Privacy Policy

Effective Date: February 18, 2026

Your child's developmental journey is sacred. At NurtureOS, we have built a privacy architecture that goes beyond standard compliance to ensure your data is always under your absolute control.

Our Privacy Commitment

End-to-End Encryption

All milestones, photos, and personal observations are encrypted on your device before being transmitted. We do not hold the keys to your private universe.

How it works: When you record a developmental milestone or upload a photo, the data is encrypted locally using industry-standard AES-256 encryption before leaving your device. Only you possess the decryption key.

Zero-Knowledge Privacy

Our decision engine operates on anonymized data patterns. Your identity is never linked to the developmental insights we generate.

What this means: Even if our servers were compromised, attackers would only see encrypted, anonymized patterns, not your child's name, face, or personal information.

Radical Data Erasure

Requesting data deletion is a single-click protocol. We don't just "hide" your data; we purge it from our global node network within 24 hours.

Your right to be forgotten: At any time, you can request complete deletion of your account and all associated data. We comply within 24 hours, permanently and irreversibly.

Information We Collect

1. Waitlist Information

When you join our waitlist, we collect:

  • Email address - To notify you of platform updates and launch
  • Name - To personalize communications
  • Phone number - Required to deliver the NurtureOS early-access, which runs on WhatsApp. If you opt in, your number is used to onboard you to the WhatsApp-based service. Phone numbers are stored securely and never shared with third parties.
  • Country/Region - To understand geographic distribution and tailor features

This data is stored securely and used solely for waitlist management and MVP access. We do not sell, rent, or share this information with third parties for marketing purposes.

WhatsApp consent: We will only onboard you to the NurtureOS WhatsApp service if you gave explicit opt-in consent on our waitlist form. You may opt out at any time by replying STOP on WhatsApp, or by emailing support@getnurtureos.com. Opting out removes you from the WhatsApp service but does not remove your waitlist registration.

Important — data processed by Meta: Because the MVP runs on the WhatsApp platform, conversations and interactions you have with NurtureOS via WhatsApp are transmitted through Meta Platforms, Inc.'s infrastructure. This includes developmental check-ins, milestone content, and guidance exchanged with the service. Please review the WhatsApp Privacy Policy to understand how Meta processes these messages.

2. Developmental Data (MVP & Future Platform)

During the WhatsApp-based pilot phase and when the standalone NurtureOS platform launches, we collect:

  • Child name - To personalize messages and activities
  • Child date of birth - Used to automatically calculate your child's age in months and select age-appropriate developmental activities
  • Language preference - Kinyarwanda, English, or French, as selected during onboarding or changed at any time
  • Activity completion responses - Your replies ("Yes", "Not yet", "Skipped") to daily activity prompts, used to measure engagement and service effectiveness
  • ASQ-3 developmental assessment scores - Five-domain scores (Communication, Gross Motor, Fine Motor, Problem Solving, Personal-Social) from the Ages & Stages Questionnaire, collected at baseline and Week 12 via a secure web form. These are classified as sensitive personal data under the Rwanda Data Protection and Privacy Law (2021) and are encrypted at rest.
  • Cohort assignment - Whether you joined via direct recruitment or clinic referral, used for internal product analysis only and never shared externally
  • Weekly check-in responses - Open-ended feedback you provide voluntarily each Sunday, reviewed by the NurtureOS team to improve the service

Standalone platform: All sensitive developmental data will be encrypted end-to-end. We will not be able to access your child's personal information even if legally compelled.

WhatsApp MVP: During the pilot phase, developmental interactions occur within WhatsApp, which is operated by Meta Platforms, Inc. via Twilio's WhatsApp Business API. While NurtureOS applies all reasonable data minimization practices, messages transmitted via WhatsApp are processed by Meta and Twilio and subject to their respective infrastructure and policies. We strongly encourage users not to share medical records, diagnoses, or other sensitive health information beyond what the service directly asks for.

How We Use Your Information

Data Processing Purposes

  • Service delivery: To provide personalized developmental guidance and track progress
  • Platform improvement: To enhance algorithms and user experience (using anonymized data only)
  • Communication: To send you important updates, new features, and platform news
  • Legal compliance: To comply with applicable laws and regulations (in anonymized form where possible)

We never use your data for:

  • Targeted advertising
  • Selling to third parties
  • Training external AI models
  • Behavioral profiling for commercial purposes

Data Sharing & Third Parties

Who Has Access to Your Data

Short answer: A small number of essential service providers, all bound by data processing agreements.

