Privacy Policy
Effective date: 14 October 2025 • Version: v2025-10-14
This Privacy Policy (the “Policy”) applies to the Nelaton mobile application (the “App”) and related services provided by Ulibkin OÜ (Estonia), acting as the data controller (“we”, “us”). You may use the App only after accepting this Policy and the Terms of Use. For the processing of health data, we will ask for your explicit consent inside the App.
1. At a glance (TL;DR)
- Your health data is stored in the EU (Supabase, Frankfurt) and protected in transit and at rest.
- We process health data only with your explicit consent (GDPR Art. 9(2)(a)). You can withdraw it at any time.
- Analytics (Amplitude, Google Analytics) and attribution (AppsFlyer) run only after you accept the in-app consent banner.
- Subscriptions are processed via RevenueCat on top of Apple App Store / Google Play; we never see your card details.
- You can export, correct or delete your data at any time. Backups are retained for up to 30 days.
- The App is intended for users aged 16 and over.
2. Data controller
Ulibkin OÜ, registered in Estonia, is the controller for personal data processed through the App. Contact: support@nelaton.app.
3. Categories of data we process
- Account data: email address, authentication identifiers, language and country settings.
- Health data (special category): catheterization log, fluid intake, urine volume, symptoms, schedules, notes and AI-generated reports you create in the App.
- Subscription data: subscription status, plan, purchase and renewal events (via RevenueCat / Apple / Google).
- Technical data: device model, OS version, app version, language, crash and diagnostic logs.
- Analytics & attribution data: pseudonymous event data and install attribution, processed only with consent.
- Support communications: messages you send to support@nelaton.app.
4. Purposes and legal bases
- Providing the App and your account — performance of a contract (GDPR Art. 6(1)(b)).
- Storing and displaying your health data, generating AI reports — your explicit consent (GDPR Art. 9(2)(a)).
- Subscription processing, fraud prevention, accounting — performance of a contract and legal obligations (GDPR Art. 6(1)(b) and (c)).
- Security, abuse prevention, service stability — our legitimate interests (GDPR Art. 6(1)(f)).
- Analytics, attribution and product improvement — your consent (GDPR Art. 6(1)(a)), collected only after you accept the in-app consent banner.
5. Recipients and processors
We share data only with processors acting on our instructions:
- Supabase (EU, Frankfurt) — cloud database, authentication, storage and edge functions for the App.
- RevenueCat — subscription management on top of Apple App Store and Google Play.
- AppsFlyer — install attribution (with consent).
- Amplitude, Google Analytics — product analytics (with consent).
- Apple and Google — app distribution, in-app purchases, push notifications.
- Email and support tooling — to answer your requests.
6. International transfers
Your health data is stored on EU servers. Some processors (for example analytics or attribution providers) may transfer limited data outside the EEA. Such transfers are protected by the European Commission’s Standard Contractual Clauses (SCC) and, where applicable, by the EU–U.S. Data Privacy Framework (DPF).
7. Retention
- Account and health data are stored as long as your account exists.
- On account deletion, your data is removed from production systems promptly. Encrypted backups are retained for up to 30 days and then irreversibly deleted.
- Billing and tax records are retained for the period required by law.
8. Your rights
Under the GDPR you have the right to:
- access your data and obtain a copy;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to processing;
- data portability;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with your local Data Protection Authority (in Estonia: Andmekaitse Inspektsioon).
You can exercise most rights directly in the App (export, delete account, manage consent) or by writing to support@nelaton.app.
9. Security
We apply technical and organisational measures appropriate to the risk: encryption in transit (TLS) and at rest, strict access controls, audit logging, segregation of duties, and regular review of our infrastructure. No method of transmission or storage is 100% secure, but we work continuously to protect your data.
10. Children
The App is intended for users aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, please contact support@nelaton.app and we will delete it.
11. AI reports
The App can generate summaries and reports from your health log using AI models. These reports are informational only, are not a medical diagnosis, and do not replace consultation with a qualified healthcare professional. AI processing is performed on data you explicitly submit for this purpose.
13. Changes to this Policy
We may update this Policy from time to time. The current version and effective date are always shown at the top of this page. For material changes we will endeavour to notify you via the App and/or the app stores.
14. Contact
Ulibkin OÜ
E-mail: support@nelaton.app
Change log
- 14.10.2025 — migration to EU cloud (Supabase); added AI reports; analytics based on consent (Amplitude / GA); attribution (AppsFlyer); subscriptions (RevenueCat); deletion procedures and 30-day backup retention; age threshold 16+; clarified international transfers (SCC / DPF).