Back to home

GDPR Policy

Last updated: June 1, 2026

1. Overview

Noxora is committed to protecting the personal data of users in the European Economic Area (EEA), the United Kingdom, and Switzerland in accordance with the EU General Data Protection Regulation (GDPR) and the UK GDPR. This page summarises your rights and how we comply.

2. Data Controller

Noxora acts as the "data controller" for the personal data you provide when using the App. You can contact us at contact@noxoraapp.com for any privacy-related request.

3. Personal Data We Process

  • Account data: email, authentication identifiers.
  • Usage data: listens, favourites, streaks, session counts.
  • Payment metadata: subscription status (card details are processed by Stripe).
  • Technical data: device type, browser, approximate location, error logs.
  • User-submitted prompts for AI manifestation generation.

4. Legal Bases for Processing

  • Contract (Art. 6(1)(b)): to provide the App and process subscriptions.
  • Legitimate interests (Art. 6(1)(f)): to secure, improve, and analyse the App.
  • Consent (Art. 6(1)(a)): for optional analytics, marketing emails, or push notifications, where required.
  • Legal obligation (Art. 6(1)(c)): tax, accounting, and regulatory record-keeping.

5. Your Rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion ("right to be forgotten").
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your local supervisory authority.

To exercise any of these rights, email contact@noxoraapp.com. We respond within 30 days.

6. International Data Transfers

Some of our service providers (Supabase, Stripe, OpenAI, ElevenLabs) may process data outside the EEA. Where this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable.

7. Data Retention

We keep personal data only as long as necessary for the purposes described in our Privacy Policy. Account data is deleted within 30 days of an account-deletion request, except where law requires longer retention (e.g. invoicing records).

8. Security

We use industry-standard technical and organisational measures including encryption in transit and at rest, access controls, and audit logging. No system is 100% secure; in the event of a personal data breach affecting your rights, we will notify you and the relevant supervisory authority as required by GDPR.

9. Children

Noxora is not directed to children under 16 in the EEA (or the minimum digital-consent age in your country). We do not knowingly collect data from children without verifiable parental consent.

10. Sub-Processors

We engage trusted sub-processors to operate Noxora: Supabase (database, auth, storage), Stripe (payments), OpenAI (AI text), and ElevenLabs (AI voice). Each is bound by a data processing agreement.

11. Contact & Complaints

For privacy questions or to file a complaint, email contact@noxoraapp.com. You may also contact your national data protection authority.