Legal

Privacy Policy

Last updated: July 2026  ·  Effective: July 2026

Summary: NOEZDAY collects only what it needs to run the app. Your journal entries and activity data are private. We do not sell your data. You can delete your account and all associated data at any time.

1. Who We Are

NOEZDAY ("we", "us", "our") is a behavioral stabilization mobile application operated by [YOUR LEGAL NAME / COMPANY NAME], based in [CITY, STATE], India. For privacy queries contact us at privacy@noeasyday.app.

2. Data We Collect

Information you provide

  • Email address — waitlist sign-up and account creation
  • Password — stored as a bcrypt hash, never in plain text
  • Journal entries — text written in free-write or guided journaling. Stored encrypted on our servers to enable cross-device sync. [Confirm: server-side or device-only?]
  • Mood and state ratings — numerical self-ratings during check-ins (e.g. Stress 7/10)
  • Profile name — optional display name you choose

Data generated by use

  • Which exercises, breathing sessions, and challenges you complete — and when
  • XP earned, level, streak count, and challenge progress
  • App session duration and frequency (not content)

Data collected automatically

  • Device type, OS version, app version
  • Crash and error logs (no personal content) via [crash tool e.g. Sentry / Firebase]
  • Anonymised usage analytics via [analytics tool or "none"]

Data we do NOT collect

  • Location, camera, microphone, contacts, or calendar
  • Biometric data of any kind

3. Sensitive Personal Data

Because NOEZDAY is a behavioral health app, data such as journal entries and mood ratings may constitute health-related personal data under India's Digital Personal Data Protection Act 2023 (DPDP Act). We process this data only under your explicit consent given at account creation. You may withdraw consent by deleting your account.

SOS data: The SOS feature connects your device directly to external helplines (iCall, Vandrevala Foundation, emergency services). We do not record, store, or log when you access the SOS screen or what calls you make. Zero SOS data touches our servers.

4. How We Use Your Data

  • Syncing your journal entries, XP, and progress across your devices
  • Personalising suggestions based on your state and activity history
  • Improving the app using aggregated, anonymised analytics
  • Sending account-related emails (verification, password reset, subscription receipts)
  • Sending launch notifications and product updates to waitlist members (opt-out available)
  • Processing Pro and Premium subscription payments

We will never use your journal entries, mood ratings, or health-related data for advertising or third-party profiling.

5. Data Sharing

We do not sell your data. We share it only with the following service providers, and only to the extent necessary:

  • Cloud servers[hosting provider + region]. Your data is stored in [data centre region].
  • Payment processing[Razorpay / Stripe] handles subscription billing. We do not store full card details.
  • Email delivery[Loops.so / Mailchimp] sends transactional and marketing emails. They receive your email address only.
  • Crash reporting[tool or "none"] for technical error logs with no personal content.

We may disclose data if required by Indian law or a valid court order. In the event of acquisition or merger, we will notify you before any transfer.

6. Your Rights (DPDP Act 2023)

  • Access — request a copy of your personal data
  • Correction — request correction of inaccurate data
  • Erasure — delete your account; all data purged within 30 days
  • Grievance redressal — raise a complaint; we respond within 30 days
  • Nomination — nominate a person to exercise your rights on your behalf

To exercise any right, email privacy@noeasyday.app with subject "Data Rights Request".

7. Data Retention

  • Active account — data retained while your account exists
  • Deleted account — personal data purged within 30 days. Payment transaction records are retained for 7 years per Indian accounting regulations.
  • Waitlist emails — retained until you unsubscribe or request deletion
  • Crash logs — auto-purged after 90 days

8. Security

  • All data in transit encrypted via TLS 1.2+
  • Passwords hashed with bcrypt (work factor ≥ 12)
  • Journal entries encrypted at rest
  • API secured with short-lived JWT access tokens and secure refresh rotation
  • Database access restricted and audit-logged

In the event of a data breach affecting your rights, we will notify you within 72 hours.

9. Children

NOEZDAY is for users aged [13 / 18] and above. If you believe a minor has registered, email privacy@noeasyday.app and we will delete the account.

10. Cookies

The website (noeasyday.app) does not use advertising or tracking cookies. Only a session cookie necessary for the waitlist form is used. The mobile app does not use browser cookies.

11. Changes

Material changes to this policy will be communicated via email (registered users) and a notice on the website. Continued use after the effective date constitutes acceptance.

12. Contact

Email: privacy@noeasyday.app
General: hello@noeasyday.app
Address: [YOUR ADDRESS, CITY, STATE, PINCODE]

Before going live: Fill in all placeholders above. Required before App Store submission.