes how Nourva, a product of Tokra, LLC ("we", "our", or "us"), collects, uses, and protects your personal information across the desktop application, the iOS app, the Android app, and our web services. Tokra, LLC is the data controller for this data.
1. Scope — The Products This Policy Covers
This Privacy Policy is a single, global policy. It applies to every way you can use Nourva:
- The Nourva desktop application for Windows and macOS (the "Agent").
- The Nourva iOS app, distributed through the Apple App Store.
- The Nourva Android app, distributed through Google Play.
- The Nourva website, account dashboard, and API at nourva.ai (together, the "web services").
Wherever this policy says "the Service", it means all four. Where a rule applies to only one platform, that platform is named explicitly. If you use Nourva on more than one platform with the same account, the same account data, the same rights, and the same deletion process apply to all of them — there is no separate iOS account, Android account, or desktop account.
Tokra, LLC, a Delaware limited liability company, is the data controller (and, under US state privacy laws, the "business") for the personal data described here. Contact details are in Section 19.
This policy is published in English. English is the controlling language of this document; any translation is provided for convenience only.
2. Information We Collect
We collect the following categories of information when you use Nourva:
Account information. When you register we collect your email address and a hashed password. We do not store plaintext passwords. If you sign in with Apple or with Google, we receive the identifier and the email address that provider releases to us (which may be a private relay address) — we never receive your provider password.
Subscription and billing information. Your plan, credit balance, renewal date, and transaction history. Payment instruments are never stored by us: card processing on the web is handled by Stripe, purchases inside the iOS app are processed by Apple, and purchases inside the Android app are processed by Google Play. We receive a confirmation, a customer or purchase identifier, and the amount — never your card number, CVV, or full billing address.
Content you send to be processed. The prompts, questions, files, images, and voice you deliberately submit for a task, together with only the context needed to answer that specific request. This is processed to produce your result and is not retained by us as a training corpus (see Section 5).
Device and permission signals. Which optional device permissions you have granted, your device platform and app version, language and time-zone offset, and — for the mobile apps — whether a feature is available on your device. Section 6 lists every sensitive permission and exactly what it is used for.
Usage data. Anonymized telemetry about feature usage (for example, which tools are activated and whether a request succeeded) used to keep the Service working and to improve it. It is not linked to the content of your requests.
Local data (desktop). On desktop, your conversation history, memory entries, generated documents, and desktop automation logs are stored in an encrypted local database on your device — not on our servers. To generate a response, only the content needed for that request is sent transiently to a cloud AI provider (see Section 5); it is not retained by us, and your memory is never automatically uploaded.
Mobile app data (iOS and Android). On the Nourva mobile apps, your conversations and memory live in your own per-user encrypted vault on our infrastructure, readable through your account alone — never used to train models, never shared, and deleted with your account. Voice audio is processed transiently to answer you and is not retained. Data you invoke on demand (your location, a calendar entry, a contact name) is used at that moment to answer and is not stored on our servers, with the single exception of the calendar mirror described in Section 5, which you can switch off by revoking calendar access.
Consent records. When you make a cookie choice or create an account, we record the consent event (what was agreed, the document version, and a timestamp) together with a salted one-way hash of your IP address — the raw IP is never stored — so that we can demonstrate compliance.
Support correspondence. If you contact us, we keep the message and our reply so we can help you and keep a record of the outcome.
We do not collect your precise advertising identifier on any platform. The Android app does not request the AD_ID permission and contains no advertising, attribution, or analytics SDK; the iOS app requests no App Tracking Transparency authorization because it performs no tracking. We do not build advertising profiles, and we do not buy personal data from data brokers.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, secure, and improve the Nourva Service
- Authenticate you and keep your account and paired devices in sync
- Execute the tasks you ask for, including AI inference, web automation, document generation, and voice
- Process transactions, meter credit consumption, and send billing-related communications
- Send service updates, security notices, and support responses
- Analyze usage patterns in anonymized form to improve product features
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations and to establish, exercise, or defend legal claims
We do not sell your personal data. We do not share it with advertisers or data brokers. We do not use your content to train AI models, and we do not permit our AI providers to train on it. We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act (CCPA, as amended by the CPRA), and we have not done so in the preceding twelve months. We do not process personal information for cross-context behavioural advertising or targeted advertising as those terms are defined under any US state privacy law.
