NuVARD Privacy Policy
Effective date: July 22, 2026
1. Introduction and scope
This Privacy Policy explains how NuVARD Biotech, Inc., a Delaware C-corporation doing business as NuVARD AI ("NuVARD," "we," "us," or "our"), collects, uses, discloses, and protects Personal Data in connection with:
- the NuVARD AI mobile application (the "App"), available on the Apple App Store; and
- the www.nuvard.ai website, including the waitlist (the "Website"); and
- related services we provide (together with the App and Website, the "Service").
"Personal Data" means information that identifies, relates to, or could reasonably be linked to an identifiable individual ("you"). This Policy applies to the App, the Website, and related services together, except where a section states that it applies only to the Website or only to the App.
Please read this Policy together with any notices we provide at the point where we collect your information, and together with our Terms of Service, which govern your use of the Service and contain the applicable warranty disclaimers, limitation of liability, and dispute-resolution terms.
2. Wellness, not medical care — important disclaimer
NuVARD provides wellness and health-intelligence information only. NuVARD is not medical care. NuVARD does not diagnose, treat, cure, or prevent any disease, and it is not a medical device or a substitute for professional medical advice, diagnosis, or treatment.
Any insights, scores, forecasts, or other outputs the Service produces — including outputs generated with artificial intelligence — are informational. AI-generated content is presented for you to review; you decide whether and how to act on it.
No reliance. Do not rely on any output of the Service to make or change a medical or treatment decision. Do not delay or disregard professional medical care because of anything you accessed through the Service. The Service is not intended for emergencies; if you think you may have a medical emergency, call your doctor or emergency services immediately. Always seek the advice of a qualified health provider with any questions you may have regarding a medical condition.
This disclaimer is also presented in the App at the point outputs are shown, and in our Terms of Service.
3. Who we are — the data controller
NuVARD Biotech, Inc. is the controller responsible for your Personal Data processed through the Service.
- Legal entity: NuVARD Biotech, Inc. (a Delaware C-corporation), doing business as NuVARD AI
- Contact for privacy, legal, and data-rights requests: support@nuvard.ai. Formal legal notice may be sent by mail to the mailing address below.
- Mailing address / principal place of business: 2828 NW 1st Avenue, #314, Miami, FL 33127, United States
- Registered office: 1007 North Orange St., 4th Floor, Wilmington, County of New Castle, DE 19801 (registered agent: Capbase Agent & Document Services LLC)
EU and UK representation. The Service is operated from the United States and is directed to users in the United States at launch. We have not appointed an EU representative under Article 27 GDPR or a UK representative under Article 27 UK GDPR, because we do not currently offer the Service to, or monitor the behavior of, individuals in the EEA or the United Kingdom. If we begin offering the Service in those regions, we will appoint representatives and update this Policy before doing so.
Data Protection Officer. Based on a documented assessment under Article 37 GDPR, we have not designated a Data Protection Officer at this stage; we will revisit this as the Service grows. Privacy governance is handled directly by NuVARD leadership, reachable at support@nuvard.ai.
4. What we collect
4.1 The Website (including the waitlist)
When you interact with the Website, we collect:
- Email address, which you provide to join the waitlist.
- Campaign attribution, if present — the
source,campaign, andlanding_variantvalues from URL parameters that indicate how you arrived at the Website. - Optional qualification answers (such as device, interest, and platform) and granular marketing, beta, and research consents, captured only if we offer them and you choose to provide them.
- Website analytics events, which capture only: event name, page, source, campaign, device class, viewport class, language, variant, and subscriber status.
We do not intentionally collect health information on the Website, and the waitlist and analytics records are not designed to store health data.
How Website information is handled:
- We protect your email address with encryption while it is stored and while it is transmitted, and we maintain a separate one-way derived value of the normalized email used only for de-duplication and lookup, which is not designed to be reversible to your email address.
- We do not store IP addresses in raw form; we use a keyed, hashed handling of IP addresses solely for abuse prevention and rate-limiting.
- We record the version of the consent you gave and the time you gave it when you sign up.
- Verification links are limited in use and time.
Additional information on our security measures appears in Section 12.
