Nura
Home

Privacy Policy

Last updated: 16th May 2026

1.Introduction

Your privacy is important to us. This policy explains how Nura collects, uses, and protects your data. Nura is operated by Nura Fit Ltd (trading as "Nura"), which acts as the data controller for the personal data described below.

2.Data controller

Nura Fit Ltd is the data controller responsible for the personal data processed in connection with the Nura app and services. As controller, we determine the purposes and means of processing your data and are accountable for compliance with applicable data protection laws, including the UK GDPR and EU GDPR.

For any privacy-related questions or to exercise your rights, contact us at hello@nurafitness.com.

3.Information we collect

We may collect:

Personal information

  • Name
  • Email address

Health & fitness data

  • Weight
  • Goals
  • Activity data (steps, workouts, etc.)

Usage data

  • App interactions
  • Device information

4.How we use your data

We use your data to:

  • Provide personalised plans
  • Improve AI coaching
  • Track progress
  • Enhance user experience

5.AI processing

Nura uses AI systems to generate recommendations.

Some of your data may be processed securely through third-party AI providers (e.g. OpenAI).

6.Apple Health / HealthKit integration

With your permission, Nura may connect to Apple Health to read and sync health and fitness data such as steps, workouts, activity, and body measurements.

This data is used solely to provide personalised fitness insights, progress tracking, reminders, and wellness features inside the app.

Nura does not use HealthKit data for advertising, marketing, or data-selling purposes.

Health data is only accessed with your explicit permission and can be revoked at any time through your Apple Health settings.

Some HealthKit data may be securely stored and synced across your devices to support your account experience and restore progress.

7.Data sharing

We do not sell your data.

We may share data with:

  • Cloud hosting and database providers (Lovable)
  • AI providers used to generate coaching responses (e.g. OpenAI, Google)
  • Paddle.com — our Merchant of Record. Paddle processes payments, handles subscriptions, manages tax compliance, and issues invoices.
  • Professional advisers and authorities where required by law

8.Data storage

Your data is stored securely using cloud infrastructure provided by Lovable and other trusted service providers.

We take reasonable technical and organisational measures to protect your personal data from unauthorised access, loss, or misuse.

9.Legal basis for processing

Where the UK GDPR or EU GDPR applies, we rely on the following legal bases under Article 6 to process your personal data:

  • Performance of a contract (Art. 6(1)(b)) — to create and maintain your account, deliver personalised plans, and provide the Nura service you've signed up for.
  • Legitimate interests (Art. 6(1)(f)) — to keep the service secure, prevent fraud and abuse, debug issues, and improve our product. We balance these interests against your rights and freedoms.
  • Consent (Art. 6(1)(a)) — for any optional processing where we ask for your permission (e.g. processing health & fitness data you choose to provide, certain analytics or marketing communications). You can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) — to comply with applicable laws, including tax, accounting, and responding to lawful requests from authorities.

Where we process special category data (e.g. health-related information you enter), we rely on your explicit consent under Article 9(2)(a). You can withdraw this consent at any time by deleting the relevant data or your account.

10.Your rights

Subject to applicable law (and in particular the UK GDPR and EU GDPR for users in the UK and EEA), you have the following rights in respect of your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data ("right to be forgotten").
  • Restriction — ask us to limit how we use your data.
  • Portability — receive your data in a portable format.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — where we rely on consent, you can withdraw it at any time.
  • Complaint — lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office at ico.org.uk).

To exercise any of these rights, contact us at hello@nurafitness.com. We aim to respond within one month, in line with GDPR requirements.

11.Data retention

We keep your personal data only for as long as necessary to provide the service and comply with our legal obligations. In practice:

  • Account & profile data — kept for as long as your account is active. If you delete your account, we erase or anonymise your data promptly, except where retention is required by law.
  • Health & fitness data — kept while your account is active so we can deliver personalised plans; deleted with your account.
  • Billing & tax records — held by Paddle (our Merchant of Record) for the period required by applicable tax law (typically 6–10 years).
  • Support communications — retained for up to 24 months after the issue is resolved.

12.International transfers

Some of our service providers (e.g. cloud hosting and AI providers) are based outside the UK and EEA, including in the United States. Where we transfer your personal data internationally, we rely on appropriate safeguards under the UK GDPR and EU GDPR — typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a recognised adequacy decision.

13.Cookies & tracking

We may use cookies or similar technologies to improve performance and user experience.

14.Third-party services

Nura uses trusted third-party services to operate effectively. These may include:

  • Cloud hosting and database services (e.g. Lovable)
  • AI providers (e.g. OpenAI)
  • Payment provider: Paddle.com (Merchant of Record)

These providers process data only as necessary to deliver the service and are expected to handle your data securely.

15.Affiliate & influencer codes

Nura may use affiliate and influencer discount codes for promotional purposes. If you sign up using a creator or influencer code, Nura may track code usage, subscription conversions, and related purchase activity for commission and analytics purposes.

16.Children's privacy

Nura is intended for users aged 18 and over. The app is not directed toward children or minors, and we do not knowingly collect personal information from individuals under the age of 18.

17.Changes to this policy

We may update this policy. Continued use of Nura means you accept the updated version.

18.Contact

If you have questions: hello@nurafitness.com