Privacy Policy
Last updated: 12 April 2026 · Operated by Nidra-N3 Ltd (“Nidra”, “we”, “us”).
This Privacy Policy is for people who use Nidra products and services: the Nidra mobile apps (iOS and Android), your account and sessions on api.nidra.io, personalised sleep audio and related processing, and the same rules apply when you use Nidra-owned web pages (for example nidra.io, waitlist signup, or contact flows that reach our API).
1. Who this applies to
This policy applies to you if you have or use a Nidra account, use the apps or backend, purchase from us, or submit personal data through Nidra contact or waitlist forms. If you are located in India, the summary below also reflects the Digital Personal Data Protection Act, 2023 (“DPDP Act”). We act as a Data Fiduciary for personal data we determine the purpose and means of processing; you are the Data Principal for your own personal data. Questions: contact@nidra.io.
2. Personal data we may collect
Depending on how you use Nidra, we may process categories of personal data including:
- Identity and contact data: name, email address, phone number, country, date of birth (where you choose to provide them for registration, orders, or support).
- Account and authentication data: identifiers linked to your account, session tokens (e.g. JWT access and refresh tokens) issued by our backend after phone verification, and similar security-related data.
- Wellness and product usage data: information you provide about sleep, preferences, and interactions with the app (including brain activity recordings from your headband used to generate personalised sleep audio). Nidra is positioned as a wellness product, not a medical device; do not use it as a substitute for professional medical advice.
- Brain activity data: brain activity recorded by your Nidra Headband and the values derived from them to create your personalised sound, along with related files (for example brain activity and audio files) stored and processed through our secure pipelines and cloud storage.
- Transaction data: device or subscription orders, delivery details, and payment-related references processed by our payment provider (Stripe); we do not store full payment card numbers on our servers.
- Communications: messages you send via contact forms, email, or in-app support; optional waitlist email addresses.
- Technical and log data: IP address, device type, app version, diagnostic logs, and security logs to operate and protect the service.
- Push notification tokens: device tokens processed via Firebase Cloud Messaging (or equivalent) to send optional notifications.
3. How we use personal data (purposes)
We process personal data to:
- Provide, maintain, and improve the Nidra apps, APIs, and website;
- Verify your identity (including OTP/SMS via providers such as Twilio);
- Generate and deliver personalised sleep audio from your brain activity recordings;
- Fulfil product orders and handle payments and refunds through Stripe;
- Send service messages, security alerts, and (where you opt in) product and launch updates;
- Meet legal, regulatory, and tax obligations;
- Detect, investigate, and prevent fraud, abuse, and security incidents.
4. Legal bases (including India)
Where the GDPR or similar laws apply, we rely on consent, contract performance, legitimate interests (such as securing our services), and legal obligation as appropriate.
For India, processing of digital personal data is carried out in line with the DPDP Act: we provide notice (this Policy and in-app notices), obtain free, specific, informed, unconditional, and clear consent where required, and support exercise of rights described below. Certain legitimate uses may apply as permitted by law without consent (for example limited processing strictly necessary to comply with law or respond to a genuine emergency affecting your vital interests).
5. Cookies and similar technologies (website)
If you use Nidra marketing pages in a browser, limited cookies or similar technologies may apply (for example font delivery). In-app storage and tokens are covered in this policy and in our Cookie Policy where relevant to the website.
6. Sharing and processors
We share personal data with a limited set of service providers who process data on our instructions, including for example:
- Cloud infrastructure (e.g. Amazon Web Services) for hosting, databases, object storage, and related services;
- Stripe for payments;
- Twilio (or similar) for SMS/OTP;
- Zego (or similar) for real-time video where the product enables it;
- Google Firebase for push notifications;
- Email delivery (SMTP) providers as configured in our environment.
We do not sell your personal data. We may disclose information if required by law, court order, or to protect the rights, safety, and integrity of Nidra, our users, or the public.
7. International transfers
Nidra-N3 Ltd is incorporated in the United Kingdom. Our service providers may process data in the UK, the European Economic Area, the United States, India, and other regions where they operate. Where Indian law requires safeguards for cross-border transfers, we implement appropriate contractual and technical measures consistent with the DPDP Act and applicable rules.
8. Retention
We retain personal data only as long as needed for the purposes above, including legal, accounting, and dispute-resolution requirements. Brain-activity-derived files and account data are retained according to operational needs and your choices (for example, account deletion requests). Specific retention periods may vary by data category and product configuration.
9. Security
We implement administrative, technical, and organisational measures designed to protect personal data, including encryption in transit where appropriate for our stack, access controls, and secure development practices. No method of transmission or storage is completely secure; we encourage strong device passcodes and updated app versions.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. India (DPDP Act): Data Principals generally have rights including: access to information about processing; correction and erasure; grievance redressal; and nomination, as provided under the Act and applicable rules. You may withdraw consent (where processing is consent-based) with comparable ease to how consent was given, subject to legal exceptions.
How to exercise rights: email contact@nidra.io or use the contact section on our FAQs page. We may need to verify your identity before fulfilling requests.
Complaints (India): you may also lodge a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Act and rules, once available and applicable to your case.
11. Children
Nidra is not directed at children under the age where parental consent is required in your jurisdiction. We do not knowingly collect personal data from children without appropriate consent. If you believe a child has provided us data improperly, contact us and we will take appropriate steps.
12. Automated decision-making
Our algorithms process your brain activity signals to generate personalised audio for wellness purposes. This is not automated decision-making with legal or similarly significant effects in the sense of profiling that denies services; it supports product personalisation. You can contact us with questions about how your data is used in that pipeline.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Material changes may be communicated through the app, email, or a prominent website notice where appropriate.
See also: Terms of Service · Cookie Policy