< Back to Noma home

Privacy Policy

Noma Privacy Policy

Effective Date: July 24, 2026
Operator and controller: Nagi Labs LLC
Website: trynoma.co
Contact for privacy requests: contact@trynoma.co
Applications covered: the Noma iOS app, listed as "Noma - for digital nomads" in the App Store, and related websites, services, and features (the Service).

This Privacy Policy explains how Nagi Labs LLC (Nagi Labs, we, us, or our) collects, uses, shares, and protects information when you use the Service. We collect data to provide, secure, personalize, support, and improve the Service. We do not sell personal information and we do not use personal information for third-party advertising.

1. Scope and Controller
   Nagi Labs LLC, which operates the Noma-branded Service, is the controller of personal data processed in connection with the Service where controller concepts apply. This Policy applies worldwide to users who access or use the Service.
   As of the Effective Date, Nagi Labs LLC operates Noma and is responsible for personal information associated with the Service.

2. Information We Collect
   2.1 Information you provide or generate in the app
   - Account and sign-in: When you sign in with Apple, we or our authentication provider receive information needed to authenticate you, such as your Apple-provided user identifier, authentication tokens, and, if Apple provides it and you allow it, your name and email address.
   - Onboarding and profile: Your name, answers to the five Nomad Archetype onboarding questions, final Nomad Archetype, app settings, temperature preference, light-mode preference, time-zone filter settings, and related profile state. These are primarily stored locally on your device, though related analytics events may be sent as described below.
   - Destination preferences and travel history: Destination filter choices, selected or searched reference locations, time-zone preferences, and countries you mark as visited.
   - Trip and itinerary inputs: Destination, destination coordinates when selected, dates or flexible day count, trip type, trip pace, work mode, work hours, work time zone, work environment, neighborhood preference, weekend side-trip preference, and activity preferences.
   - Generated itineraries: Itinerary status, generated schedules, activities, neighborhoods, map-related places and coordinates, summaries, cover image URLs, timestamps, and related itinerary records.
   - Time-zone schedule planner: Work city, destination city, city coordinates, time zones, and saved time blocks. These are currently stored locally on your device unless included in another feature such as feedback or analytics.
   - Visited countries: Countries you select manually and countries added from completed itineraries. These are currently stored locally on your device.
   - Feedback and communications: Feedback categories, description, associated user identifier, associated itinerary identifiers, timestamps, support requests, emails, and any optional contact information you include in the message.

   2.2 Information collected automatically
   - App analytics and diagnostics: Firebase Analytics may receive app events and detailed feature-usage fields, including onboarding answer tags; selected filters; a selected or inferred reference city; exact trip city and selected trip coordinates; trip dates or duration; trip type and pace; work mode, environment, hours, and time zone; neighborhood, weekend, and activity preferences; itinerary or other app-generated identifiers; Firebase installation or app-instance identifiers; itinerary-generation status and timing; screen or feature duration; error events; app version; device type; operating system; language; approximate region; and related diagnostic metadata. We do not intentionally send your name or email address as analytics event fields.
   - Subscription status: RevenueCat and Apple may process an anonymous RevenueCat app-user identifier, subscription entitlement status, product identifiers, purchase identifiers, receipts, renewal status, device/app and SDK metadata, IP address or similar network metadata, and related transaction information. We do not receive your full payment card number.
   - Security and integrity data: Firebase App Check, App Attest, DeviceCheck, authentication, abuse-prevention, and request metadata such as IP address, user agent, device/app information, and timestamps used to help protect the Service.
   - Website analytics: The website uses Google Analytics/Google tag, which may collect page views, referrers, device/browser information, approximate location, identifiers, and cookie or similar technology data.

   2.3 Location and search data
   - Device location: If you grant iOS location permission, Apple location and geocoding services process a one-time or foreground device location while you are using the app so the app can infer your current city or time zone for destination filtering and time-zone features. We do not use background location in the current app.
   - Location search and maps: If you search for or select locations, Apple MapKit and related Apple services may process the search query, selected place, coordinates, and map-related data under Apple's terms and privacy policy.
   - Weather: When generating an itinerary, Apple WeatherKit may receive the selected destination coordinates and trip dates to return weather information. These are the trip destination coordinates and are not necessarily your device's current coordinates.

