Privacy Policy

Effective Date: April 30, 2026  •  Last Updated: April 30, 2026
NUMI is a general wellness tool powered by generative AI. It is not a medical device, diagnostic tool, or substitute for professional medical advice. NUMI does not sell your personal information or health data to any third party.

1. Who We Are

NUMI is an AI-powered personal health intelligence platform developed and operated by NumentAI ("we," "us," "our," or "the Company"). This Privacy Policy describes how we collect, use, disclose, and protect your information when you use the NUMI application, website (nument.ai), and related services (collectively, the "Service").

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.

2. Information We Collect

2.1 Information You Provide Directly

CategoryExamplesPurpose
Account informationName, email address, date of birth, password or passkeyAccount creation, authentication, and security
Health profileHeight, weight, biological sex, health goals, dietary preferences, medical conditions you choose to sharePersonalize the Service to your body
Health logsMeals, sleep records, exercise, symptoms, mood, hydration, supplementsTrack patterns and generate insights
Chat messagesQuestions, health concerns, lifestyle context provided to the AI assistantGenerate personalized AI responses
FeedbackSupport requests, bug reports, feature suggestionsImprove the Service

2.2 Information from Connected Devices and Services

SourceData TypesYour Control
Wearable devices (Apple Watch, Oura Ring, Whoop, Fitbit, Garmin, etc.)Heart rate, heart rate variability (HRV), sleep stages, steps, SpO2, skin temperature, respiratory rateYou choose which devices to connect. You may disconnect at any time in Settings.
Apple Health / Google Health ConnectAggregated health metrics from compatible appsPermissions are granular by category. You choose which categories to share.

2.3 Information Collected and Logged Automatically

2.4 Information We Do NOT Collect

3. How We Use Your Information

We use the information we collect for the following purposes:

We do not use your personal information for advertising, behavioral profiling for third parties, or any purpose incompatible with those listed above.

4. How AI Processes Your Data

NUMI uses generative artificial intelligence, including large language models (LLMs), and machine learning to analyze your health data and generate personalized insights. We believe in transparency about how AI interacts with your information.

4.1 What AI Does With Your Data

4.2 AI Training

Your personal health data is never used to train, fine-tune, or improve our AI models or any third-party model. AI model training uses only de-identified, synthetic, or publicly available datasets. Your data is used solely to generate insights for you within the Service. We have configured our third-party AI providers (see §4.4) to disable model training on your data and to enforce zero-data-retention where available.

4.3 AI Limitations

NUMI's AI is generative and probabilistic. Outputs are non-deterministic — the same question may produce different answers — and may be inaccurate, incomplete, contextually inappropriate, or fabricated ("hallucination" or "confabulation"). AI output does not account for your complete medical history, medications, genetic factors, or clinical context. Treat NUMI's AI output as informational only. It is not medical advice, diagnosis, treatment, or a professional opinion. See our Terms of Service §3A and §4 for the complete intended-use boundary and AI disclaimer.

4.4 Third-Party AI Sub-Processors

To generate responses, NUMI sends contextual data to third-party AI inference providers. Data sent to these providers is de-identified before transmission (no name, email, or directly identifying account information). Providers act as data processors on our behalf and are contractually prohibited from using your data for any purpose other than serving your request.

Our current AI sub-processors are:

ProviderUsed forData retention configuration
OpenAI (OpenAI, L.L.C.)LLM inference for chat and analysisZero-data-retention (ZDR) enabled where supported; no training on your data
Anthropic (Anthropic, PBC — Claude)LLM inference for chat and analysisNo training on your data; standard retention per Anthropic enterprise terms
Google (Google LLC — Gemini)LLM inference for chat and analysisNo training on your data via paid API tier; Google Cloud data-processing terms apply

This list may change as we add or replace providers. Material changes to AI sub-processors will be reflected in this section and noted in the "Last Updated" date at the top of this Policy. To request the most current list at any time, email hello@nument.ai with subject line "Sub-Processors."

5. How We Share Your Information

We do not sell, rent, license, or trade your personal information or health data to any third party. We do not share your data with advertisers, data brokers, insurance companies, or employers for their commercial purposes.

5.1 Service Providers

We share data with the following categories of service providers who process data on our behalf:

Provider CategoryPurposeData Shared
Cloud infrastructureData storage and computingEncrypted health data, account data
Authentication servicesSecure login and account managementEmail, authentication tokens (not health data)
AI inference servicesProcess health queries and generate insightsDe-identified health context (no PII)
Email deliveryTransactional emails (verification, password reset)Email address only
Error monitoringCrash reporting and performanceAnonymized device/error data (no health data)

All service providers are bound by data processing agreements that restrict their use of your data to performing services for us.

5.2 Legal Requirements

We may disclose your information if required by law, subpoena, court order, or government regulation. We may also disclose information if we believe in good faith that disclosure is necessary to protect the safety of any person, prevent fraud, or protect our legal rights. Where legally permitted, we will notify you of such disclosures.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of the transaction. We will notify you via email and/or a prominent notice in the Service before your information becomes subject to a different privacy policy.

6. Consumer Health Data

This section provides additional disclosures required by state consumer health data laws, including the Washington My Health My Data Act (MHMDA).

