Privacy policy
In effect since:
The short version
The NurseAI app stores everything you log — blood pressure, pulse, SpO₂, glucose, weight, notes, medication and your name — in a SQLite database inside your own phone or tablet. There is no account, no sign-up, no server of ours, no analytics, no advertising and no third-party trackers. Data only leaves your device if YOU turn on one of the two optional features described below, or if YOU export a file yourself.
Who is responsible
The NurseAI Android app (package com.cherrydevlabs.nurseai) is published by cherrydevlabs, and the nurseai.dev website is maintained by the same person behind the project. Contact for anything privacy-related: [email protected]. The project is operated from Spain and is governed by Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). Important: because no server of ours ever holds your health data, for that data we act as the provider of a program that runs on your device, not as a custodian of the information.
What this policy covers
Two separate things that are worth keeping apart: (1) the NurseAI Android app, which runs on your device and is where your health data lives; and (2) this website, nurseai.dev, which is informational and only collects the email address you voluntarily leave on the waitlist. Every section that mentions vitals, medication or voice refers to the APP.
What the app stores, and where
Everything is stored in a SQLite file (constantes.db) in the app's private storage, inside your device. Specifically: measurements (systolic, diastolic, pulse, oxygen saturation, glucose with its fasting or post-meal context, date and time, time-of-day slot and a free-text note); weight (kilograms, date and note); the daily note (your spoken or typed answer to the nurse's question 'how are you feeling?', with a mood and whether it came in by voice or keyboard); medication (drug name, what it is for, when it is taken, dose, whether it is active or withdrawn and the reason for withdrawal); and settings (the name you want the nurse to greet you by, the language, the chosen voice, the warning thresholds your doctor configures and, if you use it, the address and access key of your own sync server). The app does not access your contacts, your photos, your location or the list of apps you have installed (the only thing Android lets it see is which speech recognition engine is on the device, because Android requires that in order to open dictation).
What we do NOT do
There is no account and no password: we do not know who you are. There is no usage analytics, no measurement SDK, no automatic crash reporting, no advertising identifier, no pixels and no cookies inside the app. There is no advertising of any kind. We do not sell, rent or share data with anyone, because we do not have it. We do not build profiles and we do not make automated decisions about you. The app sends nothing whatsoever to any cherrydevlabs server, because no such server exists.
Optional feature 1 — Sync with YOUR OWN server
Under Settings › Sync you can type the address and access key of a server you set up yourself (for example a small server on your home network) so your data is available on two devices. As long as those two fields are empty the feature is OFF and no connection is ever made. If you fill them in, the app sends over HTTP to that address of yours — and only to it — the rows for measurements, weight, daily notes and medication, together with a random device identifier generated locally. Your SETTINGS are not sent, so your name does not travel this way. You choose, host and control that server: we never see it and have no access to it, and the security of that connection (using HTTPS, protecting the network, keeping the key safe) is the responsibility of whoever configures it. To turn it off, clear the address and the key and save.
Optional feature 2 — AI-generated compliments (MiniMax)
The nurse greets you with a kind sentence. By default that sentence comes from a phrase bank shipped inside the app, offline. If the 'AI compliments' switch is on AND the build you installed carries a MiniMax API key, the app makes one request to api.minimax.io whose entire content is: a fixed instruction in your language asking for an encouraging sentence, plus the text 'Time of day: morning / afternoon / night'. That is all. Your name is not sent, nor the date, nor a single vital sign, nor your medication, nor any identifier. If the request fails, takes longer than 3.5 seconds or there is no network, the local phrase bank is used. To turn it off, set the switch to 'Simple compliments' in Settings.
The nurse's spoken voice never leaves the device
The nurse speaks with the Android system speech engine (expo-speech): free, offline, no API key and no audio sent anywhere. There is no premium or remote voice — the paid cloud voice that earlier versions of this page described was removed from the app before release, so the text the nurse pronounces (greeting, date, your name if you filled it in) is synthesised inside your device and never travels.
Important: the MiniMax feature in the Google Play version
AI compliments only work if the installed build has a MiniMax API key baked in by whoever compiled it. The version distributed on Google Play is published WITHOUT that key, so in it the nurse always uses the local phrase bank and the Android system voice, and no request is ever made to MiniMax. That integration exists for people who compile their own build of the source with their own key. Should this ever change in a future version, it will be announced on this page before that version is published.