4.2 The App
When you use the App, we may collect and process the following categories of Personal Data, each governed by granular, per-category consent:
- Health and activity metrics
- Wearable and device-sync data
- AI-processing data (information processed to generate insights)
- Medical history
- Biomarkers and lab results
- Location
- Camera-roll data (images you choose to share with the App, including through the in-App scanner)
- App usage and diagnostic data — see below
- Marketing preferences
For special-category data (health, biomarkers, medical history, and similarly sensitive information) — including medical history, biomarkers, and Camera-roll data — we obtain your consent at the moment of the action that requires it, rather than up front. Marketing is opt-in and is off by default.
Apple Health / Health Connect. Where you connect the App to Apple Health or Health Connect, read access is user-granted, scoped, and read-only, and you may disconnect it at any time. The App names, in plain language, the read scope it requests. Health data obtained through Apple Health or Health Connect, and health data generally, is never used for advertising and is never sold, and is shared only with the sub-processors described in Section 8 that are contractually bound to protections equivalent to those in this Policy and only as needed to provide the Service.
App usage, diagnostics, and device identifiers. The App uses first-party and service-provider analytics to collect usage and diagnostic data (such as feature interactions and crash/performance events) to operate and improve the Service. This data is not used for third-party advertising. Where the App would access a device advertising identifier or engage in tracking as defined by Apple's App Tracking Transparency framework, we will request your permission through the operating-system prompt before doing so.
Biometric identifiers. The App is not designed to capture or generate biometric identifiers (such as faceprints, fingerprint templates, or voiceprints); images you choose to share through the in-App scanner are used for the scanning feature you invoked, not to build biometric templates. If this ever changes, we will provide the separate notice, consent, and retention-and-destruction schedule required by applicable biometric-privacy laws (including the Illinois Biometric Information Privacy Act) before any collection begins, and we will not sell biometric identifiers.
4.3 Consent
Consent to processing is granular and per-category, captured before processing, versioned (with a version and timestamp), and withdrawable. Where you withdraw consent, we explain the consequence of doing so inline. We do not use silent, pre-granted toggles.
5. How and why we use Personal Data, and our legal bases (GDPR)
We use Personal Data to operate, provide, maintain, and improve the Service; to create the wellness and health-intelligence outputs you request; to communicate with you; to secure the Service and prevent abuse; to measure and understand how the Website and App are used; and to comply with law.
Where the EU/UK General Data Protection Regulation ("GDPR") applies, we rely on the following legal bases:
- Consent — for processing special-category health data, for wearable/device sync, for AI processing of your data, for medical history, biomarkers, Camera-roll data, location, and for marketing; and for joining and remaining on the waitlist and marketing list. You may withdraw consent at any time.
- Performance of a contract — to provide the Service you have requested and to manage your account.
- Legitimate interests — to secure the Service, prevent abuse, and rate-limit signups (for example, storing only a keyed, hashed form of your IP address); and to measure aggregate Website usage and attribute marketing campaigns (Art. 6(1)(f)), where those interests are not overridden by your rights. We have carried out a balancing assessment for these interests and will provide further information on request.
- Legal obligation — to comply with applicable law.
We process special-category health data only on the basis of your explicit consent under Art. 9(2)(a). Where any other Art. 9(2) condition is genuinely relied on for a defined purpose, we will identify it and tie it to that purpose.
6. Automated processing and artificial intelligence
The Service uses artificial intelligence to generate wellness and health-intelligence outputs. AI-generated content is presented for you to review; you decide whether and how to act on it. Outputs are informational and are designed to be reviewed by you rather than to make decisions for you.
We have designed the Service so that its outputs are not used to make decisions producing legal or similarly significant effects about you without human involvement. Where any feature would carry out an action on your behalf, we provide controls over that behavior and a means to review, reverse, or contest it, and certain categories of action (such as anything involving medication dosage, payments, account changes, or new data sharing) always require your explicit confirmation first. Where any processing does qualify as a solely automated decision under GDPR Article 22, we will rely on your explicit consent (Art. 22(2)(c) / Art. 9(2)(a)), provide the safeguards required (including the right to obtain human intervention, to express your point of view, and to contest the decision), and give you meaningful information about the logic involved and its significance.
Model training. We do not use your personal data to train or fine-tune AI models, and we contractually require our AI-inference providers not to use your data to train theirs.
