Nimbus Shield Privacy Policy
Effective date: July 31, 2026
Last updated: July 31, 2026
This Privacy Policy explains how the Nimbus Shield mobile application accesses, stores, uses, transmits, shares, retains, and deletes information.
1. Privacy summary
Nimbus Shield is designed as a privacy-first, local-first application.
You do not need to create an account to use Nimbus Shield. Health records you enter are stored and analysed locally on your device, and voice recordings are processed locally for transcription.
Nimbus Shield does not sell health information, use it for advertising, or upload your health journal to a Nimbus Shield cloud database. You control whether to export or share reports.
Analytics and crash reporting are optional and disabled by default. Purchase and subscription information is processed by Google Play and RevenueCat. Certain optional functions, such as weather features and model downloads, require an internet connection.
2. Information stored locally on your device
Nimbus Shield may allow you to record the following information:
- Migraine attacks and symptoms
- Attack dates, times, duration, frequency, and severity
- Suspected triggers
- Medications, treatments, and perceived treatment response
- Sleep information
- Menstrual-cycle information
- Weather-related observations
- Personal notes, warning signs, and journal entries
- Preferences, reminders, and application settings
- Insights calculated from the records you enter
This information is stored in an application-private SQLite database and related app-private storage on your Android device.
Nimbus Shield does not operate a cloud account system or health-record server. The app operator does not ordinarily receive or have access to the health information stored in your local database.
3. How local health information is used
Information stored locally may be used by the application to:
- Display your journal and history
- Calculate summaries and trends
- Identify possible patterns, correlations, or changes over time
- Compare recorded factors and outcomes
- Generate Week Review content and user-requested reports
- Support reminders
- Create user-controlled exports
- Help you prepare information you may choose to discuss with a healthcare professional
The app's findings are observational and may be incomplete, uncertain, or incorrect. They are not medical diagnoses or treatment instructions.
4. Voice logging and microphone access
Nimbus Shield may request microphone access when you deliberately start voice logging.
When voice logging is used, microphone access captures your spoken entry; audio is held temporarily in memory during recording and transcription; transcription is performed locally using an on-device speech-recognition model; recordings are not intentionally uploaded to a cloud transcription service or retained as permanent audio files; and the transcript is shown to you for review before health information is saved.
Microphone access is optional. You may deny or revoke the permission and continue using manual logging.
5. Speech-recognition model download
Nimbus Shield may download a speech-recognition model when on-device voice transcription is first enabled.
The model is downloaded over the internet from an external model-hosting provider and stored in app-private device storage. The request may disclose ordinary network information, such as your IP address, request time, and technical request metadata, to the hosting provider.
The model file is software data and is not your voice recording or health journal.
6. Location and weather information
Nimbus Shield may request foreground location access for an optional weather-related feature. Access is requested in the context of that feature, used only while the app or relevant feature is in use, not intended for continuous background tracking, and not required for core manual health logging.
When the weather feature is used, location information or a derived location may be sent to a weather service to obtain local conditions. The provider may also receive ordinary network and request metadata. Nimbus Shield does not use location for advertising.
You may deny location access without losing the ability to manually record health information.
7. Notifications and reminders
Nimbus Shield may request permission to send reminders and other notifications.
Notification content is designed to avoid detailed health information on the lock screen. Nimbus Shield uses generic wording and does not intentionally place migraine-entry identifiers, medication names, or detailed health records in notification payloads.
You may disable notifications through Nimbus Shield or Android settings.
8. Purchases and subscriptions
Nimbus Shield may offer optional paid features through Google Play. Google Play processes the financial transaction; Nimbus Shield does not directly receive or store your complete payment-card details.
Nimbus Shield uses RevenueCat to validate purchases, determine subscription status, manage access to paid features, support purchase restoration, and detect subscription lifecycle events.
RevenueCat may receive an automatically generated anonymous application user identifier, purchase history, product and subscription identifiers, transaction receipts or purchase tokens, entitlement and subscription status, expiration information, store and currency information, app version, platform information, and limited technical information required to provide the service.
