Privacy & data practices

Privacy Policy

Numa BI works with reflections, commitments, and conversations about personal growth. That is sensitive material, so we treat it that way. This page explains what we collect, why we collect it, how long we keep it, and the choices you have.

Last updated August 4, 2026. This policy is maintained by Numa BI and describes our current practices. It is not legal advice and it is not an independent certification or audit of our systems.

No sale of data

We do not sell personal information or share it for cross-context behavioral advertising.

Access controls

Accounts are authenticated and records are scoped so you see only your own data.

Growth, not diagnosis

Numa BI supports reflection and habit building. It does not diagnose or treat conditions.

1. Scope of this policy

This policy applies to numahq.io, the Numa BI web and app experiences, the Numa BI practitioner beta, our beta waitlist, and email we send you. It covers personal information about practitioners, waitlist subscribers, and people who contact us.

Where Numa BI processes information on behalf of a coach, therapist, employer, or other organization, that organization's agreement with us and its own notices govern that use. See section 17.

2. Numa BI is not a healthcare provider

Numa BI is a personal growth and behavioral insights product. It is not a medical device, not a clinical decision support tool, and not a substitute for therapy, counseling, psychiatric care, or medical advice. Numa BI does not diagnose, treat, cure, or prevent any condition, and it does not create a clinician-patient or therapist-client relationship.

Because behavioral and mental wellbeing information is deeply personal, we apply heightened handling practices to it even where the law does not require them. Those practices are described in sections 4, 11, and 12.

3. Information we collect

  • Information you give us. Name, email address, and any message content you submit through the waitlist or contact form.
  • Account information. Authentication identifiers, sign-in method, and account settings.
  • Growth content. Reflections, commitments, goals, notes, and the conversation content you choose to connect or share with Numa BI from a supported AI tool.
  • Derived insights. Patterns, themes, streaks, and progress signals Numa BI generates from your content.
  • Technical data. IP address, device and browser type, timestamps, and error diagnostics, used for security, abuse prevention, and reliability.
  • Anti-abuse signals. Limited request metadata used by our spam and rate-limiting protections on public forms.

We do not intentionally collect government identifiers, payment card numbers, precise geolocation, or biometric data. Please do not submit information about other people, or clinical records about a third party, through our public forms.

4. Sensitive and consumer health data

Content you share with Numa BI may include information about mental or emotional wellbeing, habits, relationships, faith, or personal struggles. Some state laws, including the Washington My Health My Data Act, Nevada SB 370, and Connecticut's consumer health data provisions, treat this as consumer health data. Some privacy laws, including the GDPR and UK GDPR, treat it as a special category of personal data.

  • We collect this information only when you choose to provide or connect it.
  • We use it to deliver the features you asked for: reflection, commitments, and progress insight.
  • We do not sell it, and we do not use it for advertising, profiling for advertising, or cross-context behavioral advertising.
  • We do not use geofencing around health facilities.
  • You can request deletion of this information at any time using the contact details in section 19.

5. How we use information

  • Provide, personalize, and improve Numa BI's features and insights.
  • Create and secure your account and authenticate you.
  • Respond to your messages and support requests.
  • Send beta updates and product communications you asked for. You can unsubscribe at any time.
  • Detect, prevent, and investigate spam, abuse, fraud, and security incidents.
  • Produce aggregated or de-identified statistics that cannot reasonably be linked back to you.
  • Comply with legal obligations and enforce our terms.

We do not make decisions about you that have legal or similarly significant effects using solely automated processing.

6. AI processing and model training

Numa BI uses third-party large language models to generate reflections, summaries, and insights. To do that, relevant content is transmitted to our model providers, which process it to return a result to you and act as service providers under our instructions.

  • We do not train our own foundation models on your personal content.
  • We instruct our model providers not to use content submitted through Numa BI to train their models.
  • AI output can be incomplete or wrong. Treat Numa BI's insights as supporting evidence for your own professional judgment, not as findings, assessments, or clinical conclusions.
  • Numa BI does not create or replace a clinical record, and it does not replace professional judgment or supervision.

8. HIPAA and 42 CFR Part 2

Numa BI is not a covered entity under HIPAA, and information you share with Numa BI directly as an individual consumer is generally not protected health information under HIPAA. That means HIPAA's protections do not automatically apply to consumer use of Numa BI, which is one reason we voluntarily apply the heightened practices in this policy.

If a covered entity or another business associate wants to use Numa BI in a way that involves protected health information, that use requires a written Business Associate Agreement with us before any PHI is submitted. Do not upload PHI or records covered by 42 CFR Part 2 (substance use disorder treatment records) to Numa BI without an executed agreement in place. Contact privacy@numahq.io to discuss availability and terms.

