Noreto
Privacy Terms Contact About

Privacy Policy

Effective date: 30 June 2026 · Last updated: 4 September 2026

1. Who we are

Noreto is a private relationship, promise, rhythm, and reminder app operated by Urfin Inc., a company incorporated in Canada, and available at noreto.life. For privacy questions, requests, or complaints, contact privacy@noreto.life.

2. What Noreto is not

Noreto is not a medical, mental-health, therapy, legal, financial, or emergency service. The app helps you organize personal intentions and reminders; it does not diagnose, treat, advise, or guarantee personal outcomes.

3. Information we collect

  • Account data: display name, email address, date of birth or age confirmation, public alias, timezone, language, theme, and notification preferences.
  • App content: people you add, relationship type, optional birthday, optional selected phone number, contact rhythm, contact history notes, promises, rituals, radar items, vault entries, and other content you choose to create.
  • Authentication and security data: auth tokens, OTP challenges, password reset events, sign-in/sign-out events, account deletion events, IP address, user agent, request IDs, and audit logs.
  • Notification data: in-app notifications, email delivery status, push notification preferences, and Firebase Cloud Messaging device tokens when you enable notifications.
  • Purchase data: subscription tier, product identifiers, entitlement status, renewal state, and purchase metadata from Google Play, Apple, and RevenueCat. We do not receive or store full card numbers.
  • Contact permission data: if you choose to link a phone contact, Noreto opens your device contact picker and saves only the selected information needed for the feature, such as a phone number. We do not bulk upload your address book.
  • Local device storage: secure auth token storage plus local preferences such as intro completion and home tour completion.
  • Usage analytics: product events (for example, features used and screens viewed), platform, app version, session identifiers, a truncated user agent, and an anonymized IP address (we drop the last portion of the address so it does not identify you). Analytics never include the free text you write, such as notes, reflections, or the names of people you add.
  • AI reflection data: to generate the optional "Future Self" reflection, we send a minimized, abstracted summary of your protected items — a first name, a category, timing such as "3 weeks overdue," and a short reason you wrote — to Google's Gemini API. We do not send your full notes, journal entries, or contact details.
  • Accountability data: if you link an accountability partner, we record the partnership and, when one of you is drifting (such as a missed rhythm), generate a check-in prompt for the other person.

4. How we use information

  • Provide the app, account, reminders, people, promises, rituals, vault, billing, and notification features.
  • Send transactional emails, OTP codes, account notices, subscription notices, notification emails, and user-requested support replies.
  • Register push tokens and deliver push or in-app notifications when enabled.
  • Maintain security, prevent abuse, debug service failures, and keep audit records.
  • Honor account deletion, access, correction, support, and privacy requests.
  • Generate the optional "Future Self" AI reflection by sending the abstracted summary described above to Google's Gemini API, which returns reflection text. This is automated processing intended to support self-reflection; it is not professional advice and may be imperfect.
  • Operate the optional accountability-partner feature: with the consent of both people, share limited signals with your partner — that a pact is active and when one of you is drifting — so they can check in. We do not share your notes, reflections, or the specific content that drifted.
  • Understand activation and retention through anonymized, aggregated usage analytics, without advertising profiles or sale of personal data.

5. Legal bases and regional rights

Depending on where you live, laws such as GDPR/UK GDPR, CCPA/CPRA, PIPEDA, LGPD, Indian privacy law, and similar rules may apply. Our usual legal bases are contract performance, legitimate interests in security and service operation, legal obligations, and consent where required, such as optional permissions, push notifications, or marketing.

6. Your privacy choices and rights

  • Access, correct, delete, or request a copy of your personal data.
  • Withdraw consent for optional permissions such as contacts or notifications through device settings.
  • Object to or restrict certain processing where local law gives that right.
  • Opt out of marketing emails if we send any. Transactional and security emails may still be sent.
  • Request account deletion in Profile or by contacting privacy@noreto.life. You may also complain to your local privacy authority where applicable.

7. Sharing and processors

We do not sell personal data and do not share personal data with advertisers. We use service providers only to run Noreto, including hosting/database infrastructure, transactional email providers such as Brevo, Firebase Cloud Messaging for push notifications and Firebase Crashlytics for crash diagnostics, RevenueCat for subscription entitlement management, Google Play and Apple for in-app purchases, Google's Gemini API to generate the optional "Future Self" reflection (it receives only the abstracted summary described in section 4, never your full content), and support or security tooling where needed.

Accountability partners. If you choose to link an accountability partner, both people must consent. We then share limited signals with the person you link — that a pact is active, and when one of you is drifting, such as a missed rhythm — so they can check in. We do not share your notes, reflections, or the specific content that drifted. Either person can end the partnership at any time.

8. International transfers

Your information may be processed in countries other than your own. Where required, we use reasonable safeguards such as contractual protections, provider security terms, and transfer mechanisms recognized by applicable law.

9. Retention and deletion

We keep account and app content while your account is active. Requesting deletion starts a 30-day grace period that you can cancel before the deadline. After the deadline, active account data is scheduled for permanent deletion. Backups and security logs may take additional time to cycle out, generally up to 60 days unless a longer period is required for security, fraud prevention, dispute handling, or legal obligations. Usage analytics are automatically deleted after 90 days.

10. Children and age limits

Noreto is for adults 18 and older. We do not knowingly collect personal data from children or allow children to create accounts. If you believe a child has provided data to Noreto, contact privacy@noreto.life so we can review and delete it where appropriate.

11. Security

We use HTTPS, authentication tokens, encrypted local token storage on supported devices, access controls, audit logs, and operational safeguards. No system is perfectly secure, so you should use a strong password, protect your device, and contact security@noreto.life if you suspect unauthorized access.

12. Contact

Noreto is operated by Urfin Inc., a company incorporated in Canada. Company and legal contact: contact@urfininc.com (registered mailing address available on request).

Privacy: privacy@noreto.life · Security: security@noreto.life · Support: support@noreto.life · Billing: billing@noreto.life