Skip to main content
Naviyara
AppAcademyContact
Get the app
Legal

Terms and privacy

The rules for using Naviyara and a clear account of how we handle personal data.

gavelTerms & Conditionsprivacy_tipPrivacy Policy

Effective date: August 2, 2026
Version: 1.0

Privacy at a glance

This summary is provided for convenience. The full policy below controls.

  • Naviyara processes the meals, product labels, text, voice transcripts, preferences, and questions you choose to submit so it can provide personalized learning and analysis.
  • Submitted content may reveal health-related interests or habits. We do not use it for advertising, insurance, employment decisions, or sale to data brokers.
  • AI providers receive the content and context needed to produce the feature you request. They do not need your account name, email address, or phone number for that purpose.
  • You can export your account data, delete your user content while keeping your account, or delete your account from the app. Some limited records may remain where described below.
  • We do not sell or rent your personal data.

1. Who is responsible for your data

CuraCap Schweiz GmbH ("Naviyara", "we", "us", or "our") is the controller of personal data processed through the Naviyara website, web app, and mobile apps (together, the "Service").

CuraCap Schweiz GmbH
Schänzlistrasse 37
2545 Selzach
Switzerland
Company identification number: CHE-158.321.901
Email: info@naviyara.com

2. Scope

This Privacy Policy explains what personal data we collect, why we use it, who may receive it, how long we keep it, and the choices and rights available to you. It applies whenever you visit our website, create an account, use the Service, make a purchase, or contact us.

3. Personal data we process

3.1 Account and contact data

  • Name or display name, email address, phone number, and user identifier
  • Authentication provider, verification status, and account security information
  • Support messages and other communications you send to us

Passwords and third-party sign-in credentials are handled by Firebase Authentication and the relevant sign-in provider. We do not receive your Google or Apple password.

3.2 Content you submit

  • Photos of meals, groceries, cosmetic products, packaging, and labels
  • Typed descriptions, voice recordings submitted for transcription, and transcripts
  • Clarification answers, chat messages, feedback, and prediction-review comments
  • Any people, places, brands, or other information visible in or inferable from that content

Please avoid including other people, private documents, precise location details, or any information that is not needed for your request.

3.3 Preferences and potentially sensitive data

  • Nutrition and cosmetic focus areas, ingredient concerns, learning goals, custom analysis instructions, and selected diplomas
  • Meal and product histories, estimated portion and energy information, ratings, favorites, and journal trends
  • Familiarity assessments, practice and exam answers, scores, reports, diploma progress, and audio-learning progress

Depending on what you submit and where you live, some of this data may be treated as health-related or otherwise sensitive personal data. You control whether to submit it and can remove it using the deletion controls described in Section 11.

3.4 Generated and inferred data

  • AI-generated meal or product descriptions, ingredient interpretations, qualitative ratings, learning insights, answers, summaries, reports, and suggested questions
  • Connections between your submissions, selected learning topics, and progress
  • Generated images used when a submission does not include a suitable photo

These are probabilistic inferences, not clinical findings. They may be incomplete or wrong.

3.5 Subscription and transaction data

  • Subscription tier, entitlement status, expiration date, and purchase status
  • App-store or RevenueCat customer identifiers and transaction references

Payment card and bank details are collected by the applicable app store or payment provider, not by Naviyara.

3.6 Technical, security, and usage data

  • IP address, browser or device type, operating system, app version, and language
  • Authentication events, feature requests, timestamps, rate-limit counters, and error logs
  • Model identifiers, aggregate token usage and timing, and non-content error diagnostics

Providers that deliver the Service also process ordinary network and diagnostic information when your device connects to them.

3.7 Website data stored on your device

The public website stores your theme choice and, when you play an Academy article, your audio position in local storage. The app also uses local storage and an offline database for preferences, cached account content, and reliable offline operation. This data remains on your device until it expires, is overwritten, or you clear site or app data.

The public website uses Google Analytics 4, a web analytics service provided by Google, to measure how visitors use the site. It collects aggregated statistics such as pages viewed, referral source, approximate region, and device or browser type, using cookies and local storage. We configure it to anonymize IP addresses before any location data is used. We use these statistics to understand how the website is used and to improve it. You can prevent collection by disabling cookies in your browser or by using the opt-out tools provided by Google. Google is listed as a service provider in section 7 below.

4. Where the data comes from

We receive personal data:

  • Directly from you when you create an account, submit content, or contact us
  • From your device when you use camera, microphone, storage, and network features
  • From Google or Apple if you use their sign-in services
  • From RevenueCat and the applicable app store when you subscribe or restore a purchase
  • From our systems when they generate analyses, learning records, and operational logs

5. Why we process personal data

We process personal data to:

  • Create, secure, and administer your account
  • Analyze the content you submit and deliver the features you request
  • Personalize explanations, focus areas, journals, chats, and learning paths
  • Track learning and behavioral progress across sessions and devices
  • Manage subscriptions, apply usage limits, restore purchases, and prevent fraud
  • Operate, troubleshoot, secure, and improve the Service
  • Answer support requests and send important service communications
  • Comply with law and establish, exercise, or defend legal claims

5.1 Legal bases

Where the GDPR or similar law requires a legal basis, we rely on:

  • Performance of a contract: to provide the account, analysis, learning, subscription, and support features you request
  • Legitimate interests: to keep the Service secure, prevent abuse, diagnose failures, and improve reliability, balanced against your rights
  • Consent: where required for optional device permissions or processing of sensitive data; consent can be withdrawn prospectively
  • Legal obligation: for accounting, compliance, and lawful requests

6. AI processing

Naviyara uses artificial intelligence to interpret submitted images and text, transcribe audio, answer questions, generate educational material, and create some imagery.

