Privacy Policy
Last updated: September 8, 2026
Welcome to Noereli. We believe your mental space is sacred. This Privacy Policy explains how we handle your data across the Noereli mobile application and our website. Our philosophy is rooted in transparency: we do not sell your data, we do not run ads, and we utilize encryption to protect your journal content, particularly when stored on your device or in encrypted backups.
By using Noereli, you agree to the collection and use of information in accordance with this policy. Noereli is currently intended only for users located in the United States, Canada, Australia, and New Zealand.
Who is responsible for your data
The data controller is Gammahammer LLC (United States), which operates Noereli. For any privacy question or to exercise your rights, contact noereli.app@gmail.com
Company: Gammahammer LLC ("we", "us", or "our")
The "Local-First" & Encryption Promise
Noereli is built on a "Local-First" architecture designed to keep your most sensitive data under your control.
Your Device: By default, your journal entries, AI insights, and app data are stored securely and locally on your physical device.
End-to-End Encrypted (E2EE) Cloud Sync: If you enable Cloud Sync, your journal entries and locally generated "Contextual Memory" are encrypted on your device before being sent to our servers. This data is locked with a key that only you possess. Gammahammer LLC utilizes encryption so that we cannot access your encrypted journal entries stored in our systems.
User Control: Contextual Memory is generated locally and can be deleted at any time by removing your local data or disabling cloud sync.
Data Export: If you choose to export your journal data, the exported file is not encrypted by Noereli and will be stored according to your device’s file system and settings. This means that anyone with access to your device or exported files may be able to read this data. You are responsible for securing exported files.
Voice Journaling: Speech is transcribed locally using your operating system's native tools. We do not collect or store raw audio files.
How We Use Artificial Intelligence (AI)
To provide empathetic insights, Noereli utilizes third-party AI providers (such as Google Gemini via the Firebase SDK).
Processing vs. Storage: When you request AI features, selected journal content is securely transmitted to our AI providers for processing. Unlike your E2EE cloud backups, data transmitted for AI inference must be decrypted transiently to be processed by the AI model. Only the content you choose to analyze is transmitted for AI processing.
Data Usage & Training: We configure our integrations to request that data sent to the AI is not used to train the providers' models or Gammahammer LLC’s models. We rely on provider commitments regarding these data handling practices.
Service Provider Responsibility: We rely on our providers' contractual safeguards and publicly stated security commitments to support data handling consistent with industry standards. Depending on the provider and configuration, limited temporary processing or logging may occur by the provider solely for safety, abuse monitoring, and legally required compliance.
Automated Processing Configuration: We configure our integrations to request that your data be processed only via automated systems.
No Automated Decision-Making: AI insights are for reflection only and are not used for automated decision-making that produces legal, medical, or similarly significant effects.
Security, Device Responsibility, & Breaches
While we employ state-of-the-art cryptographic security (AES-GCM 256-bit encryption), no method of transmission or storage is 100% secure.
Your Responsibility: You are solely responsible for maintaining device security and keeping your Noereli Recovery Key in a safe, offline location. If you lose your Recovery Key, your encrypted cloud backups remain permanently unrecoverable by us.
Data Breach Notification: In the event that account metadata (such as email addresses) is compromised, we will notify affected users via email within a legally compliant timeframe.
Information We Collect
We collect limited data only as necessary to provide and operate the Service:
Account & Payment: We collect your email for account creation. Subscriptions are processed via RevenueCat and your native app store; we do not store credit card info.
Application Data & Usage Metrics: Each user account includes an internal profile (“AppUser”) necessary for core app functionality, and may include a related object (“AppUsage”) containing aggregated behavioral metrics (e.g., feature interactions, interface preferences). This data is used for product functionality, improvement, and user experience optimization, and explicitly excludes journal content, mood data, or AI-generated insights.
Device Permissions: We request native permissions for Microphone, Notifications, and Camera/Gallery access only as required for app features. We do not collect or process biometric data.
Usage Telemetry: We use Firebase Analytics and Crashlytics to collect aggregated usage patterns and crash reports. These signals are not used for advertising or persistent behavioral profiling. You can opt-out of analytics in the Settings menu.
Medical Disclaimer & HIPAA Status
Gammahammer LLC provides a self-help tool, not a medical or clinical service. We are not a "Covered Entity" or "Business Associate" under HIPAA, and the information you provide is not considered Protected Health Information (PHI) under US law.
Law Enforcement
Because of our E2EE architecture, Gammahammer LLC does not possess the keys to decrypt your stored journal or Contextual Memory. In the event of a legally binding subpoena, we can only provide encrypted data blobs that we cannot decrypt, along with basic account metadata. As described in Section 2, if you choose to use AI features, those transient processing flows are subject to the policies of our third-party AI providers.