Voice dictation and the microphone permission
The app declares exactly one permission: RECORD_AUDIO (microphone). It is used only for dictation: when you press the dictate button (or the nurse button that listens for your answer of the day), Android asks you for the permission and the app opens the system speech recogniser to turn what you say into text. The app does not record audio, does not store it and does not upload it anywhere: it only receives the already-transcribed text and writes it to the local database. Note one limit that is not ours to control: the transcription is performed by the speech recognition service installed on your device (usually Google's), and that service may process the audio on its own servers depending on how your Android is configured; that processing is governed by that vendor's privacy policy, not by this one. If you would rather avoid it, do not use dictation — everything can be typed — or deny the microphone permission; the app works exactly the same. The app also needs internet access, which Android grants automatically, solely for the optional features described above.
Exports, reports and backups
You can generate a PDF report to take to your doctor and print or share it, and you can export a full copy of the database from Settings › Backup. The backup is a plain SQLite file: it is NOT encrypted by the app, so once it leaves the device it is protected only by wherever you put it — treat it as the health record it is. Before sharing it, the app removes the sync server address and access key from the copy and recompacts the file, so those credentials are not readable inside it. In both cases the Android share sheet opens and YOU decide where the file goes (email, a messaging app, a folder, whatever cloud you use). From that moment the file is governed by the terms of the service you sent it to. The 'Restore backup' option replaces all current data with the contents of the file you pick: it is irreversible, which is why it asks for double confirmation. Separately, Android's own automatic backup system may include this app's data in your device backup tied to your Google account; that is controlled by you in Android's settings, not by the app.
Legal basis for processing
The data you log is health data, a special category under Article 9 GDPR. The basis for it existing on your device is your explicit consent, given by entering it voluntarily (Art. 6(1)(a) and Art. 9(2)(a) GDPR). For each optional feature that sends something off the device, the basis is again your explicit consent, expressed by the unambiguous act of switching that feature on in Settings; you can withdraw it at any time by switching the feature off, without affecting anything you have already logged.
How long data is kept
Data stays on your device indefinitely until you delete it, because the whole point is to see trends over months or years. We set no retention period — among other reasons because we cannot: we have no access. Data is gone completely when you clear the app's storage (Android Settings › Apps › NurseAI › Storage › Clear data) or uninstall the app. If you used sync with your own server, remember to delete it there too.
Children
NurseAI is not directed to children. It is designed for adults — older adults in particular — who track their own vitals and medication, and for the people who care for them. We do not knowingly request or process data from anyone under 16 (13 where local law sets that threshold). If a minor is going to use it, they should do so under the supervision and with the consent of a parent or legal guardian.
Your rights and how to exercise them
You have the rights of access, rectification, erasure, objection, restriction and portability. Because no server of ours holds your health data, you exercise those rights directly and immediately on your own device, without asking us and without waiting: ACCESS and PORTABILITY, by exporting the database and the PDF report from Settings; RECTIFICATION, by editing or deleting any record from the history and medication screens; ERASURE, by clearing the app's data or uninstalling it; OBJECTION and RESTRICTION, by switching the optional features off. For the waitlist data on this website, or for any question, write to [email protected]. If you believe we have handled your data improperly, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es) or with the supervisory authority in your country.
Security
The data lives in the app's private storage, which Android isolates from other applications. With no account and no central server, there is no data breach that could hit every user at once: the real risk is your device and what you do with the files you export. We recommend protecting the device with a PIN, pattern or biometrics, and treating exported files for what they are: health information. The database is not separately encrypted beyond the encryption of the Android device itself.
NurseAI is not a medical device
NurseAI is a logbook and a summary generator. It does not diagnose, does not grade risk, does not recommend or adjust doses, does not raise clinical alerts and shows no risk traffic-lights. It is not a medical device within the meaning of Regulation (EU) 2017/745, nor under equivalent legislation elsewhere, and it is not intended for any medical purpose in the sense of that legislation. The ranges the app uses to flag an unusual value are soft warnings about a possible typo, they never block saving, and they are configured by the user or their doctor. Everything the app produces is meant for one thing: taking it to a healthcare professional. Clinical decisions are always theirs.
This website (nurseai.dev)
The website is informational. If you join the waitlist, we process your email address, the country you connect from and the role you select (patient, caregiver or professional), for the sole purpose of emailing you once when the beta opens. Delivery is handled by Resend (resend.com), acting as data processor. To see how many people visit the site we use Umami, a self-hosted analytics tool: it sets no cookies, creates no identifier that follows you across sites, and produces only aggregate counts (page views, country, device type). It cannot recognise you or link you to the waitlist. The website installs no marketing or third-party cookies. No health data is processed on the website. You can ask to be removed and deleted by writing to [email protected]; we do it within 30 days at most.
Changes to this policy
If any version of the app changes what is sent or where it goes, we will update this text and the effective date shown above BEFORE publishing that version, and we will call it out in the release notes. Continuing to use the app after a change means you accept it; if you do not, you can export your data and uninstall.
Contact
For anything about this policy, about your data, or to exercise your rights: [email protected]. We answer in English and Spanish.