Skip to content
NEXA
Coming soon

Privacy Policy

Last updated October 2, 2026

This policy explains what the NEXA mobile app ("NEXA", "we", "us") collects, why, who it is shared with, and the choices you have. It applies to the NEXA app for iOS (the "App").

Contact for anything about privacy: vessa.care@outlook.com

The short version

  • NEXA is a private journal. We store what you enter (your stack, plans, records, check-ins, notes and photos) so you can see it on any device you sign in to. Much of it is health-related.
  • We don't sell your data, we don't show ads, and we don't track you across other apps or websites.
  • The AI assistant sends the relevant data to our AI provider, OpenAI, only after you allow it.
  • We use product analytics (PostHog) to improve the App. We don't record your screen, and analytics never include what you type.
  • You can export your data and delete your account and all your data in the App at any time: Settings → Delete account.

1. Information we collect

Information you give us

  • Account: Email address, name (optional), and password (stored only as a hash). With Sign in with Apple: your Apple user identifier and the email or private relay address Apple shares.
  • Profile and settings: Confirmation that you are an adult, product market, display units, time zone, the check-ins you chose, your Home background choice, and notification preferences.
  • Questionnaire answers: Your goals and focus areas, how long you have been on your current stack, how many items you take and in what forms, how you track today, when you usually take them, how you'd like reminders, whether you rotate injection sites or have noticed lumps or tenderness, check-in preferences, whether you see a clinician, and what success looks like for you.
  • Your stack: The medications, peptides and supplements you add (names you give them, the catalog item or product you linked, strength, form and route), your supplies (packages, quantities, lot and expiry details if you enter them, and supply changes).
  • Plans and records: Your schedules and their history, doses you log or edit (amount and unit if entered, time, body site, notes), skipped or voided entries, and the change history of each record.
  • Check-ins and journal: Measurements such as weight and waist, ratings such as sleep, energy, appetite or skin irritation, symptoms, journal notes, and photos you add to your journal.
  • Calculator: The inputs and results of calculations you choose to save.
  • Library: Items you save and research you follow.
  • Assistant conversations: Questions you send to the AI assistant and its replies.
  • Your choices: Whether you allowed the AI assistant, when, and which version of this policy you saw.
  • Support: Anything you send us by email.

Information collected automatically

  • Product analytics (PostHog): which screens you open and what you do in the App (for example "dose logged" or "check-in logged", without any names, doses, sites, values or text), app version, device model, iOS version, approximate location derived from your IP address (country/region), and your account ID.
  • Crash and performance reports (Sentry): when the App crashes or runs into an error, details such as the error, app version, device model, iOS version and your account ID. They contain no records, check-ins, photos, notes or messages.
  • Subscription status: plan, trial and renewal state, purchase dates and your account ID. We never receive your card or payment details; Apple handles payment.
  • Push token and device name and platform, so we can deliver notifications.
  • Technical logs on our servers, such as request time, IP address and errors, used for security and debugging.

What we don't collect

No precise location, contacts, advertising identifier, or data from Apple Health. We don't use advertising SDKs, and analytics are never used for advertising or shared with data brokers.

Device permissions

  • Camera and Photos: only when you take or choose a photo for your private journal.
  • Notifications: only after you turn on a reminder. Plan reminders are scheduled on your device and never name what you take.

You can change these permissions in iOS Settings at any time.

2. How we use your information

  • To create your account and sign you in.
  • To store and show your stack, plans, records, supplies, check-ins, journal and progress.
  • To schedule reminders and show what is coming up and what has no entry recorded.
  • To create doctor reports and data exports when you ask for them.
  • To answer you in the AI assistant, using your own records so that answers are about you.
  • To send the notifications you turned on (such as plan reminders).
  • To manage subscriptions and unlock paid features.
  • To understand how the App is used and improve it (product analytics).
  • To keep the App secure, prevent abuse, enforce usage limits and fix problems.
  • To respond to support requests and meet legal obligations.

We don't use your data for advertising, and we don't make decisions about you that have legal or similarly significant effects.

NEXA does not prescribe, recommend doses or injection sites, or give medical advice.