4. Legal Bases for Processing (GDPR Art. 6)
Where the GDPR, UK GDPR, or an equivalent law applies, we process your personal data on the following legal bases:
Performance of a contract (Art. 6(1)(b)) — creating and maintaining your account, authenticating you, providing the subscription you purchased, executing the tasks you request, processing payments, and answering support requests.
Legitimate interests (Art. 6(1)(f)) — securing the Service, preventing fraud and abuse, measuring aggregate site traffic without cookies (see Section 15), and establishing or defending legal claims. We balance these interests against your rights, and you may object at any time (see Section 13).
Consent (Art. 6(1)(a)) — every optional device permission on iOS and Android (microphone, camera, photos, contacts, calendar, reminders, location, notifications, screen sharing), optional analytics cookies, any future marketing cookies, and marketing email. You can withdraw consent at any time, with effect for the future, without affecting the lawfulness of past processing — on mobile, by revoking the permission in your operating system settings.
Legal obligation (Art. 6(1)(c)) — retaining records required for tax, accounting, and responding to lawful requests by public authorities.
We do not rely on consent as the legal basis for the core Service itself, and we do not process special categories of data under Art. 9 as a designed feature. If you voluntarily include sensitive information inside a prompt, it is processed as ordinary content under the bases above and is subject to the same retention and deletion rules.
5. Local-First Storage & Cloud AI Processing
Nourva is designed with local-first privacy for your data. On desktop, your memory and files live on your device and we keep no copy of your memory on our servers. On the iOS and Android apps — where the phone must stay light — your memory lives in your own per-user encrypted vault on our infrastructure, readable through your account alone, never used for training, never shared, and erased when you delete your account.
AI processing itself runs on cloud AI providers. Nourva requires an internet connection and does not perform model inference on your device. To answer you, only the content needed for a given request — your prompt and the relevant context — is sent over an encrypted connection to a trusted AI provider, used solely to generate that response, and is not retained by us or used to train any model.
On desktop, your memory and personality profile are never automatically uploaded to our servers. If you choose, you may explicitly share a memory slice with our cloud agent (Arachne) for a limited, self-expiring window, and you can wipe it at any time.
Voice. When you speak to Nourva One, the audio of your turn is streamed to a speech-to-text provider, converted to text, used to answer you, and discarded. We do not keep recordings of your voice, and we do not use your voice to create a voiceprint or to identify you biometrically.
Screen sharing (Android). If you start a screen-sharing session, Android shows its own system consent dialog every time and displays a persistent notification for as long as capture is running. Frames are used only to answer the request you are making at that moment and are not stored on our servers after the session ends. You can stop capture at any time from the notification.
Calendar mirror (mobile). If — and only if — you have granted full calendar access, Nourva may mirror the next fourteen days of your events to your account so that morning briefings and time-aware answers work while the app is closed. This runs at most once every six hours, and never if calendar permission has not been granted. Revoking calendar permission stops it; deleting your account erases the mirror.
Desktop automation. On Windows and macOS the Agent operates your computer under your instruction. What it reads on screen, types, and clicks stays on your machine except for the specific content that must be sent to a model to decide the next step. Automation logs are written to the encrypted local database on your device.
6. Device Permissions and Sensitive Data — iOS and Android
Every device permission below is optional, is requested only in the moment a feature needs it, and is explained on-screen before the system dialog appears. Nourva keeps working if you decline; only the feature that needed the permission is unavailable. You can revoke any permission at any time in your operating system settings (iOS: Settings → Nourva; Android: Settings → Apps → Nourva → Permissions), and Nourva will detect the change and stop using it.
