Legal

Privacy Policy

Last updated: September 7, 2026

NICOLLA.AI ("we", "our", or "us") is an independent studio that builds AI-powered applications. This Privacy Policy explains how we collect, use, and disclose information across our products — including The Sanctuary — on the web and on Android. Privacy is a core design principle for us, not an afterthought.

In short: our apps store your content and progress on your own device, we do not run user accounts, and we never sell your data. Where information must leave your device — for optional AI features, optional analytics or advertising — we tell you exactly where it goes and why.

1. Information We Collect

Our apps are designed to be a private experience.

2. Optional AI Support Feature

Some apps (including The Sanctuary) offer an optional "Personalized Support" feature. It is available only after you confirm that you are at least 18. When you deliberately start it, the mood or topic text you enter is sent over HTTPS through our proxy hosted on Google Cloud Run to Google's Gemini service to generate a response. Google processes the submitted text and generated output under the Gemini API Terms and the privacy and data-processing terms applicable to the configured service and region. Do not enter sensitive personal data, account credentials, medical records, exact addresses, or other information you would not want to send to an AI service.

Our proxy processes the prompt and generated response transiently and does not store or log their content, except when you deliberately report a response (see below). To verify the Android app and prevent abuse, Google Firebase App Check / Play Integrity processes an attestation token. For fair-use limits, our proxy stores counters associated with a random installation identifier and a one-way hash of the requesting IP address. Counters are not linked to prompt or response content and include an expiry timestamp; deletion timing depends on the configured Firestore TTL and retention controls.

AI responses may be incomplete or incorrect and are not medical care, therapy, or emergency assistance. If you are in immediate danger, contact local emergency services or a trusted person. If you choose "Report response", the app sends the reported response, its response type, your app language, the time of the report and any optional comment you write to our proxy, where it is stored so that a person can review it. The mood or topic text you entered is not part of the report, and the report carries no account, device, or advertising identifier. Reports are kept for up to 180 days and are then deleted automatically. If the report cannot be sent, the app offers to send it from your email app instead; that message is sent only when you decide to send it.

3. Third-Party Services (Advertising)

To keep our apps free, we use Google advertising services:

4. On-Device Storage and Cookies

We use localStorage for functional data, including settings, content progress, the AI age-confirmation flag, local usage safeguards, and earned access to an AI session. We use sessionStorage for the active AI mood/topic and generated response until you reset that support session or the browser/WebView session ends. Third-party advertisers may use cookies or device identifiers as described in Section 3. On this website we additionally store a single localStorage flag recording your analytics choice, as described in Section 6.

5. Optional App Analytics (Android)

If you choose Allow analytics in an app that offers it (currently The Sanctuary on Android), we use Google Analytics for Firebase to understand visits and return visits, screens and features used, sharing actions, ad delivery, and whether an AI request succeeds. Analytics is disabled until you agree. Declining does not restrict any feature. This choice is separate from advertising consent, and you can change it in the app's Settings at any time.

Firebase associates usage events with a pseudonymous app installation identifier and processes app version, device/OS information, approximate region, timestamps, session information and available installation attribution. We do not send affirmation text or IDs, your saved library, your AI input, generated answers, response classifications, report comments, email addresses, or the proxy's installation identifier to Analytics. This is pseudonymous measurement, not anonymous data. Firebase Analytics advertising-ID collection and advertising personalization are disabled; AdMob's separate processing is described in Section 3.

Your analytics choice and daily measurement counters are stored on your device and excluded from Android backup. Turning analytics off stops subsequent collection, clears the SDK's local analytics data and resets its installation identifier. It does not delete events already received by Google. Those events are retained according to the Analytics property's configured retention and Google's processing terms. Analytics data is processed by Google over encrypted connections; see Google's Privacy Policy. The web versions of our apps do not load Firebase Analytics; website measurement is described in Section 6.

6. Website Analytics (nicolla.ai)

This website uses Google Analytics 4 so we can see how many people visit and which pages and referrers bring them here. Analytics runs under Google Consent Mode v2 with every storage category denied by default: until you press Accept on the banner, no analytics cookies or identifiers are written to your browser, and Google receives only aggregated, cookieless pings. If your browser sends a Global Privacy Control signal, we treat it as a decline and do not ask.

We see aggregate reports only — page views, approximate country, device and browser type, and traffic sources. Your IP address is truncated before it is stored and is never used to build an advertising profile of you on this site. We do not collect your name, your email address, or anything you type. This data is processed by Google under Google's Privacy Policy, and we do not use it for advertising personalisation.

Your choice is remembered in localStorage on your own device and you can change it at any time:

7. Data Security & Retention

Data you store in the app stays on your device and is under your control. You can clear it at any time from your device's app storage settings, and it is removed when you uninstall the app. If you have enabled Android Auto Backup for your device, Android may include app data in your own Google account backup and restore it when you reinstall; that backup is controlled by you and your device settings, and we have no access to it. An active AI support session — the text you entered and the response it generated — is excluded from that backup and stays on the device where it was created.

Information transmitted for optional AI features, optional app analytics or advertising is sent over encrypted connections (HTTPS) and handled by Google under its own privacy terms. Apart from the fair-use counters and the reports described in Section 2, we do not store your data on our own servers. Optional app analytics is stored and processed by Google as described in Section 5.

8. Age Requirements and Children's Privacy

The optional AI Support feature is for adults aged 18 or older and requires an in-app age confirmation. Our apps are not directed to children and do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date.

10. Contact Us

If you have any questions about this Privacy Policy, contact us at nicolla.ai.software@gmail.com.