01 Studio 02 Apps 03 Company 04 Support 05 Contact
London · United Kingdom contact@noventra.dev
Legal

Privacy Policy

How we handle personal data across this website and our applications — written to be read, not to be skipped.

Effective from6 August 2026
Version1.1
Applies tonoventra.dev and all Noventra applications
Data controllerNoventra Software Ltd, company no. 17373060
Governing frameworkUK GDPR & Data Protection Act 2018
Please note

Our approach in one sentence: we collect as little as we can, keep it on your device wherever possible, never sell it, and never track you across other companies' apps or websites.

Who we are

Noventra Software Ltd (“Noventra”, “we”, “us”, “our”) is a private company limited by shares, registered in England and Wales under company number 17373060, with its registered office at Suite 11083, 5 Brayford Square, London, E1 0SG, United Kingdom.

We design and publish mobile applications for the Apple App Store and Google Play, and we operate this website. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Noventra Software Ltd is the data controller for the personal data described in this policy.

We have not appointed a statutory Data Protection Officer, as we are not required to. Privacy questions are handled directly by the company's management and can be sent to contact@noventra.dev.

What this policy covers

This policy explains what personal data we collect, why we collect it, what we do with it, and the rights you have over it. It applies to:

  • this website and any subdomain we operate;
  • the mobile applications we publish under the Noventra name on the App Store and Google Play;
  • email, support and business correspondence with us.

It does not apply to third-party services that our apps or site may link to, or to applications we have built for a client where that client is the data controller. Where we build an app on behalf of a client, the client's own privacy policy governs the app and we act as a processor under a written agreement.

Individual applications may add their own privacy notice where they process something this policy does not describe. Where an app-specific notice exists, it is available inside that app and on its store listing, and it takes precedence for that app.

Information we collect

When you visit this website

This website has no analytics, no advertising and no tracking pixels. We do not set advertising or analytics cookies. Our hosting provider generates standard server logs, which may include your IP address, the time of the request, the page requested, and your browser's user-agent string. These logs exist for security and reliability and are not used to build a profile of you.

This site loads its typefaces from Google Fonts. That request necessarily discloses your IP address to Google. See the Cookie Notice for detail and for how to avoid it.

When you contact us

If you write to us or use the contact form, we process your name, email address, any company name you supply, and the content of your message. The contact form on this site does not transmit anything to a third-party form service — it opens your own email client with the message pre-filled.

When you use our applications

Our default posture is to keep data on your device. Many of our apps work entirely offline and never transmit your content anywhere. Where an app does process personal data, the categories may include:

  • Account data — where an app offers accounts: an email address, a display name, and an authentication credential (stored only as a salted hash);
  • Content you create — notes, tasks, documents, media or other material you choose to save or sync;
  • Purchase status — whether a subscription or in-app purchase is active. Payment card details are never seen by us; Apple and Google process all payments;
  • Diagnostics — crash reports and anonymised performance metrics, where you have not opted out at the OS level;
  • Support correspondence — what you send us when you report a problem, including any logs you choose to attach.

Every app's store listing carries a Privacy Nutrition Label (Apple) and a Data Safety declaration (Google) that we check line by line against the actual code before each submission.

What we never collect

  • Advertising identifiers (IDFA / AAID) — we do not request App Tracking Transparency permission because we do not track;
  • Precise location, unless an app's core function requires it and you have granted permission for that specific purpose;
  • Contacts, photos, microphone or camera data, except where you actively invoke a feature that uses them;
  • Biometric data. Where an app supports Face ID or fingerprint unlock, that verification happens entirely within the operating system and we never receive the biometric itself.

Children's privacy

We publish in Apple's Kids Category and participate in Google Play's Families programme, and we take the associated obligations seriously.

In any application directed at children, we commit that:

  • there are no third-party advertising SDKs of any kind;
  • there is no behavioural profiling, targeted advertising or cross-app tracking;
  • we do not knowingly collect personal data from a child beyond what is strictly necessary to make the app function;
  • any external link, purchase flow, social feature or contact mechanism sits behind a parental gate;
  • we never sell or share children's data with data brokers.

These apps are designed to comply with the UK GDPR and the ICO's Age Appropriate Design Code (the Children's Code), and with the United States Children's Online Privacy Protection Act (COPPA) where it applies.

If you believe a child has provided us with personal data, please write to contact@noventra.dev. We will delete it promptly and confirm to you once it is done.

How we use information, and our lawful bases

Under the UK GDPR we must have a lawful basis for every use of personal data. The table below sets out ours.

PurposeData usedLawful basis
Providing the app or service you asked forAccount data, content you create, purchase statusPerformance of a contract (Art. 6(1)(b))
Answering your enquiry or support requestName, email, message content, diagnostic detailLegitimate interests — responding to people who contact us (Art. 6(1)(f))
Keeping our apps stable and secureCrash reports, anonymised performance metrics, server logsLegitimate interests — operating a reliable, secure service (Art. 6(1)(f))
Preventing fraud and abuseAccount data, device signals, server logsLegitimate interests — protecting our users and our service (Art. 6(1)(f))
Optional features you switch on (for example cloud sync)The content covered by that featureConsent (Art. 6(1)(a)), withdrawable at any time
Meeting legal, tax and accounting dutiesTransaction and correspondence recordsLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interest does not override your rights and freedoms. You may object to that processing at any time — see Your rights.

Where we rely on consent, you can revoke or withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. In our applications, consent is revoked by turning the relevant feature off in the app’s settings; for anything else, email contact@noventra.dev and we will action it. Revoking consent does not delete data already collected — to have that removed, use the deletion route described in Your rights.

