On this page
- 1. Who we are
- 2. The short version
- 3. What we collect, why, and on what legal basis
- 4. Health information and your explicit consent
- 5. Equipment photos and AI processing
- 6. AI-generated coaches
- 7. Service providers we use (processors) and other recipients
- 8. What we do not do
- 9. How long we keep data
- 10. International transfers
- 11. Your rights
- 12. Deleting your account
- 13. Permissions on your phone
- 14. Security
- 15. Adults only (18+)
- 16. Additional information for US residents
- 17. Changes to this policy
- 18. Contact and complaints
1. Who we are
Nuvela ("Nuvela", "we", "us") is a fitness app for iPhone and Android. It is run by Dejan Horvat, an individual developer based in the Republic of Serbia. Dejan Horvat is the controller of your personal data. That means he decides why and how your data is used.
| Controller | Dejan Horvat |
|---|---|
| Business registration | To fill in if you register a business (for example as a preduzetnik) before launch, give its registered name, registration number (MB) and tax ID (PIB), and make that business the controller in this table and in the Terms. Otherwise delete this row. |
| Postal address | To fill in full postal address |
| Email (privacy and support) | [email protected] |
| EU representative (GDPR Art. 27) | To fill in name and address of the EU representative, or delete this row. See LAUNCH_CHECKLIST.md, decision O4 |
| UK representative (UK GDPR Art. 27) | To fill in name and address, or delete this row |
This policy covers the Nuvela apps, the website gonuvela.com, and our emails and support.
2. The short version
- You need an account to use Nuvela. We use it to build your plan, save your training, and keep track of your first week and your subscription.
- We collect what we need to coach you: your goal, experience, equipment, schedule, the body areas you want to go easy on, and your workout logs.
- Body areas to go easy on and "this hurts" reports are health information. We collect them only if you give explicit consent, and only to adapt your workouts.
- Equipment photos are optional. They go to an AI vision service only to recognise equipment. We do not store them.
- Our coaches (Elena, Marcus, and any coaches we add later) are AI-generated. They are not real people.
- We have no ads. We do not sell your data. We do not use third-party tracking.
- Draft — pending approvalTraining partner (optional): if you link with one person, you each see the other's first name, which days you trained this week, the title of your last workout, your shared streak, and today's planned exercises with sets and reps. Your partner never receives your weights, age, sex, body details, limits, pain reports, or email. The workout you share is built for you, though, so it reflects your goal, level, age group, sex, equipment and limits, and your partner may be able to guess some of these (section 7).
- Draft — pending approvalFriend groups (optional): in a group of up to 8 people that you join with a code, members see only the first name you choose for the group, how many workouts you logged this week, your week streak, and whether you trained today. Never your weights, exercises, body details or email. You can leave at any time; deleting your account removes you from every group.
- Draft — pending approvalTune your plan (optional AI chat): what you type goes, with a short summary of your plan, to an AI service that suggests plan changes. Never your body areas to go easy on (including no jumping, no floor work and no overhead work), "this hurts" reports, body measurements, name or email. A message about pain or a medical question is answered on your phone and never sent (section 3).
- Share cards are made on your phone. A photo you add to one stays on your phone. We count only which card and look were shared and where, with nothing that identifies you.
- Profile photo (optional) Draft — pending approval: if you add one, it is kept on your phone, and a small copy is stored with your account only so your linked training partner can see your face. Nobody else can see it. You can remove it at any time.
- You can export or delete your data in the app at any time.
- Nuvela is for adults 18 and older.