Nimbus Shield does not intentionally send your migraine journal, symptoms, medication records, voice recordings, transcripts, menstrual records, personal notes, or generated health findings to RevenueCat. Google Play and RevenueCat process information under their own privacy policies and contractual obligations.
9. Optional analytics
Nimbus Shield may offer optional analytics to understand general application usage and improve reliability or usability. Analytics are disabled by default and should not activate unless you provide consent.
When enabled, analytics may process app and operating-system versions, general device or application characteristics, feature usage events, screen or workflow events, consent state, and coarse technical performance information.
Nimbus Shield is designed to prevent health-record fields from being included in analytics events. Analytics should not include journal text, symptoms, medication names, voice transcripts, exact health-event dates, or other user-entered health content.
You may withdraw analytics consent from the application's privacy settings.
10. Optional crash reporting
Crash reporting is disabled by default and should not activate unless you provide consent.
When enabled, it may process crash type, app and operating-system versions, device model or category, technical diagnostics, application state relevant to the failure, and sanitized error categories.
Nimbus Shield is designed to avoid transmitting health records, transcript text, database contents, file paths, SQL details, or raw sensitive logs through crash reporting. No diagnostic system can guarantee that unexpected technical information will never appear in a crash report.
Crash-reporting consent may be withdrawn in the application's privacy settings.
11. Software updates and network communications
Nimbus Shield may connect to external services to check for or download application updates, download the speech-recognition model, retrieve weather information, validate subscription status, process Google Play purchases, and provide optional analytics or crash reporting.
These services may receive ordinary network information such as IP address, request time, app version, operating-system version, and technical request metadata.
Nimbus Shield does not intentionally include your locally stored health journal in application-update requests.
12. Exports and sharing
Nimbus Shield may allow you to create and share text, JSON, CSV, image, or PDF exports. Exporting is initiated and controlled by you.
Before sharing, review the export, choose available redaction options, decide what to include, select the receiving application or person, and confirm that the intended recipient is appropriate.
A receiving application, service, operating-system component, or person may retain, copy, transmit, or further disclose a shared export. Nimbus Shield cannot control or recall a file after it has been shared outside the app.
Temporary export files may be created in application cache storage. Nimbus Shield attempts to restrict sharing to intended cache locations, but copies managed by Android or a receiving application may remain outside Nimbus Shield's control.
13. Information you send to support
When you contact support, the app operator may receive information you voluntarily provide, including your email address, your name if provided, your message, screenshots or attachments, app version, device information, and technical details you choose to include.
Do not send health records, voice transcripts, medication details, or other sensitive information unless necessary and you understand the risks.
Support information may be used to answer your request, troubleshoot problems, prevent abuse, and maintain appropriate business records.
14. Information Nimbus Shield does not sell or use for advertising
Nimbus Shield does not sell your personal health information, display third-party advertising, or use health information for behavioural or targeted advertising, data-broker services, insurance or employment eligibility decisions, credit decisions, or unrelated profiling.
15. Data sharing
Limited technical, subscription, diagnostic, or operational information may be processed by service providers such as Google Play, RevenueCat, an application-update provider, a weather provider, a model-hosting provider, and, only after consent, analytics or crash-reporting providers. These providers are not intended to receive your complete local health journal.
Information is also disclosed when you deliberately export or share it.
The app operator may disclose information actually held when reasonably necessary to comply with applicable law or legal process, protect legal rights, investigate fraud or security incidents, or protect a person from serious harm. Because local health records ordinarily remain on your device, the operator may not possess records requested by another party.
If Nimbus Shield or related business assets are transferred, information controlled by the operator may be transferred subject to applicable law and appropriate privacy protections. Local records remaining solely on your device would not automatically transfer.
16. Storage and security
Nimbus Shield uses measures intended to reduce unauthorized access, including Android application sandboxing, app-private storage, device-level encryption where supported and enabled by Android, disabled application backup and device-transfer rules in release configuration, restricted sharing paths, user-controlled exports, consent controls, and production logging restrictions.
Nimbus Shield's SQLite database is not encrypted separately at the application layer. Its protection relies substantially on Android's application sandbox, operating-system security, and device encryption.