The following third-party processors handle your data as part of delivering the NurtureOS service:

  • Microsoft Azure (South Africa North region): Primary cloud infrastructure for data storage (PostgreSQL database, Blob Storage for media files, App Service for the backend). All data is stored in the Azure South Africa region to comply with the Rwanda Data Protection and Privacy Law (2021). Azure applies Transparent Data Encryption (TDE) by default. Microsoft Privacy Statement
  • Twilio Inc.: Provides the WhatsApp Business API infrastructure that delivers messages between NurtureOS and your WhatsApp account. Twilio processes your phone number and message content as a data processor on our behalf. Twilio Privacy Policy
  • Meta Platforms, Inc. (WhatsApp): Messages are transmitted through WhatsApp's infrastructure. Meta processes messages in accordance with the WhatsApp Privacy Policy. NurtureOS does not control Meta's data practices.
  • Google LLC (Google Forms): Used to deliver ASQ-3 developmental assessments. Your assessment responses are submitted via Google Forms and exported by NurtureOS to our secure database. Google processes form submissions per the Google Privacy Policy. We minimize data collected in forms to only what is required for scoring.
  • Vercel Analytics: Privacy-focused, anonymized website analytics for the NurtureOS landing page only. No personally identifiable data is collected.
  • Legal authorities: Only if required by applicable law, and only in anonymized form where possible. We will notify you unless legally prohibited.

We will NEVER:

  • Sell your data to advertisers, data brokers, or marketers
  • Share identifiable child or ASQ-3 data with third parties beyond the processors listed above
  • Use your child's data for promotional purposes without explicit consent
  • Share data between users (your data is never visible to other NurtureOS parents)

WhatsApp Communications & Data

How We Handle WhatsApp Conversations

The NurtureOS MVP is delivered entirely via the WhatsApp Business Platform (API). This means your core product experience (parenting guidance, developmental check-ins, and milestone support) happens through WhatsApp conversations. When you use NurtureOS, the following applies:

  • Twilio and Meta as intermediaries: Your WhatsApp messages are routed through Twilio's WhatsApp Business API before reaching NurtureOS and are transmitted via Meta's (WhatsApp's) infrastructure. Both Twilio and Meta process message content and metadata per their own privacy policies (linked in the Data Sharing section above). NurtureOS is the data controller; Twilio acts as a data processor on our behalf.
  • Content we receive: Information you share during WhatsApp interactions (e.g., your child's age, developmental concerns, feedback on guidance) is processed to deliver the service and improve our content. We do not store full WhatsApp conversation transcripts in our own databases beyond what is necessary to provide continuity of service.
  • Purpose limitation: Information received via WhatsApp is used solely to deliver and improve the NurtureOS service. It is not used for profiling or shared with third parties for commercial purposes.
  • Retention: Service interaction notes are retained for up to 90 days after your last session, then permanently deleted. Anonymized, non-identifiable usage patterns may be retained to improve the service.
  • Educational content, not medical advice: NurtureOS delivers science-backed educational parenting guidance and developmental milestone content. This is not a medical or telemedicine service and does not constitute medical advice, diagnosis, or treatment. Do not share medical records or diagnoses via WhatsApp, always consult a qualified healthcare professional for medical concerns.
  • Conversation data flows through Meta: Because the MVP runs on WhatsApp, your interactions (including topics discussed, milestones logged, and guidance exchanged) are transmitted through Meta's infrastructure. NurtureOS applies data minimization practices, but cannot guarantee the same for Meta's own processing.

Human Support Escalation

In compliance with the WhatsApp Business Messaging Policy (Section 2), all automated WhatsApp messaging flows operated by NurtureOS include a clear and direct path to a human agent. If you are interacting with an automated flow and need to speak with a person, you may escalate at any time through any of the following channels:

  • WhatsApp: Reply HUMAN or AGENT at any point in the conversation to be connected to a human support agent.
  • Email: support@getnurtureos.com, we aim to respond within 48 hours.
  • Phone / WhatsApp direct: +250 796 149 304
  • Web support: Use the contact details on this page or at getnurtureos.com.

For any concerns about how Meta handles your data on WhatsApp, please consult the WhatsApp Help Center.