4. AI assistant

We only send your information to our AI provider with your permission. Before the assistant answers anything, the App shows what will be sent, who receives it and why, and asks you to allow it. If you choose "Not now", nothing is sent to the AI provider and only the assistant stays off; the rest of the App keeps working. You can change your choice at any time in Settings → AI assistant.

The assistant is powered by OpenAI (United States). When you ask a question, we send:

  • your question, with your recent conversation so it can follow along;
  • the names you gave the items in your stack, how often you log them and when you last did;
  • recent check-in values (such as weight, waist, sleep, energy or skin irritation) with their dates;
  • the library entry you asked about, when you open the assistant from one.

We don't send your email, your journal photos or your notes. Data sent through OpenAI's API is not used to train its models; OpenAI may keep requests for up to 30 days to detect abuse, then deletes them. AI answers may be inaccurate and are not medical advice; see the Terms of Use.

OpenAI processes this information only on our behalf, to return an answer, under a data processing agreement that requires it to protect your information with safeguards at least equal to those described in this policy.

5. Who we share information with

We share data only with service providers that help us run the App, and only as needed:

  • Supabase: Database, authentication, file storage and server functions (our main data host)
  • OpenAI: The AI assistant, with your permission (section 4)
  • PostHog: Product analytics (section 1)
  • Sentry: Crash and error reports (section 1)
  • RevenueCat: Subscription status and purchase validation
  • Apple: Sign in with Apple, payments, push notification delivery
  • Expo: Push notification delivery

We may also disclose information if the law requires it, to protect the rights, safety or property of our users, ourselves or others, or as part of a merger, acquisition or sale of the App, in which case this policy continues to apply to your data.

We do not sell or rent your personal information, and we do not share it for cross-context behavioural advertising.

Doctor reports and exports are created on your device. We don't receive a copy; you decide who to share them with.

6. Where your data is stored and international transfers

Your data is stored on our providers' servers, which may be located outside your country, including in the United Kingdom (our main database), the European Union and the United States. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.

7. How long we keep it

  • We keep your data for as long as your account exists. Your history stays yours: it is not deleted when a subscription ends.
  • When you delete your account, your profile, answers, stack, supplies, plans, records and their history, check-ins, symptoms, notes, journal photos, saved items, assistant conversations, AI permission choices and push tokens are permanently deleted. Residual copies in backups and logs expire within about 30 days.
  • We may keep limited records where the law requires it, for example transaction records, and Apple and RevenueCat keep purchase records under their own policies.
  • Support emails are kept for as long as needed to handle your request.

8. Your choices and rights

In the App you can:

  • view and edit your name, market, units, time zone, goals and check-ins, and notification settings (Settings);
  • edit or void records, and delete stack items, check-ins, notes and photos;
  • allow or withdraw the AI assistant (Settings → AI assistant);
  • export your data as a doctor report PDF or CSV tables (Settings → Export my data);
  • delete your account and all data: Settings → Delete account. This is permanent. An active subscription must be cancelled separately in your Apple ID settings.

To have your analytics and crash data deleted, email us.

Depending on where you live (for example the EEA, UK, Ukraine, California and other U.S. states) you may have the right to access, correct, delete or export your data, to restrict or object to processing, to withdraw consent, and to complain to your local data protection authority. We don't discriminate against anyone for using these rights.

To make a request, or if you can't access the App, email vessa.care@outlook.com from the address on your account. We reply within 30 days.

Legal bases (EEA and UK): performing our contract with you (running the App), your consent (health-related information, the AI assistant, notifications, camera and photos), our legitimate interests (security, preventing abuse, improving the App through analytics) and legal obligations.

9. Security

We use encryption in transit, row-level access rules so that each user can only reach their own data, private storage for journal photos, server-side checks on paid features, and restricted access to production systems. No system is perfectly secure, and we can't guarantee absolute security. If a breach affects you, we'll notify you as the law requires.

10. Children

The App is for adults aged 18 and over; you confirm this when you start. We don't knowingly collect data from anyone under 18. If you believe a minor has given us data, contact us and we'll delete it.

11. Changes to this policy

We may update this policy. We'll change the date above and, for significant changes, tell you in the App or by email. If what the AI assistant receives changes, the App asks for your permission again.

12. Contact

vessa.care@outlook.com