Overview
Effective date: September 11, 2026
Nurra Family Hub ("Nurra", "we", "our", or "us") is a family organization application designed to help families manage daily life, communication, safety, household coordination, school information, health records, subscriptions, and other family-related activities.
This Privacy Policy explains how we collect, use, store, protect, share, and delete information when you use the Nurra Family Hub mobile application, website, and related services.
If you do not agree with this Privacy Policy, please do not use Nurra.
1. Who We Are
Nurra is designed primarily for families, parents, legal guardians, children, youth members, adult family members, service/helper users, and pet/household coordination.
- App name: Nurra Family Hub
- Website: https://nurra.app
- Company / Operator: Projekt X d.o.o.
- Contact email: support@nurra.app
- Address: Sarajevo, Bosnia and Herzegovina
2. Scope of This Privacy Policy
This Privacy Policy applies to:
- the Nurra Family Hub mobile app;
- the Nurra website;
- Nurra user accounts;
- family profiles and family circles;
- parent/guardian accounts;
- child/youth accounts or profiles;
- service/helper access where enabled;
- pet profiles;
- paid subscription and entitlement features;
- support, review, and demo accounts used for app review or testing.
2.1 Covered Nurra Modules
This Privacy Policy covers all Nurra modules, including:
- Family Core / Multi-Family Circles
- Shared Family Calendar
- Tasks & Chores
- Routines & Habits
- Rewards & Coins
- Shopping Lists
- Family Notes / Bulletin
- School Hub
- Family Communication Hub
- Maintenance / Inventory
- Emergency, Alerts & Locations
- Health Records
- Family Budget & Bills
- Pets
3. Core Privacy Principles
Nurra is built around the following privacy principles:
- We collect only the data needed to provide the features selected by the user.
- Most family information is optional and entered by the user or family administrator.
- We do not sell personal data.
- We do not use personal family data for advertising.
- We use limited first-party Product Analytics only for product operation and improvement, subject to the user choice described below.
- We do not allow advertisers to access your private family content.
- We do not intentionally expose private family content in push notifications.
- We use authentication, access controls, encryption, and other safeguards to protect sensitive information.
- Parents and family administrators control access to family spaces and role-based permissions.
- Users may request account deletion according to the process described in this policy.
4. Information We Collect
The information Nurra collects depends on which features you use. Not every user will provide every type of data listed below.
4.1 Account Information
When you create or use an account, we may collect:
- email address;
- password or authentication credential;
- account ID;
- name or display name;
- phone number, if provided;
- a Nurra-provided avatar selection or initials;
- account role;
- login status;
- account creation and update timestamps;
- device and session information.
Email is required for account registration. Other profile details are generally optional unless needed for a specific feature.
4.2 Family and Household Information
For Family Core and Multi-Family Circles, we may collect:
- family name;
- family description;
- a Nurra-provided family avatar selection or initials;
- family members;
- family roles;
- parent/guardian relationships;
- child/youth profiles;
- household settings;
- family invitations;
- role history;
- membership status;
- family preferences.
Family administrators may add other users to a family circle. Adult users may be invited by email. Child or youth access may be created through supported child-access flows, such as QR code or invitation flow, where implemented.
4.3 Role and Permission Information
Nurra uses role-based access controls. We may process role and permission information for:
- RC1 Family Administrator;
- RC2 Parent / Legal Guardian;
- co-parent or custody-related access;
- adult family member access;
- service/helper access;
- child/youth access;
- observer or emergency-only access;
- pet-related access.
This information is used to determine what each user can see, edit, create, delete, or manage.
4.4 Calendar Information
For the Shared Family Calendar, we may collect:
- event title;
- event date and time;
- location, if added by the user;
- notes;
- reminders;
- repetition settings;
- participants or family members linked to an event.
Calendar data is used to display and manage family events and reminders.