3. What we collect, why, and on what legal basis
GDPR legal bases used below: contract = Art. 6(1)(b), needed to provide the service you asked for. Consent = Art. 6(1)(a). Explicit consent = Art. 9(2)(a), for health information. Legitimate interests = Art. 6(1)(f). Legal obligation = Art. 6(1)(c).
| What | Examples | Why we use it | Legal basis | Do you have to give it? |
|---|---|---|---|---|
| Account data | Email address (with Sign in with Apple this may be an Apple "Hide My Email" relay address), the account identifier Apple or Google gives us, our internal user ID, how you sign in. Your name, only if Apple or Google shares it when you sign in or you enter it yourself. To check confirm which name fields are stored for Google sign-in; do not store the profile photo. | Create and secure your account. Send one-time sign-in codes. Send service messages about your account or subscription. Answer support requests. | Contract | Yes, except your name |
| Training profile (onboarding answers) | Goal, training experience, sex (optional), age band (18–39, 40–49, 50–64, 65+), where you train, your equipment list, days per week and minutes per session, training style | Build your weekly plan and keep adapting it. Example: gentler programming for people 65+. | Contract | Yes, except sex |
| Health information (see section 4) | Body areas to go easy on: knees, shoulders, lower back, back (scoliosis, disc, other), wrists, no jumping, no floor work, no overhead work. "This hurts" reports by body area during a workout. | Leave out or swap exercises that may not suit you | Explicit consent | No. It is optional, and you can withdraw consent at any time. |
| Workout logs | Exercises done, sets, reps, weights, your "How did that feel?" ratings, skipped or swapped exercises, session times | Show your history and progress. Suggest your next loads. Write your weekly review. | Contract | Yes, while you use workouts |
| Training partner link (optional, see section 7) Draft — pending approval | The first name you choose to show your partner, when you linked, and your 6-character invite code until it expires (7 days), even once used | Show you and the one person you link with each other's week, and let you train today's workout together. With a Duo plan, give the linked partner Nuvela Pro: they see that your Duo plan covers them, never your payment details | Contract (you ask for the feature); for today's planned exercises, which your limits help choose, your explicit consent on the linking screen | No |
| Friend groups (optional) Draft — pending approval | The group's name and invite code, who runs it, and for each member the first name they chose for the group and when they joined. Members' counts (workouts this week, week streak, trained today) are worked out from each member's own workout log when the group is opened, and are not stored separately | Let a small group of friends see who has trained this week and keep each other going | Contract (you ask for the feature) | No |
| Profile photo (optional) Draft — pending approval | A photo you take or choose in You → profile. The app crops it to a small square (256 × 256 pixels, a JPEG of 40 KB or less) on your phone. It is kept on your phone, and a copy is stored with your account in our database. | Show your photo in the app instead of your initial, and show your face to the one training partner you link with (section 7) on the partner screens and, only if you turn on Show partner name and photo for that share, on a Trained together card they share. It is never shown to anyone else, never public, and never used to identify you or to train AI models. | Contract (you ask for the feature) | No |
| Equipment photos (see section 5) | A photo you take or choose of your training space | Detect which equipment you have, so you can confirm the list | Consent, which you give each time you send a photo | No |
| Subscription and purchase status | Which plan you bought, the store, start, renewal and expiry dates, store transaction IDs, whether your subscription is active. We never receive your card or bank details. | Unlock Nuvela Pro. Restore purchases. Handle billing problems. Prevent fraud. | Contract; legitimate interests (fraud prevention) | Only if you subscribe |
| First-week record Draft — pending approval | When your first week started (when you created your account) and ended. A salted hash of an identifier for your phone: on iPhone the app's "identifier for vendor", on Android the app's Android ID, in the web preview a random ID kept in your browser. The app sends the identifier once when you sign in; our server keeps only a one-way hash made with a secret key, never the identifier itself, and never logs it. Whether your account started without a free week because the phone already had one. | Give each phone one free first week, so a new account on a phone that already had one does not get another | Contract; legitimate interests (preventing repeat free weeks) | Yes |
| Technical and security data | IP address, device model, operating system and app version, language, request and error logs | Run the service. Keep it secure. Stop abuse. Fix bugs. | Legitimate interests | Yes (technically required) |
| Support messages | Emails you send us and our replies | Help you | Contract; legitimate interests | Only if you contact us |
| Feedback in the app Draft — pending approval | What you write in You → Send feedback, the topic you pick (an idea, a problem, something else), the app version and platform, and when you sent it | Read it to improve Nuvela and fix problems, and answer you by email if you asked something | Legitimate interests | No |
