Noongil Privacy Policy
Last Updated: August 3, 2026 Effective Date: August 3, 2026
---
1. Introduction
Noongil ("we," "us," or "our") provides a voice-first general wellness application for Parkinson's family care ("the App") designed to help you capture daily check-ins, manage reminders, prepare Doctor Visit Reports, and share care context with family members or caregivers. This Privacy Policy describes how we collect, use, share, and protect your personal information when you use the App.
Noongil is a general wellness product. It is not a medical device and has not been evaluated or cleared by the U.S. Food and Drug Administration. The App does not diagnose, treat, cure, mitigate, or prevent any disease or condition.
By using the App, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the App.
---
2. Information We Collect
2.1 Information You Provide Directly
| Data Type | Examples | Purpose | |-----------|----------|---------| | Account information | Name, email address (via Sign in with Apple) | Authentication, account management | | Daily check-in responses | Mood descriptions, sleep quality, activity descriptions, concerns | Self-reported care journal and neutral log comparisons | | Medication and reminder information | Medication names, dosages, schedules, adherence logs | Reminder scheduling, routine tracking | | Caregiver relationships | Invite codes, caregiver names | Permissioned caregiver sharing with people you designate | | Caregiver voice messages | Short audio messages a caregiver deliberately records and sends to a linked member | Family communication and playback in the App | | Custom reminders | Reminder titles, schedules | Personalized reminder notifications | | Preferences | Language, voice settings, companion name | Personalizing your experience | | Subscription information | Plan, entitlement state, offering or promotion assignment, purchase/renewal/expiration events, price and currency, and store | Providing paid access, restoring purchases, support, fraud prevention, lifecycle messaging, and subscription analytics |
2.2 Information Collected Automatically
| Data Type | Examples | Purpose | |-----------|----------|---------| | Live check-in voice audio | Microphone input during live AI conversations | Real-time transcription and AI conversation (see Section 4 for details) | | Usage data | Check-in frequency, session duration, feature usage | App improvement and service operation | | Device identifiers | Firebase User ID, push notification tokens | Authentication, delivering notifications | | Attribution and campaign data | App-link source, UTM fields, and advertising click identifiers when supplied by a campaign link | Measuring which campaigns lead to app use and subscriptions |
2.3 Information Generated by the App
| Data Type | Examples | Purpose | |-----------|----------|---------| | Conversation transcripts | Text records of your conversations with the companion | Reviewing past conversations, generating summaries | | AI-generated summaries | Check-in summaries and Doctor Visit Reports | Providing summaries from your self-reported data | | Neutral log comparisons | Recorded averages or counts across groups of self-reported check-in days | Showing recorded differences without explaining why a change occurred | | Episodic and semantic memories | Key moments and recurring themes from your conversations | Continuity across conversations |
---
3. How We Use Your Information
We use your information for the following purposes:
- Providing the App's features: Voice check-ins, medication reminders, Doctor Visit Reports, caregiver sharing
- AI-powered conversation: Processing your voice input and generating conversational responses using artificial intelligence (see Section 5)
- Neutral log comparisons: Comparing groups of self-reported check-in days without inferring or explaining why a symptom changed
- Caregiver sharing and notifications: Sending shared care context and notifications to designated caregivers when you choose to share information (see Section 7)
- Push notifications: Delivering check-in reminders and medication reminders
- App improvement: Understanding how features are used to improve the App
- Security and abuse prevention: Protecting your account and preventing misuse
- Subscriptions and lifecycle communications: Providing entitlements, purchase restoration, billing-state notices, promotions, and subscription support
- Product and cost analytics: Measuring the signup and purchase funnel, feature usage, and estimated service costs using data minimized to avoid health-content payloads
Noongil does not use your information for:
- Advertising or marketing by third parties
- Selling your personal information to any party
- Training Noongil-owned AI models. Our production Gemini API project is configured as a paid service. Under Google's paid-service terms, prompts and responses are not used to improve Google products. See Section 5.3 for the limited safety and abuse-prevention logging that Google describes.
---
4. Voice Data and Biometric Information
4.1 How Voice Data Is Processed
The App handles two distinct types of voice audio:
- Live AI check-ins: When you enable cloud voice, microphone audio is streamed to Google LLC's Gemini API for real-time transcription and spoken responses. Noongil does not intentionally retain that live-session audio on its own servers; text transcripts and structured check-in context may be retained.
- Caregiver voice messages: A caregiver may deliberately record and send a short message for a linked member to play later. Noongil stores that message audio for this purpose until it is deleted or reaches the 30-day retention limit. These messages are family communications, not AI check-in audio.
4.2 Biometric Information Notice
If applicable law classifies voice audio as biometric data, we provide the following disclosures:
- What we collect: Voice audio during enabled live AI check-ins and short caregiver voice messages when a caregiver deliberately sends one
- Purpose: Real-time transcription and AI-powered responses for live check-ins; later playback of a caregiver's message by the linked member
- Who receives it: Google LLC's Gemini API processes enabled live-session audio; Noongil's cloud infrastructure stores caregiver voice messages and delivers them to the linked member
- Retention: Live-session audio is not intentionally retained by Noongil. Caregiver voice messages are retained for no more than 30 days unless deleted sooner. Text transcripts and structured check-in context follow the retention table below.
