Privacy Policy
Effective Date: February 27, 2026 | Last Updated: August 17, 2026
NAFAS ("we," "our," or "us") is a psychological safety companion application designed for endurance athletes. We are committed to protecting your privacy and ensuring transparency about how we collect, use, store, and share your personal information.
This Privacy Policy describes our practices regarding the data we collect through the NAFAS mobile application (the "App") and our associated services (collectively, the "Services"). By using our Services, you acknowledge that you have read and understood this Privacy Policy.
Our Commitment: We collect only the data necessary to provide our Services. We do not sell your personal information to third parties. Your health and wellness data remains under your control.
We use the information we collect for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Providing personalized AI companion interactions | Performance of contract |
| Analyzing WHOOP data to provide contextual psychological support | Performance of contract |
| Generating mental performance insights and trends | Performance of contract |
| Sending reminders and notifications you have opted into | Consent |
| Improving and developing our Services | Legitimate interest |
| Ensuring security and preventing abuse | Legitimate interest |
| Complying with legal obligations | Legal obligation |
We do not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:
WHOOP Data: Data received from WHOOP is used exclusively within the NAFAS App to provide contextual psychological safety insights related to your training and recovery. We do not share, sell, or transfer WHOOP data to any third party except as required to provide the core functionality of our Services.
Your data is stored on Google Cloud Platform infrastructure (Cloud Run, Google Cloud Storage) and a managed Postgres database (Neon). Authentication tokens for third-party services (such as WHOOP), your AI companion conversations, check-in voice transcripts, and AI-extracted memory data are encrypted at rest using AES-256 encryption.
We implement industry-standard security measures including:
We retain your data for as long as your account is active or as needed to provide our Services. Upon account deletion:
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, please contact us at support@nafas.health.
We use Firebase Authentication together with Google Sign-In and Sign in with Apple. Google's use of your information is governed by Google's Privacy Policy; Apple's by Apple's Privacy Policy. We receive only your basic profile information (name, email, and profile photo where provided) and do not request access to other Google or Apple services.
If you connect your WHOOP account, we access your recovery, sleep, and workout data through the WHOOP API. You can disconnect your WHOOP account at any time through the App settings, which will immediately revoke our access and delete stored WHOOP tokens. WHOOP's use of your data is governed by WHOOP's Privacy Policy.
We comply with WHOOP's API Terms of Use, including:
Conversation data is processed through Anthropic's Claude API to power the AI companion. API-processed data is not used by Anthropic to train their models. For more information, see Anthropic's Privacy Policy.
When you record a voice note, the audio is sent to OpenAI's Whisper API to generate a text transcript, which is then stored alongside the recording. API-processed data is not used by OpenAI to train their models. For more information, see OpenAI's Privacy Policy.
Our Services are intended for users aged 18 and older and are not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from someone under 18, we will take steps to delete such information promptly. If you believe someone under 18 has provided us with personal information, please contact us at support@nafas.health.
Your data may be transferred to and processed in countries other than your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses or other legally recognized transfer mechanisms, to protect your personal data in accordance with applicable data protection laws.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) as outlined in Section 6. Our legal bases for processing your data are detailed in Section 3. You also have the right to lodge a complaint with your local supervisory authority.
We may send push notifications for check-in reminders, insights, and motivational messages. You can opt out of push notifications at any time through your device settings or the App settings.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
Your continued use of our Services after such changes constitutes your acceptance of the updated Privacy Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
NAFAS
Email: support@nafas.health
Website: https://nafas.health
We will respond to all legitimate requests within 30 days.