6.1 Categories of Health Data Collected

NUMI collects the following categories of consumer health data:

6.2 Purposes for Health Data Collection

Health data is collected and processed solely for the purposes of:

6.3 Consent

We obtain your consent for the collection and use of consumer health data during the onboarding process. This consent is separate from your agreement to these general privacy terms. You may withdraw your consent at any time by deleting your account or contacting us at hello@nument.ai.

6.4 HIPAA Status

NUMI is a general wellness tool, not a healthcare provider, health plan, or healthcare clearinghouse. We are not a HIPAA-covered entity and we do not provide healthcare services, health insurance, or healthcare clearinghouse services. NUMI does not create, receive, or maintain Protected Health Information (PHI) as defined under HIPAA. If our regulatory status changes, we will update this policy and notify all users.

7. Data Retention

Data CategoryRetention Period
Account informationUntil account deletion + 30 days for processing
Health data and chat historyUntil account deletion + 30 days for processing
Usage analytics (de-identified)Up to 24 months
Crash/error logs (anonymized)Up to 12 months
Legal compliance recordsAs required by applicable law

Upon account deletion, all personal data and health data is permanently deleted from our active systems within 30 days. De-identified, aggregated data that cannot reasonably identify you may be retained for product improvement purposes.

8. Data Security

We implement commercially reasonable technical, administrative, and organizational security measures to protect your information, including:

No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach involving your health data, we will notify you and the appropriate regulatory authorities in accordance with applicable law, including the FTC Health Breach Notification Rule.

9. Your Privacy Rights

9.1 All Users

Regardless of your location, you may:

9.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:

To exercise these rights, contact us at hello@nument.ai or use the in-app privacy settings. We will respond within 45 days.

9.3 Washington Residents (My Health My Data Act)

If you are a Washington resident, you have additional rights under the My Health My Data Act:

9.4 Colorado, Connecticut, Texas, and Other State Residents

If you reside in a state with applicable consumer privacy legislation, you may have similar rights to access, correct, delete, and opt out of the processing of your personal data. Contact us at hello@nument.ai to exercise your rights.

10. Do Not Sell or Share My Personal Information

We do not sell your personal information. We do not share your personal information with third parties for cross-context behavioral advertising. If our practices change in the future, we will provide you with an opt-out mechanism in compliance with applicable law.

To submit a "Do Not Sell or Share" request, contact us at hello@nument.ai. We honor Global Privacy Control (GPC) browser signals as a valid opt-out request.

11. Limit Use of Sensitive Personal Information

Under the CPRA, health data is classified as "sensitive personal information." We use your sensitive personal information only as necessary to provide the Service you have requested. You may request that we limit the use of your sensitive personal information by contacting us at hello@nument.ai or through the in-app privacy settings.

12. Children's and Minors' Privacy

NUMI is intended for adults aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected personal information from a minor, we will promptly delete that information. If you are a parent or guardian and believe your child has provided information to NUMI, please contact us at hello@nument.ai.

13. Cookies and Tracking Technologies

Our website (nument.ai) uses the following technologies, grouped by purpose:

Essential (always active — required for the site to function securely):

TechnologyPurposeDuration
Session cookiesAuthentication and securityBrowser session
A/B testing cookie (numi_ab_test)Landing page variant assignment (A/B)30 days
Cloudflare TurnstileBot detection for signup forms (anti-spam)Session
Consent preference (numi_cookie_consent, localStorage)Remembers your cookie choice so we do not ask againUntil cleared

Performance & Analytics (opt-in — you control these via the cookie banner):

TechnologyPurposeDuration / Storage
First-party page-view eventWe log a page view (session ID, landing variant, user-agent, referrer) so we can understand how NUMI is growingStored in our own database (DynamoDB table biosync-analytics-prod)
First-party conversion eventWe log a conversion when a signup completes, so we can measure signup performanceStored in our own database (DynamoDB table biosync-analytics-prod)
Approximate geolocationAt signup, we look up the approximate country/region from the request IP so we know which countries are interestedStored alongside the waitlist entry

What we do not do: We do not use advertising cookies, retargeting pixels, third-party analytics (no Google Analytics, no Meta Pixel, no Mixpanel), cross-site tracking, or data brokers. All analytics are first-party — the data stays in our own AWS account and is never sold or shared.

Your choice: You can accept, decline, or change your analytics preference at any time using the "Cookie settings" button in the bottom-left corner of the site. Declining does not affect your ability to use the site or join the waitlist.

14. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with your information.

15. International Users

NUMI is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We will take reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy.

If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws that differ from United States law, please be aware that we may transfer your data to jurisdictions that may not provide equivalent data protection. We rely on your explicit consent and contractual safeguards for such transfers.

16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes to how we handle your health data, we will notify you via email and/or a prominent notice within the Service at least 30 days before the changes take effect. Material changes to consumer health data practices will require renewed consent where required by law.

Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the changes.

17. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or need to report a data concern, contact us at:

NumentAI
Email: hello@nument.ai
Privacy inquiries: hello@nument.ai (subject line: "Privacy Request")
Response time: Within 10 business days (within 45 days for verified CCPA/CPRA requests)