4.5 Tasks, Chores, Routines, and Habits
For Tasks & Chores and Routines & Habits, we may collect:
- task title;
- task description;
- assigned family member;
- due date;
- recurrence;
- completion status;
- rejection or approval notes;
- routine title;
- routine steps;
- habit completion information;
- activity history.
This data is used to organize family tasks, chores, routines, and habits.
4.6 Rewards and Coins
For Rewards & Coins, we may collect:
- reward title;
- reward description;
- coin balance;
- coin transaction history;
- redemption requests;
- approval or rejection notes;
- fulfillment notes;
- reward activity metadata.
This information is used to support family reward systems and child/youth motivation features.
4.7 Shopping Lists
For Shopping Lists, we may collect:
- shopping list title;
- shopping item names;
- item status;
- catalog item names;
- list event history;
- notes or payload information related to list changes.
This information is used to create, update, and share shopping lists within a family.
4.8 Family Notes / Bulletin
For Family Notes / Bulletin, we may collect:
- note title;
- note text;
- note items;
- author or creator;
- timestamps;
- family visibility settings.
This information is used to share family notes, reminders, and bulletin-style information.
4.9 School Hub Information
For School Hub, we may collect:
- school name;
- grade or class;
- section or group;
- teacher name;
- classroom;
- school phone;
- school email;
- subject names;
- grades or assessment values;
- assessment labels;
- school notes;
- school-related items.
School Hub information is entered by the family and used to help organize school-related information. Nurra does not verify school records with schools unless a separate feature or integration is explicitly introduced.
4.10 Family Communication Hub
For Family Communication Hub, we may collect:
- chat messages;
- message sender;
- message timestamps;
- family chat participation status;
- message metadata;
- moderation or access settings.
Family chat is intended for family members only, unless otherwise configured. Service/helper users are not automatically included unless a future feature explicitly permits it.
4.11 Maintenance / Inventory Information
For Maintenance / Inventory, we may collect:
- household asset names;
- asset categories;
- asset location;
- maintenance item titles;
- recurrence information;
- service provider names;
- notes;
- service records;
- inventory item names;
- storage location;
- expense notes;
- service contact details.
This information helps families manage household assets, supplies, inventory, service providers, and maintenance records.
4.12 Emergency, Alerts, and Location Information
For Emergency, Alerts & Locations, we may collect:
- emergency profile information;
- emergency contact names;
- emergency contact phone numbers;
- child name or profile label;
- emergency notes;
- emergency alert messages;
- safe-place or safe-zone names;
- safe-zone addresses;
- latitude and longitude;
- location accuracy;
- altitude, speed, or heading where supported;
- device name or model;
- operating system version;
- network type;
- emergency session data;
- location update timestamps.
Location data is used only for emergency, safety, safe-place, or location-related family features that the user or parent/guardian enables.
Nurra requests location permission only when a supported Family Safety feature requires it. Any background or "Always" location access is limited to the safety or safe-place functionality explained when permission is requested.
4.13 Health Records
For Health Records, we may collect sensitive health-related information entered by users, parents, or guardians, including:
- blood type;
- height and weight;
- allergies;
- current medications;
- important medical conditions;
- primary doctor information;
- insurance information;
- emergency contact details;
- emergency medical notes;
- medication names;
- dosage;
- frequency;
- instructions;
- vaccine records;
- doctor appointment details;
- clinic information;
- safety items;
- growth records;
- development notes.
Health Records are optional and user-entered. Nurra is not a medical provider and does not provide medical advice, diagnosis, treatment, or emergency medical services.
4.14 Family Budget & Bills
For Family Budget & Bills, we may collect:
- money account names;
- linked bank account reference labels, if provided;
- budget category names;
- bill names;
- bill due dates;
- payment method labels;
- notes;
- money transfer notes;
- wallet transaction notes;
- money request reasons.
Nurra is not a bank, financial advisor, payment processor, or regulated financial institution. Budget and bills features are for family organization only unless a future regulated integration is clearly introduced.