Android — every permission the app declares, and why:
- Internet and network state — to reach our servers. Required.
- Microphone, and modify audio settings — to hear you in Nourva One and to route audio correctly. Audio is transcribed and discarded (Section 5).
- Foreground service (microphone) — to keep a voice conversation alive while the screen is off. A persistent notification is shown for the whole session.
- Camera — to take a photo you want to ask about or attach. Nourva never opens the camera in the background.
- Photos, video, audio, and file access — to attach a file you pick and to save a generated document to your device. We read only what you select.
- Contacts — to turn a name you speak into the phone number or email address needed for an action you asked for. Contacts are not uploaded in bulk, are not indexed, and are not used to build a social graph.
- Calendar (read and write) — to brief you on your day and to create or change an event you asked for. See the calendar mirror in Section 5.
- Location (approximate and precise) — for location-aware answers you request. Location is used at the moment of the request; Nourva does not track you in the background.
- Notifications — to deliver your reminders and account alerts.
- Exact alarms and vibration — to fire a reminder at the exact minute you set, and to buzz when it does.
- Foreground service (screen capture / media projection) — only while a screen-sharing session you started is running.
- Foreground service (data sync) — to finish a task already in flight if you leave the app.
iOS — the permissions the app may ask for: microphone, camera, photo library, contacts, calendars (full access), reminders (full access), location while in use, notifications, and Face ID / Touch ID (used only to unlock the app locally; biometric data never leaves the Secure Enclave and is never seen by us).
What we never do on mobile: no background location, no background microphone outside a session you started, no reading of your messages or call logs, no device fingerprinting, no advertising or attribution SDK, no cross-app tracking, and no collection of a resettable advertising identifier.
Prominent disclosure. Where a platform rule requires a separate, in-context disclosure before a sensitive permission is requested — including Google Play's Prominent Disclosure and Consent requirement — Nourva shows that disclosure in the app at the moment of the request, in addition to this policy.
7. Data Sharing & Sub-Processors
We share data only with the following categories of third parties, each under a written contract that imposes data protection standards equivalent to ours:
Infrastructure providers — compute, storage, content delivery, edge protection, and managed database hosting for the web application and API.
Payment processors — Stripe processes payments made on the web (https://stripe.com/privacy). Apple processes purchases made inside the iOS app. Google processes purchases made inside the Android app. See Section 9.
AI inference providers — when your task requires cloud AI inference, prompts are sent to our trusted providers, including Anthropic and OpenAI, under their data-handling terms and strict confidentiality agreements, with training on your content disabled.
Speech and transcription providers — to convert the audio of a voice turn into text.
Email and notification delivery providers — transactional email, password resets, and account notices.
Search and data-enrichment APIs — live web search and page retrieval for the Arachne web agent and Adam research workflows.
We do not share your data with advertisers or data brokers. A current list of our sub-processors is published at https://nourva.ai/legal/sub-processors, and the detailed entity-level list is available on request to [email protected]. We notify users at least 30 days before adding a new sub-processor that processes personal data, unless an emergency security or legal requirement demands faster action.
We may also disclose personal data when we are legally required to do so, to enforce our Terms, to protect the rights, property, or safety of our users or the public, or in connection with a merger, acquisition, or sale of assets — in which case the successor remains bound by this policy and you will be notified before your data becomes subject to a different policy.
8. Google API Services — Limited Use
Nourva's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
When you connect your Google account, Nourva may access your Gmail messages and send mail on your behalf, only to provide features you explicitly request (for example reading, searching, summarizing, and triaging your inbox, and composing or sending email you dictate).
- No advertising. We never use Google user data for advertising.
- No sale or unauthorized transfer. We do not sell Google user data and do not transfer it to third parties except (a) as needed to provide the feature on our own infrastructure, (b) for security or legal compliance, or (c) in connection with a merger or acquisition in which the successor remains bound by these Limited Use commitments (with prior notice).