| How you heard about Nuvela and invite codes Draft — pending approval | Your answer to "How did you hear about Nuvela?" (for example Instagram or a friend). The first valid code you enter (a friend's invite code or a creator's code), when you entered it, and, for a creator's code, which creator it belongs to; this never changes once set. Your own invite code and how many people joined with it. The date of your first payment (it ends code entry and starts the rewards below). The free months you earned (on hold, given or cancelled), and a one-time App Store or Google Play code if your free month was given that way. On Android, the Google Play install referrer is read once at first launch only to fill in a code from an invite link; nothing else from it is kept. | Give the 14 free days a code brings. Give you and a friend a free month when a friend who joined with your code makes their first payment (held for 3 days, cancelled if that payment is refunded, at most 12 a year). See which channels bring people to Nuvela. The person who invited you only sees a count, never your name or email. | Contract (the free days and the free month); legitimate interests (which channels work, preventing abuse) | No |
| Creator codes and commissions Draft — pending approval | If you joined with a creator's code: for each payment you make in the 12 months after your first payment, the store transaction ID, product, price in US dollars before tax and the creator's commission. About creators themselves: name, email for payouts, commission rate, and a key for their private dashboard (stored only as a one-way hash). | Pay creators who bring people to Nuvela. A creator's dashboard shows only counts and money (sign-ups, people in their free period, people paying now, commission); never who you are, your email or what you do in the app. | Legitimate interests (paying creators correctly); legal obligation (bookkeeping) To fill in confirm the basis with your accountant | Only if you used a creator's code |
| Tune your plan: AI coach chat (optional) Draft — pending approval | The message you type. Up to the last 6 lines of the same chat (yours and the coach's), except lines about pain or a medical question. A short summary of your plan, rebuilt on our server from a fixed list so nothing else can slip in: goal, experience level, days per week, workout length, kind of place (gym, home, dumbbells, bodyweight, hotel), training style, variety setting, your standing requests (more or less of a kind of equipment, muscle focus, favourite and never-again exercises, one station per pair, a cardio finisher), and the names of up to 40 exercises in this week's plan. Never sent: the body areas to go easy on (knees, shoulders, lower back, back, wrists, no jumping, no floor work, no overhead work), "this hurts" reports, body measurements, age band, sex, name, email or account ID. A message that mentions pain, an injury or a medical question is answered by the app on your phone and never leaves it. The app asks before your first message is sent; if you tap "Not now", the app's own reader answers on your phone and nothing is sent. | Suggest changes to your plan. You see every change, and you can undo it. | Contract (you ask for the feature) | No. Plans work without the chat. |
| Share cards and share counts Draft — pending approval | The card is drawn on your phone from your workout log. A photo you add for the Photo look stays on your phone: it is never uploaded, and the app removes its own copy when you close the share screen. Only the picture you choose to share leaves your phone, to the app you pick (for example Instagram or TikTok), under that app's terms. A Trained together card shows first names and profile photos only if you turn on Show partner name and photo for that share; it is off every time. When the share screen opens or a card is shared, our own server counts which card, which look, where it went (Instagram Stories, TikTok, Save image, More) and the platform (iPhone, Android, web). No account ID, device ID, IP address or number from the card is stored with these counts, and they go to no one else. | Make sharing work. See which cards and looks people use. | Legitimate interests | Sharing is optional. The counts are made when you use the share screen. |
| Launch list (website) | Your email address, if you sign up on gonuvela.com to hear when Nuvela launches, and when you signed up | Email you when Nuvela is available in the App Store and Google Play To fill in anything else you want to send this list, such as occasional product news? If yes, say so here. The sign-up form on the website is switched off until this row and its provider in section 7 are final. | Consent. You can unsubscribe from any email or by writing to [email protected]. | No |
| Shared week from the free plan (website, optional) Draft — pending approval | Only if you tap "Share my week" on gonuvela.com/plan: your answers to the plan questions (goal, experience, age band, kg or lb, days and which weekdays, minutes, where you train, training style, split) and, only if you tick the box for it, what you chose to go easy on, plus when the link was made. No name, email, account, device ID or IP address is stored with it. If you don't share, the plan is made in your browser and your answers are not sent to us. | Show the same week to anyone who opens the link | Consent (you choose to share, and separately whether to include what you go easy on) | No |
| Consent records | Which consents you gave or withdrew (health information, equipment photos), when, and which version of this policy applied | Prove that we asked for your consent, as GDPR Art. 7(1) requires | Legal obligation | Yes, if you give a consent |
Where the data comes from: from you, from your phone (technical data), from Apple or Google when you sign in with them, and from Apple or Google through RevenueCat when you buy or renew a subscription.
