NUMERA · EVALIX

Numera — Privacy & Data

Draft. Last updated: 2026-06-11. This document is the engineering copy of Numera's privacy policy. Final wording must be reviewed by qualified legal counsel before it is published in-app or linked in the app stores. Items in [SQUARE BRACKETS] are placeholders that must be completed (legal entity details, public policy URL, hosting region, supervisory authority, DPO) before publication.

This policy explains what data Numera stores, why we store it, who we share it with, and how to exercise your rights under the EU/UK General Data Protection Regulation (GDPR) and the Israeli Privacy Protection Law. It also covers the disclosures required by the Apple App Store and Google Play (Section 12).


1. Who we are (data controller)

Numera is operated by EVALIX ("Numera", "we", "us"), registered at [REGISTERED ADDRESS — pending company registration], company number [COMPANY / REGISTRATION NUMBER — pending company registration].

For all data-protection matters we are the data controller of the information described in this policy.


2. Who this policy applies to and minimum age

This policy applies to everyone who uses the Numera app on iOS or Android.

Numera is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect data from anyone below this age. If you believe a minor has provided us data, contact us and we will delete it.

This policy also governs data you enter about other people (for example, a partner you add for a compatibility reading). See Section 9.


3. What data we store

When you create a Numera account, we store the following under your user ID:

TableContents
user_profilesEmail, display name, subscription tier, language preference
saved_chartsBirth name, Hebrew name (if provided), birth date, birth time and place, and the computed numerology values
deep_dive_cacheAI-generated narrative analyses, cached so a regenerated report doesn't re-charge the AI for the same chart
deep_dive_logsOne row per AI call (topic + chart name + timestamp) for billing/analytics
saved_reportsHTML/PDF reports you've generated
practitioner_brandingLogo, business name, contact details (practitioner accounts only)
feature_quotasPer-feature usage counters (e.g., 7 of 50 deep dives this month)
feature_quota_refundsAudit rows written when a deep-dive failed and we refunded the credit

When you use the Couple Compatibility and Relationship Insights features, we additionally store:

TableContents
partner_profilesInformation you enter about another person so you can compare charts: their name, optional Hebrew name, birth date, and optionally birth time and birth place
compatibility_analysesThe computed three-axis (numerology / astrology / Kabbalah) reading between you and a partner, including the AI synthesis paragraph
relationship_insightsThe free-text questions you ask about a saved analysis (e.g. about a breakup, an ongoing relationship, or a recurring pattern), the wellbeing classification of that question, and the AI's written response
gdpr_audit_logA short-lived record of data export and deletion requests (see Section 14)

We do not sell your data, and we do not share it with third parties for advertising or marketing.


4. Legal bases for processing

We rely on the following lawful bases under GDPR Article 6 (and the equivalent grounds under Israeli law):


5. How we use your data

We use your data only to:

  1. Generate your numerology charts (computed on your device — basic chart data does not leave your phone unless you save it or request an AI analysis).
  2. Produce AI deep-dives, compatibility readings, and relationship insights when you request them.
  3. Manage your account, subscription, and usage quotas.
  4. Route crisis-flagged questions to appropriate support resources (Section 7).
  5. Keep the service secure and prevent misuse.
  6. Comply with our legal obligations and respond to your data-rights requests.

We do not use your data to train AI models, and we do not profile you for advertising.


6. Third parties and international transfers

To run Numera we share the minimum necessary data with the following processors. Your account and app data is stored inside the European Union. Some processors operate outside the European Economic Area (EEA) (notably in the United States); where that is the case, the transfer is protected by appropriate safeguards — Standard Contractual Clauses, and, where the processor is certified, the EU–US Data Privacy Framework.

ProcessorWhat they receivePurposeLocation
Anthropic (Claude AI)Your chart data and the free-text content of your Insights questions when you request an AI analysis. Your name and email are never sent.To generate the narrative analysis and insight textUnited States
SupabaseAll account and app data (hosting, database, authentication)To store your data securelyEuropean Union (Frankfurt, Germany — eu-central-1)
RevenueCatA subscription customer ID and purchase/entitlement dataTo manage subscriptions across Apple and GoogleUnited States
Apple / GoogleBilling and receipt dataTo process in-app purchasesGlobal
OpenStreetMap (Nominatim)The birth city you type into the search box (not your name, and only when you look up a city)To resolve a city name to coordinates and time zone for astrologyEuropean Union (operated by the OpenStreetMap Foundation)

Anthropic processes the data to produce the response and, per their terms, does not retain it to train their models. We send only what is needed for the feature you requested.


7. Sensitive content and wellbeing

Some of what Numera processes is unusually personal, and we want to be explicit about it.

Your Insights questions. When you ask a relationship question, the text you write is stored in relationship_insights and sent to Anthropic to generate a response. These questions can be emotionally significant. They are visible only to you (enforced at the database level) and are deleted when you delete the analysis, the partner, or your account.

Special-category data. Your free-text questions, your spiritual/Kabbalistic inputs, or details about your relationships may incidentally reveal information that GDPR treats as special-category — for example data concerning health, religious or philosophical beliefs, or your sex life. Where this happens, our legal basis is your explicit consent, given by choosing to use the feature. You are never required to share such information, and you can delete it at any time.

