Numera — Privacy & Data
Draft. Last updated: 2026-06-11. This document is the engineering copy of Numera's privacy policy. Final wording must be reviewed by qualified legal counsel before it is published in-app or linked in the app stores. Items in [SQUARE BRACKETS] are placeholders that must be completed (legal entity details, public policy URL, hosting region, supervisory authority, DPO) before publication.
This policy explains what data Numera stores, why we store it, who we share it with, and how to exercise your rights under the EU/UK General Data Protection Regulation (GDPR) and the Israeli Privacy Protection Law. It also covers the disclosures required by the Apple App Store and Google Play (Section 12).
1. Who we are (data controller)
Numera is operated by EVALIX ("Numera", "we", "us"), registered at [REGISTERED ADDRESS — pending company registration], company number [COMPANY / REGISTRATION NUMBER — pending company registration].
For all data-protection matters we are the data controller of the information described in this policy.
- Contact for privacy matters: [email protected]
- Data Protection Officer: We have not appointed a Data Protection Officer. Numera does not carry out large-scale monitoring or large-scale processing of special-category data, so a DPO is not mandatory under GDPR Art. 37. Privacy enquiries are handled at [email protected].
- EU/UK representative (GDPR Art. 27): Not applicable — Numera is not offered to users in the EU/EEA at this time. If EU/EEA availability is enabled in a future release, an EU representative must be appointed and this section updated first.
2. Who this policy applies to and minimum age
This policy applies to everyone who uses the Numera app on iOS or Android.
Numera is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect data from anyone below this age. If you believe a minor has provided us data, contact us and we will delete it.
This policy also governs data you enter about other people (for example, a partner you add for a compatibility reading). See Section 9.
3. What data we store
When you create a Numera account, we store the following under your user ID:
| Table | Contents |
|---|---|
user_profiles | Email, display name, subscription tier, language preference |
saved_charts | Birth name, Hebrew name (if provided), birth date, birth time and place, and the computed numerology values |
deep_dive_cache | AI-generated narrative analyses, cached so a regenerated report doesn't re-charge the AI for the same chart |
deep_dive_logs | One row per AI call (topic + chart name + timestamp) for billing/analytics |
saved_reports | HTML/PDF reports you've generated |
practitioner_branding | Logo, business name, contact details (practitioner accounts only) |
feature_quotas | Per-feature usage counters (e.g., 7 of 50 deep dives this month) |
feature_quota_refunds | Audit rows written when a deep-dive failed and we refunded the credit |
When you use the Couple Compatibility and Relationship Insights features, we additionally store:
| Table | Contents |
|---|---|
partner_profiles | Information you enter about another person so you can compare charts: their name, optional Hebrew name, birth date, and optionally birth time and birth place |
compatibility_analyses | The computed three-axis (numerology / astrology / Kabbalah) reading between you and a partner, including the AI synthesis paragraph |
relationship_insights | The free-text questions you ask about a saved analysis (e.g. about a breakup, an ongoing relationship, or a recurring pattern), the wellbeing classification of that question, and the AI's written response |
gdpr_audit_log | A short-lived record of data export and deletion requests (see Section 14) |
We do not sell your data, and we do not share it with third parties for advertising or marketing.
4. Legal bases for processing
We rely on the following lawful bases under GDPR Article 6 (and the equivalent grounds under Israeli law):
- Performance of a contract (Art. 6(1)(b)) — to create your account, generate and save your charts, run compatibility analyses and insights, and provide the subscription you paid for.
- Consent (Art. 6(1)(a)) — where you choose to provide optional data (e.g. a Hebrew name, birth time, birth place) or enter data about another person. You can withdraw consent at any time (Section 11).
- Explicit consent for special-category data (Art. 9(2)(a)) — where your free-text Insights questions reveal sensitive information (see Section 7).
- Legitimate interests (Art. 6(1)(f)) — to keep the service secure, prevent abuse, enforce usage quotas, and maintain a short audit trail of deletion/export requests. We balance these interests against your rights and only process what is necessary.
- Legal obligation (Art. 6(1)(c)) — to retain limited billing/tax records and to evidence that a data request was honoured.
5. How we use your data
We use your data only to:
- Generate your numerology charts (computed on your device — basic chart data does not leave your phone unless you save it or request an AI analysis).
- Produce AI deep-dives, compatibility readings, and relationship insights when you request them.
- Manage your account, subscription, and usage quotas.
- Route crisis-flagged questions to appropriate support resources (Section 7).
- Keep the service secure and prevent misuse.
- Comply with our legal obligations and respond to your data-rights requests.
We do not use your data to train AI models, and we do not profile you for advertising.
