Nomicho Consumer Health Data Privacy Policy (United States)
Operator: Chris Hashimoto (橋本クリス), sole proprietor Trade name: Nomicho Contact: support@nomicho.jp Effective date: 2026-09-03 Last updated: 2026-09-03 Version: 1.0
This is a separate and distinct policy covering consumer health data, published alongside our general Privacy Policy rather than inside it. It exists because Washington’s My Health My Data Act, Nevada SB 370, and Connecticut’s health-data provisions treat this category differently from ordinary personal information, and require it to be addressed on its own.
It applies to you if you are a resident of, or your data is collected in, a state with a consumer health data law. Nothing in it reduces any right you have under our general Privacy Policy; where the two differ, whichever gives you more control wins.
1. What we treat as consumer health data
We take a deliberately broad view rather than arguing about the edges. We treat the following as consumer health data:
- Your drink logs — what you drank, how much, when, and the notes and feeling tags you attach.
- Everything derived from them — blood alcohol concentration estimates, intoxication-state transitions, pace status, the hangover forecast, and the statistics and reflection cards built on top of them.
- Your BAC profile — date of birth, sex, height, weight, alcohol-flush tendency, and drinking frequency.
- Apple Health readings, where you have granted permission — sleep, heart rate, heart rate variability, and the profile values (sex, date of birth, height, weight) we read to fill in your BAC profile.
2. Where it comes from
Only from you, in one of three ways: you typed or logged it; the App calculated it from something you logged; or Apple Health provided it after you granted permission. We buy no health data from anyone, and we obtain none from data brokers, advertisers, or public sources.
3. What we collect it for, and why we are allowed to
We collect and use it for one purpose: providing you the features of the App you are using. Logging a drink, estimating your BAC, drawing your calendar, writing your reflection card, forecasting a hangover, and reminding you about water.
Collection is limited to what is necessary to provide those features to you. Where a feature is optional (Apple Health, location, photos, the Lock Screen forecast), we collect nothing for it until you turn it on, and turning it off stops collection immediately.
We do not use it for advertising, profiling, scoring, research, or training AI models, and we do not use it to make any decision about you outside the App.
4. Who we disclose it to
We do not share your consumer health data with anyone in exchange for anything, and we do not disclose it for advertising.
The only parties that ever receive any of it are the service providers who operate the App on our instructions:
| Provider | What it receives | Why |
|---|---|---|
| Supabase (data stored in Japan) | (a) Your drink logs, BAC profile, and derived session data, only if you turn on cloud sync. (b) Your Lock Screen forecast (projected BAC curve, drink count, grams of pure alcohol, predicted peak and hangover tier), only while you have the Lock Screen forecast turned on, sent whether or not you are signed in, keyed to a random per-installation identifier and never linked to an account. See Privacy Policy §2.11. | (a) Storing your own data so it reaches your other devices. (b) Keeping the Lock Screen card updating while your phone is locked. |
| Anthropic | Aggregate session metrics only: drink count, total pure-alcohol grams, category counts, peak feeling, duration, and an optional hangover-severity estimate. No notes, no profile or body data, no photos, no location. | Writing your reflection card. Under a Zero Data Retention agreement, nothing is retained after the request. |
Each is contractually restricted to processing on our instructions. Neither may use your data for its own purposes.
Apple Health data is disclosed to no one. It is read on your device, used on your device, and never leaves it. It is not synced, not backed up by us, not sent to Anthropic, and not included in analytics.
Analytics and crash reporting receive none of the data in §1. Sentry receives crash diagnostics and PostHog receives interaction events plus a small set of non-identifying app settings. Neither receives your drink content, your body data, or any BAC, hangover, or pace estimate.
5. We do not sell it
We have never sold consumer health data, and we do not sell it. We will not sell it in the future without first obtaining your separate, specific, written authorization on a form that tells you exactly what would be sold and to whom, which you would be free to refuse and free to revoke.
6. We do not use geofencing
We operate no geofence of any kind. We do not establish a virtual boundary around a health care facility, a pharmacy, a provider of consumer health services, or anywhere else, and we do not track you, collect data from you, or send you messages based on your proximity to such a place.
The optional location feature attaches a place to a drink you log, and only when you turn it on. It records nothing in the background and nothing outside a session.
7. Your rights
You have the right to:
- Confirm whether we hold consumer health data about you.
- Access it, including a list of every third party and affiliate we have shared it with, and how to contact them.
- Withdraw consent to its collection and to its sharing, at any time.
- Delete it.
The third-party list is currently empty. We have shared consumer health data with no third party and have no affiliates. The only parties that ever receive any of it are the processors named in §4, which handle it solely on our instructions and may not use it for their own purposes. If that ever changes, this section will name the third party and its contact details before any sharing begins.
How to use the App’s own controls, which are faster than writing to us:
| What you want | Where |
|---|---|
| See and export everything you contributed | Settings → Export Data (JSON, immediate) |
| Delete a single drink, note, or place | Edit or delete it directly in the App |
| Stop Apple Health collection | Settings → Apple Health, or iOS Settings → Health → Data Access |
| Stop location collection | Settings → Location |
| Stop cloud storage of your data | Settings → Sync |
| Delete everything, including cloud copies | Settings → Delete Account |
To make a request in writing, email support@nomicho.jp. We respond within 45 days and may extend once by a further 45 days where reasonably necessary, telling you before we do. Requests are free. To verify you, please write from your registered email address or include an account identifier sufficient to locate the data.
If we deny a request, we will tell you why and how to appeal. To appeal, reply to our response with “Appeal” in the subject line; we will respond within 45 days with a written explanation. If we deny the appeal, you may contact your state Attorney General.
8. Deletion, and what it reaches
When you delete your account, or ask us in writing to delete consumer health data:
- Data on your device is deleted immediately.
- We delete your rows directly from our cloud database and storage. Copies may persist briefly in backups and replicas; deletion completes there within 30 days at the latest.
- Our AI provider holds nothing to delete: under its Zero Data Retention agreement, nothing is retained after each request is processed.
- Our analytics and crash-reporting providers hold no consumer health data, so there is nothing for them to delete.
- Apple Health data needs no deletion request, because we never held a copy.
Deleting your account in the App confirms completion on screen. If you asked us in writing, we will write back when deletion is complete.
9. How long we keep it
While your account is active, and for the 30-day window described in §8 after you delete it. Crash and analytics records, which contain no consumer health data, follow the retention in the general Privacy Policy §5.1.
The Lock Screen forecast is the shortest-lived: it is deleted when the card ends, and in all cases no later than 2 hours after your session’s projected end time.
10. Security
Row-Level Security on every user-owned table, so one account cannot reach another’s rows. Encryption in transit. Private-by-default storage objects. Device attestation on calls to our AI proxy. Access to production data is limited to the operator.
11. Contact
- Email: support@nomicho.jp
- Operator: Chris Hashimoto (橋本クリス), sole proprietor
- Address: disclosed without delay upon request
12. Changes
If we change this policy we will post the revised version with a new effective date, and for material changes will give notice in the App before it takes effect.
| Version | Date | Summary |
|---|---|---|
| 1.0 | 2026-09-03 | Initial version. |