Healura App - Privacy Notice

The short version

Healura is a caregiver support tool. It is not a medical device, and it does not diagnose or treat any condition.

A small wrist band called Numi is worn on the wrist. You can wear it yourself, or it can be worn by someone you support. It measures body signals and sends them to our servers in Germany. We turn those signals into a simple description of how the wearer seems to be doing right now - words, never numbers - and send supportive suggestions.

Where the wearer is someone you support, the alerts and suggestions go to you. Where you wear it yourself, they come to you about you.

  • Everything is stored in the European Union. Our database and our servers are in Frankfurt, Germany.
  • The body-signal data is encrypted with a key held for that one person. We drop the readable copy.
  • We do not track you. There is no advertising, no analytics, and no advertising identifier in the app.
  • You can ask us to delete everything at any time, and we will confirm when it is done.
  • Anyone you nominate as a second contact receives a text message only. They get no app access and no body-signal information at all - their message says only that someone should check in.

If you want the detail, it is all below. If you want to ask us something, write to [email protected].


If the person wearing the band is a child

(This section is only needed where the wearer is a child. Plain language, intended to be readable by a child of roughly 7-12. Read it with them. An adult wearing their own band does not need this section - the full notice below covers them.)

The band on your wrist notices things about your body - how warm your skin is, how much you move, how your heart is beating. It does not listen, and it does not have a camera.

It sends those things to a computer. The computer does not know your last name.

If your body seems to be having a hard time, the band buzzes so you know first. You get half a minute to sort it out yourself. If you press the button, nobody gets told.

If you do not press it, the grown-up looking after you gets a message saying you might need them. They never see the numbers from your body - only words like "seems calm" or "might need you".

You can ask the grown-up looking after you to delete everything the computer knows about you, and it will be deleted.


Full notice

1. Who is responsible

The controller under Art. 4(7) GDPR is:

Vanessa Bella Ndaa
Altensteinstraße 40, 14195 Berlin, Germany
[email protected]
Imprint: https://www.healurahealth.com/imprint/

Referred to below as "we", "us" and "our".

This notice covers the Healura mobile app and the Numi wrist band. Our website is covered by a separate notice at https://www.healurahealth.com/privacy-policy/, because it processes different data on different legal bases.

2. Who the people in this notice are

TermWho
Account holderThe adult who holds the account and uses the app.
Supported personThe person who wears the band. This may be the account holder themselves, or someone they support. Where they are a child, they are the data subject for the health data and the account holder acts for them.
Second contactSomeone the account holder nominates to receive a text message if they cannot be reached. Receives SMS only.

Two configurations exist and the difference matters for consent:

  • Self. An adult wears their own band and holds their own account. They are both the data subject and the person who consents.
  • Supported. One person wears the band and another holds the account. Where the wearer is a child, consent is given by a holder of parental responsibility. Where the wearer is an adult supported by someone else, that adult is the data subject and gives their own consent.

3. What we collect, and why

3.1 Body-signal data - special category data (Art. 9 GDPR)

The band records and uploads raw sample arrays for:

  • electrodermal activity (skin conductance),
  • three axes of movement (accelerometer),
  • skin temperature,
  • blood volume pulse.

These concern the health and physiological characteristics of the supported person and are special category data under Art. 9 GDPR.

Purpose. To produce an interpreted description of the supported person's current state, and to decide whether to alert the caregiver.

Legal basis. Explicit consent under Art. 9(2)(a) GDPR, together with Art. 6(1)(a).

  • Where the wearer is the account holder themselves, they give that consent for themselves.
  • Where the wearer is a child, consent is given by a holder of parental responsibility (Art. 8 GDPR).

How it is protected. Every window is encrypted under a key held for that individual supported person, and the readable copy is discarded. The supported person's name is stored separately from their body-signal data.

What the app never sees. No raw physiological value ever reaches the app. The caregiver sees interpreted state language only - never microsiemens, never milliseconds, never a score. This is enforced in our code and tested automatically.

3.2 The baseline questionnaire

A short set of questions at setup, describing how the supported person responds to their surroundings. It shapes which suggestions appear. Stored encrypted; the readable columns were removed.

Legal basis. Art. 9(2)(a) and Art. 6(1)(a) GDPR.