Automated plan generation. Your weekly plan, your exercise choices, and your suggested loads are produced automatically by fixed training rules. These suggestions do not have legal effects or similarly significant effects on you, as described in GDPR Art. 22. You can always change your answers, swap exercises, or ignore a suggestion.
4. Health information and your explicit consent
Two things you can tell Nuvela count as information about your health:
- the body areas to go easy on (knees, shoulders, lower back, back (scoliosis, disc, other), wrists, no jumping, no floor work, no overhead work), and
- "this hurts" reports you add during a workout.
Under the GDPR these are a special category of personal data (Art. 9). Some US state laws, such as Washington's My Health My Data Act, also treat them as consumer health data.
- We ask for your explicit consent on a separate onboarding screen before you can enter this information. The consent is not bundled with our Terms of Use. To check the screen must be separate and have its own unticked control, the "No thanks" path must work, and the server must store the consent record.
- If you say no, Nuvela still works. It just cannot adapt your workouts to those limits.
- Draft — pending approvalWe use this information only to choose, leave out, or swap exercises for you. We never use it for advertising. We never sell it. We never share it, except with the service providers in section 7 that host and process it for us. If you link a training partner, your partner sees today's planned exercises, and your limits help choose them, so a partner may notice that some exercises are left out. Your partner never sees the limits or "this hurts" reports themselves.
- Nuvela does not diagnose, treat, or monitor any condition. A "this hurts" report is not a medical assessment. If something hurts, stop and talk to a doctor or physiotherapist.
- To withdraw consent: in the app, go to You → Your plan → Go easy on, remove the areas and save. To delete your "this hurts" reports, go to You → Paused exercises → Delete all pain notes. Both are deleted from our live database the next time the app syncs. Withdrawing does not affect processing done before you withdrew. To fill in decide whether removing the areas should also delete the "this hurts" reports in one step; today they are two separate actions.
5. Equipment photos and AI processing
Taking a photo of your equipment is optional. You can always pick equipment from a list or search for it instead.
- Before the first photo is sent, the app explains what happens and asks your permission. To check this explicit permission is required by App Store Review Guideline 5.1.2(i).
- The photo goes from your phone to our server and then to a third-party AI vision service To fill in name the provider you sign up with, e.g. "OpenAI (OpenAI, L.L.C., USA)". The server works with any OpenAI-compatible service, set with VISION_BASE_URL and VISION_MODEL.. The service recognises the equipment in it. Nothing changes in your equipment list until you confirm it.
- We do not store your photos. Our server handles the photo in memory only for that request and does not save it.
- The AI provider handles the photo under its business terms. It does not use API data to train its models unless we opt in, and we do not. It may keep API inputs in abuse-monitoring logs for up to 30 days before deleting them. To check if zero data retention is approved for our account, replace this sentence with "does not retain them". If a different provider is used, describe that provider's terms instead.
- Please do not photograph other people, or anything you would not want to share. The photo is used only to detect equipment. We do not use it to identify anyone.
