Privacy policy
Last updated: July 2026
1. Introduction
Norva, Inc., a Delaware corporation ("Norva," "we," "our," or "us") provides a unified life intelligence platform that connects your financial, health, and calendar data to surface personalized insights and recommendations (the "Service"). We built Norva on a simple principle: your data belongs to you. We do not sell your data, we do not share it with advertisers, and we do not use it for any purpose other than providing and improving the Service you signed up for.
This Privacy Policy explains what personal data we collect, how we collect it, why we collect it, who we share it with, how long we keep it, how we protect it, and the rights and choices you have. It applies to the Norva mobile application, the norvaapp.com website (the "Site"), and all related services.
By using the Service, you acknowledge the practices described in this Privacy Policy. If you do not agree with this Policy, please do not use the Service. If you have questions at any time, contact us at privacy@norvaapp.com.
2. Information We Collect
We collect information in three ways: (a) information you provide directly to us, (b) information collected automatically from connected data sources you authorize, and (c) technical information collected automatically when you use the Service.
2.1 Information You Provide Directly
• Account information: your email address and a password (stored in hashed form only; we never store plain-text passwords). If you use Sign in with Apple, we receive only the information Apple shares, which may be a name and an anonymized relay email address.
• Goals and preferences: goals you create, focus categories you select during onboarding, working hours you set, budget limits you define, and any preferences you configure in Settings.
• Norva AI conversations: messages you send to the Norva AI chatbot and the conversation history we maintain so the assistant can respond in context.
• Manual inputs: manual cash holdings you enter, transaction amount edits you make, and notes or explanations you attach to transactions.
• Payment information: we use Stripe, Inc. to process subscription payments. Your full payment card details are provided directly to Stripe and are never stored on Norva servers. We receive only limited billing information such as subscription status, plan type, card brand, and the last four digits of your card.
• Student verification: if you apply for a student discount, verification is performed by a third-party verification service (such as SheerID or IDme). We receive only the result of the verification (verified or not verified), not your underlying student documents.
2.2 Financial Data (via Plaid)
Norva connects to your financial accounts through Plaid Technologies, Inc. ("Plaid"). When you link an account, you provide your bank credentials directly to Plaid — Norva never sees, receives, transmits, or stores your bank username or password. Plaid's collection and use of your information is governed by the Plaid End User Privacy Policy, available at plaid.com/legal.
Through Plaid, and only with your authorization, we collect:
• Account balances across your connected accounts, used to calculate your net worth
• Transaction history, including merchant name, amount, date, and category
• Recurring transaction patterns, used to detect bills and subscriptions
• Investment account balances and their changes over time
• Credit card and loan balances, used for debt tracking
Data minimization is built into our architecture. We permanently discard routing numbers and full account numbers after initial account setup and store only an internal account identifier. All financial access is strictly read-only: Norva cannot initiate transactions, move money, open or close accounts, or modify your financial accounts in any way.
2.3 Health Data (via Apple HealthKit)
With your explicit, granular permission requested through Apple's native HealthKit permission flow, Norva reads the following data types from Apple Health (iOS):
• Sleep analysis: total sleep duration, time in bed versus time asleep, and sleep start and end times
• Daily step count
• Resting heart rate
• Heart rate variability (HRV), where available from a compatible device such as Apple Watch Series 4 or later
• Workouts: workout type, duration, and frequency
• Standing time
HealthKit operates under read-only scopes. Norva never writes to, modifies, or deletes any data in Apple Health. Permissions are requested one data type at a time with an explanation of why each is needed, and you may decline any individual data type. Health data is aggregated into daily summaries on your device before transmission to our servers; we do not continuously stream raw sensor data.
Consistent with Apple developer requirements: your HealthKit and Health Connect data is used solely to provide health and wellness features directly to you. It is never used for advertising, never used for marketing, never sold, never shared with data brokers, and never disclosed to third parties except the service providers necessary to operate the Service as described in Section 6.
2.4 Calendar Data (via Apple Calendar / EventKit)
With your explicit permission, Norva reads events from Apple Calendar within a rolling window of 6 months for pattern analysis and recommendations. To minimize the data we hold, the following are permanently discarded at the moment of ingestion and never stored on our servers: attendee names and email addresses, meeting descriptions and notes, and video conference links.
We store only the event start time, end time, event title (used solely to classify the event as work, personal, health, social, travel, or free time), and the calendar name. Calendar access is read-only: Norva never creates, edits, or deletes calendar events.
2.5 Information Collected Automatically
• Usage data: app events, feature interactions, and session information, collected through PostHog analytics to understand how the Service is used and to improve it
• Device data: device model, operating system version, app version, language, and time zone
• Diagnostic data: crash reports and error logs
• Site data: if you visit norvaapp.com, standard web log data (IP address, browser type, pages visited) and cookies as described in Section 11
We do not collect your precise GPS location. We do not access your contacts, photos, microphone, or camera.
2.6 Information We Do Not Collect
For clarity: we never collect or store your bank login credentials, your full bank account or routing numbers (discarded after setup), your full payment card number (held by Stripe), calendar attendee information or meeting content (discarded at ingestion), precise geolocation, or any data from your device beyond the categories described above.
