Nuoli Privacy Policy
Last updated: 20 September 2026
Nuoli is a product of torrhes.com. This policy says what Nuoli collects, why, where it goes, how long it stays, and what you can do about it. It is written to match what the app actually does today; when the app changes, this page changes with it.
1. What we collect
What you type into the app. Your trips: destinations, dates, activities, notes, ideas, bookings you mark, where you are staying, nearby places you add, and the answers you give about your trip (who is travelling, pace, tastes, budget, rhythm, accessibility needs, what you already know you want to do). Also anything you write to the assistant, and any feedback or rating you send us.
Your account, if you create one. Your email address, a password (stored only as a one-way hash; we never see or store the password itself), the name you choose to show, your language, and the profile photo you choose. Nuoli works without an account; an account is what lets your trips follow you to another device.
Your location, only when you ask for places around you. Three controls in Nuoli use your location: "Around me" on the "Ask for an idea" sheet, sending a question to the Nuoli Companion, and "Near me", which lists real places around you so you can pick the ones you want. Pressing any of them asks your device for your position at that moment, and your device asks you for permission the first time. Before it leaves your phone that position is rounded to roughly a hundred metres, and only the rounded version is sent, so what we and the AI service see is the neighbourhood you are in rather than the spot you are standing on. We ask your device for a precise position, because the "approximate" one Android offers can be off by more than a kilometre, which is further than any walk the screen suggests; a hundred metres is well inside the shortest of them, so nothing useful is lost in the rounding. The exact position your device gave stays on your phone and is used only to show you how far away a suggestion is. The rounded position is not saved to your trip, it is not in the backup of your trips on our server, and it is not in the usage records described above. It does appear in the record we keep of that one AI request, described in section 4, which is kept for the period in section 9. The same rounded position is also sent to Google Places, so that the suggestions you get back are real places that are near you and open, rather than places the AI recalls; Google receives the rounded position, how far you said you would walk, and what you asked for, and nothing that identifies you or your account. "Near me" sends exactly those same three things to Google and asks no AI at all. What comes back is a list of places, and nothing of it is saved unless you tick a place and add it to your day; for the ones you do, what is saved is the name, the category, Google's identifier for the place and its point, and nothing else. If you refuse, or your device cannot get a position, Nuoli says so and answers from your plan for that day instead, and it does not ask again while you stay on that screen. Nothing else in the app asks for your location, and nothing asks for it in the background or while the app is closed.
Your invite code and a device identifier. While Nuoli is a closed beta, every device holds an invite code and a random device identifier that we generate. They tell us that a device is allowed in and let us count how many free plans it has used. The device identifier is not your phone's advertising identifier and is not shared with advertisers.
How the app is used. The app records which screens are opened and which buttons are tapped, together with the app version, the platform, the session, and the device identifier above. It does not record what you type into fields. If the app fails to start on the web, it records the browser version and the failure reason.
Crash and performance reports. The app reports crashes and slow screens to Kotzilla, a monitoring service. Those reports include the device model, operating system version, app version and the sequence of screens before the problem.
Purchases. If you subscribe to Nuoli Plus, the purchase is handled by the App Store or Google Play. We receive a confirmation of the subscription and its status through RevenueCat, tied to your account or device identifier.
2. What we do not collect
- Your location in the background, or while the app is closed. Nuoli only ever reads it while you are using the app, at the moment you press one of the two controls in section 1, and it keeps no record of it. See section 1.
- A history of where you have been. Nuoli stores no position, so there is nothing to build one from.
- Your contacts, calendar, messages or photo library, beyond the single photo you choose for your profile.
- Payment details. The App Store and Google Play handle payment; we never receive a card number or bank details.
- Passport numbers, government IDs or booking confirmations. Nuoli books nothing, so it never needs them.
- Anything for advertising. Nuoli shows no ads and uses no advertising trackers.
3. What we use it for
- To plan and keep your trips, including a copy on our server so they are not lost with the device and can be restored on another one.
- To generate and refine itineraries with an AI model (section 4).
- To keep the closed beta closed and to count free plans.
- To see which parts of the app are used, so we fix what matters and remove what is not used.
- To find and fix crashes.
- To run subscriptions.
- To answer you when you write to us.
We do not sell your data, and we do not use it for advertising.
4. The AI
When you ask Nuoli to build or change a plan, or ask the assistant a question, the trip content needed for that answer is sent to Anthropic, the provider of the Claude models, through their API. That content is your destination and dates, the plan itself, your answers about the trip (including where you are staying, if you said), the text of your ask, and, when you ask to change a plan, the date and time on your device so the answer suits the hour where you are. Your email, name and photo are not sent. Anthropic processes this data under its API terms and does not use API data to train its models.
When a plan is built, the names of the places in it are also looked up with Google Places so that the pins and the links go to the right venue rather than to somewhere with a similar name. What is sent is a place name and the city, nothing about you; what we keep from the answer, on the activity, is Google's identifier for the place and its name and point.