4.15 Pets
For Pets, we may collect:
- pet profile information;
- pet color or markings;
- microchip ID, if provided;
- pet health records;
- allergies;
- conditions;
- surgeries;
- injuries;
- emergency notes;
- emergency phone number;
- insurance number;
- vaccine records;
- medication details;
- vet visit information;
- clinic and veterinarian names;
- treatment notes;
- pet care routines;
- pet expense notes.
Pet information is used to help families organize pet care, health, routines, and expenses.
4.16 Subscription and Payment-Related Information
If you purchase a subscription or paid feature, Apple App Store or Google Play may process your payment. We may receive or store subscription-related information needed to verify entitlement, such as:
- subscription plan;
- product ID;
- purchase status;
- entitlement status;
- transaction identifiers;
- original transaction identifiers;
- purchase verification payloads;
- subscription renewal or cancellation status;
- sandbox/test subscription status where applicable.
We do not directly collect full payment card details through the app. Payments are processed by Apple, Google, or other approved app-store/payment providers.
4.17 Device, Technical, and Security Information
We may collect technical information needed to operate, secure, and troubleshoot the service, including:
- device type;
- operating system;
- app version;
- language/locale;
- IP address;
- authentication logs;
- error logs;
- security events;
- push notification token and associated app-installation identifier;
- operational error and request diagnostics generated by Nurra services.
This information is used for security, debugging, reliability, abuse prevention, and service improvement.
4.18 Website and Cookie Information
When you visit our website, we may collect limited website data such as:
- browser type;
- device type;
- pages visited;
- approximate region;
- referral source;
- cookies or similar technologies, if used.
If analytics cookies or marketing cookies are introduced, the website should explain them and provide any required consent mechanism.
4.19 Product Analytics
Nurra uses limited first-party Product Analytics operated by Projekt X/Nurra to understand product and feature interaction, approved success or failure states, and general product usage patterns, and to improve Nurra.
Product Analytics events use an event UUID and an HMAC-pseudonymous account identifier. An event may also include a pseudonymous family identifier or pseudonymous family-account identifier when needed to understand a family-scoped feature. Analytics events do not contain raw account IDs, names or email addresses as identifiers, IDFA, or another advertising identifier.
Eligible users can control optional Product Analytics in the app under "My Profile → Privacy & Data → Share Product Analytics." When this setting is ON, Nurra may collect approved optional Product Analytics events. Turning it OFF stops future optional Product Analytics collection. Essential authentication, security, audit, notification, and operational processing continues. This preference is not an Apple AppTrackingTransparency control.
Child roles RC6–RC9 follow the preference selected by the responsible or primary child administrator and cannot independently manage this setting.
- Optional Product Analytics does not collect the actual content or private values of Health records;
- optional Product Analytics does not collect private financial details or precise location;
- optional Product Analytics does not collect private family Chat content or School content;
- optional Product Analytics does not collect search query text;
- an approved search event may record that a search occurred and its result state, but not the search text, a hash of that text, its length, or another representation from which it could be reconstructed.
Nurra retains raw analytics events for 7 days, processing receipts for 14 days, pseudonymous presence and contribution records for 120 days, and aggregate analytics for 12 months.
Previously generated pseudonymous analytics data is not necessarily deleted immediately when an account is deleted. It remains subject to the applicable retention schedule and is deleted or anonymized when that period expires.
Nurra does not use Product Analytics for advertising, targeted advertising, remarketing, ad measurement, attribution, or cross-app or cross-site tracking. Nurra does not use ATT, IDFA, Firebase Analytics, third-party behavioral analytics SDKs, or advertising-attribution SDKs.
4.20 Camera, Photos, and Files
Nurra accesses the camera only when a user chooses to scan a supported invitation QR code. Camera frames are processed for the scan and are not collected as still images.
Current Nurra functionality does not provide Photo Library selection, still-photo upload, general document or file upload, or attachment upload. Profile and family avatars use Nurra-provided assets or initials.