Advertising, analytics and tracking

We want to be unambiguous about this, because it is the single question users ask most often.

  • We do not sell personal data. We never have and it is not part of our business model.
  • We do not operate cross-app or cross-site behavioural tracking.
  • We do not embed third-party advertising SDKs in children's or educational titles.
  • This website carries no analytics and no advertising.

Where an application uses crash reporting or performance monitoring, it is limited to diagnostics we need to fix defects, and it can be disabled in the app's settings and through your operating system's own analytics-sharing controls.

If we ever introduce advertising in an app aimed at adults, it will be disclosed on that app's store listing, in that app's own privacy notice, and in this policy before it goes live.

Service providers and third parties

We keep our supplier list deliberately short. Every provider that handles personal data on our behalf does so under a written agreement that restricts them to our instructions.

We confirm that any third party with whom we share user data — including analytics providers, advertising networks and third-party SDKs, and any parent, subsidiary or other related entity that has access to user data — is contractually required to provide the same or equal protection of that data as is stated in this policy. Where a provider cannot meet that standard, we do not use them.

ProviderWhat they doWhere
Apple Inc.App Store distribution, payments, TestFlight, subscription managementUSA / global
Google LLCGoogle Play distribution, payments, Play Console reporting, web fontsUSA / global
Website hosting providerServing this website; standard server logsUK / EU
Email providerBusiness and support correspondenceUK / EU
Cloud infrastructureBackend services for apps that require themUK / EU where available

Apple and Google act as independent controllers for the data they collect through their own storefronts and payment systems. Their handling of that data is governed by their own privacy policies, not by ours.

We may also disclose personal data where we are legally required to — for example in response to a valid court order or a lawful request from a regulator or law-enforcement body. We will not disclose more than is necessary, and we will notify you where we are permitted to do so.

If our business is sold or transferred, personal data may transfer with it. You would be told before that happened, and the data would remain subject to protections no weaker than those in this policy.

International transfers

We prefer to keep data in the United Kingdom or the European Economic Area. Some of our providers — notably Apple and Google — operate globally, so personal data may be transferred outside the UK.

Where that happens, we rely on one or more of the following safeguards required by Chapter V of the UK GDPR:

  • an adequacy decision or adequacy regulation made by the UK government in respect of the destination country;
  • the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum;
  • for transfers to the United States, certification under the UK Extension to the EU–US Data Privacy Framework where the recipient is certified.

You can request a copy of the safeguards that apply to a particular transfer by writing to contact@noventra.dev.

How long we keep information

We keep personal data only for as long as we have a reason to, then delete it.

CategoryRetention period
Account dataFor the life of the account, then deleted within 30 days of deletion or of 24 months' inactivity
Content you create in an appUntil you delete it, or until your account is deleted
Support correspondence24 months from the last message in the thread
Crash and diagnostic reports90 days
Server logs30 days
Transaction and accounting records6 years, as required by UK tax law

Backups are rotated on a rolling schedule and anything deleted from our live systems is removed from backups within 30 days.

Security

We take appropriate technical and organisational measures to protect personal data, including:

  • encryption in transit (TLS 1.2 or above) and at rest for data held on our infrastructure;
  • use of the operating system's own secure storage — Keychain on Apple platforms, Keystore on Android — for credentials and tokens on the device;
  • passwords stored only as salted hashes, never in a recoverable form;
  • access to production systems restricted to those who need it, protected by multi-factor authentication;
  • keeping dependencies patched and reviewing the third-party code we include;
  • collecting as little as possible in the first place, which is the most effective control we have.

No system is perfectly secure, and we will not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and will tell you directly where the risk is high.

If you believe you have found a vulnerability, please report it privately to contact@noventra.dev. We will acknowledge within 72 hours and we will not pursue researchers acting in good faith.

Your rights

Under the UK GDPR you have the following rights in relation to your personal data:

  • Access — to be told whether we hold data about you and to receive a copy of it;
  • Rectification — to have inaccurate data corrected and incomplete data completed;
  • Erasure — to have your data deleted where there is no continuing reason for us to hold it;
  • Restriction — to have processing limited in certain circumstances, for example while accuracy is contested;
  • Portability — to receive data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible;
  • Objection — to object to processing based on legitimate interests, and an absolute right to object to direct marketing;
  • Withdrawal of consent — where processing is based on consent, to withdraw it at any time;
  • Automated decisions — not to be subject to solely automated decisions with legal or similarly significant effects. We do not make such decisions.

To exercise any of these, write to contact@noventra.dev. We will respond within one month. If a request is complex we may extend that by up to two further months, and we will tell you within the first month if we need to.

There is no charge. We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else.

Many of our apps also let you exercise these rights yourself, directly in the app: export your data, and delete your account and its contents, without needing to contact us at all.

Cookies and local storage

This website does not use cookies for analytics, advertising or profiling. It stores a single preference in your browser's local storage — whether you chose the light or dark theme — which never leaves your device and is not transmitted to us.

Full detail, including the third-party font request, is in our separate Cookie Notice.

Changes to this policy

We may update this policy as our products change or as the law does. The effective date at the top of this page always reflects the current version.

Where a change materially affects your rights or the way we use your data, we will give notice through the app, by email where we hold your address, or by a prominent notice on this website before the change takes effect.

Contacting us, and how to complain

For any question about this policy or about how we handle personal data:

  • Email: contact@noventra.dev
  • Post: Data Protection, Noventra Software Ltd, Suite 11083, 5 Brayford Square, London, E1 0SG, United Kingdom

We would like the chance to resolve any concern first. You also have the right to complain at any time to the UK supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Helpline: 0303 123 1113  ·  ico.org.uk