6. AI-generated coaches
Elena, Marcus, and any other Nuvela coaches are AI-generated personas. Their images, videos, and voices are made with generative AI. They are not real people and not licensed professionals. The app labels them "AI coach". Coach videos do not use your personal data.
7. Service providers we use (processors) and other recipients
Draft — pending approval
We use the service providers below to run Nuvela. Each one processes personal data only on our instructions, under a data processing agreement (DPA) and with its own security measures, and gives the same or equal protection to your data as this policy. We do not share personal data with anyone else, except the training partner you choose to link (see "Training partner" below), and where the law requires it (for example, a valid court order).
| Provider | What they do for Nuvela | Personal data involved | Where / safeguards |
|---|---|---|---|
| Cloudflare, Inc. (USA) | Hosting of our API (Cloudflare Workers), our database (Cloudflare D1), our website, DNS, security, and routing of emails sent to [email protected] | All data in section 3 except equipment photos, which only pass through | Database stored in Cloudflare's EU jurisdiction To fill in true only if the production D1 database is created with --jurisdiction eu (LAUNCH_CHECKLIST 3.1); it cannot be added later, so confirm it before publishing or rewrite this. Requests are handled at Cloudflare's network edge worldwide. Cloudflare DPA with Standard Contractual Clauses. |
| RevenueCat, Inc. (USA) | Subscription management: checks App Store and Google Play purchases and tells our server when you subscribe, renew or cancel. Gives the free month for inviting a friend (a "promotional" entitlement) when no store bills you at the time. | Our internal user ID, purchase history and subscription status | RevenueCat DPA |
| To fill in vision provider, e.g. OpenAI, L.L.C. (To fill in country) | Recognises equipment in photos you choose to send | The photo; no name or email is sent with it (the server sends only the image and an instruction, apps/server/src/scan.ts) | Provider DPA; see section 5 for retention |
| To fill in AI chat provider. By default the same service as the vision provider (OpenAI, L.L.C., USA, model gpt-4o-mini); COACH_BASE_URL and COACH_MODEL can point elsewhere Draft — pending approval | Reads your "Tune your plan" message and suggests plan changes | The message, recent chat lines and the plan summary described in section 3; no name, email, account ID or health information is sent | Provider DPA. It does not use API data to train its models unless we opt in, and we do not; it may keep API inputs in abuse-monitoring logs for up to 30 days (section 5). |
| Resend (USA) | Sends sign-in codes and service emails | Email address, email content | Resend DPA. Our sending domain is set to the EU (Ireland) sending region To check confirm. Resend stores account data in the USA. |
| Expo (650 Industries, Inc.) (USA) | Delivers app updates (EAS Update) | Technical data: IP address, device and app version | Expo DPA |
| To fill in email inbox provider, e.g. Google Gmail | Hosts the inbox where emails to [email protected] arrive | Your support emails | Provider terms |
| To fill in launch-list provider, for example Resend Audiences or another newsletter service, with its country. Delete this row if the website sign-up form stays off. | Stores the launch list and sends the launch email | Email address, sign-up date | To fill in provider DPA and data region |
Draft — pending approval
Training partner (only if you link one). You can link your account with one other person, by sending them a code or entering theirs. Linking is always your choice: the app shows what is shared, and creating or entering a code means you agree to share it with that one person. While you are linked, you each see:
- the first name the other person chose to show,
- their profile photo, if they added one (You → profile; you can remove yours at any time, and it stops showing right away) Draft — pending approval,
- which days they trained this week, and the title and day of their last workout,
- your shared streak (weeks in a row you both trained), and
- their planned workout for today: the exercises, with sets and reps, so you can do the same session with your own weights.
Your partner never receives your weights, workout history beyond the items above, age or age band, sex, body details, limits or "this hurts" reports, email address, or account ID. The workout you share is built for you, though: its exercises, sets and reps reflect your goal, training experience, age group, sex, equipment, settings and limits, and an exercise you paused after a "this hurts" report is left out. So your partner may be able to guess some of these. For example, from age 50 a balance exercise is added and strength-goal plans use more repetitions, and from 65 workouts are gentler, with fewer sets. To check keep these examples in step with the plan engine (packages/engine: repsFor, age slots, gentle mode) and with the linking screen in the app. Rest times, effort targets and session length are not shared: each phone uses its own. Either of you can stop at any time in the app (Train with a partner → Stop training together). That ends the sharing for both of you right away. Deleting your account also ends it.