- No AI/ML training. We do not retain or use your Gmail or Google Workspace data to develop, improve, or train generalized or non-personalized AI/ML models. Data is used transiently to fulfill your immediate request.
- Limited human access. No human reads your Google data except with your explicit consent, for security, abuse, or legal reasons, or on anonymized and aggregated data for operations.
- Encryption and control. Connection tokens are stored encrypted (AES-256-GCM); you can disconnect at any time, which deletes the stored credentials.
This section governs data obtained through Google APIs when you connect your Google account. It is separate from Google's role as the payment processor for Android purchases, which is covered in Section 9.
9. Mobile App Stores — Apple and Google as Processors
Apple (iOS). For the Nourva iOS app, Apple processes App Store payments (we never receive your card details), Sign in with Apple, and push notification delivery, under Apple's own privacy terms. Apple provides us with a transaction identifier and subscription status; it does not give us your payment instrument.
Google (Android). For the Nourva Android app, Google Play processes purchases made inside the app under Google's own privacy terms (https://policies.google.com/privacy). We receive a purchase token, the product purchased, and the subscription state so we can activate your plan and honour renewals, cancellations, and refunds. We never receive your card details. Google Play also records the standard install, update, and crash information that it collects for every app on the platform, under Google's policy rather than ours.
The Android app contains no Google advertising, analytics, or attribution library. The only Google component it embeds is the Google Play Billing Library, which exists solely to complete a purchase you start.
Push notifications. Reminders and alerts you schedule are stored and fired on your device. Where remote push delivery is enabled for a platform, the delivery transport is Apple Push Notification service on iOS and Firebase Cloud Messaging on Android; in that case the platform receives an opaque device token and the notification payload for delivery only. Turning notifications off in your operating system settings stops both paths.
Store data disclosures. Our Google Play Data safety declaration and our Apple App Store privacy labels are prepared from this policy and describe the same practices. If you ever find a discrepancy between a store label and this policy, write to [email protected] and we will correct the label.
10. International Data Transfers
Your personal data may be processed by us and our service providers on cloud infrastructure located in multiple regions around the world; the specific region can vary by service and over time.
Wherever your data is processed, and whenever it is transferred across a border, we apply appropriate safeguards: Standard Contractual Clauses (and the UK International Data Transfer Agreement / Addendum), reliance on adequacy decisions where applicable, participation in recognized transfer frameworks where our providers are certified, and equivalent contractual, organizational, and technical measures — including TLS encryption in transit and least-privilege access controls.
For users in the EU, our designated representative under GDPR Art. 27 is listed at https://nourva.ai/legal/eu-representative. You can contact the representative or us directly ([email protected]) on any transfer-related question.
Where local law requires a specific transfer mechanism — for example the transfer conditions of the Saudi Personal Data Protection Law, Brazil's LGPD, or Korea's PIPA — we apply that mechanism in addition to the safeguards above.
11. Data Retention & Deletion
Account data is retained for as long as your account is active. You may permanently delete your account at any time, from any surface, without contacting us:
- On the web — in your account dashboard settings, under Delete account.
- In the iOS app — Settings → Security → Delete account.
- In the Android app — Settings → Security → Delete account.
- Without installing anything — at https://nourva.ai/delete-account, which explains the process and takes you straight to the deletion step.
Deletion is self-service on every platform, and deleting from one platform deletes the whole account. When you delete your account:
- Your profile, conversations, settings, paired devices, calendar mirror, billing and credit history, and your Stripe subscription are erased immediately from our primary databases.
- Encrypted database backups containing your data are purged on a rolling 30-day cycle. We retain backups for that window for disaster-recovery purposes only — they are not accessible to staff for any other reason.
- Tamper-evident audit log entries (which we are required to keep for fraud and security forensics) are anonymized: your name and email are replaced with a synthetic identifier such as [deleted-user-N].