3. How We Use Your Information
We use your information exclusively to provide, maintain, secure, and improve the Service. Specifically:
• To operate your unified dashboard, including net worth, cash flow, budgets, debt, investments, sleep, activity, heart metrics, calendar analysis, and goal progress
• To calculate your Norva Score and domain scores
• To generate personalized insights and recommendations through our intelligence engine, including cross-domain insights that combine your financial, health, and calendar patterns
• To power the Norva AI chatbot so it can answer questions about your data
• To track your progress toward goals you create
• To process subscriptions, manage free trials, and handle billing through Stripe
• To send service communications such as billing notices, security alerts, and material product updates
• To provide customer support when you contact us
• To monitor, detect, and prevent fraud, abuse, and security incidents
• To comply with legal obligations
We do not use your data for advertising. We do not sell your data. We do not rent your data. We do not share your data with data brokers. We do not use your personal data to train artificial intelligence or machine learning models without your explicit opt-in consent.
3.1 Aggregated and De-Identified Data
We may create aggregated or de-identified data sets that can no longer reasonably be linked to you (for example, the approximate number of Norva users who have set a particular popular goal, shown as inspiration in the Goals tab). Aggregated data never includes personally identifiable information, and we do not attempt to re-identify de-identified data. Where a group is too small to protect anonymity, we do not display the statistic.
4. AI Processing
Norva's intelligence features are powered by the Claude API, provided by Anthropic, PBC. To generate your insights and power the Norva AI chatbot, we send Anthropic a token-efficient, structured summary of your recent data — aggregated metrics such as weekly cash flow totals, budget status, average sleep, and upcoming meeting load — together with your messages to the chatbot.
Under the API terms applicable to our use of Anthropic's services, data submitted through the API is not used to train Anthropic's models.
AI-generated outputs may occasionally be inaccurate or incomplete. Insights are informational only and are not medical, financial, investment, tax, or legal advice. See the Terms of Service for important disclaimers.
5. Legal Bases for Processing (EEA, UK, and Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data under the following legal bases:
• Contract performance: processing necessary to provide the Service you signed up for, including connecting your authorized data sources, generating your dashboard and insights, and managing your subscription (GDPR Art. 6(1)(b))
• Consent: for health data, which is special category data under GDPR Art. 9, we process only with your explicit consent, which you may withdraw at any time by disconnecting Apple Health/Google Health Connect or deleting your account (GDPR Art. 9(2)(a)); consent also applies to optional communications
• Legitimate interests: securing the Service, preventing fraud and abuse, and performing analytics to improve the Service, balanced against your rights and interests (GDPR Art. 6(1)(f))
• Legal obligation: where processing is required to comply with applicable law (GDPR Art. 6(1)(c))
6. How We Share Information
We share personal data only in the limited circumstances below, and never for advertising or commercial resale.
6.1 Service Providers (Processors)
We share data with service providers who process it on our behalf, under contracts that restrict their use of your data to providing services to us:
• Plaid Technologies, Inc. — financial account connectivity (Plaid also acts as an independent controller under its own End User Privacy Policy)
• Supabase, Inc. — database hosting, authentication, and storage infrastructure, with row-level security isolating each user's data
• Anthropic, PBC — AI processing via the Claude API, as described in Section 4
• Stripe, Inc. — payment processing and subscription billing
• PostHog, Inc. — product analytics
• Resend or SendGrid — transactional email delivery
• SheerID or IDme — student status verification, only if you request a student discount
6.2 Legal Requirements
We may disclose personal data if we believe in good faith that disclosure is required by law, regulation, subpoena, court order, or other legal process, or is necessary to protect the rights, property, or safety of Norva, our users, or the public. Where legally permitted, we will notify you before disclosing your data in response to a legal request.
6.3 Business Transfers
If Norva is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of its assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent in-app notice before your personal data becomes subject to a different privacy policy, and any successor will be required to honor the commitments made in this Policy with respect to previously collected data.
6.4 With Your Direction
We will share your data with third parties when you explicitly direct us to do so. We never share on the basis of implied consent.
6.5 What We Never Do
• We never sell your personal data, in any form, to anyone
• We never share your data with advertisers, ad networks, or data brokers
• We never use your financial or health data for marketing or advertising purposes
• We never share individual-level data with other Norva users; community features (such as popular goals) display only aggregate counts
7. Data Security
We employ administrative, technical, and physical safeguards designed to protect your personal data, including:
• Encryption of all data in transit using TLS 1.3 and at rest using AES-256
• Row-level security in our database, so each user can query only their own records
• Tokenized financial access: we store Plaid access tokens only, never bank credentials
• On-device health data processing where possible, so raw sensor data does not leave your device
• API rate limiting, access controls, and least-privilege principles across our infrastructure
• Independent penetration testing before public launch and periodically thereafter
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach of security affecting your personal data, we will notify you and applicable regulators without undue delay, consistent with applicable law (including GDPR's 72-hour authority notification requirement and U.S. state breach notification statutes).