5. How We Use Information
We use information to:
- create and manage user accounts;
- create and manage family circles;
- support role-based access and permissions;
- provide each Nurra module selected by the family;
- send reminders and notifications;
- support emergency and safety features;
- process subscription entitlement status;
- provide customer support;
- maintain security;
- prevent abuse or unauthorized access;
- improve reliability and app performance;
- understand approved product and feature interactions through limited first-party Product Analytics;
- comply with legal obligations;
- respond to account deletion or privacy requests.
We do not use private family content for third-party advertising.
6. Legal Bases for Processing
Where applicable under privacy laws such as the GDPR, we process personal data based on one or more of the following legal bases:
- performance of a contract, to provide the Nurra service;
- consent, where required for optional data or permissions;
- legitimate interests, such as security, fraud prevention, and service improvement;
- compliance with legal obligations;
- protection of vital interests, where emergency or safety features are used.
For child/youth profiles and family-managed accounts, parents or legal guardians are responsible for creating, managing, and authorizing the relevant family data where required by law.
7. Children and Family Accounts
Nurra is designed for family use and may include child/youth profiles or child/youth access features managed by parents or legal guardians.
Parents or legal guardians may create, manage, or supervise child/youth profiles. Children should not create independent accounts or provide personal information without appropriate parent or guardian involvement where required by law.
Nurra does not request or store child dates of birth, exact ages, or years of birth through the child-role flow. It uses configured child-role classifications RC6–RC9 instead.
RC6–RC9 users cannot independently own a family through the child-role flow. Their applicable privacy controls, including the optional Product Analytics preference, are managed by the responsible or primary child administrator.
Parents or legal guardians may:
- create child/youth profiles;
- manage access permissions;
- control participation in family modules;
- request deletion of child/youth data;
- manage emergency and safety information;
- control whether a child/youth device is linked to the family.
We do not knowingly collect personal data from children without parental or guardian involvement where required.
Nurra does not sell child personal data, use it for advertising or commercial profiling, or track child users across other companies' apps or websites. Supported child location processing is limited to Family Safety functionality and the permissions granted on the device.
8. Location Data
Nurra may process location data only when location-related features are enabled or used, such as:
- emergency alerts;
- child safety status;
- safe places or safe zones;
- location sharing requested by a parent/guardian;
- emergency session tracking;
- location-based family safety indicators.
Nurra requests location permission only when needed for the relevant Family Safety feature. If a user denies location permission, non-location features remain available where they do not depend on location.
Location data may include approximate or precise location depending on the feature and operating system permission selected by the user.
Nurra does not sell location data. Nurra does not use family location data for advertising.
9. Health and Emergency Information
Health and emergency information may be sensitive. This information is optional and entered by users, parents, or guardians for family organization and emergency preparedness.
Nurra is not a healthcare provider. Nurra does not provide medical advice, diagnosis, treatment, or emergency response services. In an emergency, users should contact local emergency services.
Health and emergency information should be shared only with trusted family members or authorized users according to family permissions.
10. Push Notifications
Nurra may send push notifications for:
- family updates;
- task reminders;
- calendar reminders;
- chat or communication updates;
- emergency or safety alerts;
- location/safe-place events;
- subscription or account-related notices.
Nurra uses generic notification content where possible and excludes private family content such as health details, exact location coordinates, full chat content, budget details, or sensitive child information unless the information is necessary for the requested feature and permitted.
Users can manage push notification permissions through their device settings.
11. Data Sharing
We do not sell personal data.
We may share limited information only in the following situations:
11.1 Within Your Family Circle
Information may be visible to family members or authorized users based on roles and permissions. For example, a parent or family administrator may see more information than a child/youth user or limited observer.
11.2 Service Providers
Nurra uses the following service providers for current production services:
- Hostinger provides production hosting and infrastructure, PostgreSQL and Redis infrastructure, backups, and SMTP services;
- Apple provides the App Store, Sign in with Apple, Apple Push Notification service (APNs), and applicable Apple platform services;
- Google provides Google Sign-In, Google Play where applicable, Firebase Cloud Messaging, and supporting SDK infrastructure.