3.3 Contact and account information

  • The caregiver's email address, held by our authentication provider.
  • The supported person's display name (first name only), stored encrypted.
  • Second contacts' names and phone numbers - this is another person's data, supplied by the caregiver. See §7.

Legal basis. Art. 6(1)(b) GDPR - necessary to provide the service.

3.4 Identifiers

Account, member and supported-person identifiers generated by us; the band's serial number; and a push notification token so alerts can be delivered.

There is no advertising identifier and no cross-app tracking identifier.

Legal basis. Art. 6(1)(b) and Art. 6(1)(f) GDPR - providing a functioning, secure service.

3.5 Things the caregiver writes

How they responded to an alert, an optional free-text note, and whether a suggestion helped.

Legal basis. Art. 6(1)(a) and Art. 6(1)(b) GDPR.

3.6 Camera

The app uses the camera only to scan the QR code on the band's box, to pair the device. The permission prompt says exactly this.

3.7 Technical logs

When the app contacts our servers we record the request, the time, the response status and technical information needed to keep the service working and secure.

Legal basis. Art. 6(1)(f) GDPR - our legitimate interest in a functional and secure service.

3.8 Downloading the app

When you download from the Apple App Store or Google Play, data such as your account name, email address, the time of download and a device identifier is transmitted to that store. The store collects and processes this on its own responsibility and we have no influence over it.

4. What we do NOT do

  • We do not use analytics, advertising or attribution tools. There is no such software in the app - no Firebase, no Sentry, no PostHog, no advertising SDK of any kind.
  • We do not use your data for advertising.
  • We do not sell data.
  • We do not use it to make automated decisions producing legal or similarly significant effects on anyone (Art. 22 GDPR). The app's output is a suggestion to a human, who decides what to do.

5. Who else processes the data

All of these act on our instructions under Art. 28 GDPR data processing agreements.

ProcessorWhat forWhere
SupabaseDatabase and authenticationFrankfurt, Germany (eu-central-1)
RenderApplication and background workersFrankfurt, Germany
Apple (APNs)Delivering push notifications to iOS devicesApple infrastructure
TwilioSending text messages to second contactsIreland (EU)

No data is stored outside the European Union. Push notification delivery necessarily passes through Apple's network; the notification carries no body-signal information.

6. How long we keep it

Body-signal data is retained for 48 months by default, after which it is deleted automatically.

Account and contact information is kept while the account exists.

Records of consent and our audit log are append-only and are excluded from deletion. They exist to prove what was consented to and what was done, which is itself a legal obligation, and keeping them is how we can demonstrate compliance under Art. 5(2) GDPR.

7. Second contacts - a note about someone else's data

When a caregiver nominates a second contact, they give us that person's name and phone number. The caregiver is responsible for having told that person. We ask caregivers to do so before nominating anyone.

A second contact receives a text message only. They get no app access, no account, and no body-signal information of any kind. Their message says only that someone should check in. They can reply STOP at any time to receive no further messages.

8. Your rights

The caregiver, acting for the supported person, and any individual whose data we hold, may exercise:

  • right of access (Art. 15),
  • right to rectification (Art. 16),
  • right to erasure (Art. 17),
  • right to restriction of processing (Art. 18),
  • right to data portability (Art. 20),
  • right to object (Art. 21),
  • right not to be subject to automated decision-making (Art. 22),
  • right to withdraw consent at any time (Art. 7(3)), and
  • right to lodge a complaint with a supervisory authority.

Write to [email protected]. We respond within one month.

Withdrawing consent takes effect from when you tell us and does not affect the lawfulness of what we did before that.

Erasure is built into the product. When an account is erased, the link between the account and any identifying record is removed, so the remaining copies resolve to nothing.

The competent supervisory authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
https://www.datenschutz-berlin.de

9. Security

We use technical and organisational measures appropriate to the sensitivity of the data (Art. 32 GDPR), including encryption in transit, encryption of body-signal data at rest under a per-individual key, separation of the supported person's name from their body-signal data, access controls, and an append-only audit log.

If a personal data breach occurs that poses a risk, we notify the supervisory authority within 72 hours and affected individuals without undue delay (Art. 33-34 GDPR).

10. Changes

We may need to update this notice as the product develops or the law changes. The version in force is always the one published here, and the version you consented to is recorded against your consent.

Version: 3 August 2026