Privacy Policy

Last Updated: June 5, 2026

1. Introduction

norabel ("we", "us", "our") provides an AI-powered therapy and wellness platform that offers guided therapy sessions, mood tracking, journaling, and self-help tools directly to individuals. We are committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, and disclose information when you use our platform.

We comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

2. Data Controller

norabel acts as the Data Controller for all personal data you provide when using our platform. This means we determine the purposes and means of processing your personal data and are responsible for its protection.

3. Information We Collect

3.1 Account Data

  • Email address
  • Hashed password (bcrypt, cost factor 12)
  • Billing and subscription information (processed by Stripe)

3.2 Session & Wellness Data

  • AI therapy session transcripts and session summaries
  • Mood check-in entries and mood history
  • Journal entries and thought records
  • Worksheets and homework you complete
  • Assessment results (e.g., PHQ-9, GAD-7)
  • Session feedback and helpfulness ratings you choose to provide

3.3 Voice Data

  • Voice input — audio is transcribed in real time to power the conversation and is not stored; only the text transcript is kept

3.4 Technical Data

  • IP address, browser type, device information (for session security)
  • Operational product metrics derived from first-party service events (no personal health data included)
  • Error logs (sanitised to exclude personal content)

4. Lawful Basis for Processing (GDPR)

  • Contract performance — Processing your data to provide the service you subscribed to (Art. 6(1)(b) GDPR).
  • Legitimate interests — Platform security, fraud prevention, and service improvement (Art. 6(1)(f) GDPR).
  • Consent — Where required, we obtain explicit consent before processing (Art. 6(1)(a) GDPR), e.g., marketing communications.
  • Legal obligation — Compliance with tax records and other applicable laws (Art. 6(1)(c) GDPR).

5. How We Use Your Data

  • Deliver AI-guided therapy sessions, including real-time safety monitoring
  • Provide mood tracking, journaling, and self-help tools
  • Authenticate users and manage session security
  • Process billing through Stripe (PCI DSS compliant)
  • Detect and prevent abuse, fraud, or security incidents
  • Comply with legal and regulatory obligations
  • Improve the quality of the service using aggregated, de-identified data

We never sell your data to third parties. We do not use your data for advertising or marketing. Therapy session content is not used to train AI models. We may use aggregated, de-identified feedback (such as session helpfulness ratings) to evaluate and improve the quality of the service.

6. Data Sharing & Sub-Processors

These are the companies that process your data, named, and exactly what each one sees:

  • DigitalOcean (United States) — hosts the app and the database, so it holds everything you store with us.
  • Deepgram (United States) — turns your spoken words into text during a voice session. We ask them not to use your audio to improve their models.
  • Microsoft Azure OpenAI (European Union) — writes the AI therapist's replies and your session summaries from what you say. Not used to train models.
  • ElevenLabs (United States) — turns the AI therapist's replies into the voice you hear. It receives what the AI says to you, not your own words, and we delete each line from their systems immediately after it is spoken.
  • Stripe (United States / EEA) — payments only: name, email and amount. Never therapy content.

We never sell your data, and none of it goes to advertisers.

7. Data Security

We implement administrative, technical, and physical safeguards including:

  • Encryption in transit (TLS 1.2+) for all network communications
  • AES-256-GCM encryption at rest for stored credentials and access tokens. We would rather be straight with you than round this up: your session transcripts, journal entries and mood history are not encrypted by the app today — they sit as readable text in our database, protected by access control over the server rather than by encryption
  • Bcrypt password hashing with appropriate cost factor
  • HTTP security headers (CSP, HSTS, X-Frame-Options, etc.)
  • CSRF protection on state-changing operations
  • Rate limiting on authentication endpoints
  • Automatic session timeout after 60 minutes of inactivity
  • Role-based access controls

8. Data Retention

We retain your data for as long as your account is active. After you request account deletion, your data is retained for a grace period of 30 days to allow for data export.

After the grace period, all data is permanently and irreversibly deleted from our systems, including backups, within 90 days.

9. International Data Transfers

Our infrastructure is hosted in the United States, so if you are in the European Economic Area your data is transferred to the US. The safeguard we rely on is your explicit consent to that transfer at registration (Art. 49(1)(a) GDPR).

We are not certified under the EU-US Data Privacy Framework, and we have not executed Standard Contractual Clauses of our own — the US providers listed above are used under their published data-processing terms. If EEA-only storage is a requirement for you, we cannot offer it today, and we would rather you knew that before you sign up than after.

10. Your Rights

Under GDPR (EEA residents)

  • Right of Access — Request a copy of your data
  • Right to Rectification — Correct inaccurate data
  • Right to Erasure — Request deletion of your account and data
  • Right to Data Portability — Export your data in a machine-readable format (JSON)
  • Right to Restrict Processing — Limit how we use your data
  • Right to Object — Object to processing based on legitimate interests
  • Right to Withdraw Consent — Withdraw consent at any time

Under CCPA (California residents)

  • Right to know what personal information is collected
  • Right to delete your personal information
  • Right to opt-out of the sale of personal information (we do not sell data)
  • Right to non-discrimination for exercising your rights

You can exercise your rights directly from your Account Settings page (Export Data, Delete Account) or by contacting us at the address below.

11. Cookies & Similar Technologies

We use the following cookies:

  • Essential cookies — Authentication session token (httpOnly, secure, SameSite=Lax). Required for the platform to function. Cannot be disabled.
  • CSRF token — Cross-site request forgery protection cookie. Essential for security. Cannot be disabled.
  • Locale cookie — Remembers your language preference. Strictly necessary for displaying the site in your chosen language.

We do not use advertising, tracking, or analytics cookies. We do not use third-party cookies. We do not use marketing cookies of any kind.

12. Children's Privacy

Our platform is intended for adults. You must be at least 18 years old to create an account. We do not knowingly collect data from individuals under the age of 18.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or a prominent notice on the platform at least 30 days before the changes take effect.

14. Contact Us

If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a security concern, please contact us:

EU residents may also lodge a complaint with your local Data Protection Authority.

norabel is operated by NobleBlocks LLC, a limited liability company formed in Wyoming, United States. NobleBlocks LLC is the data controller for the information described on this page.

1603 Capitol Ave Ste 415 #248597Cheyenne, WY 82001United States

Questions about this policy, or a request about your own data, go to info@nobleblocks.com.