1. Who is responsible for data processing
Nora is operated by:
- Legal name
- Nora AI
- Trade name
- Nora
- CNPJ
- 66.045.624/0001-33
- Address
- Rua Leopoldo Couto de Magalhães Júnior, 1098, IT Office, suite 21, São Paulo, ZIP Code 04542-001
- Privacy contact
- dev@noraai.co
For the purposes of the LGPD, the company identified above acts as the controller of the personal data processed by Nora, determining the purposes and means of such processing.
2. Data we collect
Nora collects only the categories of data listed below. Which of them actually apply depends on the features the user uses, the permissions the user grants, and the accounts the user chooses to connect.
Account data
- Name and email address;
- Password, stored only as a cryptographic hash — we never store or transmit the password itself;
- The account identifier returned by Sign in with Apple or Sign in with Google, when the user signs in that way, together with the name and email address those services share with us;
- The preferences the user sets during setup, such as language and areas of focus.
Recordings and transcripts
- Audio the user records in the app, and the transcripts generated from that audio;
- A voice sample the user records during initial setup, used to identify who is speaking in later recordings. The sample and the mathematical voice signature derived from it are processed on Nora’s own systems and are not sent to the AI providers listed in section 5;
- Summaries, titles, topics, reminders, and other content Nora generates from the user’s recordings.
Chat content
- Messages the user writes to Nora and Nora’s replies;
- Photos, images, documents, and other files the user attaches in the chat.
Content from connected apps
When the user connects an account, Nora receives content from that account within the scope the user authorizes. Accounts that can be connected include:
- Google — Gmail, Calendar, Drive, Docs, Sheets, Slides, and Tasks;
- Microsoft — Outlook, Teams, OneDrive, and Excel;
- Slack, Notion, and Linear;
- WhatsApp, including messages and media;
- Instagram and other social accounts, such as LinkedIn, YouTube, TikTok, X, and Reddit;
- Whoop and Oura, including sleep, recovery, readiness, and activity data;
- Work and productivity tools, such as GitHub, GitLab, Figma, Canva, ClickUp, Trello, Todoist, Calendly, Stripe, Vercel, and Grafana.
The complete, current list is shown on the Integrations screen in the app. No connection is made without the user’s explicit authorization, and the user may disconnect any of them at any time.
Data from the device, with the user’s permission
- Calendar events and reminders from the iPhone, when the user grants calendar and reminders access;
- Contacts, when the user grants contacts access;
- Location: points collected during recordings, places the user saves, and the regions Nora monitors in order to deliver location-based reminders;
- Photos and camera images, when the user chooses to attach them or grants photo library access;
- Speech the user dictates into the message box, which is converted to text using the operating system’s speech recognition.
Technical and subscription data
- The device token used to deliver push notifications, including notifications about the user’s recordings and reminders;
- Usage data required to operate the subscription and enforce its quota, such as the number and length of recordings, number of messages, and the processing cost attributed to the account;
- Device and diagnostic information, such as app version, operating system, language, and error reports, used to keep the service working;
- Billing data when the user subscribes, processed by our payment provider.
Health data received from Whoop, Oura, or similar sources may be considered sensitive personal data under the LGPD and is processed in accordance with that classification.
Nora does not collect anything from an app the user has not connected, and does not use the microphone outside of recordings the user starts.
3. How we collect the data
All of the data described above reaches Nora as the direct result of an action taken by the user in the app. Specifically, Nora receives data when the user:
- Creates an account, or signs in with Apple or Google;
- Starts a recording;
- Records the voice sample during initial setup;
- Writes a message, or attaches a photo, document, or other file;
- Connects an external account and authorizes the scope of that connection;
- Grants a system permission on the device;
- Subscribes to a paid plan.
Each device permission — microphone, speech recognition, calendar, reminders, contacts, location, notifications, camera, and photo library — is requested separately and granted explicitly by the user through iOS. Nora cannot access any of them until iOS records that permission, and the user may revoke any of them at any time in the iOS Settings app. Revoking a permission stops the corresponding collection, and features that depend on it stop working.
Nora does not buy personal data from third parties and does not collect data about people who are not users, except for information contained in content the user themselves records, writes, attaches, or imports from an account they connected.
