Privacy policy framework
Draft — not effectivePrivacy should be understandable.
This page is a review framework, not NUEMI’s effective Privacy Policy. It avoids claiming facts that have not yet been confirmed by the product owner, technical audit, and legal review.
Information the final policy must identify
- Account and identity information NUEMI collects or receives.
- Health, fitness, calendar, financial, transaction, device, diagnostics, and usage data actually processed.
- Which information stays on-device, which is sent to NUEMI’s server, and which is processed by third parties.
- Purposes, legal bases where applicable, sharing, sale or tracking status, and whether advertising is used.
- Retention periods for active accounts, deleted accounts, logs, backups, and integration records.
Services and transfers to confirm
The final inventory must name only services actually used, including any Apple services, Plaid, hosting, databases, authentication, analytics, crash reporting, notifications, email, calendar providers, or customer-support tools. International transfers and processors must be reviewed for each launch region.
Connected-financial-account handling is outlined separately in the financial data disclosure draft.
User controls to verify
- Access, correction, export, disconnection, and deletion behavior.
- How users withdraw permissions in NUEMI, Apple Health, Plaid, and provider settings.
- What is deleted immediately, what remains temporarily in backups, and what must be retained by law.
- How privacy requests are authenticated and where users submit them.
Owner and legal-review inputs
Confirm the legal company name, DBA or product name, business address, privacy contact, supported countries and ages, data inventory, data map, retention schedule, subprocessors, incident process, and governing law. Counsel should review the completed policy before publication.