These providers may process the data necessary to provide their respective services to Nurra, subject to their applicable terms and data-protection obligations. Nurra does not treat this processing as a sale or use it for advertising. Nurra does not use Firebase Analytics.
11.3 App Stores and Payment Providers
Apple, Google, and related payment systems may process subscription purchases, refunds, cancellations, and entitlement information according to their own terms and privacy policies.
11.4 Legal or Safety Reasons
We may disclose information if required to:
- comply with law;
- respond to valid legal requests;
- protect users, children, families, or the public;
- investigate fraud, abuse, or security issues;
- enforce our terms.
11.5 Business Transfers
If Nurra is involved in a merger, acquisition, restructuring, or asset transfer, user information may be transferred as part of that transaction, subject to this Privacy Policy or a replacement policy with appropriate notice.
12. Data Security
We use technical and organizational safeguards designed to protect user information, including:
- HTTPS/TLS for data in transit;
- authentication and access control;
- role-based permissions;
- server-side secret management;
- application-level encryption for selected sensitive backend fields;
- a SQLCipher-encrypted mobile offline database;
- Keychain or secure storage for supported credentials and secrets;
- Messaging Layer Security (MLS), RFC 9420, for supported Chat flows;
- client-side encryption for supported Health v2 flows;
- encrypted database backups;
- logging controls;
- review of sensitive push payloads;
- restrictions on access to production systems.
These safeguards apply according to the relevant data flow and do not mean that every Nurra data item is end-to-end encrypted or that every production data store uses the same at-rest encryption mechanism. No system is completely secure. Users should protect their account credentials and use strong passwords where applicable.
13. Data Retention
We keep information for as long as needed to:
- provide the Nurra service;
- maintain family records selected by users;
- support subscriptions and entitlement status;
- comply with legal obligations;
- resolve disputes;
- prevent abuse;
- maintain security.
When an account or family data is deleted, we will delete or de-identify associated personal data unless we are required to retain limited information for legal, security, fraud prevention, accounting, or compliance reasons.
Previously generated pseudonymous Product Analytics data follows the retention schedule in Section 4.19 rather than being deleted immediately solely because the related account is deleted.
The standard backup model includes daily encrypted PostgreSQL backups retained for up to 7 days, Hostinger VPS restore points available for approximately up to 14 days, and encrypted off-site database backups stored in Frankfurt as the latest 7 backups. Deleted information may therefore remain temporarily in a rotating backup until that backup expires or is replaced.
Standard rotation does not, by itself, describe any separately created manual backup. Any such backup requires separately documented retention and deletion controls.
14. Account Deletion
An adult user can request account deletion in the app under "My Profile → Delete Account." Privacy choices and account-deletion guidance are available at https://nurra.app/legal/account-deletion-instructions/. Users who cannot access the in-app flow may contact support@nurra.app.
Removing or managing a child profile is an administrator-managed family action and is not the child's independent account-deletion flow.
Account deletion is intended to remove the user account and associated personal data, subject to legal, security, subscription, fraud-prevention, or operational exceptions.
An owned family may enter a recovery period before final family deletion: 7 days for Free, 15 days for Premium, and 30 days for Family+. Account deletion therefore does not necessarily remove all associated family data immediately.
Certain shared family data may require additional handling depending on:
- whether the user is the family administrator;
- whether other family members still use the family space;
- whether ownership must be transferred;
- whether child/youth profiles are managed by a parent or guardian;
- whether legal or safety retention obligations apply.
When an account is deleted, Nurra invalidates active sessions and removes or disables applicable authentication tokens. Previously generated pseudonymous analytics and rotating backups follow the retention periods described in this policy.
15. Your Privacy Rights
Depending on your location, you may have rights to:
- access your personal data;
- correct inaccurate data;
- delete your personal data;
- object to certain processing;
- restrict certain processing;
- receive a copy of certain data;
- withdraw consent where processing is based on consent;
- complain to a data protection authority.
