1. Who We Are
Novra ("Novra," "we," "us") is operated by Novra Vault LLC. This policy describes how we collect, use, store, and share information when you use the Novra app (the "Service"). Novra is not a HIPAA-covered entity or business associate — this policy does not create, and should not be read to imply, HIPAA coverage.
2. Information We Collect
- Account information: name, email, profession/professional category.
- Credential documents you choose to upload or enter: licenses, certifications, insurance documents, immunization records, background check documents, and details you provide about them (issuer, license number, dates, notes).
- Some of these documents may be "consumer health data" under applicable state law because they reveal your physical or mental health status (for example, immunization records).
- Sharing activity: records of who you've shared credential packets with, when, and access activity on shared links.
- Technical data: IP address, device/browser information, and timestamps, collected for security and audit purposes.
3. How We Use Information
We use your information only to operate the Service for you: storing and organizing your credentials, sending expiration reminders, and letting you share read-only credential packets with recipients you choose. We do not use your health-category data for advertising, do not sell it, and do not share it with data brokers or ad networks.
4. How We Share Information
We only share your credential data when you affirmatively direct us to, by creating a share link for a recipient you choose. You control the recipient, what's included, and when access expires, and you can revoke access at any time. We do not otherwise disclose your documents to any third party unless you initiate the share yourself, or where required by law.
5. Your Rights
From your account, you can export a complete copy of your data and files, delete your account and all associated data permanently, and view, revoke, or check the status of any share you've created. To exercise other rights available under applicable law — including access, correction, or withdrawal of consent for consumer health data — contact us at novra.vault@gmail.com.
6. Consent
Before you can store any credential or health-category document, we require your affirmative, opt-in consent to this policy. Before you share any credential packet, we require a separate, specific consent confirming what will be shared and with whom. You may withdraw consent at any time by deleting the relevant document or your account.
7. Security
We use encryption in transit and at rest, private storage with no public URLs, access controls scoped to your account, and a complete audit log of access to your credential data.
8. Data Retention
We retain your information while your account is active. If you delete your account, your data and files are permanently deleted, other than records we're required to retain for legal or security purposes.
9. Breach Notification
If a breach affecting your unsecured personal or health information occurs, we will notify you and, where required, applicable regulators, consistent with applicable law.
10. Changes to This Policy
We will notify you of material changes and, where required, seek renewed consent before materially different use of your consumer health data.
11. Contact
Questions about this policy: novra.vault@gmail.com.