nufa Italiano

Privacy Policy

Last updated: 28 July 2026

nufa helps you track your mood and your habits so you can see how the two connect. That is intimate data, so this page explains plainly what we collect, where it goes, how long we keep it, and what you can ask for at any time.

1. Who processes your data

The data controller is Daniel Sadun, an individual based in Italy. For anything concerning your data, write to nufasupport@gmail.com. We reply within 30 days, as the GDPR requires.

2. What we process

Account data

Your email address and display name. You can sign up with email and password, with Sign in with Google or with Sign in with Apple. We never see your password: authentication is handled by Firebase Authentication.

Data you enter

Preferences and data the app generates

Usage and diagnostic data

3. Why we process it, and on what legal basis

PurposeLegal basis (GDPR)
Creating and running your account Performance of a contract — art. 6(1)(b)
Storing your check-ins, trackers and notes and showing you your history Performance of a contract — art. 6(1)(b), and explicit consent for wellbeing data — art. 9(2)(a)
Generating insights and personalised messages Performance of a contract — art. 6(1)(b), and explicit consent — art. 9(2)(a)
Sending the reminders you turned on Consent — art. 6(1)(a); you can turn them off in Settings at any time
Understanding how the app is used so we can improve it Legitimate interest — art. 6(1)(f); you can object by writing to us
Finding and fixing errors and crashes Legitimate interest — art. 6(1)(f)

We do not sell your data, we do not share it with third parties for advertising, and we do not build advertising profiles.

4. Your wellbeing data

Mood, trackers and notes concern your wellbeing and deserve the care the GDPR reserves for special categories of data (art. 9). We process them solely on the basis of your explicit consent, which you give by creating an account and starting to record check-ins, and only for the purposes listed above. You can withdraw it at any time by deleting your account in Settings; withdrawal does not affect the lawfulness of processing carried out beforehand.

5. Notes and encryption

Check-in notes are encrypted on your device with AES-256-GCM before being saved. The key is generated on your phone and kept in the operating system's secure store (iOS Keychain, Android Keystore): it never leaves your device and we do not know it. Notes reach the database already encrypted, and nobody — including us — can read them.

So that this promise stays honest, two stated limits:

6. Artificial intelligence

nufa uses a single AI provider: Groq (Llama 3.3 model), with servers in the United States. When the model is unreachable, the app shows messages we wrote in advance and sends nothing at all.

What gets sent, and only at the moment it is needed:

We never send the AI provider your name, your email or your user ID. The check for content indicating a crisis runs entirely on your device, sending nothing to anyone.

7. Who else processes your data, and where

ProviderWhat forWhere
Google Firebase (Firestore)Database holding your dataEuropean Union
Google Firebase (Authentication, Cloud Messaging, Analytics, Crashlytics)Sign-in, notifications, analytics, crashesUnited States
Google Cloud FunctionsInsights, streaks, scheduled notificationsUnited States
GroqGenerating the AI textUnited States
PostHogProduct analyticsEuropean Union
MixpanelProduct analyticsUnited States
SentryCrash reportingEuropean Union (Germany)

8. Transfers outside the European Union

The database holding your check-ins, trackers and notes is located in the European Union. Some of the services listed above operate in the United States: those transfers rely on the Standard Contractual Clauses approved by the European Commission and, where applicable, on the EU-US Data Privacy Framework, under each provider's data processing terms.

9. How long we keep it

10. Your rights

You have the right to access your data, correct it, erase it, restrict or object to its processing, receive it in a portable format and withdraw the consent you gave. In practice:

If you believe the processing of your data breaches the GDPR, you can lodge a complaint with your country's supervisory authority. In Italy that is the Garante per la protezione dei dati personali.

11. Automated decisions

Insights are generated automatically, but they are statistical observations about your own data: they produce no legal effects and nothing similarly significant, and there is no automated decision-making within the meaning of art. 22 GDPR.

nufa is not a medical or therapeutic tool. Insights are not a diagnosis and do not replace professional advice.

12. Minors

nufa is intended for people aged 15 and over, and we do not knowingly collect data from anyone younger. If we find that we have, we delete it. If you are under 18, use the app with a trusted adult's awareness.

13. Security

Notes are encrypted on the device, as described above. Database access is governed by rules that let each user read and write only their own data, and all traffic between the app and our servers runs over HTTPS. We take reasonable measures, but no system is 100% secure and we cannot guarantee absolute protection.

14. Changes to this policy

If we change how we handle your data we update this page and the date at the top. For substantial changes we will tell you inside the app.

15. Contact

Any question about this policy or your data: nufasupport@gmail.com.