Privacy Policy
Last updated: October 3, 2026
Read this together with our Terms of Service.
1. Scope and our relationship to you
This policy explains how Navora handles personal information across our websites, Naomi consumer support, Navora clinic workspaces, messaging, uploads, and connected tools. It covers adults using our service and information they are authorized to share about a child. It is not a consent form, a Business Associate Agreement, or a clinic’s Notice of Privacy Practices.
For direct consumer use, Navora handles information to provide your requested service. When a clinic uses Navora on its behalf, the clinic may determine the purpose of patient-data processing, and signed agreements and applicable law govern that processing. Ask your clinic about its own practices; it may retain its records separately from Navora.
2. Information you and your clinic provide
We collect account and contact information such as names, preferred names, phone numbers, email addresses, and verification information. Clinic accounts also provide professional roles, organization contacts, membership details, and team invitations. Roles used for addressing staff are not independent verification of credentials.
We process messages, voice or image content where used, documents, and information you or an authorized clinic share about pregnancy, postpartum recovery, a baby, delivery, feeding, symptoms, appointments, insurance, providers, discharge instructions, and care plans. Extracted fields, summaries, task notes, and inferred context may also be saved. These can be sensitive health information.
3. Connected accounts, tasks, and billing
If you connect Google or another supported service, we process the account identifiers, permissions, connection credentials, and information returned by authorized tools. Depending on the permissions and request, this may include email content and recipients, calendar events, files, and related task results. Information needed to interpret and complete a request may be passed to AI and tool providers.
We retain relevant task instructions, confirmations, status, results, and coordination history. For subscriptions, the payment processor handles payment details; Navora receives subscription identifiers, payment status, and related billing records rather than asking you to enter card details in chat or public-web tasks.
4. Technical information and feedback
The service and its infrastructure process device and browser information, IP addresses, session information, timestamps, request and delivery status, errors, and activity records. We also store conversation ratings, message feedback, staff notes, and operational audit events. Logs and error records can contain contextual information needed to investigate problems.
Cookies, browser storage, and similar technologies support sign-in, session continuity, settings, and reliable operation. Blocking or clearing them may sign you out or affect features. This policy does not represent that a particular analytics or advertising technology is present when it is not.
5. How we use information
We use information to create and secure accounts; deliver messages and requested assistance; extract and review documents; coordinate care-plan tasks; remember relevant context; connect authorized tools; manage subscriptions and invitations; provide support; and investigate failures or misuse.
We also use operational information and feedback to evaluate service quality, improve reliability, and meet legal obligations. Health information and identifiable patient content are not granted unrestricted use merely because they were uploaded. Separate legal requirements, permissions, and organizational agreements constrain their processing.
6. AI processing and human access
AI systems process relevant conversation context, documents, images, and tool results to generate responses, summaries, and extracted information. This can require sharing the content of a request with an AI provider. Do not assume that a connected email or uploaded document remains only on your device.
Authorized Navora personnel may access information for support, safety, troubleshooting, and service operations. Clinic staff can access information within their authorized workspace. Feedback can be associated with the account and conversation being evaluated. This policy does not promise that every model provider has identical retention or training terms; those terms and any required contractual restrictions must be assessed for the intended clinic use.
7. When information is shared
We disclose information needed to operate the service to hosting and storage providers, AI and document-processing providers, messaging carriers and delivery providers, account-connection and task providers, payment processors, and other operational providers. These recipients receive information appropriate to the function they perform, subject to applicable law and agreements.
For clinic-enrolled patients, authorized clinic staff may receive patient details, care-plan progress, notes, and issues raised for human review. When you approve an external action, information needed for that action may be sent to the specified provider, recipient, or website; their handling is governed by their policies.
We may disclose information where required by valid legal process, to protect rights and safety where legally permitted, or as part of a business transfer subject to applicable safeguards and notice requirements. We do not sell personal information or use sensitive health information for targeted advertising. These statements do not remove consent requirements for other legally regulated disclosures.
8. Health information and HIPAA
Whether HIPAA applies depends on the parties, data, and actual service relationship—not the name of an app or the channel used. A direct-to-consumer service is not automatically HIPAA-covered. When Navora creates, receives, maintains, or transmits protected health information on behalf of a covered clinic, business-associate obligations and a Business Associate Agreement may be required.
