Privacy Policy
Last updated: August 28, 2026
This policy explains how the Nurelio app (iOS/Android) and the website at
nurelio.net handle your data.
1. Controller
Helge Lange / PrettyLights Software. Contact: PrettyLightsSoftware@gmail.com.
2. Principle: Data Minimization
Nurelio is designed so that sensitive health information stays on your device. Anything synced or backed up through our server is end-to-end encrypted and cannot be decrypted by us. There is one exception: the optional AI companion — whatever you write to it, it has to be able to read (see section 9).
3. Data kept locally on your device
- Medications, intake schedules, containers, supply info
- Doctor appointments and contacts
- Health values (glucose, heart rate, blood pressure) — optionally synced with Apple Health / Health Connect
- Notes and intake photos (if used)
- Local notification settings
These live in a local database on your device and only leave it if you actively enable backup or family sharing.
4. Sign-in (Google / Apple)
To use family sync and the dead-man-switch, you sign in with your Google or Apple account. We store only:
- your provider subject ID (
google_suborapple_sub) - a public key generated locally on your device
- timestamps (created / updated)
We do not store your email, name or profile picture from Google/Apple. Legal basis: contract performance (GDPR Art. 6(1)(b)).
5. Family sync (end-to-end encrypted)
When you explicitly pair with a family member, the categories you share are transmitted to our server as encrypted records and distributed to your paired members.
- Encryption and decryption happen only on the participating devices.
- The server holds only: random ID, patient ID, category, nonce, ciphertext, timestamp — no plaintext.
- The symmetric key is wrapped separately for each recipient using their public key.
- When a pairing is removed, the associated key wrappings are deleted on the server.
6. Push notifications
If you grant permission, the app registers a push token (Apple APNs / Google FCM) with our server. We store the device token, platform (ios/android), your user ID, and timestamps. Pushes are sent for event-driven purposes only (e.g. a pairing was revoked, a watch event fired). Delivery is handled by Apple/Google. Legal basis: consent (GDPR Art. 6(1)(a)). You can revoke it anytime in your device settings.
7. Optional cloud backup
You may back up your local data to your own iCloud or Google Drive private app folder. We do not have access to this backup.
8. Health integration
If you grant permission, Nurelio reads health values (e.g. glucose, heart rate) from Apple Health / Health Connect. Processing is local; no health data is transmitted to our server unless you explicitly share it via family sync (in which case it is end-to-end encrypted).
9. AI companion (chat)
When you use the AI companion, the content of your message leaves your device. This is the one part of Nurelio that is not end-to-end encrypted — a language model can only answer what it is able to read.
What is processed:
- your message (typed or spoken)
- an extract of your data as conversation context: names and intake times of your medications, names and specialties of your doctors, upcoming appointments
- the most recent messages of the running conversation, plus short notes remembered about you from earlier conversations
Recipients:
- Google (Gemini API) — generates the reply and extracts the memory notes. Processing outside the EU is possible.
- ElevenLabs (USA) — receives the reply text for speech synthesis if you use voice output.
- For voice input on Android, your speech is transcribed by the operating system's speech recognition (Google); this happens outside Nurelio under your device vendor's terms. On iOS, recognition runs locally on the device.
Storage: The conversation is stored on our server so the companion still knows what you were talking about in the next sentence. Only a rolling window of the most recent messages is kept; older ones are condensed into short notes and then deleted. This data is stored unencrypted — unlike your medication and appointment data, which never leaves your device unencrypted.
Deletion: In the app under Companion → Chat memory → "Delete history" you can erase the transcript and the notes completely and immediately at any time. Deleting your account removes them as well.
The companion does not diagnose and does not replace a doctor. Please only share what is actually needed for the answer.
Legal basis: consent under GDPR Art. 6(1)(a) in conjunction with Art. 9(2)(a). Using the companion is optional; if you do not use it, none of this is processed.
10. Website nurelio.net
Our web server logs connection metadata (IP, timestamp, URL, user-agent) for up to 14 days for operational and debugging purposes. The website sets no cookies, uses no tracking, and embeds no third-party resources.
11. Server location
The Nurelio server runs on infrastructure in Germany (Strato). Your encrypted data does not leave the EU. The only processing outside the EU is what the service inherently requires: push delivery via Apple (APNs) and Google (FCM), and the contents of the AI companion at Google and ElevenLabs (see section 9) — each under their own terms.
12. Anonymous usage counts
So we can see where the app gets stuck and what it actually achieves, we count in aggregate: how far the setup flow gets, how many doses were confirmed and how many were missed, how often the final alarm stage did the job, how many appointment reminders came due, how often a companion was notified, and whether the installation was active on a given day.
Only a count per day is transmitted — never medication names, times of individual doses, or any other content. Along with it goes a randomly generated identifier: not a hardware identifier, not an advertising ID, and a different one from the one used for error reports.
This identifier is not connected to your account. The counts live in their own table with no account reference, they are transmitted without authentication, and there is no server-side way to attribute them to an account. From the daily counts we also build permanent grand totals with no identifier at all (e.g. "X doses supported in total").
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the app). You may object at any time under Art. 21 GDPR by emailing PrettyLightsSoftware@gmail.com; you will find your usage-counts identifier in the app under Settings → Sync log.
13. Error reports
When an error occurs in the app, we transmit the error message with a context tag, app version, platform and an installation identifier — never the contents of your data. Unlike the usage counts in section 12, this transmission is authenticated and therefore linked to your account; it is deleted along with your account. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning app).
14. Retention
- User record + public key: until you revoke / delete your account.
- Push tokens: until invalidated by APNs/FCM or revoked.
- Encrypted records: until you delete them on your device (a tombstone then marks deletion on the server).
- Pairing invitations (QR): automatically expire after a few minutes.
- AI companion: a rolling window of the most recent messages; the notes condensed from them until you delete them in the app.
- Web access logs: ≤ 14 days.
- Anonymous usage counts (section 12): 180 days; the identifier-free grand totals are kept permanently.
- Error reports (section 13): 90 days, or until you delete your account.
15. Your rights
You have the right to access, rectify, erase, restrict, export or object to processing of your personal data (GDPR Arts. 15–21), and to file a complaint with a supervisory authority (Art. 77). To delete your account and all related server-side data, email us at PrettyLightsSoftware@gmail.com.
16. No sharing for advertising
We do not sell data, do no profiling, and use no ad IDs or third-party analytics. The anonymous usage counts described in section 12 are evaluated by us alone and only in aggregate; they are never shared with anyone.
17. Children
Nurelio is not directed at children under 13. We do not knowingly collect data from children.
18. Changes
We update this policy when features or legal requirements change. The current version is always available at this URL.