Your Privacy Rights

You Are In Control

Under GDPR, CCPA, and other privacy regulations, you have the right to:

  • Access: Request a copy of all data we hold about you
  • Rectification: Correct inaccurate or incomplete information
  • Erasure: Request complete deletion of your account and data (within 24 hours)
  • Portability: Export your data in a machine-readable format (JSON, CSV)
  • Objection: Object to certain data processing activities
  • Restriction: Request temporary suspension of data processing

To exercise any of these rights, contact us at support@getnurtureos.com or send DELETE MY DATA via WhatsApp to +250 796 149 304 to trigger immediate anonymization of your personal data within 30 days.

Data Retention

How Long We Keep Your Data

  • Waitlist data: Until MVP onboarding or until you request removal (whichever comes first)
  • Active user account data (name, phone number, language preference): For the duration of your active participation + 30 days after a deletion request, then permanently deleted
  • Child profile data (name, date of birth): Same as account data, deleted with the account
  • Activity engagement data (completion responses, timestamps): Retained for 90 days after your last interaction, then anonymized (user link removed, aggregate patterns retained)
  • ASQ-3 assessment scores: Retained for up to 2 years to enable longitudinal developmental analysis. After 2 years, scores are anonymized (personal identifiers removed) and may be retained in aggregate form for research purposes
  • Weekly check-in responses: Reviewed and retained for 90 days, then permanently deleted
  • Encrypted backups: Retained for 30 days on Azure, then permanently deleted
  • Anonymized analytics: Retained indefinitely (cannot be traced back to you)

Security Measures

How We Protect Your Data

  • AES-256 encryption for data at rest and in transit
  • Zero-knowledge architecture - we can't read your encrypted content
  • Regular security audits by third-party cybersecurity firms
  • Multi-factor authentication (MFA) for account access
  • SOC 2 Type II compliance (targeted for 2026)
  • HTTPS/TLS 1.3 for all web communications

Children's Privacy

COPPA Compliance

NurtureOS is designed for parents and guardians to track their children's development. Children under 13 should not create accounts or use the platform independently.

We do not knowingly collect personal information from children under 13 without verifiable parental consent. If we discover such data has been collected, we will delete it immediately.

International Data Transfers

Data Residency & Cross-Border Flow

NurtureOS is headquartered in Rwanda. In compliance with the Rwanda Data Protection and Privacy Law (Law No. 058/2021), all primary user data is stored on Microsoft Azure's South Africa North region (the nearest Azure region to Rwanda) to minimize cross-border data exposure.

  • Primary storage: Azure South Africa North (PostgreSQL database, Blob Storage)
  • Message routing: Twilio routes WhatsApp messages through its global infrastructure (US/EU data centers). This is an inherent characteristic of using the WhatsApp Business API and is disclosed here transparently.
  • Assessment forms: Google Forms responses are temporarily processed on Google's global infrastructure before being exported to our Azure database.

All international transfers involving personal data from Rwanda or the EU are governed by:

  • GDPR Standard Contractual Clauses (SCCs) with Twilio and Google
  • Microsoft's Data Processing Addendum for Azure
  • Encryption requirements (TLS in transit, AES-256 at rest)

Cookies & Tracking

What We Track (And Don't)

Essential cookies: Used for core functionality (login, preferences). Cannot be disabled.

Analytics cookies: Vercel Analytics (privacy-focused, anonymized). Can be disabled in settings.

We do NOT use:

  • Third-party advertising cookies
  • Social media tracking pixels (Facebook, TikTok, etc.)
  • Cross-site tracking or fingerprinting

Changes to This Policy

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes via:

  • Email notification (to your registered address)
  • In-app notification (when platform launches)
  • Website banner announcement

Continued use of the Services after such changes constitutes acceptance of the updated policy.

Contact Us

Privacy Questions & Requests

For privacy-related inquiries, data requests, or concerns:

Email: support@getnurtureos.com
General Support: support@getnurtureos.com
Phone: +250 796 149 304
WhatsApp: +250 796 149 304

Response time: We aim to respond to all privacy requests within 48 hours.

Regulatory Compliance

Legal Frameworks

NurtureOS complies with:

  • GDPR (General Data Protection Regulation - EU)
  • CCPA (California Consumer Privacy Act - US)
  • COPPA (Children's Online Privacy Protection Act - US)
  • Rwanda Data Protection and Privacy Law (Law No. 058/2021)
  • African Union Data Protection Convention
Back to Homepage