We also honor applicable US state automated-processing and profiling rights (including opt-out rights under California's automated decision-making rules and the Colorado and Connecticut privacy acts) where they apply to our forecast or insight features. You may exercise them by contacting support@nuvard.ai.
7. No sale of Personal Data; no sharing for cross-context advertising
We do not sell your Personal Data, and we do not share it for cross-context behavioral advertising. For the Website waitlist specifically, your email is not sold. If we ever change this practice, we will update this Policy, provide the disclosures and opt-out mechanism required by applicable law, and, where required, obtain your consent before the change takes effect.
8. Sub-processors and disclosures
We share Personal Data with service providers ("sub-processors") that process it on our behalf under contract and only on our instructions.
8.1 Website sub-processors
- Vercel (United States) — Website hosting and privacy-friendly Web Analytics.
- Supabase (United States) — Postgres database host that stores the encrypted waitlist records. The database is hosted in the AWS us-east-1 region (Northern Virginia, United States).
- Resend — transactional email provider that sends verification and cohort emails.
8.2 App sub-processors
We disclose the categories of App sub-processors in-App — artificial-intelligence inference, push-notification delivery, billing, and weather. The specific named vendors are:
- Billing: Apple In-App Purchase (iOS) and, for web checkout, Stripe.
- Artificial-intelligence inference, push-notification delivery, and weather: the current named vendors are listed in-App within the relevant consent flows and are available at any time on request at support@nuvard.ai. We will name them in this Policy at or before the App's public relaunch.
Any sub-processor that receives health data is contractually bound to protections equivalent to those in this Policy, is permitted to use the data only to provide the Service, and is prohibited from using it for advertising or from selling it.
We may also disclose Personal Data where required by law, to enforce our agreements, or to protect the rights, safety, and security of NuVARD, our users, or the public.
9. International data transfers
We are based in the United States, and our sub-processors may process Personal Data in the United States or other countries. Where we transfer Personal Data from the EEA or the United Kingdom to a country that has not received an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with any additional measures required. You may request a copy of the safeguards we use for these transfers by contacting support@nuvard.ai.
10. Retention and deletion
We retain Personal Data only for as long as necessary for the purposes described in this Policy or as required by law, and then delete or de-identify it.
- Retention periods by category:
- Waitlist records (Website): retained until you request removal, or until 12 months after the Service's public launch, whichever comes first; then deleted or de-identified.
- Account profile and App data, including health data you provide or connect: retained while your account is active; on account deletion, deleted or de-identified within 30 days (subject to the per-category treatments described below), with residual copies purged from encrypted backups within a further 35 days.
- Consent, acknowledgment, and data-rights records: retained as long as needed to demonstrate compliance, up to 6 years after account closure.
- Payment and tax records: retained as required by tax and accounting law (typically up to 7 years).
- Usage diagnostics and crash logs: retained up to 24 months, then deleted or aggregated.
- Website analytics (aggregate, cookieless): event-level data retained up to 24 months; only aggregates thereafter.
- Where a precise period cannot be stated, we determine it using these criteria: the purpose the data serves, our legal obligations, and the limitation periods for legal claims.
- Account deletion (App): You may delete your account, which is user-initiated, both in-app and by contacting support@nuvard.ai. Depending on the data category, we apply a delete, de-identify, or retain treatment. Where we describe data as anonymized, we mean it is rendered no longer reasonably capable of identifying you; where data remains capable of re-identification, it continues to be treated as Personal Data. Where a legal hold applies, deletion may be paused; if that happens, we will tell you.
- Website removal: You may request removal of your waitlist record at support@nuvard.ai.
11. Your rights and how to exercise them
Depending on where you live, you have the following rights. To exercise any of them, contact support@nuvard.ai. We will respond within the time required by applicable law. You will not be discriminated against for exercising your rights.
11.1 EEA and UK (GDPR)
You have the right to access your Personal Data; to rectification of inaccurate data; to erasure; to restriction of processing; to data portability; to object to processing based on legitimate interests; to withdraw consent at any time (without affecting processing already carried out); and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. This last right is provided to you even though we have designed the Service not to make such solely-automated decisions about you (see Section 6). You also have the right to lodge a complaint with your local supervisory authority.