Apple and Google as independent companies. When you use Sign in with Apple or Sign in with Google, buy through the App Store or Google Play, or receive push notifications, Apple and Google also process your data. They do this as independent controllers under their own privacy policies:
They handle payments. We never see your payment card.
8. What we do not do
- No advertising, and no advertising or attribution SDKs. The share counts in section 3 stay on our own server; nothing goes to Meta, TikTok or any analytics service.
- We do not sell personal data, and we do not "share" it for cross-context behavioral advertising as California law defines that term.
- No tracking across other companies' apps or websites, and no data brokers.
- Our website gonuvela.com sets no cookies of its own and runs no analytics or tracking scripts. Cloudflare, our host, processes your IP address and request details to deliver and protect the site (section 7).
- Draft — pending approvalThe free plan at gonuvela.com/plan is made in your browser. Your answers reach us only if you tap "Share my week", and then only the answers (section 3). If the link has a code in it (gonuvela.com/plan?code=…), the page asks our server whether the code works and how many free days it gives: only the code is sent, and the code is not stored.
- We do not use your data, photos, or health information to train AI models.
- We do not send marketing emails unless you opt in. To check there is no marketing email at launch. If we add any, add an opt-in and an unsubscribe link first.
9. How long we keep data
| Data | How long |
|---|---|
| Account data, training profile, workout logs, health information | Until you delete your account. Health information is also deleted when you withdraw consent. After deletion it is removed from our live database right away. It then drops out of our database's point-in-time recovery history (Cloudflare D1 Time Travel) within another 30 days. |
| Inactive accounts | To fill in choose one: (a) "If you do not sign in for 24 months, we will email you, and delete the account 30 days later unless you sign in", or (b) delete this row |
| Equipment photos | Not stored by us. See section 5 for the AI provider's retention. |
| Profile photo Draft — pending approval | Until you remove it (You → profile → Change → Remove photo) or delete your account. Removing it deletes our copy right away and the copy on your phone. It is part of your data export. |
| One-time sign-in codes | They expire after 10 minutes and are deleted by our daily clean-up within 24 hours. We store them only in hashed form. |
| Account deletion clean-up Draft — pending approval | If RevenueCat or Apple cannot be reached when you delete your account, we keep only what that request needs (your former account's random ID and, for Sign in with Apple, the token to revoke) and try again until it succeeds, for at most 30 days. Nothing else about you is kept for this. |
| First-week phone record Draft — pending approval | The link between your account and your phone's hash is deleted with your account. The hash itself, with no account attached, is kept for 12 months after the first free week on that phone and then deleted by our daily clean-up, so deleting an account and signing up again on the same phone does not bring a second free week. The hash on its own does not say whose phone it was. |
| Training partner link Draft — pending approval | Until either of you stops training together or deletes the account. An invite code expires after 7 days and is deleted by our daily clean-up. |
| Subscription status | While your account exists. When you delete your account, we also ask RevenueCat to delete its customer record To check built: the server calls RevenueCat's delete-customer API after a deletion when REVENUECAT_SECRET_KEY is set (LAUNCH_CHECKLIST 3.2). Confirm the production secret is set before publishing. Apple and Google keep their own purchase records under their own policies. |
| Technical and security logs | Up to 30 days To check confirm Workers log retention |
| Support emails | Up to 24 months after our last message To fill in confirm |
| Feedback in the app Draft — pending approval | Until you delete your account To fill in or a shorter period, for example 24 months like support emails |
| How you heard about Nuvela, invite codes Draft — pending approval | Until you delete your account. If you delete yours, people who joined with your code keep their extra days, and the link to you is removed. A one-time store code given to you stays marked as used, without your account. |
| Creator commissions Draft — pending approval | The payment rows (transaction ID, product, price, commission) are kept for bookkeeping. When you delete your account, your account ID is removed from them; the rows stay so the creator's payout adds up. To fill in how long Serbian bookkeeping rules require, for example 10 years; confirm with your accountant |