- A confirmation email is sent at the start (with a 1-hour single-use link) and at the end of the deletion process.
Subscriptions billed by a store are not cancelled by deleting your account. An Apple-billed subscription must be cancelled in your App Store subscription settings and a Google Play-billed subscription in your Google Play subscription settings, or it will keep renewing. We tell you this in the app before you confirm deletion.
Local agent data (desktop). Data stored on your device is under your full control. You may delete it at any time by removing the Nourva application data folder.
Mobile. Your conversations and memory on iOS and Android live in the encrypted vault on our infrastructure, not on the handset, so uninstalling the app does not erase them — only account deletion does. Use one of the paths above.
Other retention periods. Anonymized usage telemetry may be retained for up to 24 months. Records we must keep for tax and accounting are retained for the period the applicable law requires. Consent records are retained for as long as needed to demonstrate compliance and are deleted with your account.
12. Security
We implement industry-standard security practices including:
- TLS encryption for all data in transit, on every platform
- Encrypted password storage (bcrypt); we never store plaintext passwords
- An encrypted per-user vault for local data on your device
- AES-256-GCM encryption for stored third-party connection tokens
- Principle of least privilege for all internal data access, with tamper-evident audit logging
- Regular security reviews, dependency review, and a documented incident-response process
Breach notification. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where GDPR Art. 33 applies, and notify affected users without undue delay where the law requires it.
No method of transmission over the internet or electronic storage is 100% secure. We strive to use commercially acceptable means to protect your data but cannot guarantee absolute security.
Reporting a vulnerability. If you believe you have found a security issue, write to [email protected] with the details. We do not pursue legal action against good-faith security research that respects user privacy and does not degrade the Service.
13. Your Rights (GDPR, UK GDPR, CCPA/CPRA & Equivalent Laws)
If you are in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with similar privacy laws (CCPA/CPRA, LGPD, PIPEDA, PDPL, APPI, PIPA, DPDP, and others), you have the following rights. They apply identically whether you use Nourva on desktop, iOS, Android, or the web.
Right of access (GDPR Art. 15) — see what we hold. Use the data export in your dashboard settings to download a JSON+CSV bundle of your profile, conversations, ledger, audit log, and more. The link arrives by email and is valid for one hour, single download.
Right to rectification (GDPR Art. 16) — correct inaccurate personal data. Edit your profile in dashboard settings, or contact [email protected].
Right to erasure / "right to be forgotten" (GDPR Art. 17) — permanently delete your account and personal data. Self-service from the web dashboard, from inside the iOS app, from inside the Android app, or at https://nourva.ai/delete-account. Your data is wiped from primary databases promptly and backups are purged within 30 days.
Right to data portability (GDPR Art. 20) — download a structured, machine-readable copy of your data. Same export endpoint as right of access.
Right to restrict processing (GDPR Art. 18) — temporarily pause our use of your data while you contest accuracy or legality. Contact [email protected].
Right to object (GDPR Art. 21) — object to processing based on legitimate interests, including any direct marketing or profiling. You can disable marketing email any time from notification preferences in dashboard settings.
Right to withdraw consent — wherever our processing is based on consent (device permissions, optional analytics cookies, marketing email), you can withdraw it at any time without affecting the lawfulness of past processing.
Right to lodge a complaint — with your local data protection authority. For EEA users, see https://edpb.europa.eu/about-edpb/about-edpb/members_en. UK users may complain to the Information Commissioner's Office (https://ico.org.uk).
To exercise any right that is not covered by self-service, email [email protected]. We verify your identity through the email address on your account before acting, and we respond within 30 days (or the shorter period your local law requires). We do not charge a fee for a first request, and we do not discriminate against you for exercising any right.