4. How we use the data
Nora uses the data collected for the following purposes, and no others:
- Transcribing the audio the user records;
- Identifying who is speaking in the user’s recordings;
- Answering the user in the chat, including answers based on attached files;
- Generating summaries, titles, topics, reminders, and suggestions from the user’s content;
- Executing routines and actions the user requests, including actions in the accounts the user connected;
- Personalizing the assistant, so that it takes into account what the user has previously recorded, written, saved, and set as a preference;
- Organizing and retrieving the information the user has stored in Nora;
- Delivering notifications and location-based reminders the user asked for;
- Creating and maintaining the account, and authenticating the user;
- Operating the subscription, including billing and quota control;
- Keeping the service secure, stable, and working, including diagnosing errors and preventing abuse;
- Providing support and responding to user requests;
- Complying with legal and regulatory obligations.
Nora does not sell personal data, does not use user content for advertising, and does not use user content to train artificial intelligence models — neither its own nor those of third parties.
Processing is carried out on the legal grounds applicable to each activity, including performance of a contract, consent, compliance with a legal or regulatory obligation, the regular exercise of rights, legitimate interest, and, for sensitive personal data such as health data, the specific legal grounds provided by the LGPD.
5. Third-party AI providers
To operate Nora, we share user content with artificial intelligence providers that process it on our behalf: Anthropic, Google, and OpenAI. We route each task to the model that handles it best, so the specific models change over time; the companies listed above are the only AI companies whose models process user content.
Each of these providers processes the data under a data processing agreement that requires protection equal or equivalent to the protection we provide under this Policy, exclusively for the purpose of operating Nora, and that does not permit the use of the data to train their own models.
The content sent to them is limited to what is necessary to perform the requested feature: the audio and transcripts of the user’s recordings, the messages and files sent in the chat, content from the accounts the user connected, places the user saved or shared when location is enabled, and the user’s name and setup preferences. The user’s password is never sent, and neither is anything from an app the user has not connected.
Two technical intermediaries carry that content to those models on our behalf, under the same contractual terms described above — the same purpose limitation, the same protection requirement, and the same prohibition on training:
- OpenRouter, the routing service through which we reach the models that answer the user in the chat, generate summaries and reminders, and run requested actions;
- Groq, which runs the speech-to-text model that converts the audio the user records into text.
Separately, when the user asks Nora for something that requires a web search, the search query — which may include content the user wrote — is sent to our search provider, Exa, and, if the user has connected a web research tool such as Firecrawl or Tavily, to that tool. These providers receive the query, not the user’s recordings, files, or connected-account content.
Before any of this content is sent, the app itself discloses what is sent and which companies receive it, and asks for the user’s explicit agreement. Nora cannot transcribe, answer, or organize anything without that agreement.
6. Other providers that process data for us
Besides the AI providers named in section 5, the following providers process personal data on Nora’s behalf, each under a contract that requires protection equal or equivalent to the protection we provide under this Policy, limited to the purpose described:
- Amazon Web Services (AWS) — hosting of our servers and databases, and storage of recordings and attached files;
- Composio — technical connection to the external accounts the user connects, which transmits the content exchanged with those accounts;
- Expo and Apple (Apple Push Notification service) — delivery of push notifications to the user’s device;
- Stripe — payment and subscription processing. Nora does not receive or store full card numbers;
- Sentry — error and diagnostic reporting, used to detect and fix failures;
- Vercel — hosting and audience measurement for the noraai.co website. This applies to the website only, not to data from the app.
Nora may also share personal data with public authorities and regulatory bodies when required by law, court order, or regulatory obligation; with professional advisors, when necessary to exercise or defend rights; and with a company involved in a corporate restructuring, merger, or acquisition, subject to the protections of this Policy. Nora does not sell personal data.
7. Accounts the user connects
When the user connects an external account, Nora accesses it only within the scope authorized and only to perform the features the user requests. Each of those platforms is an independent controller of the data it holds and has its own terms and privacy policy, which Nora does not control.
The user may disconnect any integration at any time in the app. Disconnecting stops all further access. Content already imported remains in the account until the user deletes it or deletes the account.
8. Storage and retention
Recordings, transcripts, chat content, imported content, and other data associated with the account remain stored while the account is active, so that the user can access their history and so that Nora’s memory and personalization features can work.