| Tune your plan chat Draft — pending approval | Not stored by us. Our server passes the message on and logs only counts (how many changes, and whether the AI or the app's own rules answered). The AI provider may keep API inputs up to 30 days (section 5). The chat on your phone is kept only while the screen is open. |
| Share counts Draft — pending approval | 180 days. Then our daily clean-up deletes them. They identify no one. |
| Launch list (website) | Until you unsubscribe, or To fill in choose, e.g. "6 months after Nuvela launches", whichever comes first |
| Shared week from the free plan (website) Draft — pending approval | 30 days after you share it. Then the link stops working and our daily clean-up deletes the answers. |
| Consent records | For the life of your account, and up to 3 years after it is deleted, so we can show that we had consent. The record holds an internal ID, the type of consent, the policy version, and the time. It never holds the health information itself. To fill in confirm 3 years |
We may keep specific data for longer only if the law requires it, or to establish or defend a legal claim. Even then, we keep it only for as long as needed.
10. International transfers
Nuvela is run from Serbia and serves users worldwide. Some of our providers are in the United States or process data in other countries. Serbia and the United States are not, as such, covered by an EU adequacy decision. Where a transfer needs a safeguard, we rely on one of these:
- the European Commission's Standard Contractual Clauses, included in our providers' data processing agreements,
- the provider's certification under the EU-U.S. Data Privacy Framework, where it has one, and
- for transfers from Serbia, the safeguards required by Serbia's Law on Personal Data Protection.
You can ask us for more information about these safeguards at [email protected].
11. Your rights
Depending on where you live, and in any case if you are in the EU, the EEA, the UK, or Serbia, you have the right to:
- Access your data and get a copy of it
- Correct inaccurate data. You can edit most of your answers in the app.
- Delete your data and your account
- Data portability: receive your data in a machine-readable format
- Restrict our processing of your data
- Object to processing based on legitimate interests
- Withdraw consent at any time (health information, equipment photos, notifications). Withdrawing does not affect processing that happened before.
- Complain to a data protection supervisory authority (section 18)
How to use your rights:
- Export: in the app, go to You → Account and data → Download my data. You get a JSON file of your account, answers, and workout logs.
- Delete: in the app, go to You → Account and data → Delete account (section 12).
- Or email [email protected] from the email address on your account.
We reply within one month. For complex requests we may extend this by up to two more months, and we will tell you if we do. There is no fee. We may ask you to confirm that the account is yours, for example by sending a code to your account email.
12. Deleting your account
- In the app: You → Account and data → Delete account. Then confirm.
- Without the app: follow the steps at https://gonuvela.com/delete-account, or email [email protected] from your account email with the subject "Delete my account".
- Deleting your account does not cancel your subscription. Apple or Google handle billing. Cancel your subscription first:
- iPhone: Settings → your name → Subscriptions, or https://apps.apple.com/account/subscriptions
- Android: Google Play → profile icon → Payments & subscriptions → Subscriptions
The app reminds you of this and links there before you confirm. To check required by Apple
- Draft — pending approvalWhat we delete: your account, training profile, health information, workout logs, subscription status, your profile photo, and any link to a training partner (your partner stops seeing your week and your photo). We also ask RevenueCat to delete your customer record. If you used Sign in with Apple, we revoke our access to your Apple sign-in. To check built: the server revokes the Apple token after a deletion when
APPLE_TEAM_ID,APPLE_KEY_IDandAPPLE_PRIVATE_KEYare set, and only for people whose app sent Apple's authorization code at sign-in. Confirm both before publishing (LAUNCH_CHECKLIST 1.9, 3.2, 3.4) - What we keep: only what section 9 lists, such as consent records and anything the law requires. Apple and Google keep their own purchase records. Draft — pending approval We also keep the salted hash of your phone's identifier, without any link to you, for up to 12 months after its first free week, so the phone does not get a second free week (section 9).