9. How we share information

We do not sell personal information. We share it only as described here:

  • With service providers that process data on our behalf under contract and only for our stated purposes.
  • With a coach, therapist, or organization when you explicitly connect your account to them or direct us to share specific content.
  • When required by law, subpoena, or valid legal process, and where permitted we will attempt to notify you first.
  • To protect the rights, safety, or property of users, the public, or Numa BI.
  • In connection with a merger, acquisition, or asset sale, subject to this policy and with notice to affected users.

10. Service providers

We use a small set of vendors to run Numa BI: cloud hosting and managed database and authentication infrastructure, large language model providers, transactional and product email delivery, and error and performance monitoring. Each is bound by contractual confidentiality and data protection obligations, and we limit them to the data they need.

A current list of subprocessors is available on request at privacy@numahq.io. We will update this section as our vendor set changes.

11. Retention and deletion

  • Account and growth content is retained while your account is active.
  • Waitlist name and email are retained until you ask us to remove them or the beta program ends.
  • Contact form messages are retained for up to 24 months so we can maintain a record of the conversation.
  • Security and anti-abuse logs are retained for a short operational window, typically no more than 90 days.
  • On a verified deletion request, we delete or de-identify your personal information within 30 days, except where we must retain records to comply with law, resolve disputes, or enforce agreements. Routine backups are purged on their normal cycle.

12. Security practices

  • Data is encrypted in transit with TLS and encrypted at rest by our infrastructure provider.
  • Access is authenticated, and database rules scope records so users can access only their own data.
  • Administrative access is role-based, limited to personnel who need it, and privileged functions are restricted at the database layer.
  • Public forms are protected by input validation, rate limiting, and automated abuse checks.
  • Secrets and credentials are stored in managed secret storage, never in application code.

No system is perfectly secure, and we do not claim to be. If we become aware of a breach affecting your personal information, we will notify you and the applicable regulators as required by law and without undue delay. To report a suspected vulnerability, email privacy@numahq.io with details and we will acknowledge receipt; please do not access or alter other people's data while testing.

13. Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, to withdraw consent, and to opt out of sale, sharing, targeted advertising, and certain profiling. We do not sell or share personal information for targeted advertising, so there is nothing to opt out of on that front.

To exercise a right, email privacy@numahq.io from the address associated with your account, or use our contact form. We verify requests before acting on them and respond within the timeframe the applicable law requires, generally 30 to 45 days. You may use an authorized agent where the law allows it.

We will not discriminate against you for exercising a privacy right. If you are in the EEA or UK you may also lodge a complaint with your local supervisory authority. California residents may request information about disclosures of personal information under the Shine the Light law.

14. International transfers

Numa BI is operated from the United States and our infrastructure and model providers may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or another lawful transfer mechanism, together with supplementary technical and organizational safeguards.

15. Children and teens

Numa BI is intended for adults 18 and older. We do not knowingly collect personal information from children under 13, and we do not knowingly collect information from anyone under 18 without verifiable parental or guardian consent. If you believe a minor has provided information to us, email privacy@numahq.io and we will delete it promptly.

16. Crisis and safety limitations

Numa BI is not a crisis service and is not monitored in real time. It cannot dispatch help, notify a clinician, or intervene in an emergency. If you are in danger or thinking about harming yourself, contact your local emergency number, or in the United States call or text 988 to reach the Suicide and Crisis Lifeline.

We do not scan your content for the purpose of reporting it, and we do not sell or disclose wellbeing content to insurers, employers, or advertisers. We may disclose information in a genuine emergency involving a risk of serious harm, consistent with section 9 and applicable law.

17. Coaches, therapists, and organizations

When a professional or organization uses Numa BI with the people they support, that organization is the controller of the personal information it submits and Numa BI acts as a processor or service provider under our written agreement, including a Data Processing Addendum on request and a Business Associate Agreement where HIPAA applies. The organization is responsible for obtaining the consents and giving the notices its own regulations and licensing rules require, including any state mental health confidentiality obligations.

Numa BI does not provide clinical documentation, billing records, or a system of record for treatment. Individuals connected through an organization should direct access and deletion requests to that organization first; we will support them in fulfilling the request.

18. Changes to this policy

We will update this policy as Numa BI evolves. When changes are material, we will revise the “last updated” date and notify you by email or in the product before the change takes effect. For changes that expand how we use sensitive or consumer health data, we will ask for your consent.

19. Contact and privacy requests

Privacy questions, rights requests, agreement requests, and vulnerability reports: privacy@numahq.io. General inquiries: hello@numahq.io.

Numa BI is operated by Human Development Intelligence Agency LLC, United States. You can also reach us through our contact page.