# Privacy Policy

> What NannaLife collects, how uploaded lab reports are processed, which third-party services are involved, retention and deletion, and how to contact us.

Last updated August 18, 2026.

The authoritative legal text is the HTML page at https://nannalife.com/legal/privacy. This Markdown version is provided for machine reading; if the two ever differ, the HTML page governs.

## Summary of key points

- **What is collected:** account information, profile information, uploaded medical and laboratory reports, and biomarker data extracted from those reports.
- **Health data:** test names, results, reference ranges, report dates, and patient information appearing on an uploaded report may be processed.
- **AI processing:** relevant report content may be sent to the AI provider used by NannaLife to extract and structure data.
- **Third parties:** Google Sign-In, Neon Postgres, Cloudflare R2 storage, and Cloudflare AI Gateway are the main services currently used.
- **Analytics:** NannaLife does not install Google Analytics or similar third-party web analytics in the application, and does not send report contents or health data to analytics providers.
- **Deletion:** there is no self-service account or report deletion flow yet. Email privacy@nannalife.com or support@nannalife.com to request deletion.

## What is collected

Information you provide: name, email address, and login details; profile information such as display name, avatar, date of birth, and gender if provided; uploaded medical and laboratory reports; health information contained in those reports, including test names, results, units, reference ranges, dates, and patient details shown on the report; and information generated by the app when it extracts and structures report data.

Information collected automatically: session and authentication data, device and browser information, and basic server logs or operational metadata, used for account access, security, troubleshooting, and reliability.

NannaLife does not source personal data from third-party databases or advertising networks.

## How information is used

To create and manage accounts and sessions; to store uploaded reports and make them available in the app; to extract and structure biomarker data; to generate educational summaries about extracted biomarkers; to operate dashboard, account, and profile features; to maintain security and reliability; and to respond to support and privacy requests and comply with legal obligations.

## Third-party services

- **Google Sign-In:** email address, name, and profile image URL are received to create or link an account.
- **Neon Postgres:** the main application database, holding account data, profile data, report metadata, extracted biomarker data, and other app records.
- **Cloudflare R2:** object storage for uploaded report files and profile images.
- **Cloudflare AI Gateway:** routes relevant report content to AI models for extraction and other in-app features. The current implementation uses a Google AI Studio Gemini model for report parsing and an OpenAI model for educational biomarker content, both through the gateway.
- **Application infrastructure and hosting:** a managed Next.js environment and related infrastructure.

Information is shared with these providers only as needed to operate the service. No separate Google Analytics, advertising, or marketing partner is used for app analytics.

## AI processing

A user uploads a report, NannaLife processes it to extract test names, results, units, reference ranges, and dates, and relevant report content may be sent to the AI provider to complete that functionality. The structured result is returned and associated with the user's account and profile. Only the information necessary for the requested feature is sent. The policy does not make blanket claims about provider retention or training uses beyond the functionality required by the product and the provider terms that apply.

## Cookies and tracking

Necessary authentication and session cookies keep you signed in and protect access to your account. No Google Analytics, third-party advertising scripts, or cross-site trackers are currently installed in the app.

## Retention and deletion

Account and profile records are stored while the account is active. Uploaded reports and extracted data are retained while they remain part of the active account and are not removed through a supported deletion process. The database schema includes soft-delete fields for reports, profiles, documents, and users, but the app does not currently expose a full self-service account or report deletion flow. Backups and operational copies may temporarily retain deleted data. Information may be retained longer where required by law or for security.

To request account deletion, report deletion, or removal of personal information, contact privacy@nannalife.com or support@nannalife.com.

## Security

Reasonable administrative, technical, and organizational safeguards are used, including secure authentication, in-app access controls, managed database hosting, secure storage for uploaded files, and encrypted connections. No system is completely secure, and no certifications are claimed beyond measures actually implemented.

## Age requirement

The service is intended for users aged 18 or older. There is currently no technical age gate.

## India and the DPDP Act

The policy is written with the Digital Personal Data Protection Act, 2023 and applicable rules in mind. For Indian users, personal and health data is processed only for the limited purposes described above. Users may contact NannaLife to request information about their personal data, ask for correction, or request deletion where the product or applicable law supports it. NannaLife does not claim full compliance with every provision of the DPDP Act.

## Contact

- Privacy requests: privacy@nannalife.com
- Product and support requests: support@nannalife.com

## Links

- [Privacy Policy (HTML)](https://nannalife.com/legal/privacy)
- [Terms & Conditions](https://nannalife.com/legal/terms-and-conditions)
- [Homepage](https://nannalife.com/)
