Nora/Trust/Privacy
Trust

Privacy.

A plain-English account of what we collect, why we collect it, who can see it, and how to make it stop.

Effective May 1, 2026

01 Scope of this policy

This policy covers data about you — the people who visit our website, sign up for our waitlist, or interact with Nora as an agency owner, caregiver, or family member.

Protected health information that Nora processes on behalf of a home care agency is governed separately by our HIPAA · BAA page and by the Business Associate Agreement between Atlas AI, Inc. and that agency. This policy does not modify or replace that agreement.

02 What we collect

We try to collect as little as possible. The categories below are exhaustive — if it isn't listed here, we don't have it.

CategoryExamples
Account informationName, work email, role, the agency you represent.
AuthenticationHashed credentials, SSO identifiers, MFA tokens.
Product usagePages viewed, features used, errors encountered. Aggregated; never linked to PHI.
CommunicationsEmails you send us, support chats, sales calls (with consent).
Device & networkIP address, browser, operating system, approximate region.
MarketingWaitlist email, opt-in newsletter subscription, UTM source.

We do not use third-party advertising trackers on our site. We do not sell or rent your data.

03 Why we collect it

  • To run the service. Authenticate you, route your requests, send your notifications, generate your invoices.
  • To improve the service. Measure feature use in aggregate, fix bugs, understand which capabilities help which kinds of agencies.
  • To support you. Answer your questions, debug your issues, write your onboarding plan.
  • To stay compliant. Maintain audit logs, respond to lawful requests, meet our security obligations.
  • To talk to you about Nora. Send you waitlist updates, product changes, and the occasional field note — only if you opt in, and only until you opt out.

04 Who we share it with

We share data only with the parties below, only for the purposes named, and only after they sign appropriate contractual protections:

  • Service providers — hosting, email, analytics, payments, support. Each is bound by a data processing agreement.
  • Your agency — if you are a caregiver, family member, or client, the agency that retained Nora is the controller of your PHI under HIPAA.
  • Law enforcement and regulators — when we are legally compelled. We push back on overbroad requests and notify you where we are permitted to do so.
  • Acquirers — in the unlikely event of a merger, acquisition, or sale of substantially all of our assets, with continued protection under this policy or a successor of equal protection.

We have never sold customer data and we will not. If that ever changes, we will require your consent in writing first.

05 How long we keep it

Account data is retained for as long as your account is active. After termination, we delete or anonymize personal data within 60 days unless retention is required by law (e.g. tax records, HIPAA audit logs retained six years).

Waitlist emails are retained until you unsubscribe or until 18 months after the last interaction, whichever is sooner.

Marketing analytics are aggregated within 30 days; the underlying event records are deleted on a rolling 90-day window.

06 Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your account and the data associated with it.
  • Port your data in a machine-readable format.
  • Object to processing, including profiling and marketing.
  • Withdraw consent at any time, without affecting prior lawful processing.

To exercise any of these, email privacy@nora.care. We respond within 30 days.

07 Children

Nora is a service for adults running and working in home care agencies. We do not knowingly collect data from anyone under 18. If you believe a child has shared data with us, write to us and we will delete it.

08 International transfers

We process data in the United States. If you are accessing the service from outside the U.S., you understand that your data will be transferred to, stored, and processed in the U.S. under appropriate safeguards (including Standard Contractual Clauses where applicable).

09 Changes to this policy

If we change this policy, we will update the effective date at the top of the page. For material changes, we will email everyone with an active account before the change takes effect.

10 Contact

Questions, concerns, or requests under this policy go to our Privacy Officer.

Atlas AI, Inc.
Privacy Officer · San Francisco, CA
privacy@nora.care