14. Regional Disclosures
United States — California and other states. Under the CCPA/CPRA and the privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, and other states with comparable laws, you have the right to know what personal information we collect, to access and correct it, to delete it, to obtain a portable copy, to opt out of the "sale" or "sharing" of personal information and of targeted advertising, and to opt out of profiling in furtherance of decisions producing legal or similarly significant effects. We do none of those three things, so there is nothing to opt out of; we honour Global Privacy Control signals regardless. We do not use or disclose sensitive personal information for purposes beyond those permitted by CCPA Section 7027(m). You may use an authorized agent to submit a request. If we decline a request, you may appeal by replying to our decision email or writing to [email protected]; if the appeal is denied you may contact your state attorney general.
Categories collected in the last 12 months, in CCPA terms: identifiers (email, account ID, device platform); commercial information (subscription and transaction records); internet or network activity (anonymized feature telemetry); geolocation, audio, and visual information (only from permissions you granted, at the moment of a request you made); and the contents you deliberately submit for processing. Each category is collected for the business purposes in Section 3, retained as described in Section 11, and disclosed only to the service-provider categories in Section 7.
European Economic Area, United Kingdom, and Switzerland. Sections 4, 10, and 13 govern. Our GDPR Art. 27 representative is listed at https://nourva.ai/legal/eu-representative. Swiss users may also contact the Federal Data Protection and Information Commissioner.
Canada. We comply with PIPEDA and, for residents of Quebec, Law 25, including the right to be informed of automated decision-making (we perform none), the right to data portability, and the right to withdraw consent. You may complain to the Office of the Privacy Commissioner of Canada or to the Commission d'accès à l'information du Québec.
Brazil. Under the LGPD you have the rights of confirmation, access, correction, anonymization or deletion, portability, information about sharing, and revocation of consent. Our controller contact is [email protected]; you may complain to the ANPD.
Saudi Arabia. We process personal data in accordance with the Personal Data Protection Law and its Implementing Regulations, including its rules on notice, consent, purpose limitation, and cross-border transfer. Requests may be made to [email protected] and complaints to the Saudi Data and Artificial Intelligence Authority (SDAIA).
United Arab Emirates, Qatar, Bahrain, Oman, and Kuwait. We honour access, correction, deletion, objection, and portability rights under the applicable federal or national data protection law of your country, through the same contact point.
Australia and New Zealand. We handle personal information in accordance with the Australian Privacy Principles and the New Zealand Privacy Act 2020. Complaints may be made to the OAIC or to the New Zealand Privacy Commissioner.
Japan. Under the APPI you may request disclosure, correction, suspension of use, and deletion, and we will identify the purpose of use on request. Korea. Under PIPA you have the rights of access, correction, suspension, and deletion, and we obtain separate consent where PIPA requires it. India. Under the Digital Personal Data Protection Act, 2023 you have the rights of access, correction, erasure, grievance redressal, and nomination; our grievance contact is [email protected]. Türkiye. Under KVKK you have the rights listed in Art. 11 and may apply to us in writing before applying to the KVKK Board. South Africa. Under POPIA you may object to processing and complain to the Information Regulator. Nigeria. Under the NDPA you may exercise access, rectification, erasure, restriction, portability, and objection rights.
Anywhere else. If your country grants you a data protection right that is not listed above, write to [email protected] and we will honour it to the extent the law requires.
Automated decision-making. We do not use your personal data for automated decisions that produce legal or similarly significant effects on you, and we do not perform profiling.
15. Cookies, Analytics, and the Absence of Mobile Tracking
Our website uses three categories of technology, governed by a granular consent banner shown on your first visit:
Essential cookies — authentication/session, locale preference, CSRF protection, and the consent record itself. Always active; the site cannot function without them.
Optional analytics (consent only) — Google Analytics and our first-party measurement cookie (nv_sid) are loaded or set ONLY after you opt in via the cookie banner. IP anonymization is enabled and cookie lifetimes are capped at 12 months. If you do not opt in, no analytics cookie is ever set.