"Near me" uses Google Places on its own, with no AI in it: nothing is sent to Anthropic, no record of an AI request is written for it, and the list you see is Google's answer rather than a model's. The ratings, the review counts, whether a place is open and how far away it is are shown while that list is open and are not saved anywhere.
We keep a record of each AI request and its answer on our server, so we can see why a plan came out the way it did and improve the prompts. When the request carried your position, that record contains the sentence that carried it, so your position for that one moment is in it too, rounded to roughly a hundred metres as section 1 describes, for as long as section 9 says. The AI can make mistakes: opening hours, prices, availability and distances should be checked before you rely on them.
5. Legal basis
Where a data protection law asks for one, this is ours: performing the service you asked for (your trips, your account, the AI plans, subscriptions); our legitimate interest in keeping the service secure, working and improving (the beta gate, usage records, crash reports); and your consent where a law requires it, which you can withdraw by deleting the data or the account.
6. Cookies and site tracking
The nuoli.app landing page counts visits with Umami, an analytics tool that runs on our own server (analytics.torrhes.com). It sets no cookies, stores no IP address and no identifier of you, does not follow you to other sites, and shares nothing with anyone. What it records is the page you opened, the country and browser it came from, and which button you pressed (the App Store badge, Start on the web, a screenshot). No advertising script runs anywhere on the site.
The web app itself (nuoli.app/go) runs no analytics script and keeps its data in your browser's local storage, on your device, which is how it works offline. The only records of its use are the in-app events described in section 1, which go to our own server.
7. Who processes your data
We share data only with the services that make a feature work:
| Service | What they receive | Why |
|---|---|---|
| Hostinger (our hosting, United States, Boston) | Everything stored on our server | Running Nuoli's server and database |
| Anthropic (Claude) | Trip content and your asks, as in section 4. When you tap "Around me", also your position at that moment rounded to roughly a hundred metres, and the walking distance you chose | Generating and refining plans, the assistant; suggesting places within a short walk of where you are |
| Kotzilla | Crash and performance reports, usage events | Finding crashes and slow screens |
| RevenueCat | Your account or device identifier, subscription status | Nuoli Plus subscriptions |
| Apple App Store and Google Play | Handled by them under their own policies | Payment for Nuoli Plus |
| Open-Meteo, OpenStreetMap (Nominatim), Photon by Komoot | The place names you type or search for | Finding places and their coordinates |
| Google Places | The names of places in your plan and the city they are in. When you tap "Around me" or "Near me", also your position at that moment rounded to roughly a hundred metres, how far you said you would walk, and what you asked for | Checking that a place in your plan is real and where it is; finding places near you that are open now |
| Wikimedia Commons | The name of a destination | A photo of the city on your trip |
| Google Maps or Apple Maps | The place or pin you choose to open | Opening a place or directions, in the app you chose |
Opening a place in a maps app, or a booking site from a plan, takes you out of Nuoli; those sites have their own policies.
8. International transfers
Our server is in the United States. Anthropic, Kotzilla and RevenueCat process data in the United States and, for some of them, in the European Union. If you are outside those places, your data crosses a border to reach them. Where a law requires safeguards for that, we rely on the providers' standard contractual clauses and equivalent terms.
9. How long we keep it
- Your trips, your answers and your photo: for as long as you keep them, and on the server until you delete the trip or the account.
- Your account: until you delete it. When you delete it, your trips on the server and your photo are deleted at once and the account is marked deleted. We keep the email address itself so it cannot be re-registered by someone else and attached to old data.
- Usage events, crash reports and AI request records: 24 months, then deleted or anonymised. This is about the records we keep about how the app is used, never about your trips.
- Feedback you send: until we have acted on it, and at most 24 months.
10. Your choices and rights
- See and change your data: everything about a trip is editable in the app. Your name, photo and language are in Profile and Settings.
- Delete your account: see section 11.
- Sign out of a device: Settings, then "Sign out of this device". The trips stay on the server.
- Ask us: to access, correct, export or delete data we hold about you, write to hello@nuoli.app from the address of your account. If you live in the EU, the UK, Brazil, California or another place with a data protection law, you have the rights that law gives you, including to complain to your local authority.
11. Delete your account
In the app: open Profile, then Settings, then Delete my account, and type your password to confirm. This deletes your trip backups and your photo from our server at once, deletes the stored AI requests and answers made under the account, detaches the account from the usage records, marks the account deleted and signs you out on every device. Trips still on the device are yours to delete from the device. If you cannot use the app, email hello@nuoli.app from the address of the account and we delete it for you within 30 days.
12. Security
Everything between the app and our server travels over TLS. Passwords are stored as Argon2id hashes. Sign-in uses short-lived tokens that rotate. Profile photos are stored on our server and served only to the account they belong to.
13. Children
Nuoli is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us data, write to us and we will delete it.
14. Changes
We will post changes here with a new date. For a change that matters to you, we will say so in the app.
15. Contact
Nuoli is a product of torrhes.com, the trading name of Hector Torres, Seattle, Washington, USA.
hello@nuoli.app