Privacy
Privacy Policy
Your privacy matters. This Privacy Policy explains how NoticeMe collects, uses, stores, and protects personal data. NoticeMe is currently developed as a student project based in Zurich, Switzerland, and is available to an international audience.
Data we collect
NoticeMe collects only the information needed to provide its core functionality:
- Account information: your email address, an optional display name, and your password (stored only as a secure one-way hash, never in readable form).
- The entries you choose to log: pain level, energy, mood, sleep and stress ratings, symptom tags, and any free-text notes you add.
- Limited technical data needed to run the service, such as a session cookie that keeps you signed in and standard server logs (for example, request times and IP addresses).
These server logs may include IP addresses as part of standard request logging, and are retained according to our hosting providers’ standard practices.
Health-related data
Any health-related information you enter is provided voluntarily. It is used to let you track and reflect on your own symptoms over time, to generate personal insights from your data, and to produce reports you can choose to share with your own doctor.
NoticeMe does not diagnose, treat, or predict health conditions, and it does not make clinical decisions.
How your data is used
Your personal data is used to operate the app’s features: recording your entries, showing your history, and generating your insights and reports. It is not used for advertising, and NoticeMe does not sell, rent, or trade your personal data.
Your entries are private to your account and are not shown to other users.
AI and third-party services
To turn the patterns in your data into readable insights, NoticeMe sends the statistical patterns it finds (for example, that two of your tracked variables such as sleep and pain tend to move together, along with counts and the symptom or mood labels involved) to OpenAI, a third-party AI provider. NoticeMe does not send your free-text notes, your email, your identity, or your raw daily entries to OpenAI. This happens only once you have logged enough data and you open your insights.
NoticeMe runs on third-party infrastructure: Vercel serves the app, and Railway hosts the backend and database. These providers process data on NoticeMe’s behalf so the service can run. Once data is sent to a third party such as OpenAI, it is also subject to that provider’s own handling and retention, which NoticeMe does not control.
How your data is stored and protected
The health-related fields in our database are encrypted at rest using field-level encryption. This covers your symptom logs (pain level, energy, mood, sleep quality, stress level, symptom tags, and free-text notes), your profile details, and your stored insight summaries. If the database contents alone were exposed, these fields would be unreadable ciphertext.
There are limits to what this protects, and we would rather be clear about them than overstate it:
- Encryption relies on the app’s encryption key. Anyone who holds that key can decrypt the data, so it does not protect against a compromised key.
- While you are signed in, the app decrypts your data to show it to you. Access to your account or an active session therefore means access to your data in readable form.
- Not everything is field-encrypted. Your email is stored so you can sign in, and any PDF reports you generate are stored as files (not field-encrypted) until you delete them or your account.
- Because NoticeMe is a student project under active development, the people and tools involved in building it, including AI-assisted development tools, may have access to the codebase and to data in development and testing environments.
Connections to the app use HTTPS. No system can be guaranteed to be completely secure.
Consent
Before you can create an account, you must actively check a box confirming that you agree to this Privacy Policy and the Terms of Service. Your acceptance is stored as a dedicated consent record, including the policy version you accepted and the time you accepted it. If a future version is significantly different, we will ask you to review and accept it again.
Your rights and controls
You can manage your data yourself, directly from your profile, without sending a request and waiting:
- Export: you can download a full copy of your data (your account information, symptom logs, consent history, and report metadata) as a JSON file.
- Deletion: you can permanently delete your account and its associated data, including your symptom entries and generated reports. This cannot be undone. Your consent record is kept in anonymized form, with the link to your account removed, as proof that consent was given. It is no longer tied to your identity.
Account deletion takes effect immediately within the app. For operational safety, database backups may retain a copy of deleted data for a limited period before they rotate out.
Depending on where you live, you may also have additional rights to access or correct your personal data under applicable law.
NoticeMe is provided for educational and informational purposes only and is not a medical product.
Version 1.0. This Privacy Policy may be updated as the app evolves; if a change is significant, we will ask you to review and accept the updated version. Questions? Contact support@noticeme.app.