Overview
Your reports are your work. This policy explains what information Nonu handles, where reports are stored, and what happens when you use an online feature.
We do not sell personal information or use clinical content for advertising.
1
Information we collect
Account details. Your name, email address, professional profile and information needed to sign you in and manage your account.
Reports and workspace content. Reports, templates, snippets, files and sharing activity that you choose to create, upload or store through Nonu. Reports may contain patient information.
Service information. Device and browser details, IP addresses, usage events, error logs and security activity needed to operate and protect the service.
Billing and support. Your plan, payment status and transaction references, together with information you send when requesting help. Paystack handles payment details; Nonu does not receive full card numbers.
We use cookies and browser storage where needed for sign-in, security, preferences and workspace functions. We do not use clinical content for behavioral advertising.
2
Cloud and local report storage
Nonu offers two options for storing reports:
Cloud storage. Reports saved to the cloud are stored through Nonu's service infrastructure. This makes cloud features, such as access across devices and supported sharing or collaboration, possible. The information is processed by the providers needed to deliver those features.
Local storage. Reports saved locally are stored in your browser on the device you use. They are not uploaded to Nonu's cloud report storage merely because you write or save them locally. Local reports may be lost if you clear browser data, change devices, remove the browser profile or lose access to the device. Export and safeguard copies you need to keep. Local storage does not itself provide cloud backup or cross-device sync.
Your storage option applies to report storage, not automatically to your whole account or every Nonu feature. Account, billing, security and other service information may still be processed online. If you explicitly export, share, upload, sync or use a cloud feature with a local report, the information involved may leave your device. Check the action before submitting patient information.
3
How we use information
We use information to:
- run the workspace,
- secure accounts,
- store and export reports as you direct,
- provide requested features,
- manage subscriptions,
- investigate problems, and
- answer support requests.
Where the law requires a legal basis, we rely on the basis appropriate to the activity, including our contract with you, legitimate interests in running and securing the service, legal obligations or consent where required. You can withdraw consent for processing based on consent, without changing the lawfulness of earlier processing.
4
Patient information, AI and dictation
Only enter patient information when you and, where applicable, your healthcare organization are authorized to use Nonu for it. The clinician or organization directing clinical work will usually decide why patient information is processed; Nonu will usually process it to provide the service on their instructions. The applicable legal roles depend on the circumstances.
When you request cloud AI, selected instructions and report content are sent to the relevant AI provider. When you request cloud dictation, audio is sent to a transcription provider. Offline dictation processes audio on your device. The rules governing provider retention and model training depend on the provider agreement and configuration; do not assume every provider handles submissions in the same way.
Using local report storage does not prevent information from being sent when you deliberately use a cloud feature. Automated removal of patient identifiers may miss details. Review what you send, and obtain any institutional approvals and provider agreements required for clinical use.
AI suggestions support drafting and review. They do not replace a clinician’s judgment.
5
Providers, security and retention
We use providers for infrastructure, account management, storage, payments and features you request. These include Cloudflare, Convex, Clerk and Paystack, as well as relevant AI and transcription services. The current subprocessor list identifies providers, the information they receive and their processing locations.
Information may be processed outside your country. Where required, we use applicable transfer safeguards. We apply measures designed to protect the service and investigate security incidents, but no online service can guarantee absolute security.
We keep information for as long as needed to provide the service, meet legal obligations, resolve disputes and maintain security. Deleting an account starts a verified deletion process. Some records may need to remain for legal or clinical-record reasons; backups and provider deletion queues may take longer to clear. Removing locally stored reports from a device is separate from deleting your Nonu account or cloud data.
6
Your rights and contact
Depending on applicable law, you may request access to, correction of, export of or deletion of your personal information. You may also have rights to restrict or object to processing, withdraw consent and complain to a data protection authority. We may need to verify your identity and authority before acting.
For patient records, requests should normally go to the clinician or healthcare organization responsible for those records. We will assist where required.
Nonu is operated by Gerald Batariwah in Ghana. For privacy questions or requests, email support@usenonu.com. Do not send patient information or medical images by email.
We may revise this policy as the service or law changes. We will update the effective date and provide additional notice where required. Mandatory rights under applicable law continue to apply.