8. Data Retention
• Active accounts: we retain your data while your account is active. Basic plan users can access 6 months of data history in the app; Premium plan users have unlimited history.
• Account deletion: when you delete your account, all personal data is permanently deleted from our production systems within 30 days. Encrypted backups are purged on a rolling basis within [90] days.
• Disconnected sources: when you disconnect a data source, we stop collecting new data from it immediately; previousl collected data remains in your account unless you delete it or your account.
• Legal retention: we may retain limited records where required for legal, tax, or accounting obligations (for example, billing records retained per tax law), and will delete them when the obligation expires.
9. Your Rights and Choices
9.1 Rights Available to All Norva Users
Regardless of where you live, we extend the following to every user, self-service from the app:
• Access: view the data Norva holds about you throughout the app
• Export: download a complete copy of your Norva data as a JSON file from Settings → Privacy & Data
• Deletion: permanently delete your account and all associated data from Settings, with a confirmation flow
• Disconnect: remove any connected data source (Plaid, Apple Health, Google Health Connect, Apple Calendar) at any time from Settings
• Correction: edit your profile information, goals, working hours, and transaction amounts in the app
• Communication choices: opt out of non-essential emails via the unsubscribe link in any such email or in Settings → Notifications; service and billing emails will still be sent as they are necessary to operate your account
9.2 California Residents (CCPA/CPRA)
If you are a California resident, you have the right to: (a) know the categories and specific pieces of personal information we collect, use, and disclose; (b) delete your personal information; (c) correct inaccurate personal information; (d) opt out of the sale or sharing of personal information; (e) limit the use of sensitive personal information; and (f) not be discriminated against for exercising these rights.
Norva does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined by California law. We collect the following categories of personal information as described in Section 2: identifiers (email); commercial information (transactions, subscriptions); financial information (balances, transactions via Plaid); health information (via Apple Health, with consent); sensory/activity data (calendar events); internet activity (app usage); and inferences (insights and scores generated for you). We use sensitive personal information only to provide the Service, which is a permitted purpose that does not trigger a "Limit Use" obligation, but we honor limit requests regardless.
To exercise any right, use the in-app tools described in Section 9.1 or email privacy@norvaapp.com. We will verify your request using your account email. You may designate an authorized agent to act on your behalf; we will require proof of authorization.
9.3 Washington and Nevada Residents (Consumer Health Data)
Washington's My Health My Data Act and Nevada's SB 370 provide specific rights over "consumer health data." Norva collects consumer health data (sleep, steps, heart rate, HRV, workouts) only with your affirmative consent through the HealthKit permission flow. You have the right to: withdraw consent at any time (disconnect Apple Health/Google Health in Settings); access your health data; have it deleted; and obtain a list of the third parties with whom it has been shared (see Section 6.1). We do not sell consumer health data and do not process it for advertising.
9.4 Other U.S. State Privacy Laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have similar rights of access, correction, deletion, portability, and the right to opt out of targeted advertising, sale, and certain profiling. Norva does not engage in targeted advertising, does not sell data, and does not profile users in furtherance of decisions producing legal or similarly significant effects. To exercise rights or appeal a decision we make on a rights request, email privacy@norvaapp.com; appeals are reviewed by a different reviewer than the original decision.
9.5 EEA, UK, and Swiss Residents (GDPR)
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time without affecting the lawfulness of prior processing. You also have the right to lodge a complaint with your local supervisory authority. We do not make automated decisions producing legal or similarly significant effects about you. To exercise your rights, use the in-app tools or contact privacy@norvaapp.com.
10. International Data Transfers
Norva is operated from the United States, and your data is stored and processed in the United States. If you access the Service from outside the United States, you understand that your data will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction. Where required, we rely on appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework certifications of our service providers.
11. Cookies and Website Tracking
The Norva mobile app does not use cookies. The norvaapp.com website uses a minimal set of cookies: strictly necessary cookies for site function and security, and, with your consent where required, analytics cookies to understand site traffic. We do not use advertising or cross-site tracking cookies. You can manage cookie preferences through the banner presented on the Site and through your browser settings. Because we do not track users across third-party websites, we do not respond differently to "Do Not Track" browser signals; however, we honor Global Privacy Control (GPC) signals where required by law.
12. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. Users must be at least 16 years old (or the higher minimum age required in their jurisdiction, unless parental consent is provided). If we learn that we have collected personal information from a child below the applicable minimum age, we will delete it promptly. If you believe a child has provided us personal information, contact privacy@norvaapp.com.
13. Third-Party Services and Links
The Service integrates with and links to third-party services, including Plaid, Apple Health, Apple Calendar, and Stripe. Your use of those services is governed by their own privacy policies, which we encourage you to review: Plaid (plaid.com/legal), Apple (apple.com/privacy), and Stripe (stripe.com/privacy). Norva is not responsible for the privacy practices of third parties.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and/or prominent in-app notice at least 14 days before the changes take effect, and we will update the "Last Updated" date above. If a change materially expands how we use previously collected data, we will seek your consent where required by law. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
15. Contact Us
For privacy questions, rights requests, or complaints:
Email: privacy@norvaapp.com