← Back to homepage

Privacy Policy

Last updated: 30 August 2026

1. Controller

The controller responsible for the processing of your personal data is:

Norena Technologies AG Wadsack Zug AG Bahnhofstrasse 7, 6300 Zug, Switzerland CHE-202.093.568 Email: privacy@norena.ai

2. Scope & Applicability

This Privacy Policy applies to all personal data collected through the Norena mobile application ("App"), the website at norena.ai ("Website"), and any related services (collectively, the "Services"). This policy applies to all users, including participants in our pilot programme.

The Services are designed for use by adults, including elderly persons and their caregivers. If you are setting up or managing the Services on behalf of another person, you are responsible for ensuring that person understands and, where possible, consents to the data processing described in this policy.

If you are in the United Kingdom, the UK Privacy Addendum also applies. It supplements this Swiss Privacy Policy and takes priority where UK data protection law requires a different result.

3. Pilot Programme & Special Terms

By participating in the Norena pilot programme, you acknowledge and consent to the following additional terms:

  • Development use: All data collected during the pilot period, including voice recordings, conversation transcripts, usage patterns, and any other data generated through your use of the Services, may be used by Norena Technologies AG for product development, improvement, testing, training of AI models, analytics, and research purposes.
  • Consent as condition of access: Your consent to this data use is a condition of receiving access to the pilot programme. You may withdraw your consent at any time by contacting us at privacy@norena.ai. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.
  • De-identification: Data used for development purposes will be de-identified using industry-standard techniques (such as pseudonymisation, voice anonymisation, and removal of identifying metadata). However, given the nature of voice and conversational data, complete anonymisation cannot always be guaranteed. Where true anonymisation is achieved, the data falls outside the scope of data protection law and may be retained without restriction.
  • Duration: These pilot-specific terms apply for the duration of the pilot programme and for a period of five (5) years thereafter, during which Norena Technologies AG retains the right to use previously collected pilot data for the purposes stated above.

4. Data We Collect

4.1 Data you provide directly

  • Name, email address, and contact details (registration)
  • Role or relationship to the end user (e.g. family member, caregiver)
  • Voice recordings and conversation transcripts
  • Profile information about the end user (health notes, preferences, medication schedules)
  • Any other information you voluntarily submit through the Services

4.2 Data collected automatically

  • Device information (device type, operating system, unique identifiers)
  • Usage data (features used, session duration, interaction patterns)
  • Log data (IP address, access times, app crashes, system activity)
  • Cookies and similar technologies on the Website (see Section 16)

4.3 Sensitive Personal Data

The Services process the following categories of sensitive personal data as defined by Art. 5 para. 1 let. c FADP:

  • Health-related data (e.g., medication reminders, wellness check-ins, health notes)
  • Biometric data: voice recordings that may uniquely identify a natural person

By using the Services, you explicitly consent to the processing of such sensitive personal data as described in this policy, in accordance with Art. 6 para. 7 let. a FADP. You may withdraw this consent at any time (see Section 10 below), though withdrawal may limit the functionality of the Services.

5. Purposes of Processing

We process your personal data for the following purposes:

  • Providing, operating, and maintaining the Services
  • Delivering personalised AI companion interactions
  • Sending medication reminders and wellness check-ins
  • Generating and preserving life stories and keepsakes
  • Communicating with you about your account and the Services
  • Product development, improvement, and research (especially during the pilot)
  • AI model training and optimisation
  • Ensuring security, preventing fraud, and enforcing our terms
  • Complying with legal obligations under Swiss law

6. Legal Basis

Under Swiss data protection law, the processing of personal data by private persons is generally permitted unless it breaches the personality rights of the data subject (Art. 30 FADP). A breach of personality rights is unlawful unless justified by consent, an overriding private or public interest, or the law (Art. 31 FADP).

We rely on the following justifications for processing your data:

  • Consent (Art. 6 para. 6–7 FADP): We obtain your explicit consent for the processing of sensitive personal data (health data, biometric voice data) and for the use of your data for AI model training during the pilot programme.
  • Performance of a contract (Art. 6 para. 3 FADP): We process data as necessary to provide the Services you have requested.
  • Overriding interests (Art. 31 para. 2 FADP): We process data for analytics, security, and product improvement where our legitimate business interests are not overridden by your rights.
  • Legal obligations: Where required by Swiss law.