Data is deleted:
- When the user deletes the account;
- Upon the user’s request;
- When it is no longer necessary for the purposes described in section 4;
- When its storage is no longer permitted by applicable law.
Even after a deletion request, certain information may be retained for the period necessary to comply with legal or regulatory obligations, for the regular exercise of rights, for fraud prevention, and for service security. Residual copies may temporarily remain in backup systems until they are overwritten according to our technical retention cycles.
9. Deleting your data and withdrawing consent
Deleting your data. The user may delete their account directly in the app, under Settings, using the “Delete account” option. Deleting the account removes the user’s data from Nora — including recordings, transcripts, the voice sample and the voice signature derived from it, chat content, attached files, saved places, imported content, and preferences — subject to the technical deadlines and the limited retention cases described in section 8. Deletion is irreversible.
The user may also request deletion by email at dev@noraai.co. We may request additional information to confirm the requester’s identity and prevent improper deletion.
Withdrawing consent. The user may withdraw consent at any time, by any of the following means:
- Revoking a specific device permission — microphone, speech recognition, calendar, reminders, contacts, location, notifications, camera, or photo library — in the iOS Settings app, which stops that collection;
- Disconnecting an integration in the app, which stops all further access to that account;
- Deleting the account in Settings, which withdraws consent for the processing of user content by the AI providers named in section 5 and removes the user’s data from Nora;
- Writing to dev@noraai.co, for any request that cannot be completed in the app.
Because Nora cannot transcribe, answer, or organize anything without sending content to an AI provider, withdrawing that consent means the assistant can no longer be used. Withdrawal does not affect processing carried out lawfully before the withdrawal.
10. International data transfers
The providers named in sections 5 and 6 may store or process information outside Brazil, including in the United States. In those cases, Nora adopts the mechanisms and safeguards required by the LGPD and applicable regulations, including contractual clauses that require protection equal or equivalent to the protection provided by this Policy.
11. Security
Nora adopts technical, administrative, and organizational measures intended to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, disclosure, or improper processing. These include encryption of data in transit, access controls limited to what each provider needs, and storage of passwords only as cryptographic hashes.
No system is completely immune to risk. Users should protect their access credentials, use secure passwords, and immediately report any suspicion of unauthorized access to their account.
In the event of a security incident that may create relevant risk or damage to data subjects, Nora will adopt the measures required by law, including any applicable notifications.
12. User rights
Under the LGPD, the user may request, when applicable:
- Confirmation of the existence of processing;
- Access to personal data;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in violation of the law;
- Data portability, in accordance with applicable regulations;
- Information about the entities with which the data has been shared;
- Information about the possibility of refusing consent and the consequences of such refusal;
- Revocation of consent;
- Deletion of data processed based on consent, subject to legal exceptions;
- Objection to processing carried out in violation of the LGPD;
- Review of decisions made solely on the basis of automated processing, when applicable;
- Filing a petition with the Brazilian National Data Protection Authority.
Requests may be sent to dev@noraai.co. Nora may request additional information to confirm the identity of the requester and prevent improper access or deletion.
13. Children and adolescents
The processing of personal data of children and adolescents is carried out in accordance with their best interests and the protections provided by applicable law.
When required, the processing of children’s data depends on specific and highlighted consent from at least one parent or legal guardian. Nora may adopt reasonable measures to verify such authorization.
Parents and legal guardians may contact dev@noraai.co to request access, correction, or deletion of data related to children under their responsibility.
14. Data Protection Officer
The Data Protection Officer, also known as the DPO, is the person appointed to act as the communication channel between the company, users, and the Brazilian National Data Protection Authority.
Until Nora appoints and publishes the identity of its Data Protection Officer, privacy-related questions and requests may be sent to dev@noraai.co.
15. Changes to this Policy
This Policy may be updated to reflect changes in Nora’s services, operations, or applicable law. If we add a provider that receives user content, or a new purpose for which the data is used, this Policy is updated before that change takes effect.
When relevant changes occur, Nora may notify users through the application, by email, or by another appropriate means. The date of the most recent version is indicated at the beginning of the document.
16. Contact
For questions, requests, or complaints related to this Policy or to the processing of personal data:
- dev@noraai.co
- Address
- Rua Leopoldo Couto de Magalhães Júnior, 1098, IT Office, suite 21, São Paulo, ZIP Code 04542-001