- Destruction: Live-session audio is intended to be transient. Caregiver voice messages are deleted on user deletion, explicit message deletion, or automated expiry.
We will not sell, lease, trade, or otherwise profit from your biometric data. We will not disclose your biometric data to any third party except as described above or as required by law.
Your consent is required before any voice streaming to cloud services. You will be asked to provide separate health-data, AI-analysis, and cloud-voice choices before live voice features are enabled. You may withdraw cloud-voice consent in App settings; future cloud voice processing will remain disabled unless you grant the current consent version again.
---
5. Artificial Intelligence
5.1 How AI Is Used
The App uses artificial intelligence to:
- Engage in natural conversation during voice check-ins
- Generate check-in summaries and Doctor Visit Reports from your self-reported experiences
- Organize neutral comparisons across your self-reported check-in days; AI does not determine why symptoms changed
- Respond to your questions about your care journal
5.2 Limitations
AI responses are generated from your self-reported information and general wellness knowledge. They are not reviewed by a healthcare professional. AI may produce inaccurate, incomplete, or inappropriate responses. The App does not infer, rank, or state reasons a symptom changed. You should not rely on AI-generated content as a substitute for professional care.
The App's AI companion is not a human. It is an artificial intelligence system. It is not a therapist, counselor, medical professional, or licensed healthcare provider.
5.3 AI Data Processing
With your permission, Noongil uses Google LLC's Gemini API as an AI and speech-processing service provider.
- Data sent: Live microphone audio when cloud voice is enabled; check-in transcripts; self-reported sleep, mood, symptoms, activity, medication timing, and other check-in context; and report text submitted for generation or narration
- Purposes: Real-time transcription and spoken responses, organizing saved check-in entries, generating summaries and Doctor Visit Reports, and reading a report aloud
- Consent: Health-data and AI-analysis consent are required before personal check-in context is sent for AI processing. Separate cloud-voice consent is required before microphone audio is streamed or a Gemini Live session token is issued.
- Google's data use: The production Gemini API project uses a Cloud project with active billing and is therefore a paid service under the Gemini API Additional Terms. Google states that paid-service prompts and responses are not used to improve Google products. Google may log prompts and responses for a limited period solely for safety and abuse prevention and required legal or regulatory disclosures. Noongil does not claim zero data retention.
- No search grounding: Noongil does not send check-in data to Google Search or Google Maps grounding features.
- No medical use: Noongil does not use Gemini to diagnose, treat, provide medical advice, or explain why a symptom changed.
Google processes prompts and responses under the data-processing terms incorporated into its paid-service terms. Noongil requires the configured processor to use personal data only to provide and secure the service, not for advertising or general model improvement. If this provider or these practices materially change, Noongil will update this Policy and require a new consent review before the changed processing begins.
---
6. How We Share Your Information
6.1 Service Providers
We share your information with the following categories of service providers to operate the App:
| Category | Data Shared | Purpose | |----------|-------------|---------| | Cloud infrastructure and storage providers | Account data, check-in data, summaries, medications, and related product data | Primary storage, synchronization, and application operations | | Google LLC — Gemini API (AI and speech processing) | Live microphone audio when cloud voice is enabled; check-in transcripts and self-reported health context; report text submitted for generation or narration | Real-time transcription and responses, organizing check-ins, summaries, Doctor Visit Reports, and report narration | | Data analysis and product infrastructure providers | Self-reported entries, neutral comparison aggregates, technical usage signals, and related product data | Log comparison processing, reliability, and performance monitoring | | Alert delivery providers | Device token, contentless notification copy, neutral routing type, and opaque notification identifier; no member identifier or health detail | Delivering reminders and caregiver notifications | | Subscription infrastructure (RevenueCat, Apple, and Google) | Account identifier, product, entitlement, offering, store, purchase lifecycle, and limited attribution fields | Processing and synchronizing subscriptions, restoring purchases, experiments, and subscription support | | Product analytics and customer messaging providers (Amplitude and Customer.io) | After your optional Product Analytics opt-in: account identifier, app/device context, campaign attribution, subscription-funnel events, and non-content feature usage | Funnel measurement and lifecycle communications |
Through the applicable service terms and data-processing agreements, we require service providers, including Google, to provide the same or equal protection of user data described in this Policy. We configure providers to limit processing to the disclosed purposes and do not permit them to sell this data or use it for advertising.
6.2 Caregiver Sharing
If you choose to link a caregiver, shared care context, check-in summaries, reminders, and caregiver-facing notifications may be shared with that person. You control this relationship and can revoke caregiver access at any time. Caregiver notifications contain general notifications only — specific health details are not included in push notification text visible on lock screens.
6.3 Other Disclosures
We may disclose your information:
- When required by law, regulation, legal process, or governmental request
- To protect our rights, privacy, safety, or property
- In connection with a merger, acquisition, or sale of assets (with prior notice to you)
6.4 We Do Not Sell Your Information
We do not sell or share your personal information for cross-context behavioral advertising. We do not share your information with advertisers or data brokers.