7. Data Sharing & Third Parties

We do not sell your personal data. We may share data with the following categories of recipients:

  • Service providers: Cloud hosting, AI processing, analytics, and communication services that process data on our behalf under strict contractual obligations
  • Family members and caregivers: Certain data (wellness summaries, stories, status updates) may be shared with designated family members or caregivers as configured by you or your authorised representative. You may modify or revoke these sharing settings at any time within the App or by contacting us.
  • Legal requirements: Where required by Swiss law, court order, or governmental request
  • Corporate transactions: In connection with a merger, acquisition, or sale of assets, subject to standard confidentiality obligations

8. International Data Transfers

Your data may be transferred to and processed in countries outside of Switzerland. Where such transfers occur, we ensure an adequate level of data protection through:

  • Transfers to countries recognised by the Swiss Federal Council as providing adequate protection
  • Standard contractual clauses approved by the FDPIC
  • Other appropriate safeguards as required under Art. 16-17 FADP

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required by law. Specifically:

  • Account data: Retained for the duration of your account and up to 12 months after deletion
  • Pilot data: Retained for up to 2 years after the conclusion of the pilot programme for development purposes, unless fully anonymised (in which case the data is no longer personal data and may be retained without restriction).
  • Voice recordings & transcripts: Retained for as long as the account is active; de-identified versions may be retained indefinitely for AI training
  • Legal records: Retained as required by Swiss commercial law (typically 10 years)

10. Your Rights

Under the Swiss FADP, you have the following rights with respect to your personal data:

  • Right of access (Art. 25 FADP): You may request information about the data we hold about you
  • Right to rectification (Art. 32 FADP): You may request correction of inaccurate data
  • Right to deletion (Art. 32 FADP): You may request deletion of your data, subject to legal retention obligations. Please note that fully anonymised data (which is no longer personal data) cannot be attributed to you and therefore cannot be deleted.
  • Right to data portability (Art. 28 FADP): You may request your data in a commonly used electronic format
  • Right to withdraw consent: You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Withdrawal of consent for sensitive data processing may limit the functionality of the Services.
  • Right to object (Art. 30–32 FADP): You may object to processing that you believe breaches your personality rights.

To exercise any of these rights, contact us at privacy@norena.ai. We will respond within 30 days. You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, in accordance with Art. 8 FADP. These measures include:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and role-based permissions
  • Regular security assessments and penetration testing
  • Employee confidentiality obligations and training
  • Incident response procedures

No method of transmission or storage is completely secure. In the event of a data security breach that poses a high risk to your personality or fundamental rights, we will notify the FDPIC as quickly as possible and inform you where required for your protection, in accordance with Art. 24 FADP.

12. Children

The Services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@norena.ai and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via the App or by email at least 30 days before they take effect. Your continued use of the Services after such changes constitutes acceptance of the updated policy. Previous versions of this policy will be archived and available on request.

14. Governing Law & Jurisdiction

This Privacy Policy is governed by Swiss law. Any disputes arising from or in connection with this policy shall be subject to the exclusive jurisdiction of the courts of Zug, Switzerland.

15. Contact

Norena Technologies AG Wadsack Zug AG Bahnhofstrasse 7, 6300 Zug, Switzerland Email: privacy@norena.ai

16. Cookies & Similar Technologies on the Website

The Website (norena.ai) uses cookies and comparable browser storage (local storage and session storage). This section explains what is used and how you control it. It does not apply to the App, which does not use cookies.

16.1 Your choices

When you first visit the Website you are shown a consent banner. Strictly necessary storage is always active because the Website cannot function without it. Every other category is off by default and is activated only if you accept it. You can change or withdraw your choice at any time through the "Cookie settings" link in the Website footer.

Your consent preferences are recorded and managed on our behalf by our consent-management provider (Inth / c15t). A record of your choice, together with the time and the applicable policy version, is stored so that we can demonstrate compliance and so that you are not asked again on every visit. This record is kept for up to 12 months, after which you will be asked again.