6. Third parties and international transfers
To run Numera we share the minimum necessary data with the following processors. Your account and app data is stored inside the European Union. Some processors operate outside the European Economic Area (EEA) (notably in the United States); where that is the case, the transfer is protected by appropriate safeguards — Standard Contractual Clauses, and, where the processor is certified, the EU–US Data Privacy Framework.
| Processor | What they receive | Purpose | Location |
|---|---|---|---|
| Anthropic (Claude AI) | Your chart data and the free-text content of your Insights questions when you request an AI analysis. Your name and email are never sent. | To generate the narrative analysis and insight text | United States |
| Supabase | All account and app data (hosting, database, authentication) | To store your data securely | European Union (Frankfurt, Germany — eu-central-1) |
| RevenueCat | A subscription customer ID and purchase/entitlement data | To manage subscriptions across Apple and Google | United States |
| Apple / Google | Billing and receipt data | To process in-app purchases | Global |
| OpenStreetMap (Nominatim) | The birth city you type into the search box (not your name, and only when you look up a city) | To resolve a city name to coordinates and time zone for astrology | European Union (operated by the OpenStreetMap Foundation) |
Anthropic processes the data to produce the response and, per their terms, does not retain it to train their models. We send only what is needed for the feature you requested.
7. Sensitive content and wellbeing
Some of what Numera processes is unusually personal, and we want to be explicit about it.
Your Insights questions. When you ask a relationship question, the text you write is stored in relationship_insights and sent to Anthropic to generate a response. These questions can be emotionally significant. They are visible only to you (enforced at the database level) and are deleted when you delete the analysis, the partner, or your account.
Special-category data. Your free-text questions, your spiritual/Kabbalistic inputs, or details about your relationships may incidentally reveal information that GDPR treats as special-category — for example data concerning health, religious or philosophical beliefs, or your sex life. Where this happens, our legal basis is your explicit consent, given by choosing to use the feature. You are never required to share such information, and you can delete it at any time.
Crisis and wellbeing handling. Before generating an insight, your question passes through an automated wellbeing classifier. If it detects crisis-level content (such as references to self-harm or abuse), the app prioritises showing you localised support resources (e.g. ERAN 1201 in Israel, 988 in the US, Samaritans 116 123 in the UK) ahead of any chart content. This classification is automated; flagged questions are not reviewed by staff as a matter of course, and the classifier result is stored alongside your question solely to deliver the correct response. The classifier is a safety feature, not a substitute for professional help, and does not contact any third party or authority on your behalf.
8. How long we keep your data
- Account and app data (charts, analyses, insights, quotas) is kept for as long as your account is active, and is deleted when you delete it or close your account (Section 11).
- Billing records required by law are retained for the period mandated by applicable tax/accounting rules.
- The deletion/export audit log is kept for 30 days and then automatically purged (Section 14).
- Cached AI analyses expire automatically after 30 days.
9. Data about other people (partner profiles)
The Couple Compatibility feature lets you add another person as a "partner profile." That person is a separate data subject with their own privacy rights, even though they don't have a Numera account.
By adding someone, you confirm you have a legitimate reason to enter their birth information and that you will honour their wishes if they ask you to remove it. Numera stores this data only to provide the reading you requested, never contacts the person, and never makes their profile visible to anyone but you.
You can delete a partner and everything tied to them at any time, from the partner detail screen — see Section 13. If a person whose data you entered contacts us directly and asks for removal, we may need to coordinate with you to identify and erase the relevant records, and we will act on a valid request.
10. How we protect your data
- All app data is stored with row-level security: every database query is automatically scoped to the requesting user, so one user cannot read another user's data even in the event of a bug.
- The Anthropic API key and all AI prompt logic live server-side, never on your device.
- Data is transmitted over encrypted connections (HTTPS/TLS) and stored by our hosting provider with encryption at rest.
- No security measure is perfect; we cannot guarantee absolute security, but we work to protect your data using industry-standard practices.
11. Your rights
Under GDPR and Israeli privacy law you have the following rights. To exercise any of them, use the in-app controls below where available, or contact [email protected].
- Access — get a copy of the data we hold about you.
- Rectification — correct inaccurate or incomplete data. Most fields can be edited directly in the app.
- Erasure — delete your data ("right to be forgotten").
- Portability — receive your data in a machine-readable format.
- Restriction — ask us to limit how we process your data while a query is resolved.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where processing relies on consent, withdraw it at any time (this does not affect processing already carried out).
- Lodge a complaint — you may complain to a supervisory authority. In Israel this is the Privacy Protection Authority (PPA) — https://www.gov.il/en/departments/the_privacy_protection_authority ; in the UK it is the Information Commissioner's Office (ICO) — https://ico.org.uk ; in the EU it is your local data-protection authority (the full list is published by the European Data Protection Board — https://edpb.europa.eu/about-edpb/about-edpb/members_en ).
We respond to rights requests within 30 days (GDPR Article 12).
Right to access (download your data)
Settings → Privacy & Data → Download my data.
Produces a JSON file containing every record listed in Section 3. The download is a one-shot operation; we don't store the export.
Right to erasure (delete everything)
Settings → Privacy & Data → Delete all my data.
Requires you to re-enter your password (a defence against an unattended device wiping your account). After confirmation:
- Your account record is deleted, which automatically cascades to every table listed above via foreign-key constraints.
