Privacy Policy

Effective Date: October 02, 2025

This Privacy Policy ("Policy") for Dr. Nur AI ("Company," "we," "us," or "our") describes how and why we might process your Personal Information when you use our services ("Services"), such as when you:

This Policy is intended to inform you ("User," "you," "your") of our policies and practices regarding the collection, use, and disclosure of any information that can be used to identify you, hereinafter referred to as "Personal Information." Your use of the Services is contingent upon your acceptance of this Policy. Should you not agree with the terms set forth herein, you are hereby advised to refrain from using our Services.

For inquiries or concerns regarding this Policy, please contact our Data Protection Officer at support@drnur.ai.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Policy. For a comprehensive understanding, we encourage you to review the full document.

TABLE OF CONTENTS

  1. Information We Collect
  2. How We Process Your Information
  3. Legal Bases for Processing Your Information
  4. When and With Whom We Share Your Personal Information
  5. Use of Cookies and Other Tracking Technologies
  6. Artificial Intelligence-Based Products
  7. Social Logins
  8. Data Retention
  9. Information Security
  10. Collection of Information from Minors
  11. Your Privacy Rights
  12. Controls for Do-Not-Track Features
  13. United States Residents' Specific Privacy Rights
  14. Amendments to This Policy
  15. Contact Information
  16. Reviewing, Updating, or Deleting Your Data

1. INFORMATION WE COLLECT

Personal Information You Disclose to Us
In Short: We collect Personal Information that you voluntarily provide to us.

We collect Personal Information that you provide to us upon registration for the Services, when expressing interest in our products, participating in activities on the Services, or otherwise contacting us. The Personal Information we collect may include:

  • Full Name
  • Email Address
  • Telephone Number
  • Username and Password
  • Date of Birth and Gender

Sensitive Information. Subject to your explicit consent and as permitted by applicable law, we process the following category of sensitive information:

  • Health Data: With your express permission, we access specific health-related data points from the Apple Health application ("HealthKit") on your device. This data is limited to metrics such as heart rate, sleep patterns, and physical activity levels ("HealthKit Data").

Application Data. Should you use our Application, we may collect the following information, provided you grant us access or permission:

  • Apple HealthKit Access: We will request your permission to read specific HealthKit Data. The Application is designed solely to interact with Apple's HealthKit framework; no other third-party health platforms or wearable devices are supported in this version.
  • Push Notifications: We may request your permission to send you push notifications regarding your account or Application features. You may revoke this permission at any time in your device's settings.

All Personal Information you provide must be true, complete, and accurate, and you must notify us of any changes thereto.

2. HOW WE PROCESS YOUR INFORMATION

In Short: We process your information to provide, improve, and administer our Services, to communicate with you, for security and fraud prevention, and to comply with law.

We process your Personal Information for various legitimate business purposes, including:

  • To facilitate account creation, authentication, and management.
  • To deliver Services to the User. This includes processing your HealthKit Data to provide you with wellness insights and to facilitate your interaction with our AI-driven mental wellness support features.
  • To evaluate and improve our Services, products, and your experience. We may process your information when we believe it is necessary to identify usage trends, determine the effectiveness of our campaigns, and to evaluate and improve our Services, products, and your experience.

4. WHEN AND WITH WHOM WE SHARE YOUR PERSONAL INFORMATION

In Short: We may share information in the limited situations described herein. We shall not share your HealthKit Data with third parties for care or marketing purposes.

We may need to share your Personal Information in the following situations:

  • Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • Affiliates. We may share your information with our affiliates, in which case we will require those affiliates to honor this Policy.

Notwithstanding any other provision in this Policy, we shall not sell, rent, lease, or otherwise disclose your Personal Information for marketing purposes.

5. USE OF COOKIES AND OTHER TRACKING TECHNOLOGIES

We may utilize cookies and similar tracking technologies to collect and store your information, primarily for security, preference management, and basic site functionality.

6. ARTIFICIAL INTELLIGENCE-BASED PRODUCTS

We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.

As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products"). These tools are designed to enhance your experience and provide you with innovative solutions. The terms in this Privacy Notice govern your use of the AI Products within our Services.

Use of AI Technologies

We provide the AI Products through third-party service providers ("AI Service Providers"), including OpenAI and Gemini. As outlined in this Privacy Notice, your input, output, and personal information will be shared with and processed by these AI Service Providers to enable your use of our AI Products for purposes outlined in "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" You must not use the AI Products in any way that violates the terms or policies of any AI Service Provider.

Our AI Products

Our AI Products are designed for the following functions:

  • Machine learning models
  • AI applications
  • AI insights
  • AI predictive analytics
  • Image analysis

How We Process Your Data Using AI

All personal information processed using our AI Products is handled in line with our Privacy Notice and our agreement with third parties. This ensures high security and safeguards your personal information throughout the process, giving you peace of mind about your data's safety.