11.2 California (CCPA/CPRA)
You have the right to know what Personal Data we collect and how we use and disclose it; the right to access and delete your Personal Data; the right to correct inaccurate Personal Data; the right to opt out of the sale or sharing of Personal Data (note: we do not sell or share Personal Data for cross-context advertising); the right to limit the use of sensitive personal information; and the right not to receive discriminatory treatment for exercising your rights. You may use an authorized agent to submit a request.
We use sensitive personal information (including health data, biomarkers, and precise geolocation) only to provide the wellness and health-intelligence features you request, and not to infer characteristics about you. Because we do not use sensitive personal information beyond providing the requested Service, the right to limit its use is honored by default.
11.3 Consumer health data (US state health-privacy laws)
NuVARD is a consumer wellness application and is not a HIPAA-covered entity or business associate; the information the App processes is not protected health information under HIPAA. Certain US state laws regulate "consumer health data" collected by non-HIPAA businesses, including the Washington My Health My Data Act, Nevada SB 370, and Connecticut's consumer health-data provisions, and the FTC Health Breach Notification Rule applies to health apps like ours; we treat these regimes as applicable to the App and, in the event of a breach of unsecured identifiable health data, will provide the notifications the Health Breach Notification Rule requires.
Where these laws apply, we:
- collect the categories of consumer health data described in Section 4.2 from the sources described there, for the purposes described in this Policy;
- obtain your consent before collecting consumer health data, and obtain a separate authorization before sharing or selling it (we do not sell consumer health data);
- share consumer health data only with the sub-processors in Section 8, bound to equivalent protections; and
- honor your rights to access, to withdraw consent, and to delete your consumer health data. To exercise these rights, contact support@nuvard.ai.
To exercise any of these rights, contact support@nuvard.ai.
12. Security
We use technical and organizational measures designed to protect Personal Data, including:
- encryption of data at rest and in transit;
- hashed and keyed handling of IP addresses rather than storage of raw IP addresses;
- access controls; and
- rate-limiting and abuse-prevention measures.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Data-breach notification
If a breach affecting your Personal Data occurs, we will notify you and the relevant authorities as and to the extent required by applicable law.
14. Children and minors
The Service is intended for users who are at least 16 years old, and sign-up by anyone under 16 is not permitted. We do not knowingly collect Personal Data from anyone under 16. The 16-year threshold applies across the regions we serve. If you believe a person under 16 has provided us Personal Data, contact support@nuvard.ai and we will take appropriate steps.
15. Cookies and analytics
The Website uses Vercel Web Analytics, which is privacy-friendly and cookieless, to measure aggregate visitor metrics and a first-party conversion event. Our legal basis for this measurement and for campaign attribution is our legitimate interest under Art. 6(1)(f) (or your consent where required).
The Website sets no advertising or third-party tracking cookies. The only cookie the Website sets is a single strictly-necessary, first-party session cookie, created when you click your email verification link so the site can show you your own signup status; it is not used for tracking or analytics. Because strictly-necessary cookies are exempt from consent requirements under the EU ePrivacy rules and the UK PECR, the Website does not display a cookie banner.
App usage and diagnostic data, and device identifiers, are described in Section 4.2.
16. Platform availability
The App is currently available on the Apple App Store (iOS only at present).
17. California Confidentiality of Medical Information Act (CMIA)
To the extent the California Confidentiality of Medical Information Act applies to our handling of medical information (California extends the CMIA to certain apps and services designed to maintain medical information), we comply with its consent and disclosure requirements, including not disclosing medical information without the authorization it requires.
18. Changes to this Policy
We may update this Policy from time to time. When we make non-material changes, we will update the effective date above and, where required, provide additional notice; your continued use of the Service after such an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law. For material changes that affect Personal Data already collected — in particular any change that expands our use of health or other sensitive data, or that would require your consent — we will provide advance notice and, where required, obtain your renewed affirmative consent before the new processing begins, rather than relying on continued use alone.
19. Contact us
For any question about this Policy or to exercise your rights, contact us at:
NuVARD Biotech, Inc. (doing business as NuVARD AI) Email: support@nuvard.ai Mailing address: 2828 NW 1st Avenue, #314, Miami, FL 33127, United States