16.2 Strictly necessary (always active, no consent required)

  • NEXT_LOCALE (cookie) — Remembers the language you selected (English or German). Retention: up to 12 months.
  • norena-onboarding (session storage) — Holds your progress through the sign-up and onboarding steps, including a temporary session token. Cleared when you close the browser tab.
  • norena-pending-plan (session storage) — Remembers the plan you selected while you complete sign-up. Cleared when you close the browser tab.
  • norena-plan-choices (local storage) — Remembers the plan associated with your email address between visits. Retained until you clear it.
  • c15t consent record (cookie and local storage) — Stores your cookie choices so the banner is not shown again. Retention: up to 12 months.
  • Checkout frame (only if you start a purchase) — Our payment provider (Polar) loads a secure embedded checkout on the subscription page and sets its own cookies needed to process the payment. This happens only after you actively begin checkout.
  • Abuse prevention — Our hosting provider (Netlify) applies short-lived rate-limiting counters to sign-up, login and checkout requests. These are processed on the server and store nothing in your browser.
  • Icons — Icon graphics are loaded on demand from the Iconify content delivery network. These requests set no cookies and contain no personal data.

16.3 Optional categories (activated only with your consent)

Everything in this section stays off until you accept the relevant category, and stops if you withdraw it.

  • Marketing — the Meta (Facebook) Pixel. If you accept this category we load Meta's pixel to measure our advertising, understand which campaigns lead to sign-ups, and build audiences for future ads. It sets the _fbp and _fbc cookies (roughly 90 days; _fbc stores the ad-click identifier from the link you arrived on) and sends event data to Meta Platforms Ireland Ltd: a SHA-256 hash of your email address (never your email in clear), a hashed internal account id, those two cookies, your IP address and your browser user-agent. We also send the same events from our server (Meta Conversions API); this too happens only with your consent, and the hashed data is never shared with our payment provider or app backend.
  • Marketing — Klaviyo (email marketing platform, Klaviyo Inc., USA). With this category accepted, we set a first-party nrn_attr cookie (roughly 90 days) that records the campaign you arrived from (UTM parameters) and the first page you landed on. When you create an account, start a checkout or complete a purchase, our server sends that event to Klaviyo together with your email address, first name, that campaign information and, if you are setting up Norena for someone, their first name and your relationship to them, so we can follow up on your sign-up or unfinished purchase. Nothing is sent to Klaviyo without your consent, and no Klaviyo script runs in your browser. Sending these events does not sign you up to our marketing emails. Marketing emails are sent only if you tick the optional box when creating your account (or switch them on later on your account page): we then add your email address to our Klaviyo mailing list, and you confirm by clicking the link in the email we send you. Klaviyo keeps a record of when and where you agreed. You can unsubscribe at any time with the link in every email or on your account page; emails about your account and purchases are not affected.
  • Site experience — session replay with PostHog (see Analytics). If you accept both this category and Analytics, PostHog records how pages are used (mouse movement, clicks, scrolling and page changes) so we can see where people get stuck. Everything you type into form fields is hidden, and in the account and sign-up area all text on screen is hidden too, so names, email addresses and codes are never recorded. We also use Microsoft Clarity (Microsoft Corporation, USA) for the same purpose, only when you accept both Site experience and Analytics: it records the same kind of page interactions, builds click and scroll heatmaps, and applies the same hiding of form fields and of the account and sign-up area. Clarity sets the _clck (1 year) and _clsk (1 day) cookies; if you have also accepted Marketing, Microsoft may set its MUID cookie (about 1 year), which it can use for advertising. When you withdraw consent, Clarity is stopped and removed from the page. A/B testing and personalisation are not in use yet.
  • Analytics — PostHog (PostHog Inc., data hosted in the EU, Frankfurt). If you accept this category we load PostHog to understand how visitors use the Website: pages viewed, clicks, scroll depth, page-load performance, technical errors, the campaign that brought you here (UTM parameters and ad-click identifiers), and the steps of sign-up and checkout. It stores an anonymous identifier in a first-party cookie and local storage (ph_<project>_posthog, up to 1 year) and sends this data together with your IP address (used to derive an approximate location) and browser details. Once you create an account or log in, we link these events to your internal account id, but we do not send your name or email address to PostHog.

If we introduce further technology in these categories it will be listed here and will load only after you have given consent for that category.

16.4 Managing cookies in your browser

You can also block or delete cookies through your browser settings. If you do, some parts of the Website (such as staying signed in during sign-up) may not work correctly.

Related Document

For the contractual terms governing the service, see Terms of Service.

UK users should also read the UK Privacy Addendum, UK Consumer Terms, and Cancellation & Refund Policy.