- Timing: see section 9. When deletion is finished, we confirm it in the app or by email.
13. Permissions on your phone
- Camera / photos: asked for only when you choose to photograph your equipment, to add a photo to a share card, or to add a profile photo. On Android we use the system photo picker, so Nuvela does not get access to your whole photo library. Save image on the share screen asks only to add pictures to your photos, never to read them.
- Notifications: asked for only after the app explains what reminders it sends. Nuvela works without them. With reminders on, you also get a short Week recap on Sunday evening in weeks you trained. All of these notes are made on your phone; no push service is used for them. To check keep true while there is no server push
- You can change these at any time in your phone's settings.
14. Security
We encrypt data in transit (HTTPS/TLS). On your phone, the sign-in token is kept in the phone's secure storage (the iPhone Keychain or the Android Keystore), not with the app's other data, and it is not copied into a backup restored on another phone. We limit access to the developer, and we use separate keys for each environment. Secret keys stay on the server and never ship in the app. We store sign-in codes in hashed form, and we use rate limits against abuse. No system is perfectly secure. If a personal data breach puts your rights at risk, we will notify the competent supervisory authority and, where required, you, within the time limits set by law.
15. Adults only (18+)
Nuvela is only for people aged 18 or older. We do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18, we delete it. If you think a minor has given us data, contact [email protected].
16. Additional information for US residents
16.1 Consumer Health Data Privacy Policy
This section applies under Washington's My Health My Data Act and similar state laws, such as those in Nevada and Connecticut. It is also published on its own at https://gonuvela.com/health-data, which is linked from the gonuvela.com homepage.
- Consumer health data we collect: body areas to go easy on, and "this hurts" reports by body area (section 4). Workout logs and your age band may also count as consumer health data under some state definitions, and we treat them with the same care.
- Why: only to provide and personalise your workouts.
- Source: you, in the app. On gonuvela.com/plan, only if you share your week and tick the box to include what you go easy on (section 3). Draft — pending approval
- Draft — pending approvalSharing: we do not sell consumer health data. We share it only with the processors in section 7, who process it on our behalf. We do not disclose it to any other third party or affiliate. If you choose to link a training partner, your partner sees today's planned exercises, which your limits help choose; they never see the limits or "this hurts" reports. That happens only at your direction, after you agree on the linking screen, and you can stop it at any time (section 7).
- Consent: we collect it only after your consent, which is separate from our Terms. If we ever wanted to share it beyond our processors and the partner you choose, we would ask for your separate consent first.
- Your rights: confirm whether we collect your consumer health data, access it, delete it (section 12), and withdraw consent (section 4). Email [email protected] or use the in-app tools.
- Appeals: if we refuse a request, you can appeal by replying "Appeal" to our answer. We reply within 45 days. If you are not satisfied, you can contact your state Attorney General. For Washington: https://www.atg.wa.gov/.
16.2 Other US state privacy laws
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about you. Where a state privacy law applies to us, you can use the rights it gives you, such as access, deletion, correction, and opt-outs, by emailing [email protected]. We will not treat you differently for using them.
17. Changes to this policy
If we change this policy in a way that matters, such as a new purpose, a new kind of data, or a new type of recipient, we will tell you in the app or by email before the change takes effect. If a change affects health information or anything else based on consent, we will ask for your consent again. The date at the top always shows the latest version.
18. Contact and complaints
- Contact us: [email protected], Dejan Horvat, To fill in postal address
- Serbia: Commissioner for Information of Public Importance and Personal Data Protection (Poverenik), https://www.poverenik.rs
- EU/EEA: the data protection authority in your country. Find it at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
- UK: Information Commissioner's Office, https://ico.org.uk