Numa · Period & Pregnancy
Privacy Policy
Draft prepared on 5 October 2026 for the current Android beta.
Numa is a cycle, pregnancy and wellbeing tracking application developed by BuildrStudio. This policy explains how the current app handles information you choose to record, optional accounts and backups, and privacy enquiries. It does not describe BuildrStudio’s separate AI marketplace services.
- You can track without creating an account.
- Tracking records are encrypted on your device. Signing in does not upload them.
- Cloud backup is optional and uploads an encrypted snapshot only when you request it.
- This version has no advertising SDK, health analytics, or external AI processing of your journal.
1. Information you choose to record
Numa may store your chosen profile name, cycle or pregnancy settings, period dates, bleeding and spotting, symptoms and severity, mood, journal notes, fertility observations such as LH tests, basal temperature and cervical mucus, appointments, questions, intentions, and documents you select. These entries can contain sensitive health information. Optional fields can be left blank.
The app uses these records to display your history, calculate tracking estimates and summaries, organise care information, and create reminders or exports you request. Missing entries remain unknown. Numa does not diagnose conditions, confirm ovulation, or identify safe days for unprotected sex.
2. Local storage and security
Tracking records and saved document contents are encrypted on your device using AES-256-GCM. On Android and iOS, the encryption key is held separately in the operating system’s secure key store. Optional app lock uses your device’s biometric or device-credential authentication; Numa does not receive or store your biometric template.
If you use a browser version, records and keys use that browser’s storage, which has different protections from a phone’s secure key store. No storage or transmission system is guaranteed to be completely secure. Keep an encrypted backup and its separate recovery key before reinstalling, clearing app or browser data, or changing devices. Numa cannot recover a lost recovery key.
3. Optional accounts and Firebase
If you create an account, Google Firebase Authentication processes your email address, password authentication information, account identifier, and technical information such as IP address and user agent to provide sign-in, account management and abuse prevention. Numa uses your account identifier to keep account spaces and optional backups separate. Account creation and sign-in do not automatically upload your tracking records.
Google processes information for these services under its applicable Firebase and Google Cloud terms. See Firebase’s privacy and security information. The cloud backup database is configured in Mumbai, India; this does not mean that all authentication, operational or support processing occurs only in India.
4. Optional encrypted cloud backup
Signed-in users can explicitly save a cloud snapshot. Numa encrypts the snapshot on the device before sending it to Google Cloud Firestore. A snapshot may include your saved tracking records and document contents. Your recovery key is not included in the upload. Later edits are not automatically backed up.
Cloud services and authorised project administrators can observe your account identifier, request timing, encrypted payload size, and backup metadata such as timestamps and piece counts. The stored snapshot contains ciphertext rather than readable health entries. Numa’s cloud restore requires the matching account and the separate recovery key.
An explicitly requested backup write may remain pending if connectivity is lost and may finish after reconnection. Turning off backup availability does not delete a snapshot that was already uploaded. Use the cloud deletion action and confirm its result.
5. Sharing, files and support
Readable record exports, visit summaries and individual documents can contain private information. You choose what to include and review the content before using your device’s sharing or printing flow. The app creates temporary readable files for these actions and removes its temporary copy when sharing completes or fails. Files saved elsewhere and copies retained by recipients, email providers, printers or other applications are controlled there.
Feedback opens a draft in your mail application. It is sent only after you choose to send it. If you contact support, we receive your email address and the message or attachments you provide and use them to handle your enquiry. Email is outside Numa’s encrypted record storage. Please do not send passwords, recovery keys, health documents, or identifying health screenshots.
We do not sell your tracking records or use them for targeted advertising. Information may be disclosed when you direct a share, to service providers needed for a requested feature, or where required by applicable law.
6. Permissions, reminders and local processing
Notifications are optional local reminders with generic text. Enabling them requests the relevant device permission. You can change reminders in Numa or revoke notification permission in your device settings. Numa uses system file selection and sharing when you import or export files; the file-provider’s original copy remains separate.
Journal tag suggestions, cycle estimates and recorded-data summaries run locally. Suggestions need your review before saving. The current version does not send journal text, health documents or tracking records to an external LLM provider. It contains no advertising, Firebase Analytics, or Crashlytics SDK. If a future version introduces different processing, its notice and applicable choices will be updated before that feature is enabled.
7. Retention and deletion
| Information | Retention and removal |
|---|---|
| Device tracking records | Remain in the current space until you remove entries or use Account → Privacy & data → Delete device records. Signing out does not delete records. Device deletion does not remove cloud snapshots, exported files or copies on other devices. |
| Cloud snapshot | Remains in your account until replaced by a later snapshot or removed with Delete cloud backup or successful account deletion. The app removes live snapshot records and pieces; provider-held operational or backup copies may follow separate deletion processes. |
| Firebase account | Remains until you request deletion. Delete my account requires reauthentication, removes the enabled cloud snapshot and the account’s records on this device, then deletes the Firebase account. Failures are reported for retry. Firebase states that logged authentication IP addresses are retained for a few weeks and other authentication information is removed from live and backup systems within 180 days after customer-initiated user deletion. See Firebase’s current disclosure. |
| Exports and recipient copies | Remain wherever you or a recipient saved them. Delete those copies separately; deleting a Numa account cannot remove them. |
| Support correspondence | Proposed policy for owner confirmation: retain only for the time needed to resolve the enquiry and applicable legal or security obligations, then delete or de-identify it. An exact operational schedule has not yet been confirmed. |
We do not promise immediate removal from every provider-held backup or operational log. Operator-managed Firestore backup settings and any additional retention periods must be confirmed before this draft becomes the launch policy.
8. Privacy enquiries and account deletion requests
You can review, correct, export and delete recorded information using the app. For an account deletion request outside the app or another privacy enquiry, contact buildrstudioin@gmail.com with the subject “Numa privacy request.” Send from the account email where possible. We may need to verify ownership; do not send your password or recovery key. The owner must confirm the support process and response schedule before publishing this external request route.
9. Visiting this website and third-party links
This app policy is separate from website processing. BuildrStudio’s site uses Vercel hosting, Vercel Analytics, Speed Insights and Umami. These services may process website visit, request, browser and performance information. Visiting this page does not upload your Numa tracking records. See the BuildrStudio website privacy policy for website and other service processing. External education links and destinations you open have their own privacy policies.
10. Changes and contact
When the policy changes, its published update date will change. Material changes to the app’s data handling will be explained in the app and, where required, presented with an appropriate choice before new processing occurs.
Numa privacy contact: buildrstudioin@gmail.com.