NorthwardBack to website

PRIVACY BY DESIGN

Privacy policy

Northward minimizes information sent to servers and keeps your core planning data under your control, on your device.

Last updated: August 8, 2026

No account required

You do not need to register or identify yourself to use the application.

Local data

Habits, goals, logs and preferences are stored primarily on your device.

Transparent AI

Only the context required is sent when you choose to use an artificial intelligence feature.

01

Controller and scope

The data controller is MPER STUDIO S.L., Spanish tax ID B26788224, registered in the Valladolid Commercial Registry under electronic folio IRUS 1000468045680, record VA-36252.

This policy applies to the Northward mobile application and its associated services. For privacy questions, contact apps.con.ai@gmail.com.

02

Data stored on your device

Northward is designed with a local-first approach. Core information is stored in a local database on your device and no account is required.

  • Preferred name and onboarding answers.
  • Goals, habits, routines, availability and daily logs.
  • Coach conversations and actions, memories you have approved, and reviews.
  • Preferences, notification settings and application state.

You can export a copy of this data and import it on another device. The exported file may contain personal information, so you must store and share it securely.

03

Artificial intelligence features

When you use an AI feature, Northward sends the text and context needed to respond to its secure gateway. The gateway is deployed in Google Cloud’s European europe-west1 region and forwards the request to OpenAI.

Requests may include your messages, goals, habits, availability, date and time zone where needed to generate a plan or response. OpenAI is called with store: false; Northward does not request that those responses be stored by OpenAI.

Do not enter highly sensitive data or unnecessary information about third parties. Coach suggestions must be confirmed before they change your plan.

04

Voice, microphone and audio

Speech recognition uses the recognition services available in the operating system. Northward requests microphone and speech recognition permission only when you choose these features.

The resulting transcript may be sent to the AI feature as if it were a written message. To generate certain voices or previews, text may be sent to Google Cloud Text-to-Speech, which returns synthesized audio.

05

Firebase and technical data

Northward uses Firebase Core and Firebase Remote Config to retrieve technical parameters, enable features and maintain secure configuration without publishing a new version. Under Google’s documentation, these services may process installation identifiers, app version, platform, IP address and technical connection data.

The reviewed version does not include sign-in, cloud profiles, advertising, cross-app tracking or the sale of personal data.

06

Permissions and notifications

Notifications are scheduled locally for habit reminders, summaries and reviews. You can deny or withdraw permission in the operating system and set quiet hours within Northward.

Widgets may display selected information about your day through local operating-system mechanisms. Northward may also request access to files when you choose to import or export your data.

07

Purposes and legal bases

  • Performance of the service: storing your local plan and providing requested features.
  • Consent: access to the microphone, speech recognition, notifications and voluntary use of AI features.
  • Legitimate interests: security, abuse prevention, availability and technical improvement of the service.
  • Legal obligation: responding to rights requests, valid demands and applicable obligations.
08

Retention and deletion

Local data remains on the device until you change or delete it or uninstall the application. Exports remain wherever you choose to store them.

AI requests are processed to provide a response and are not deliberately stored by the gateway. Limited technical security and error logs may exist for as long as needed to maintain the service. Providers apply their own retention periods under their contracts and policies.

09

Providers and transfers

The main technical providers are Google Cloud/Firebase and OpenAI. Some processing may involve transfers outside the European Economic Area. Where this occurs, mechanisms recognized under the GDPR will be used, such as adequacy decisions or standard contractual clauses.

10

Your rights

Where applicable, you may request access, correction, deletion, objection, restriction and portability by emailing apps.con.ai@gmail.com. We may need to verify your request.

Much of the information exists only on your device, where you can review, change and export it directly from the application. You may also lodge a complaint with the Spanish Data Protection Agency or your competent supervisory authority.

11

Children and security

Northward is not intended for children under 16. If you are between 16 and 18, you must use it with parental or guardian permission and supervision where required by applicable law.

We use encryption in transit, access controls, server-managed secrets, rate limiting and data minimization. No system is completely infallible, so we recommend protecting your device and exported files.

12

Changes and contact

We may update this policy when the application, its providers or the law changes. We will publish the current version and its update date on this page.

Contact: apps.con.ai@gmail.com.