Ordinary SMS does not cause protected health information to lose that status. This policy makes no blanket claim that Navora is HIPAA compliant and does not establish required vendor agreements or security controls. Clinics and Navora must evaluate and establish those arrangements before processing real-patient information where required. Other privacy and consumer-health laws may apply even when HIPAA does not.
9. Messaging privacy and choices
Carrier-delivered texts and device notifications may be visible to carriers, other device users, or people with access to your phone. Ordinary SMS is not a secure clinical portal. Avoid sending detailed clinical records or highly sensitive information by text, and use the secure method your clinic recommends.
You can revoke text permission, including by replying STOP or contacting us, and use unsubscribe links for promotional email where provided. A permitted confirmation or necessary non-marketing notice does not authorize new marketing. Opting out of messaging does not itself erase records or cancel a subscription. If you receive messages after opting out, contact us.
10. Uploads and shareable links
Provider chat attachments are saved in owner-scoped private storage for the related conversation and analysis. Sending a chat attachment into the enrollment workflow does not by itself enroll or activate a patient. Direct enrollment extraction processes a document to produce reviewable fields; extracted information may be retained when the clinic saves the record even when the source document is not retained by that workflow.
Files or notes you share through a link may be accessible to anyone who obtains that link; forwarding it expands access. Link previews may reveal a note title or destination even when they do not show the contents. Do not put patient identifiers or sensitive health details into titles intended for public previews, and do not treat a shareable link as a confidential clinical channel.
11. Retention and deletion
We retain account information, conversations, saved clinic records, task history, attachments, feedback, and relevant logs while needed to provide the service, support clinic obligations, address disputes, maintain security, or satisfy legal requirements. There is no universal retention period for every category. Disconnection of a tool does not automatically delete previously saved information.
You can request deletion through the contact below. We may need to verify your identity and clarify the scope. Legal obligations, clinical recordkeeping, fraud prevention, unresolved disputes, or a clinic’s lawful instructions may limit deletion. Backup and vendor copies may persist for their applicable retention cycles. We do not promise immediate erasure from every system.
If your clinic controls the relevant patient record, we may direct the request to the clinic or coordinate with it. Closing Navora access does not delete the clinic’s own medical records. We will handle requests under applicable law and explain any lawful limitation.
12. Your privacy rights
Depending on your location and the laws that apply, you may have rights to know about and access your information, obtain a copy, correct inaccuracies, request deletion, restrict certain processing, withdraw consent, or opt out of a regulated sale, sharing, or targeted-advertising use. Some laws also provide appeal or complaint rights. Not every right applies to every record or service relationship.
Submit a request to privacy@navorahq.com. We will verify requests proportionately and respond within applicable legal deadlines; an authorized agent may submit a request where law permits. We will not unlawfully discriminate against you for exercising a privacy right. You may contact the relevant regulator, and appeal a denied request by replying and asking for review where applicable.
This policy is not a waiver of California privacy rights, state consumer-health protections, or other mandatory rights. Where a separate notice or consent is required by applicable law, this general policy does not replace it.
13. Children and family information
Navora is intended for adults aged 18 or older, not for children to register or use directly. A parent, guardian, or authorized clinician may share relevant information about a child for the adult’s requested support or authorized coordination. That information is treated as sensitive personal information, not as consent for a child to open an account.
Contact us if you believe a child registered directly or information about a child was provided without authority so we can investigate and take appropriate action.
14. Security, incidents, and international processing
We use access controls and infrastructure safeguards intended to protect information, but no system, authentication method, messaging channel, or transmission is risk-free. Protect your devices and sign-in links, avoid shared accounts, and tell us promptly about suspected unauthorized access. This policy is not a security certification or a guarantee that every access is logged.
Information may be processed in the United States and other locations used by operational providers. Privacy laws may differ by location; applicable transfer safeguards and organizational agreements must be used where required. We will provide incident or breach notices when required by applicable law or contract. Using the service does not waive those duties.
15. Changes and contact
We may update this policy as practices change. We will identify the new date and give notice of material changes, and seek consent where legally required before a new use. Posting a change does not retroactively authorize an unlawful disclosure.
For privacy, access, correction, deletion, or consent requests, email privacy@navorahq.com. For clinic agreements, email legal@navorahq.com. In an initial email, provide only enough information to identify your request; do not attach sensitive patient records. Ask for an appropriate secure method if further documentation is needed.