7. SOCIAL LOGINS

Our Services may offer you the ability to register and log in using third-party social media account details (e.g., Apple). In such an event, we will receive certain profile information about you from the social media provider, typically limited to your name and email address, solely for authentication purposes.

8. DATA RETENTION

We shall retain your Personal Information only for as long as is necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law. Generally, we will retain your Personal Information for the duration your account is active. Upon account termination, we shall either delete or anonymize such information in accordance with our data retention schedule.

9. INFORMATION SECURITY

We aim to protect your personal information through a system of organizational and technical security measures.

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

10. COLLECTION OF INFORMATION FROM MINORS

We do not knowingly solicit data from or market to individuals under the age of 18. By using the Services, you represent that you are at least 18 years of age. If you become aware of any data we may have collected from user under age 18, please contact us at support@drnur.ai.

11. YOUR PRIVACY RIGHTS

In certain jurisdictions, you may have rights under applicable data protection laws to request access to, rectification of, or erasure of your Personal Information. To make such a request, please contact us using the details provided herein.

12. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.

California law requires us to let you know how we respond to web browser DNT signals. Because there currently is not an industry or legal standard for recognizing or honoring DNT signals, we do not respond to them at this time.

13. UNITED STATES RESIDENTS' SPECIFIC PRIVACY RIGHTS

If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. More information is provided below.

Categories of Personal Information We Collect

The table below shows the categories of personal information we have collected in the past twelve (12) months. The table includes illustrative examples of each category and does not reflect the personal information we collect from you. For a comprehensive inventory of all personal information we process, please refer to the section "INFORMATION WE COLLECT"

We only collect sensitive personal information, as defined by applicable privacy laws or the purposes allowed by law or with your consent. Sensitive personal information may be used, or disclosed to a service provider or contractor, for additional, specified purposes. You may have the right to limit the use or disclosure of your sensitive personal information.

We do not collect or process sensitive personal information for the purpose of inferring characteristics about you.

We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:

  • Receiving help through our customer support channels;
  • Participation in customer surveys or contests; and
  • Facilitation in the delivery of our Services and to respond to your inquiries.

We will use and retain the collected personal information as needed to provide the Services or for:
Category L-As long as the user has an account with us

Sources of Personal Information
Learn more about the sources of personal information we collect in "INFORMATION WE COLLECT"

How We Use and Share Personal Information
Learn more about how we use your personal information in the section "HOW WE PROCESS YOUR INFORMATION"

Will your information be shared with anyone else?
We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider. Learn more about how we disclose personal information in the section, "WHEN AND WITH WHOM WE SHARE YOUR PERSONAL INFORMATION"

We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be "selling" your personal information.

We have not disclosed, sold, or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. We will not sell or share personal information in the future belonging to website visitors, users, and other consumers.

Your Rights

You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:

  • Right to know whether or not we are processing your personal data
  • Right to access your personal data
  • Right to correct inaccuracies in your personal data
  • Right to request the deletion of your personal data
  • Right to obtain a copy of the personal data you previously shared with us
  • Right to non-discrimination for exercising your rights
  • Right to opt out of the processing of your personal data if it is used for targeted advertising (or sharing as defined under California's privacy law), the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")

Depending upon the state where you live, you may also have the following rights:

  • Right to access the categories of personal data being processed (as permitted by applicable law, including the privacy law in Minnesota)
  • Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in California, Delaware, and Maryland)
  • Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in Minnesota and Oregon)
  • Right to review, understand, question, and correct how personal data has been profiled (as permitted by applicable law, including the privacy law in Minnesota)
  • Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including the privacy law in California)
  • Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including the privacy law in Florida)

How to Exercise Your Rights

To exercise these rights, you can contact us by visiting our website, by emailing us at support@drnur.ai, or by referring to the contact details at the bottom of this notice.

We will honor your opt-out preferences if you enact the Global Privacy Control (GPC) opt-out signal on your browser.

Under certain US state data protection laws, you can designate an authorized agent to make a request on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with applicable laws.

Request Verification

Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.

If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request and the agent will need to provide a written and signed permission from you to submit such request on your behalf.

Appeals

Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at support@drnur.ai. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may submit a complaint to your state attorney general.

California "Shine The Light" Law

California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us by using the contact details provided in the section "CONTACT INFORMATION"

14. AMENDMENTS TO THIS POLICY

We may update this Policy from time to time. The updated version will be indicated by a revised "Effective Date." Should we make material changes to this Policy, we will notify you either by prominently posting a notice of such changes or by directly sending you a notification.

15. CONTACT INFORMATION

For questions or comments about this Policy, you may contact our team by email at support@drnur.ai.

16. REVIEWING, UPDATING, OR DELETING YOUR DATA

Based on the applicable laws of your jurisdiction, you may have the right to request access to, correct inaccuracies in, or delete the Personal Information we collect from you. To initiate such a request, please contact us at support@drnur.ai.