---
7. Caregiver Data Sharing
The App allows you to invite a trusted person (a "caregiver") to receive wellness-related notifications about you.
- What is shared: General wellness alerts and summaries that you authorize
- Consent: You must explicitly authorize caregiver access. Sharing requires your active, informed consent.
- Revocation: You can remove a caregiver at any time. Revocation takes effect immediately.
- Caregiver obligations: Caregivers agree to usage terms before accessing any shared information.
Caregiver sharing is separate from your general consent to use the App. You can use the App without ever linking a caregiver.
---
8. Data Retention and Deletion
8.1 Retention
| Data Type | Retention Period | |-----------|-----------------| | Account information | Until you delete your account | | Check-in data and transcripts | 1 year from creation, then automatically deleted | | Medication information (active) | Until deactivation + 1 year, then automatically deleted | | Medication adherence logs | 1 year from recording, then automatically deleted | | Conversation memories | 1 year from creation, then automatically deleted | | Check-in sessions | 90 days, then automatically deleted | | Caregiver relationships | Until revoked + 90 days, then automatically deleted | | Invite codes | 30 days, then automatically deleted | | Wellness graph data | 2 years, then automatically deleted | | Live AI check-in audio | Not intentionally retained by Noongil — processed for the active session | | Caregiver voice messages | Until deleted or 30 days from creation, whichever comes first | | Push notification tokens | Until you delete your account or revoke notifications | | Subscription and purchase state held by Noongil | Until account deletion, then only as needed for fraud prevention, dispute handling, legal obligations, or de-identified reporting | | Store and subscription-processor transaction records | Controlled by Apple, Google, and RevenueCat under their policies and applicable financial, tax, fraud-prevention, and legal requirements | | Campaign attribution and subscription-funnel events | Up to 2 years unless a shorter vendor setting or deletion obligation applies | | First-party aggregate usage ledger | Up to 13 months for annual cohort comparison |
8.2 Deletion
You can delete your account and all associated data at any time through the App settings ("Delete Account"). Upon deletion:
- All your data stored in our cloud database is permanently deleted
- All your data in our graph database is permanently deleted
- Your authentication account is permanently deleted
- Local data on your device is cleared
- Noongil subscription identifiers and lifecycle profiles are deleted or suppression-marked where supported, subject to legal, fraud-prevention, and transaction-record exceptions
Deleting your Noongil account does not automatically cancel a subscription billed by Apple or Google. You must cancel it in the applicable store's subscription settings to stop future renewal charges. Noongil does not receive or store your full payment-card details.
We process deletion requests within 30 days. Some anonymized, aggregated data that cannot be linked back to you may be retained for analytics purposes.
---
9. Data Security
We use industry-standard security measures to protect your information, including:
- Encrypted data transmission (TLS/SSL)
- Encrypted data storage
- Authentication-based access controls
- Audit logging of data access
- Rate limiting to prevent abuse
No system is perfectly secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security.
---
10. Your Privacy Rights
Regardless of where you live, we provide the following rights to all App users:
Right to Access
You can request a copy of all personal information we hold about you. Use the "Export My Data" feature in the App settings, or contact us at the address below.
Right to Delete
You can request deletion of your personal information. Use the "Delete Account" feature in the App settings, or contact us. We will process your request within 45 days.
Right to Correct
You can request correction of inaccurate personal information by contacting us.
Right to Withdraw Consent
You can withdraw consent for specific data processing activities:
- Cloud voice processing: Turn off Cloud Voice in Privacy Choices. Voice streaming stops immediately; local/account functions remain available.
- External product analytics: Turn off Product Analytics in Privacy Choices. New app events stop being sent to analytics providers.
- Health-context collection and AI review: Change the corresponding Privacy Choices. Noongil will stop the affected future cloud processing while preserving access to account, export, deletion, and legal settings.
- Caregiver sharing consent: Remove the caregiver in App settings
- Delete retained data: Use Delete Account or submit a privacy request. Withdrawal stops future processing but is separate from deletion of information already collected.
Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights.
California Residents (CCPA/CPRA)
In addition to the rights above, California residents have the right to:
- Opt out of the sale or sharing of personal information — we do not sell or share your information, so there is nothing to opt out of
- Limit the use of sensitive personal information — contact us to exercise this right
- Request information about our data practices
Do Not Sell or Share My Personal Information
We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is necessary.
Limit the Use of My Sensitive Personal Information
We use sensitive personal information (health data, biometric data) only to provide the App's core features as described in this policy. To request further limitations, contact us at the address below.
---
11. Children's Privacy
The App is intended for users who are 18 years of age or older. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child under 18, please contact us immediately and we will delete it.
---
12. Cross-Border Data Transfers
Your information is processed and stored in the United States on servers operated by our cloud infrastructure provider. If you are located outside the United States, your information will be transferred to and processed in the United States.
---
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the App or by other appropriate means before the changes take effect. Your continued use of the App after changes take effect constitutes acceptance of the revised policy.
---
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:
Noongil Email: privacy@noongil.ai