Privacy Policy
Last Updated: March 25, 2026
Introduction
Nitrotech Inc., a Delaware corporation ("Nitrotech," "we," "us," or "our"), operates the Naya mobile application ("Naya" or the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Naya on iOS and Android platforms.
We do not sell, rent, or trade your personal information or health data to third parties for their marketing purposes.
By using Naya, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.
Information We Collect
Account Data
When you choose to create an account (via Apple Sign-In or Google Sign-In), we collect:
- Email address (from your Apple or Google account)
- Display name (optional, from your sign-in provider)
- Firebase Authentication identifiers
- Subscription status and in-app purchase records (via RevenueCat)
- Support communications and user feedback
You are not required to create an account. Naya works fully anonymously with a local anonymous account.
Health & Wellness Data
When you use Naya, you may choose to enter the following health data:
- Menstrual cycle dates and period flow intensity
- Mood, symptoms (12 categories), and energy levels
- Water intake, sleep duration, and sleep quality
- Weight, exercise, and personal notes
- Age, cycle length, and period duration preferences
All health data is stored locally on your device by default. It is only transmitted to our servers if you explicitly enable Cloud Sync in your Profile settings.
Health Platform Data
With your permission, Naya integrates with Apple Health (iOS) and Google Health Connect (Android) to read and write health data including menstrual flow, weight, steps, sleep, heart rate, basal body temperature, and water intake.
Health platform data is never sent to our servers or any third party. It stays between the Naya app and Apple Health / Google Health Connect on your device.
AI Health Assistant Data
If you use the AI Health Assistant (Naya Plus feature), your current cycle day, phase, and today's logged symptoms/mood/flow are sent to Google AI (Vertex AI) to generate personalized responses. The AI does not see your name, email, birth year, historical data, or account information. Chat conversations are stored locally on your device and are never saved on our servers.
Automatically Collected Data
We automatically collect:
- Device type and operating system version
- App usage patterns and feature interactions
- Crash logs and error reports (via Firebase Crashlytics)
- Approximate location (country-level, never precise)
How We Use Your Information
We use the information we collect to:
- Provide and maintain the Naya app and its features
- Calculate cycle predictions, fertile windows, and ovulation dates
- Generate AI-powered health insights (Naya Plus)
- Process subscriptions and in-app purchases
- Sync your data across devices (when Cloud Sync is enabled)
- Send local notifications (period reminders, daily logging, fertile alerts)
- Analyze app usage to improve features and fix bugs
- Comply with legal obligations
Cloud Sync & Data Storage
Cloud Sync is opt-in only. When enabled, your data is encrypted in transit (HTTPS/TLS) and at rest (Firebase/Google Cloud encryption). You control exactly what syncs via three granular toggles:
- Sync Cycles & Periods
- Sync Daily Logs (symptoms, moods, flow)
- Sync Profile Settings
When you turn off Cloud Sync, a dialog asks whether to keep or delete your cloud data. Cloud data is stored in Google Cloud Firestore under your unique user ID.
On Android, local data is encrypted using AES-256-GCM via the AndroidX Security library. On iOS, data is protected by the iOS Secure Enclave and Keychain.
Third-Party Services
Analytics
- Firebase Analytics & Crashlytics — always active (first-party, Apple ATT-exempt). Tracks anonymous app events and crash reports.
- GameAnalytics, AppsFlyer, Facebook SDK — gated behind user consent. On iOS, requires App Tracking Transparency (ATT) permission. On Android, implicit consent with opt-out toggle in Profile settings.
Analytics events include anonymized data such as feature usage, onboarding completion, and aggregate health metrics (e.g., cycle length range). No personally identifiable health data is sent to analytics providers.
Payment Processing
- RevenueCat — manages subscription status and entitlements. Receives your Firebase UID to link purchases.
- Apple App Store / Google Play Store — handle all payment processing. We never receive your full card details.
AI Services
- Google AI (Vertex AI) — powers the AI Health Assistant. Receives only current-day health context (no historical data, no PII).
Infrastructure
- Firebase Authentication — manages user accounts (anonymous, Apple Sign-In, Google Sign-In)
- Cloud Firestore — stores synced health data (encrypted, access-controlled per user)
Data Retention & Deletion
Personal information is retained only as long as needed to provide the service. Analytics data is typically kept for up to 26 months.
You can delete your data at any time through the Naya app:
- Clear All Data — wipes local data and cloud data (if sync was enabled). Account remains.
- Delete Account — permanently deletes all Firestore data, your Firebase Auth account, local app data, and resets your RevenueCat user. This action is irreversible.
Apple Health and Google Health Connect data is managed separately through those platform apps and is not affected by account deletion.
Ad Opt-Out
Naya does not display ads. To manage analytics tracking:
- iOS:Settings → Privacy & Security → Tracking → Disable "Allow Apps to Request to Track"
- Android: Naya app → Profile → Analytics toggle
Children's Privacy
Naya is rated 13+. We do not knowingly collect personal information from children under 13 (or 16 in certain regions). If we discover that a child has provided personal information, we will delete it promptly. If you believe a child is using Naya, please contact us at support@nitrotech.app.
Your Rights
All users may:
- Access and export their data
- Request corrections to their information
- Request deletion of their account and data
- Opt out of analytics tracking
- Manage notification preferences
EU/EEA residents (GDPR) have additional rights including data portability, processing restrictions, right to object, and the right to lodge a complaint with a supervisory authority.
California residents (CCPA)have the right to know what information is collected, opt out of data sales (we don't sell data), and receive equal service regardless of privacy choices.
Security
We implement technical and organizational measures to protect your data, including end-to-end encryption for cloud sync, AES-256 encryption for local storage on Android, and iOS Secure Enclave integration. However, no electronic transmission or storage system is 100% secure, and we cannot guarantee absolute security.
International Data Transfers
If you use Naya outside the United States, your data may be transferred to and processed in the United States where our servers and service providers are located. By using Naya, you consent to this transfer.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the App or by updating the "Last Updated" date. Your continued use of Naya after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
- Email: support@nitrotech.app
- Company: Nitrotech Inc., Delaware, United States