Privacy Policy
Last updated August 18, 2026
NannaLife ("we," "us," or "our") helps people store, organize, and understand personal health information contained in uploaded medical and laboratory reports. This Privacy Policy explains what information we collect, how we use it, which third-party services are involved in operating the service, and how you can contact us.
Important: NannaLife is a tool for organizing and understanding health information. It is not a substitute for professional medical advice, diagnosis, or treatment.
SUMMARY OF KEY POINTS
We process only the information needed to operate NannaLife and provide the features available in the app.
- What information we collect: account information, profile information, uploaded medical and laboratory reports, and extracted biomarker data from those reports.
- Health data: NannaLife may process health information contained in user-uploaded reports, including test names, results, reference ranges, report dates, and patient information appearing on the report.
- AI processing: relevant report content may be sent to the AI provider used by NannaLife to extract and structure data from the report.
- Third parties: Google Sign-In, Neon Postgres, Cloudflare R2 storage, and Cloudflare AI Gateway are the main services currently used by the app.
- Analytics: NannaLife does not currently install Google Analytics or similar third-party web analytics in the application.
- Deletion: the product currently does not provide a self-service account or report deletion flow. If you need deletion, contact [email protected] or [email protected].
TABLE OF CONTENTS
- WHAT INFORMATION DO WE COLLECT?
- HOW DO WE USE YOUR INFORMATION?
- THIRD-PARTY SERVICES AND DATA SHARING
- AI PROCESSING OF HEALTH INFORMATION
- GOOGLE SIGN-IN
- COOKIES AND TRACKING
- RETENTION AND DELETION
- SECURITY
- AGE REQUIREMENT AND MINORS
- INDIA AND THE DPDP ACT
- CONTACT INFORMATION
1. WHAT INFORMATION DO WE COLLECT?
Information you provide to us
In short: We collect the personal and health information needed to create and operate your account and manage your uploaded reports.
Depending on how you use the app, we may collect the following information:
- Account information, including your name, email address, and account login details used by the service.
- Profile information, such as your display name, avatar image, date of birth, and gender, if you choose to provide or update that information.
- Uploaded medical and laboratory reports, including PDF or other supported report files.
- Health information contained in uploaded reports, including test names and results, units, reference ranges, report dates, and patient information shown on the report.
- Health information entered directly by users in or associated with their account or profile when available in the app.
- Information generated by the app when it extracts and structures uploaded report data for display in the dashboard.
We do not source personal data from third-party databases or advertising networks for the current NannaLife service.
Information automatically collected
We also collect technical information necessary to operate the service, such as session and authentication data, device and browser information used by the app, and basic server logs or operational metadata. These are used for account access, security, troubleshooting, and service reliability.
2. HOW DO WE USE YOUR INFORMATION?
In short: We use your information to create and maintain your account, store and process your uploaded reports, organize your health data, provide AI-based extraction and educational features, and keep the service secure and operational.
We process personal and health information for the following purposes:
- To create and manage your NannaLife account and sign-in session.
- To store uploaded medical and laboratory reports and make them available to you in the app.
- To extract and structure information from uploaded reports so that relevant biomarkers and values can be displayed and tracked.
- To generate educational summaries related to extracted biomarkers when those features are used.
- To operate the dashboard, account, and profile features that are part of NannaLife.
- To maintain the security, reliability, and integrity of the service.
- To respond to support and privacy requests and comply with legal obligations.
3. THIRD-PARTY SERVICES AND DATA SHARING
In short: NannaLife uses a small number of third-party services to provide authentication, storage, database, AI, and infrastructure functions. We do not share your health data with unrelated ad-tech or marketing vendors.
The main services currently used by the app are:
- Google Sign-In: used for Google authentication. When you sign in with Google, NannaLife receives the Google account email address, name, and profile image URL needed to create or link your account.
- Neon Postgres: used as the main application database. This stores account data, profile data, uploaded report metadata, extracted biomarker data, and other app records.
- Cloudflare R2: used for object storage. This stores uploaded report files and profile images needed by the application.
- Cloudflare AI Gateway: used to send relevant report content to AI models for extraction and other in-app features. The current implementation uses the Google AI Studio Gemini model for report parsing and the OpenAI GPT-5.6-luna model for educational biomarker content, both accessed through the Cloudflare AI Gateway.
- Application infrastructure and hosting: the app runs on a managed Next.js environment and related infrastructure used to provide the service. We do not publish or share internal infrastructure credentials in this policy.
We share information with these providers only to the extent necessary to operate the service. We do not currently use a separate Google Analytics, advertising, or marketing partner for app analytics.