Crisis and wellbeing handling. Before generating an insight, your question passes through an automated wellbeing classifier. If it detects crisis-level content (such as references to self-harm or abuse), the app prioritises showing you localised support resources (e.g. ERAN 1201 in Israel, 988 in the US, Samaritans 116 123 in the UK) ahead of any chart content. This classification is automated; flagged questions are not reviewed by staff as a matter of course, and the classifier result is stored alongside your question solely to deliver the correct response. The classifier is a safety feature, not a substitute for professional help, and does not contact any third party or authority on your behalf.


8. How long we keep your data


9. Data about other people (partner profiles)

The Couple Compatibility feature lets you add another person as a "partner profile." That person is a separate data subject with their own privacy rights, even though they don't have a Numera account.

By adding someone, you confirm you have a legitimate reason to enter their birth information and that you will honour their wishes if they ask you to remove it. Numera stores this data only to provide the reading you requested, never contacts the person, and never makes their profile visible to anyone but you.

You can delete a partner and everything tied to them at any time, from the partner detail screen — see Section 13. If a person whose data you entered contacts us directly and asks for removal, we may need to coordinate with you to identify and erase the relevant records, and we will act on a valid request.


10. How we protect your data


11. Your rights

Under GDPR and Israeli privacy law you have the following rights. To exercise any of them, use the in-app controls below where available, or contact numera@evalix.io.

We respond to rights requests within 30 days (GDPR Article 12).

Right to access (download your data)

Settings → Privacy & Data → Download my data.

Produces a JSON file containing every record listed in Section 3. The download is a one-shot operation; we don't store the export.

Right to erasure (delete everything)

Settings → Privacy & Data → Delete all my data.

Requires you to re-enter your password (a defence against an unattended device wiping your account). After confirmation:

  1. Your account record is deleted, which automatically cascades to every table listed above via foreign-key constraints.
  2. You are signed out and returned to the welcome screen.
  3. An audit row is written recording that the deletion took place (your user ID, your email at the time, the timestamp, and the per-table row counts that were removed).

Deletion is permanent and irreversible. We cannot recover deleted accounts.

Right to data portability

The downloaded JSON is machine-readable and structured per-table, so you can import the relevant pieces into any other system you choose.


12. Platform privacy disclosures (Apple App Store & Google Play)

Numera is distributed through the Apple App Store and Google Play, and we comply with their privacy requirements in addition to the law.

Where to find this policy. This policy is available inside the app (Settings → Legal → Privacy Policy) and at a public URL: https://numera-privacy.evalix.io/privacy. Both stores require a publicly reachable privacy-policy link in the store listing.

Account and data deletion. Both Apple and Google require that any app offering account creation also lets you delete your account and data.

Tracking (Apple App Tracking Transparency). Numera does not track you across other companies' apps or websites. We do not use the advertising identifier (IDFA), and we do not show the App Tracking Transparency prompt because there is nothing to track. We do not use third-party advertising SDKs.

Apple "App Privacy" / Google "Data safety" summary. To help you read the store labels (these must match exactly what we declare in App Store Connect and the Play Console Data safety form — all three are kept in sync):

Sign-in providers. You currently sign in with an email address and password. (Sign in with Apple and Google Sign-In are planned for a future release; when they launch, this policy will be updated to cover them — including Apple's private-relay email option — and their use will also be governed by Apple's and Google's own privacy policies.)

Purchases. Subscriptions are processed by Apple and Google (via RevenueCat). Payment and receipt data is handled under Apple's and Google's privacy policies; we receive only a subscription identifier and entitlement status, never your full payment-card details.

Device permissions. Numera requests no special device permissions.


13. Per-partner data deletion

When the Couple Compatibility feature is enabled, you can add another person as a "partner profile" for a compatibility reading. That partner is a separate data subject. From the partner detail screen you can "Delete this person and all related data" — which removes their profile and every compatibility analysis or insight you generated about them, without touching anything else on your account.

This is for situations where:


14. Audit log retention

We keep one row per delete-or-export request for 30 days, after which the audit row itself is automatically purged. The audit row records the action (delete / export), timestamp, your user ID at the time, your email, and a per-table row-count summary — never the content of the data that was deleted.

Why we keep it: if a user disputes that a deletion took place ("you said you deleted my data, did you really?"), the audit row is the evidence. After 30 days the dispute window closes and we no longer need it.


15. Changes to this policy

We may update this policy as Numera evolves (for example when a new feature changes what data we process). When we make a material change, we will update the "last updated" date and notify you in-app before the change takes effect. Continued use of Numera after an update means you accept the revised policy.


16. Contact

For data-related questions or to invoke a right you can't access in-app:

We respond within 30 days, per GDPR Article 12.


Provenance of this document

This draft is mirrored in the Numera codebase at PRIVACY.md and surfaced in-app at Settings → Legal → Privacy Policy, and at the public URL in Section 12. The in-app version is the user-facing source of truth; this file is the engineering copy used to keep them in sync.

Last technical change: GDPR + app-store policy expansion (2026-06-11) — added data-controller identity, legal bases, sub-processor and international-transfer disclosures, special-category/wellbeing handling, the full set of data-subject rights, retention, security, children, and change-notification sections; added Section 12 covering Apple App Store and Google Play requirements (public policy URL, in-app and external deletion routes, App Tracking Transparency, App Privacy / Data safety summary, sign-in providers, purchases, device permissions); aligned the data table with the relationship features; corrected the contact email to numera@evalix.io.

To delete your account and data, see our data-deletion page. · Contact: numera@evalix.io