Privacy Policy
Last updated: 19 September 2026 · Version 4
In short
- Your records are kept encrypted on your phone. Even if your phone ends up in someone else’s hands, the database cannot be read.
- If you do not create an account, we hold no copy on our servers. The app works fully offline.
- If you create an account, your records are backed up. The backup is tied to your account alone; no other user can reach it.
- The app shows no ads and we do not sell your data. The Meta SDK is there only to measure our own ad campaigns; your health records never go to Meta.
- You can export or completely delete your data at any time.
Protection on your device
- The local database is encrypted with SQLCipher; the key is held in the device’s secure hardware store (Keychain/Keystore) and never leaves the device.
- App backup is disabled: your records are not included in iCloud/Google Drive backups.
- On the journal, illness and maternal-health screens, screenshots are blocked on Android. iOS does not allow this, so only the app-switcher preview is hidden.
- You can lock the journal with biometrics/PIN. Fingerprint/face data stays in the operating system; the app never accesses it.
If backup is on
Backup is optional and off by default. When you turn it on, we ask for separate explicit consent to store your health data on the server.
Your records on the server are protected by TLS in transit, by the provider’s encryption at rest, and are bound to your account alone by row-level security (RLS).
To be straightforward: this data is readable on the server. The Nursea team looks at production data only at your request or during a fault investigation; every access is logged and bulk export is forbidden.
Photos are backed up on a Premium subscription only.
Ad measurement (Meta)
- We promote Nursea with Instagram and Facebook ads. To see which ad actually turned into an install, the app contains Meta’s Facebook SDK.
- The only events sent to Meta are: app installed/opened, setup steps completed (baby or pregnancy mode), Premium screen viewed, checkout started, subscription or trial started (plan and price).
- These events travel with the device model, OS and app version and — if you allowed it — the device advertising identifier. No baby name, no health record, no e-mail and nothing you enter is sent.
- On iOS this measurement depends on Apple’s "Allow this app to track your activity?" prompt; if you choose "Ask App Not to Track", the advertising identifier is not shared. You can change your decision under Settings → Privacy & Security → Tracking.
- On Android you can delete or reset the advertising identifier under Settings → Google → Ads.
- This data is transferred to Meta Platforms Ireland Ltd. (abroad). Meta’s use and retention rules: facebook.com/privacy/policy
What we do not collect
- Location data.
- Contacts, call logs, SMS.
- Health records, your baby’s name or anything you enter, for advertising purposes (none of it goes anywhere).
- Crash reports or session recordings (not in this version); the events sent to Meta are limited to the list above.
- Payment card details.
Services we use
- Hosting, database and file storage: Supabase — European Union (Ireland).
- Subscription management: RevenueCat, Inc. (USA); payment is taken through the Apple App Store or Google Play.
- Phone sign-in: the SMS verification code is sent through Twilio Inc. (USA); only your mobile number is passed to Twilio.
- Sign in with Apple / Google: Apple Inc. or Google LLC verifies your identity; we receive only an account identifier and e-mail address.
- Notification delivery: scheduled on the device only; content never goes to a server.
- Shop catalogue: the product list is read from the server without an account; that read is not linked to you.
- Ad measurement: Meta Platforms Ireland Ltd. (Facebook SDK) — only the events listed under "Ad measurement (Meta)".
Children
Nursea is designed for parents and is not directed at people under 18. Children’s data in the app is entered by the child’s parent or guardian.
If we learn that a child has created an account on their own, we delete the account and its data.
Exporting and deleting your data
From Profile → Privacy and my data you can export all your records as a single file, or delete everything. Deletion covers the on-device database, photos, settings and, if present, your records on the server.
Data breach
If we learn of a personal data breach we notify the Turkish Data Protection Board within 72 hours at the latest, and affected users as soon as possible.
Changes and contact
If this text changes we inform you in the app and, where necessary, ask for your consent again.
Questions: [email protected]