  • For analysis and chat, the relevant photos, descriptions, preferences, prior messages, and learning context are sent through OpenRouter to the model provider selected for that feature.
  • Voice recordings are sent to OpenAI for transcription.
  • We do not intentionally include your name, email address, phone number, or payment details in AI prompts unless you put that information in content you submit.
  • Naviyara does not create separate AI audit copies of app-user prompts, submitted images, or model responses. Admin-authored curriculum operations may be audited separately and do not use app-user submissions.

Do not submit information you do not want processed by these systems. AI outputs do not make decisions that produce legal or similarly significant effects about you.

7. Service providers and recipients

We disclose data only as needed to operate the Service, including to:

  • Google Firebase and Google Cloud: authentication, database, file storage, server functions, hosting, security, operational logging, and web analytics (Google Analytics 4). Google Privacy Policy
  • OpenRouter: routing image and text requests to configured AI model providers. OpenRouter Privacy Policy
  • AI model providers: processing the prompt, image, and context required to generate an analysis or answer. The particular provider can change as models are updated.
  • OpenAI: voice transcription. OpenAI Privacy Policy
  • RevenueCat: subscription and entitlement management. RevenueCat Privacy Policy
  • Google Play or Apple App Store: account-based purchases, billing, refunds, and store compliance where the Service is offered through that store.
  • Google or Apple: sign-in, when you choose that provider.

We may also disclose personal data to professional advisers, courts, regulators, law enforcement, or a successor in a merger or sale where lawfully required or reasonably necessary. We do not sell or rent your personal data or share it for third-party behavioral advertising.

8. International transfers

Naviyara is operated from Switzerland. Core Firestore and server-function resources are configured in European regions, but some providers and their support systems process data in the United States or other countries. Data may therefore be transferred outside Switzerland, the EEA, or your home country.

Where required, we rely on an adequacy decision, an applicable data privacy framework, recognized standard contractual clauses with any required Swiss adaptations, or another lawful transfer mechanism. No transfer mechanism can eliminate all risks associated with foreign legal access.

9. Retention

We retain data only for as long as reasonably necessary for the purposes described above:

  • Account and user content are generally retained while your account is active.
  • Incomplete or uncommitted submissions may be removed earlier as part of routine cleanup.
  • Security events, rate-limit records, and operational logs are retained as needed for security, debugging, abuse prevention, and legal obligations, then removed according to configured or provider retention processes.
  • Subscription and transaction records may be retained by us, RevenueCat, and app stores for accounting, fraud prevention, and statutory retention periods.
  • Backups and provider copies may persist until their normal rotation or deletion processes complete.

We may retain information longer where required by law, needed for a dispute, or necessary to protect the Service. We may retain data that has been irreversibly anonymized.

10. Security

We use technical and organizational safeguards appropriate to the nature of the Service, including encrypted transport, provider encryption at rest, authenticated backend functions, access controls, and database and file-storage rules. No internet service is completely secure, and we cannot guarantee absolute security.

11. Your choices and deletion controls

  • You can deny or revoke camera and microphone permissions in your device settings.
  • You can edit many account details and preferences in the app.
  • Export your data creates a ZIP containing your account data and stored files behind a short-lived download link.
  • Delete user data removes stored meals and scans, photos, chats, feed items, journal entries, learning progress, and reports while keeping your account active.
  • Delete account removes your primary profile, account-scoped content and files, Firebase Authentication account, and account-linked RevenueCat customer profile.

Deletion from active account storage does not necessarily remove records that must be kept by payment providers, security records, already-created anonymized data, or copies awaiting routine deletion from logs and backups. Clearing or uninstalling the app may be needed to remove data cached on your device. Deleting a Naviyara account does not itself cancel a subscription managed by an app store.

12. Your data protection rights

Depending on where you live and subject to applicable exceptions, you may have the right to:

  • Ask whether we process your personal data and receive a copy
  • Correct inaccurate or incomplete personal data
  • Request deletion or restriction of processing
  • Receive certain data in a portable format
  • Object to processing based on legitimate interests
  • Withdraw consent without affecting earlier lawful processing
  • Lodge a complaint with a competent data protection authority

To exercise a right, email info@naviyara.com. We may need to verify your identity. In Switzerland, you may contact the Federal Data Protection and Information Commissioner. EEA and UK residents may contact their local supervisory authority.

13. Children

The Service is not directed to children under 16, and they may not create an account. If you believe a child has provided personal data, contact us so we can investigate and delete it as appropriate.

14. Changes to this policy

We may update this policy when the Service, providers, or legal requirements change. We will post the revised policy with a new effective date and provide additional notice for material changes where required.

15. Contact

Questions, privacy requests, and complaints can be sent to info@naviyara.com or mailed to the address in Section 1.

Last updated: August 2, 2026

NaviyaraA CuraCap Schweiz GmbH product.
HomeAppAcademyGet the appContactTermsPrivacy
Educational, not medical advice. Health-related statements follow applicable EFSA guidance and EU Regulation 1924/2006. © 2026 Naviyara · CuraCap Schweiz GmbH · Selzach, Switzerland

This website contains content partly created with AI (text, images, video).