Privacy Policy
Last updated: August 2026
Overview
The Ital Factory LLC ("we", "our", or "us") operates Nuru. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.
Information We Collect
Information You Provide
- Account Information: When you create an account, we collect your name, email address, and authentication credentials.
- Captured Content: Audio recordings, video recordings, photos, transcripts, and notes you create within the app.
- User-Generated Content: Folders, tags, study materials, reports, and other organizational data you create.
Automatically Collected Information
- Device Information: Device model, operating system version, and app version.
- Usage Data: Features used, session duration, and app performance metrics.
- Crash Reports: Anonymous crash data and error logs to improve app stability.
How We Use Your Information
We use the collected data for various purposes:
- To provide and maintain our Service
- To process your recordings using AI transcription and analysis
- To sync your data across your devices
- To improve and optimize the app experience
- To communicate with you about updates, security alerts, and support
- To detect, prevent, and address technical issues
Data Storage and Security
Cloud Storage
Nuru syncs your data across your devices so your library is available everywhere you sign in. Your recordings, transcripts, and study materials are protected in transit and at rest.
Security Measures
- Encryption for data in transit and at rest
- Secure authentication using industry-standard protocols
- Regular security audits and updates
- No third-party access to your captured content
AI Processing
When you use AI features (transcription, analysis, study-material generation), your content is processed using secure, privacy-focused AI services. We do not use your content to train AI models or share it with third parties for advertising purposes.
Data Retention
Your data is retained as long as your account is active. When you delete content from the app, it is permanently removed from our systems within 30 days. You can request complete account deletion at any time through the app settings.
Your Rights
You have the right to:
- Access and download your personal data
- Correct or update your information
- Delete your account and all associated data
- Opt-out of crash reporting and analytics
- Export your data in standard formats
Children's Privacy
Nuru is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal data, please contact us.
Browser Extension
The Nuru browser extension saves links to your Nuru account. It is a remote for the Nuru iOS and macOS app. The extension sends nothing about the pages you save to anyone except your own Nuru account.
What the extension collects
- Link data: the URL of the page you click Save on, its domain, the page title and preview image extracted in your browser, the note you typed and folder you picked (if any), and save timestamps. This lands in the same account your iOS app writes to, protected by row-level security so only your authenticated session can read it.
- Account identity: your Apple
subidentifier (an opaque stable ID, not your Apple ID email), plus your email and display name only if you chose to share them with Apple. - Usage analytics: extension version, browser and OS major version (e.g. "Chrome 124", "macOS 14"), an anonymous session support code, a one-way hashed user ID, connectivity status, queue length, and lifecycle events from a fixed allow-list — popup opens, save outcomes, queue drains, sign-in and sign-out. These record which features get used and where saves fail. They are on by default and can be switched off at any time from the extension's options page; collection stops immediately, and anything recorded but not yet uploaded is discarded rather than sent.
What the extension never collects
Usage analytics and every other telemetry surface never carry the URLs of pages you save,
page titles, personal notes, folder names or IDs, your email, display name, or raw Apple
sub, your raw user-agent or precise device model, your timezone or locale, or
any page HTML, text, or screenshots. Crash stack traces are not collected at all.
Every value attached to an event passes through a validator covering eight patterns — email, phone, SSN, credit card with a Luhn check, address, name-with-title, password, and generic quoted strings — and then a static allow-list. Anything outside the allow-list is rejected before transmission. This is enforced in source, not by a runtime setting, and the allow-list is mirrored as a database constraint so an event outside it cannot be recorded even by a modified client.
The extension runs no code on the pages you browse. It has no content script and asks for no access to websites in general. When you open its popup on a page — and only then — it reads that one page for the metadata you would see by inspecting the HTML yourself: Open Graph tags, the document title, and the favicon link. That access is granted by your click and lapses with it, so pages you never open the popup on are never touched at all.
Who receives extension data
We do not sell, trade, or rent any data, and the extension sends nothing to an outside analytics company — usage events go to the same Nuru backend that holds your links. The only third parties that receive anything are Supabase (our backend — stores your link data, authentication, and usage analytics), Apple (the Sign in with Apple flow), and Netlify, which hosts this site including the Apple sign-in callback page. The callback receives Apple's token in the URL fragment, which browsers never transmit to the server, and forwards it straight to the extension.
Retention and control
- Link data is kept as long as your account exists, and is removed when you delete links in the app.
- Usage analytics are retained for 90 days, then deleted automatically. If you opt out, anything not yet uploaded is discarded immediately and already-uploaded events tied to your hashed ID are requested for deletion within 30 days.
- Local extension storage — session token, folder cache, offline queue, privacy settings — is cleared when you sign out or uninstall.
- Deleting your account from the iOS or macOS app also deletes every link the extension saved.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Email: privacy@nuruai.com
- Website: Contact Form