Cookieless measurement — without analytics consent, we still count page views server-side under an anonymized identifier derived from a one-way hash that rotates daily. Nothing is stored on your device, and visits cannot be linked across days or sites. This is done under our legitimate interest in aggregate traffic measurement.
We do not use advertising cookies, social-media trackers, or any third-party tracking cookies. You can change or withdraw your cookie consent at any time on the Cookie Policy page (https://nourva.ai/cookies), which also lists every cookie, its purpose, and its retention.
The mobile apps. Neither the Nourva iOS app nor the Nourva Android app sets cookies for tracking, contains an advertising or attribution SDK, collects an advertising identifier, or performs any cross-app or cross-site tracking. The Android app declares no AD_ID permission. The iOS app displays no App Tracking Transparency prompt because it has nothing to track.
The desktop app. The Agent controls a browser on your instruction. Cookies encountered during that automation belong to the sites you direct it to and stay in the browser profile on your machine; we do not collect them.
16. Artificial Intelligence — Transparency and Human Oversight
Nourva is an artificial intelligence system, and you are always interacting with one. We state this plainly here in line with the transparency obligations of the EU AI Act (Regulation (EU) 2024/1689) and equivalent emerging rules.
- You are talking to an AI. Every response, document, summary, and automated action in Nourva is produced by an AI system, not by a human.
- Output can be wrong. AI output may be inaccurate, incomplete, or unsuitable for your situation. Review it before you rely on it, and never use it unreviewed where an error could cause harm.
- Your content is not training data. We do not use your prompts, files, voice, documents, or memory to train AI models, and our providers are contractually barred from doing so.
- No significant automated decisions about you. Nourva does not use your personal data to make automated decisions with legal or similarly significant effects, and does not score, rank, or profile you.
- You stay in control. Every automated action the Agent takes on your computer is one you asked for, and you can stop it at any time.
- Synthetic content. Where Nourva generates media that could be mistaken for authentic, it is machine-generated content produced at your request; you are responsible for labelling it appropriately if you publish it.
17. Children's Privacy
Nourva is not intended for use by children under the age of 13, and we do not knowingly collect personal information from anyone under 13. Users aged 13 to 17 may use the Service only with the consent of a parent or legal guardian. The Service contains no content directed at children, and is not part of Google Play's Designed for Families programme or Apple's Kids Category.
If we discover that we have inadvertently collected personal information from a child under 13, we will delete it promptly. A parent or guardian who believes a minor has provided us with personal data may write to [email protected] and we will remove it.
18. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice within the application, and we keep the previous version's date on this page so you can see when the document last moved.
This version is effective August 16, 2026 and replaces the version dated August 11, 2026. The August 16 update makes this a single global policy covering the Nourva Android app alongside desktop, iOS, and web: it adds the full device-permission inventory for both mobile platforms, Google as the payment processor for Android purchases and the Play Billing Library as the only Google component in the app, the calendar mirror and screen-sharing disclosures, deletion from every surface plus a public deletion page, the AI transparency section, and expanded regional disclosures for the United States, Canada, Brazil, Saudi Arabia, the Gulf, Australia, New Zealand, Japan, Korea, India, Türkiye, South Africa, and Nigeria.
19. Contact, Data Controller, and Representatives
Tokra, LLC is the data controller for the personal data described in this policy.
Tokra, LLC (a Delaware limited liability company)
131 Continental Dr, Suite 305, Newark, DE 19713, USA
Privacy inquiries and rights requests: [email protected]
General support: [email protected]
Legal notices: [email protected]
Account deletion: https://nourva.ai/delete-account
Company information: https://nourva.ai/legal/company
EU representative (GDPR Art. 27): https://nourva.ai/legal/eu-representative
Sub-processor list: https://nourva.ai/legal/sub-processors
Cookie Policy: https://nourva.ai/cookies
Terms of Service: https://nourva.ai/terms
We answer privacy requests within 30 days, or sooner where your local law requires it.
© 2026 Nourva. All rights reserved.