- You are signed out and returned to the welcome screen.
- An audit row is written recording that the deletion took place (your user ID, your email at the time, the timestamp, and the per-table row counts that were removed).
Deletion is permanent and irreversible. We cannot recover deleted accounts.
Right to data portability
The downloaded JSON is machine-readable and structured per-table, so you can import the relevant pieces into any other system you choose.
12. Platform privacy disclosures (Apple App Store & Google Play)
Numera is distributed through the Apple App Store and Google Play, and we comply with their privacy requirements in addition to the law.
Where to find this policy. This policy is available inside the app (Settings → Legal → Privacy Policy) and at a public URL: https://numera-privacy.evalix.io/privacy. Both stores require a publicly reachable privacy-policy link in the store listing.
Account and data deletion. Both Apple and Google require that any app offering account creation also lets you delete your account and data.
- *In-app:* Settings → Privacy & Data → Delete all my data (Section 11).
- *Without the app (required by Google Play):* you can request deletion at any time by emailing [email protected] with subject
[GDPR], or via the web page at https://numera-privacy.evalix.io/delete. We honour external requests the same way as in-app deletion.
Tracking (Apple App Tracking Transparency). Numera does not track you across other companies' apps or websites. We do not use the advertising identifier (IDFA), and we do not show the App Tracking Transparency prompt because there is nothing to track. We do not use third-party advertising SDKs.
Apple "App Privacy" / Google "Data safety" summary. To help you read the store labels (these must match exactly what we declare in App Store Connect and the Play Console Data safety form — all three are kept in sync):
- Data we collect and link to you: contact info (email), your charts and birth data, your relationship questions and insights, purchase history, and limited usage data (the deep-dive call logs and quota counters in Section 3). No third-party analytics or crash-reporting SDK is integrated in the app, so we do not collect diagnostic or device-telemetry data through one. *(Verified 2026-06-11 by dependency audit — see
PRIVACY_COMPLIANCE_AUDIT.md. Re-confirm if such an SDK is ever added.)* - Data used to track you across other apps/sites: none.
- Data shared for advertising: none.
- Data is encrypted in transit, and you can request its deletion.
Sign-in providers. You currently sign in with an email address and password. (Sign in with Apple and Google Sign-In are planned for a future release; when they launch, this policy will be updated to cover them — including Apple's private-relay email option — and their use will also be governed by Apple's and Google's own privacy policies.)
Purchases. Subscriptions are processed by Apple and Google (via RevenueCat). Payment and receipt data is handled under Apple's and Google's privacy policies; we receive only a subscription identifier and entitlement status, never your full payment-card details.
Device permissions. Numera requests no special device permissions.
- We do not request device location, contacts, camera, microphone, photos, or health data. Birth place is typed in by you as a city name, not read from your device.
- *Notifications:* the current version does not request the notification permission. If optional monthly-forecast reminders are added in a future release, we will request that permission then and update this policy.
13. Per-partner data deletion
When the Couple Compatibility feature is enabled, you can add another person as a "partner profile" for a compatibility reading. That partner is a separate data subject. From the partner detail screen you can "Delete this person and all related data" — which removes their profile and every compatibility analysis or insight you generated about them, without touching anything else on your account.
This is for situations where:
- You broke up and want to remove their data
- They asked you to remove it
- You added them by mistake
14. Audit log retention
We keep one row per delete-or-export request for 30 days, after which the audit row itself is automatically purged. The audit row records the action (delete / export), timestamp, your user ID at the time, your email, and a per-table row-count summary — never the content of the data that was deleted.
Why we keep it: if a user disputes that a deletion took place ("you said you deleted my data, did you really?"), the audit row is the evidence. After 30 days the dispute window closes and we no longer need it.
15. Changes to this policy
We may update this policy as Numera evolves (for example when a new feature changes what data we process). When we make a material change, we will update the "last updated" date and notify you in-app before the change takes effect. Continued use of Numera after an update means you accept the revised policy.
16. Contact
For data-related questions or to invoke a right you can't access in-app:
- Email: [email protected]
- Subject line:
[GDPR]or[ISR-PRIVACY]so it's routed correctly
We respond within 30 days, per GDPR Article 12.
Provenance of this document
This draft is mirrored in the Numera codebase at PRIVACY.md and surfaced in-app at Settings → Legal → Privacy Policy, and at the public URL in Section 12. The in-app version is the user-facing source of truth; this file is the engineering copy used to keep them in sync.
Last technical change: GDPR + app-store policy expansion (2026-06-11) — added data-controller identity, legal bases, sub-processor and international-transfer disclosures, special-category/wellbeing handling, the full set of data-subject rights, retention, security, children, and change-notification sections; added Section 12 covering Apple App Store and Google Play requirements (public policy URL, in-app and external deletion routes, App Tracking Transparency, App Privacy / Data safety summary, sign-in providers, purchases, device permissions); aligned the data table with the relationship features; corrected the contact email to [email protected].