   2.4 Information from third parties
   - Apple: Sign in with Apple information you authorize, App Store transaction information, MapKit data, WeatherKit data, App Attest, and DeviceCheck information.
   - Firebase/Google Cloud: Authentication identifiers, Firestore records, Storage records, Remote Config/App Check data, and Analytics events.
   - RevenueCat: Subscription entitlement and receipt information.
   - OpenAI: Itinerary prompts, relevant trip context, generated outputs, and image-generation inputs/outputs needed to provide AI-assisted features.
   - Google Analytics: Website analytics and related identifiers.

   Some laws may treat precise location as sensitive personal information. Optional foreground location is used only for the location, time-zone, and destination-filter features described in this Policy, and you can revoke permission in iOS Settings. Apart from this optional location processing, we do not intentionally seek to collect sensitive personal information such as precise identity-document numbers, financial account numbers, passwords, health information, religious beliefs, or government identifiers. Please do not submit such information to the Service.

3. How We Use Information
   We use information to:
   - provide and operate the Service, including authentication, subscriptions, onboarding, destination discovery, filters, trip planning, itinerary generation, saved itineraries, maps, weather summaries, time-zone schedules, visited-country tracking, settings, and feedback;
   - personalize the Service, including Nomad Archetype results, For You filters, destination relevance, time-zone-friendly destinations, itinerary structure, and activity recommendations;
   - process subscriptions, trials, entitlements, and billing status through Apple and RevenueCat;
   - generate AI-assisted itineraries, summaries, schedules, maps-related content, and cover images;
   - process and store itinerary-generation requests and records through Firebase/Google Cloud;
   - provide support, respond to feedback, and communicate important service notices;
   - analyze performance, troubleshoot errors, improve usability, test features, and understand aggregate usage;
   - prevent fraud, abuse, unauthorized access, paywall circumvention, and security incidents;
   - comply with legal obligations, enforce our Terms, and protect rights, safety, and security.

   Legal bases where required may include contract performance, legitimate interests, consent, legal obligations, and protection of rights and safety.

4. AI Providers
   We use OpenAI to generate itineraries, schedules, destination-related text, and cover images. We send the itinerary inputs needed for generation, such as destination, dates or duration, trip type and pace, work schedule and time zone, work environment, neighborhood and weekend preferences, activity preferences, and available weather context. We try to limit what we send to what is reasonably needed for the feature.
   AI provider processing, retention, and review are governed by provider terms and policies and by the settings we configure. We configure OpenAI text responses to be stored as retrievable Responses API application state so we can review generation records and troubleshoot the Service. OpenAI may retain API inputs, outputs, and related metadata in that application state and in abuse-monitoring logs according to its provider terms, our configured retention controls, and applicable law. Do not submit sensitive personal information or confidential information in itinerary inputs or feedback.
   AI outputs may be inaccurate, incomplete, unsafe, duplicated, or outdated and are provided for informational purposes only, not professional advice.

5. Sharing of Information
   We share information only as needed for the purposes described in this Policy:
   - Apple: App Store transactions, Sign in with Apple, MapKit, WeatherKit, App Attest, DeviceCheck, and device permission flows.
   - Firebase/Google Cloud: Authentication, Firestore database, Cloud Storage, Remote Config, App Check, Analytics, cloud functions, hosting, and infrastructure.
   - RevenueCat: Subscription management and entitlement checks.
   - OpenAI: AI itinerary, content, and image generation.
   - Google Analytics: Website analytics.
   - Email and support providers: Communications you send to us or that we send in response.
   - Legal and safety disclosures: We may disclose information if required by law, legal process, platform rules, or to protect rights, safety, security, users, Nagi Labs LLC, or third parties.
   - Business transfers: Information may be transferred in connection with a reorganization, merger, acquisition, financing, sale of assets, change of operator, or formation of a business entity to operate the Service, subject to this Policy or a successor policy.

   We require service providers that process personal information for us to protect it consistently with this Policy and applicable law. We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising.

6. Local Storage and Cloud Storage
   Some information is stored locally on your device using Apple platform storage, including onboarding state, profile settings, schedules, visited countries, and itinerary data. Some information is processed or stored in Firebase/Google Cloud, including authentication records, itinerary-generation requests and inputs, generated itinerary records, feedback, and related operational records. The current app does not provide cross-device backup or restoration of your locally saved itinerary list.
   Removing the app may delete local data on your device but does not automatically cancel subscriptions or necessarily delete cloud records. Subscription cancellation must be handled through Apple ID settings. Account or cloud-data deletion requests can be sent to contact@trynoma.co.