To exercise privacy rights, contact us at:
support@nurra.app
We may need to verify your identity before processing a request.
16. International Data Transfers
Nurra may process and store information in countries other than the country where you live. Where required, we use appropriate safeguards for international data transfers, such as contractual protections or other legally recognized transfer mechanisms.
17. Third-Party Links and Services
Nurra may contain links to external websites, app-store pages, payment systems, or third-party services. We are not responsible for the privacy practices of third parties. Users should review the privacy policies of those third parties.
18. Advertising and Tracking
Nurra does not use personal data or private family content for advertising, targeted advertising, remarketing, ad measurement, or advertising attribution.
Nurra does not sell personal data.
Nurra does not track users across other companies' apps or websites, access Apple's IDFA, or use AppTrackingTransparency for tracking purposes.
Nurra's limited Product Analytics is first-party. Nurra does not use Firebase Analytics, third-party behavioral analytics SDKs, or advertising-attribution SDKs.
19. App Store and Google Play Disclosures
Nurra maintains its Apple App Store Privacy Nutrition Labels and Google Play Data Safety disclosures to reflect this Privacy Policy and the app's actual behavior.
Depending on enabled features, Nurra may disclose collection of data categories such as:
- contact information;
- identifiers;
- user content;
- health and fitness or health-related information;
- financial information related to budget/bills features;
- location;
- diagnostics;
- usage data;
- purchase/subscription information.
Store disclosures are reviewed against the final app build, enabled SDKs, first-party Product Analytics, and actual data flows.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and may provide additional notice through the app, website, or other appropriate means.
Continued use of Nurra after an updated Privacy Policy becomes effective means you accept the updated policy where permitted by law.
21. Contact Us
For privacy questions, account deletion requests, or data rights requests, contact:
- Projekt X d.o.o.
- Email: support@nurra.app
- Website: https://nurra.app
- Address: Sarajevo, Bosnia and Herzegovina
22. Module-Specific Data Summary
The table below summarizes the main data types that may be processed by each Nurra module.
| Module | Main Data Types | Purpose |
|---|---|---|
| Family Core | family name, roles, memberships, invitations, profiles | family setup and access control |
| Shared Family Calendar | events, dates, reminders, locations, notes | family scheduling |
| Tasks & Chores | task titles, descriptions, assignments, completion status | family task management |
| Routines & Habits | routine names, steps, completion records | family routines and habits |
| Rewards & Coins | reward titles, coin transactions, redemption notes | reward management |
| Shopping Lists | list titles, item names, item status | family shopping coordination |
| Family Notes / Bulletin | note titles, note text, note items | family notes and announcements |
| School Hub | school name, class, teacher, subjects, grades, notes | school organization |
| Family Communication Hub | messages, sender, timestamps | family communication |
| Maintenance / Inventory | asset names, locations, service records, notes | household management |
| Emergency, Alerts & Locations | emergency contacts, location, safe zones, device status | safety and emergency features |
| Health Records | allergies, medications, doctor info, vaccines, health notes | family health organization |
| Family Budget & Bills | account labels, bill names, budget categories, notes | household budget organization |
| Pets | pet profiles, health records, vaccines, vet visits, routines | pet care organization |
23. Data Not Collected by Current Features
Current Nurra features do not collect:
- full payment card numbers;
- government identification numbers;
- biometric identifiers;
- advertising identifiers for tracking;
- child dates of birth, exact ages, or years of birth through the child-role flow;
- still photos, Photo Library content, general documents, files, or attachments;
- personal data for sale to advertisers;
- private family content for third-party advertising.
If this changes, this Privacy Policy and app-store disclosures must be updated before or at the time of the change.
24. Important Safety Notice
Nurra helps families organize information, reminders, and safety-related data. Nurra is not a substitute for emergency services, medical professionals, legal professionals, financial advisors, schools, or law enforcement.
In an emergency, contact local emergency services immediately.