Nirantar. Privacy Policy

The streak that survives a bad day.

Last updated: August 30, 2026

Back to Nirantar

Supplemental Policy. This Nirantar Privacy Policy is supplemental to, and governed by, the GenAI Unplugged master Privacy Policy. Rights, legal bases, and general practices not restated here are inherited from the master Policy. In the event of a conflict between this Policy and the master Privacy Policy, the master Privacy Policy shall control.

1. Data Controller

GENAI UNPLUGGED LLC is the data controller for Nirantar. There is no co-brand partner, distribution partner, or joint operator for this product. GENAI UNPLUGGED LLC alone is responsible for the data practices described in this Policy, and no other entity receives your data for marketing or any other purpose beyond what Section 5 describes.

2. What We Collect

We do not collect any photo, image, or video of you or your body. See Section 9, "No Images Stored."

3. What We Do With It

We do not run usage analytics on your account, do not run advertising, and do not enroll your email in a newsletter through Nirantar.

4. No Analytics, No Advertising, No Tracking

Nirantar loads no third-party analytics script, no advertising or retargeting pixel, and no third-party font or script CDN. The app is served from our own origin with our own stylesheet and our own icons. Nothing you do inside Nirantar is measured by, or shared with, an outside analytics or advertising company, because there is not one in the stack.

5. Third-Party Processors

ProcessorPurposeData SentRetention
Oracle Cloud Infrastructure (United States) Runs the Nirantar application and the SQLite database Everything you enter into Nirantar; this is where it lives For the lifetime of your account, or until you delete a record or wipe your account
Cloudflare CDN and TLS in front of our origin, Full (strict) mode Standard request metadata (IP address, headers) needed to route and secure traffic. No Nirantar application data is stored by Cloudflare. Held by Cloudflare under its own privacy policy. We are not on a plan that gives us access to raw edge logs, so we neither receive nor store them.
Amazon SES (primary) / Resend (fallback) Sends your sign-in magic link email, and nothing else Your email address and the one-time link Not retained by us at all. Delivery metadata is held by the provider under its own privacy policy.
Lemon Squeezy (future, once the one-time purchase ships) Merchant of record for your purchase Your email address and an order identifier are shared back to us. Your payment details stay with Lemon Squeezy. Per Lemon Squeezy's own retention policy

We never see, receive, or store your payment card details. When the one-time purchase ships, Lemon Squeezy is the merchant of record: it processes your payment and is responsible for collecting and remitting any sales tax or VAT that applies to your purchase. You are not separately billed by us for taxes, and we do not ask you to handle a tax obligation that Lemon Squeezy has already collected on your behalf.

6. Sessions and Cookies

Sign-in is passwordless. We email a single-use magic link that expires in one hour. Once you use it, we set fit_session, an HttpOnly session cookie carrying a JWT (issuer and audience nirantar), for 90 days. It is a first-party, essential cookie: it does not track you across other sites and is not used for analytics or advertising. Nirantar sets no other cookie.

Separately, your browser keeps an offline write queue (an IndexedDB "outbox") on your own device, so you can log a day with no connection. Those writes live locally until your connection returns, at which point they sync to our server and are cleared from the queue. The queue itself never leaves your device; only the individual writes it holds, once synced, reach us.

7. Retention

Data TypeRetention Period
Profile answersUntil you edit them, delete them, or wipe your account
Daily logs (weight, measurements, task history)For the lifetime of your account, so your history and trend charts stay intact. Never deleted automatically.
fit_session cookie90 days, or until you sign out
Magic link tokenSingle-use, expires in 1 hour, then discarded
Offline outbox (IndexedDB)Device-only; cleared once synced
Web server request logs (IP, timestamp, path, user agent)14 days on our server, then deleted by daily log rotation
Email delivery metadata (SES / Resend)Not held by us. The provider retains it under its own policy.
Cloudflare edge / request logsNot held by us. We cannot access raw edge logs on our plan.

8. Your Data, Self-Service

You can export your entire account as JSON from inside the app at any time. You can also delete everything yourself with one button. The wipe clears every record keyed to you except your sign-in email address, your unit and timezone preferences, and the record that you accepted these Terms. Those three survive so the app still knows who you are and how to show you a number correctly if you come back.

9. No Images Stored

Nirantar does not store any photo of you. An earlier version briefly supported a progress-photo upload; that feature, and every photo it had collected, has been deleted from our infrastructure. The daily progress photo is now a task you tick off after taking it on your own device, on your own camera. Nothing about that photo, including the file itself, ever reaches our server.

10. Health Data Is Never Sold or Shared for Marketing

We never sell your health data, and we never share it with an advertiser or a data broker. This is absolute, with no carve-outs. The only places your data goes are the processors listed in Section 5, each acting on our instruction to run the app, never to market to you.

11. Is Nirantar a HIPAA Covered Entity?

No. HIPAA applies to health care providers, health plans, health care clearinghouses, and their business associates, when they conduct specific regulated transactions. Nirantar is none of those. It is a self-tracking tool operated by a software company, and you use it directly, not through a doctor's office, a clinic, or an insurer. Because of that, HIPAA does not apply to Nirantar or to the data you put into it.

What does apply instead: the FTC Health Breach Notification Rule (Section 12), applicable state consumer-health-data laws such as Washington's My Health My Data Act (Section 13), and the commitments in this Policy, including Section 10 above.

12. Breach Notification

If a breach affecting your personal information occurs, we will notify affected users without unreasonable delay, consistent with the FTC Health Breach Notification Rule, which covers consumer health apps like Nirantar that fall outside HIPAA. We will also notify the FTC and any other authority required by law.

13. Your Rights

General US users. You can request access to, correction of, or deletion of your data at any time by emailing [email protected], in addition to using the in-app export and wipe tools described in Section 8. If you are a California resident, the voluntary rights described in the master Privacy Policy, Section 7 (CCPA) apply to you.

Washington residents. Washington's My Health My Data Act treats information like your weight, body measurements, and fitness data as "consumer health data" and gives you the right to confirm what we collect about you, access it, delete it, withdraw any consent you have given, and appeal a denial of these rights. This law applies regardless of our revenue. To exercise any of these rights, email [email protected].

14. International Transfer

GENAI UNPLUGGED LLC is based in Pennsylvania, USA, and Nirantar's application and database run on Oracle Cloud Infrastructure in the United States. If you use Nirantar from outside the US, your information is transferred to, and stored in, the United States.

15. Conflict With the Master Privacy Policy

Where this Policy and the master Privacy Policy disagree, the master Privacy Policy controls.

16. Effective Date

This Nirantar Privacy Policy is effective August 20, 2026.