No security system is perfect. Security may be affected by a rooted, compromised, or unsupported device; malware; an unlocked device; weak screen-lock protection; insecure backups outside Nimbus Shield's control; exports saved or shared elsewhere; software vulnerabilities; or physical access to your device.
You are responsible for maintaining a secure device, installing security updates, using a strong screen lock, and carefully controlling exports.
17. Backup and device transfer
Nimbus Shield's release configuration is intended to prevent app data, including the local database, preferences, exports, and speech model, from being included in Android cloud backup or normal device-to-device transfer.
Operating-system behaviour may vary by Android version, device manufacturer, or system modification. You should not rely on Nimbus Shield as your only permanent record.
18. Retention and deletion
Local health information remains on your device until you delete an entry, use Clear All Data, clear the app's storage through Android, uninstall the application, or otherwise delete the underlying application data.
Clear All Data is intended to remove Nimbus Shield databases, preferences, local exports, caches, reminders, and downloaded model data under the app's control. Some information may remain temporarily because of operating-system behaviour, external applications, shared exports, or service-provider retention.
Google Play and RevenueCat may retain purchase and subscription records for legal, accounting, fraud-prevention, and contractual purposes. Clearing local data does not cancel a subscription or necessarily erase store purchase history.
Support correspondence may be retained as reasonably necessary to answer requests, maintain records, resolve disputes, prevent abuse, and comply with legal obligations. If enabled, analytics and crash information may be retained according to the applicable service configuration and provider practices.
19. Your choices and rights
Depending on applicable law, you may have rights to request information about processing, access, correction, or deletion; object to or restrict certain processing; withdraw consent; and complain to an appropriate data-protection authority.
Because most Nimbus Shield health information remains solely on your device, the app operator may not possess or be technically able to retrieve, access, correct, or delete it remotely.
You can directly manage local information using the app's editing, deletion, consent, export, and Clear All Data functions.
Requests relating to information controlled by the app operator may be sent to [email protected] with the subject 'Nimbus Shield Privacy Request.' Reasonable identity verification may be required before fulfilling a request.
20. International processing
Some service providers used for subscriptions, app distribution, software updates, weather, analytics, crash reporting, or model delivery may process information in other jurisdictions.
Privacy and data-protection laws may differ between jurisdictions. Where required, reasonable contractual or technical safeguards will be used.
21. Children
Nimbus Shield is not directed to children under 13 and is not intended for use by a child without involvement and supervision from a parent, legal guardian, or qualified healthcare professional.
The app operator does not knowingly collect personal information directly from children through an account system because Nimbus Shield does not require an account. However, locally entered information could concern a child.
A parent or guardian should assess whether the application is appropriate and control the device, permissions, exports, purchases, and information shared with healthcare professionals.
If you believe information about a child has been submitted directly through support or another external channel, contact [email protected].
22. Medical and emergency disclaimer
Nimbus Shield is a personal tracking and informational tool. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition.
The app does not replace a physician, pharmacist, emergency service, or other qualified healthcare professional. App-generated findings may be incomplete, inaccurate, or unsuitable for your circumstances.
Always seek advice from a qualified healthcare professional regarding symptoms, diagnosis, medication, treatment, pregnancy, menstrual health, or changes in your condition. Do not use Nimbus Shield to decide whether to start, stop, increase, reduce, or otherwise change medication or treatment.
If you believe you may be experiencing a medical emergency, contact local emergency services immediately. Do not rely on Nimbus Shield for emergency detection, warnings, or response.
23. Changes to this Privacy Policy
This Policy may be updated to reflect changes in the application, service providers, law, security practices, or business operations.
The updated version will be posted at https://zymric.com/nimbus-shield/privacy. The effective or last-updated date will change when material revisions are made. Where appropriate, notice may also be provided inside the application.
Continued use after an update does not remove any consent rights provided by applicable law.
24. Contact
For privacy questions, data requests, or complaints relating to Nimbus Shield, email [email protected] with the subject 'Nimbus Shield Privacy Request.'
Website: https://zymric.com