Data Retention & Business Transfers
Data Retention: We retain encrypted cloud backups only while your account is active. Account data, including AppUser and AppUsage data, is retained while your account is active and deleted or anonymized within a reasonable period after account deletion. We do not retain AI processing data ourselves beyond what is necessary to provide the service, and rely on provider policies for any processing performed by them.
Account Deletion: You can initiate complete account deletion at any time directly within the Noereli app settings. Doing so will permanently remove your AppUser profile, delete your encrypted cloud backups, and remove associated metadata from our servers
Business Transfers: If Gammahammer LLC is involved in a merger, your information may be transferred as a business asset. We will provide notice before your information becomes subject to a different policy.
Age Requirements
Noereli is strictly for users 18 years of age or older. If we discover a user under 18, we will immediately delete their account and associated data in compliance with COPPA.
Third-Party Services, Account Data, Usage Metrics, and Communications
To operate Noereli, we rely on trusted third-party service providers and collect limited additional information as described below.
Cloud Infrastructure (Firebase / Firestore): We use Google Firebase, including Firestore, to store encrypted user data and limited account and application data. Journal content is encrypted on your device prior to transmission and cannot be decrypted by Gammahammer LLC. In addition to encrypted content, we store certain application data required for the Service to function, including account information (such as email address and account identifiers) and application state data associated with your profile (“AppUser”). This information may be stored in an unencrypted or service-managed format where necessary to support core functionality.
Application Data & Usage Metrics (AppUser & AppUsage): Each user account includes an internal application profile (“AppUser”) that stores core data required for the app to function and personalize your experience. Processing of AppUser data is necessary to provide the core functionality of the Service. AppUser may include a related data object (“AppUsage”) containing aggregated behavioral metrics, such as feature interactions (e.g., button taps), interface preferences (e.g., theme changes), and general usage patterns.
This data does not include journal content, mood data, or AI-generated insights.
This data is used for product functionality, improvement, and user experience optimization.
AppUsage data may be stored in a non-encrypted format.
We implement reasonable administrative, technical, and organizational safeguards to protect this data.
If you opt out of analytics, collection and updating of AppUsage data will be disabled. Core AppUser data will continue to be processed as it is necessary to provide the Service.
Authentication Providers: If you create an account using third-party login providers (such as Apple or Google), we receive limited account information such as your email address and a unique user identifier. Authentication is handled by these providers in accordance with their respective privacy policies. We do not receive or store your third-party account passwords.
Product Feedback & Support Tools: We use Featurebase to manage feature requests and support submissions. If you choose to submit a request, you may provide your email address and message content, which is processed and stored by Featurebase on our behalf.
Website Contact Forms, Email Signups and Communications: If you contact us through our website or sign up for updates, we collect your email address and any information you choose to provide. We use MailerLite to manage email signups, subscriber lists and email communications. MailerLite may process information such as your email address, signup source, consent status and related technical information, including IP address, location, date and time where required for consent records. We use this information solely to respond to your inquiry, provide support or send product updates where you have opted in. You may unsubscribe from non-essential communications at any time by using the unsubscribe link in our emails.
Website Analytics: We use Umami to understand how visitors interact with our website, such as which pages are visited and how the site is used. Umami is a privacy-focused analytics tool and does not use cookies in its tracking code. We use this data to improve the website and understand general visitor behavior. We do not use Umami for advertising or cross-site tracking.
Website Hosting and Cookies: The Noereli website is hosted by Carrd. Carrd and related service providers may use cookies or similar technologies that are necessary for site functionality, performance and security. If we use MailerLite pop-up forms, embedded surveys or similar features, MailerLite may use cookies or local storage to manage form behavior and submissions. We do not use third-party advertising trackers.
How We Use Contact Information: We may use your email address to respond to support inquiries, provide important service-related communications, and send product updates or announcements (where you have opted in). You may opt out of non-essential communications at any time.
Data Sharing & Service Providers: We do not sell your personal data. We share limited information with third-party service providers strictly as necessary to operate the Service, including cloud infrastructure providers, authentication providers, analytics providers, and customer support tools. These providers process data on our behalf and are contractually obligated to protect it and use it only for providing services to us.
International Data Transfers: Your information may be processed and stored in countries other than your own, which may have different data protection laws than your jurisdiction, including the United States, where our service providers operate. By using the Service, you acknowledge that your data may be transferred to and processed in these jurisdictions.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top. You are advised to review this Privacy Policy periodically for any changes.
Contact us
Email: team@gammahammer.co Address: 8 The Green, Suite A, Dover, DE 19901, United States