7. Retention
   We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain subscriptions and records, resolve disputes, enforce agreements, comply with law, protect security, and maintain backups.
   Retention periods vary by category:
   - Account/authentication records: for the life of the account, plus a reasonable period for deletion, backup, security, and legal needs;
   - Itinerary records and prompts: while needed to generate itineraries, operate the app, debug and improve the product, protect security, and meet legal needs, unless deleted or anonymized earlier;
   - Itineraries deleted in the app: the local device copy is removed, but the existing cloud record, including the itinerary inputs and generated output, currently remains in Firestore with its status marked as deleted until we process a separate verified deletion request or delete or anonymize it under our retention process. Residual copies may remain longer in backups or where needed for security, abuse prevention, debugging, or legal obligations;
   - Feedback and support messages: as long as needed to respond, improve the Service, track issues, and maintain business records;
   - Analytics and diagnostics: according to our provider settings and business needs, generally in aggregated or event-level form;
   - Transactions and receipts: as required or permitted by Apple, RevenueCat, tax, accounting, platform, and legal requirements;
   - Aggregated, de-identified, or anonymized information: may be retained indefinitely where it cannot reasonably identify you.

8. Your Rights and Choices
   Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, withdraw consent, receive a copy of personal information, appeal a decision about a request, or use an authorized agent. You may also have the right not to receive discriminatory treatment for exercising a privacy right. To submit a request, request account/cloud-data deletion, or appeal a decision, email contact@trynoma.co from your account email and include your name, the email used for Noma, and the request type. We may ask for information reasonably necessary to verify and fulfill the request.
   If European Economic Area or United Kingdom data-protection law applies, you may also lodge a complaint with the supervisory authority in the place where you live or work or where you believe a violation occurred.
   You can control location and notification permissions in iOS Settings. You can cancel subscriptions in Apple ID settings. Browser and cookie controls may limit some website analytics. The current iOS app does not provide an in-app control for Firebase Analytics collection.
   We do not sell personal information and do not share personal information for cross-context behavioral advertising.

9. International Data Transfers
   We and many of our providers are based in the United States. If you access the Service from outside the United States, your information may be processed in the United States and other countries that may have different data protection laws. Where required, we rely on applicable provider contractual terms and other legally recognized safeguards for cross-border transfers.

10. Security
   We use technical and organizational measures designed to protect information, including platform authentication, app-integrity checks, encryption in transit, operational controls, and provider infrastructure and security measures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children
   The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.

12. Third-Party Links and Services
   The Service may link to or rely on third-party services. Third-party privacy practices are governed by their own policies. We are not responsible for third-party privacy practices.

13. Do Not Track
   Some browsers offer a "Do Not Track" signal. Our website and Service do not currently respond to DNT signals. Google Analytics and other service providers may collect information about activity on the website over time and across websites or online services as described in their own policies. We do not sell personal information or use it for cross-context behavioral advertising. Where applicable law requires us to recognize a legally valid browser-based opt-out preference signal for a processing activity we perform, we will do so. You may also use browser, device, and cookie controls to limit some collection.

14. Changes to This Policy
   We may update this Policy from time to time. We will post the updated version with a new effective date and, where required, provide additional notice of material changes. Your continued use of the Service after an updated Policy takes effect means you acknowledge the updated Policy.

15. Governing Law and Venue
   Governing Law: New York, USA.
   Venue: State and federal courts located in New York County, New York, USA, subject to the dispute-resolution terms in our Terms of Service.

16. Contact
   Operator and controller: Nagi Labs LLC
   Email: contact@trynoma.co
   Website: trynoma.co
   For legally required postal correspondence, email contact@trynoma.co to request our current business mailing address.

Summary of Key Practices
   - No sale of personal information and no third-party advertising use by Nagi Labs LLC.
   - Sign in is currently through Apple.
   - Location is optional foreground location used for time-zone and destination-filter features.
   - Itinerary generation uses Firebase/Google Cloud and OpenAI.
   - The website uses Google Analytics.
   - Subscriptions are handled by Apple In-App Purchase and RevenueCat.
   - You can request access, correction, or deletion by emailing contact@trynoma.co.