4. AI PROCESSING OF HEALTH INFORMATION
In short: A user uploads a medical or laboratory report, NannaLife processes it to extract relevant information, and relevant report content may be sent to the third-party AI provider used by the app to complete the requested functionality.
The current workflow is:
- A user uploads a medical or laboratory report to NannaLife.
- NannaLife processes the report to extract relevant data such as test names, results, units, reference ranges, and dates.
- Relevant report content may be sent to the AI provider used by the app for parsing and extraction.
- The provider processes that information to return the structured result needed for the feature.
- The resulting structured information is returned to NannaLife and associated with the user’s account and profile.
In the current production implementation, the report parsing flow uses the Google AI Studio Gemini model through Cloudflare AI Gateway, and educational biomarker content is generated using an OpenAI model through the same gateway. We do not make blanket claims about provider retention or training uses beyond the functionality required by the product and the provider terms applicable to the service.
Only the information necessary for the requested feature is sent to the AI provider. We do not currently send unrelated personal data or non-health information to the model for this purpose.
5. GOOGLE SIGN-IN
In short: If you sign in with Google, NannaLife receives the Google account information needed to create or link your account.
When Google Sign-In is used, we receive the Google account email address, full name, and profile image URL. We use that information to create or sign in to your NannaLife account and display your account profile within the app.
We do not use Google Sign-In for unrelated advertising or marketing purposes.
6. COOKIES AND TRACKING
In short: NannaLife uses necessary authentication and session cookies to keep you signed in and to operate the app. We do not currently use Google Analytics or similar third-party web analytics in the app.
Authentication cookies and related session data are used to maintain your sign-in state and protect access to your account. These cookies are required for normal app functionality.
We do not currently install Google Analytics, third-party advertising scripts, or other cross-site trackers to monitor user activity within the app. NannaLife does not send uploaded report contents, health data, or laboratory results to Google Analytics or similar analytics providers.
7. RETENTION AND DELETION
In short: Account and report data are retained while the account is active and while the app is providing the service. We do not currently operate a fixed auto-expiry period for active accounts, but the app stores records in a database and object storage system with soft-delete fields where appropriate.
In the current implementation:
- Account records and profile records are stored while the account remains active.
- Uploaded report files and associated extracted report data are retained as long as they remain part of the user’s active account and are not removed through a supported deletion process.
- The database schema includes soft-delete fields such as deletedAt for reports, profiles, documents, and users, which indicates that deleted records are not normally returned by active queries. However, the app does not currently expose a full self-service account deletion or report deletion flow.
- Backups, restore snapshots, or operational copies may temporarily retain deleted data for recovery or security purposes even after a logical deletion record is set.
- We may retain information for longer periods where required by law, contractual obligations, or operational security needs.
At the moment, NannaLife does not currently provide a self-service “delete account” or “delete report” screen. This is a product gap and a required implementation task. To request account deletion, report deletion, or removal of personal information, contact [email protected] or [email protected].
8. SECURITY
In short: We use reasonable administrative, technical, and organizational safeguards to protect the personal and health information we store and process.
These measures include secure authentication, access controls in the app, managed database hosting, secure storage for uploaded files, and restrictions on who can access the data needed to run the service. We use encrypted connections for app traffic, and the underlying infrastructure providers used by NannaLife provide security controls as part of their managed services.
No system is completely secure. We do not claim certifications or guarantees beyond the security measures that are actually implemented and maintained in the current product.
9. AGE REQUIREMENT AND MINORS
In short: NannaLife is intended for users who are 18 years of age or older.
The service is designed for adult users and is not intended for children under the age of 18. We do not currently implement a technical age gate that blocks minors from creating an account, but the product is intended for adult users and should not be used by minors without appropriate adult supervision or consent.
10. INDIA AND THE DPDP ACT
In short: NannaLife is currently launching in India, and this policy is written with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules in mind.
For Indian users, we process personal and health data only for the limited purposes described in this policy: account management, report storage, AI processing for report extraction and educational features, security, and service operation. We use reasonable security measures and limit the data we process to what is necessary for these features.
Users may contact us to request information about their personal data, ask for correction of inaccurate data, or request deletion where the product or applicable law supports that action. We do not claim that NannaLife is fully compliant with every provision of the DPDP Act or every future rule without continued review and operational compliance measures.
11. CONTACT INFORMATION
For privacy-related requests, please contact us at [email protected].
For general product or support requests, please contact [email protected].
We do not publish a personal residential address for privacy reasons and do not use residential contact details as the official public contact for the service.
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above. If material changes are made, we may notify users through the app or another reasonable channel.
NannaLife