Data Privacy Policy
Updated: August 2026
Your privacy is fundamental to Norim Labs, Inc. This Data Privacy Policy outlines our privacy principles, security safeguards, and legal rights regarding consumer health personal data, including protected health information (“PHI”) where applicable, within the Norim platform and services. This policy applies to all employees, contractors, and vendors while doing business with Norim Labs, Inc. and others who may have access to PHI in connection with Norim Labs, Inc.’s covered entity and/or business associate activities.
Health Privacy & Ecosystem Overview
At Norim Labs, Inc., we believe privacy is a fundamental human right. Four core principles inform everything we build into Norim health features:
Data Minimization: We minimize the personal and health data accessible to anyone, including ourselves. Norim health data is end-to-end encrypted whenever possible. As a result, stored health data cannot be read by anyone — not even Norim Labs, Inc.
On-Device Processing: We minimize server data collection by processing health data on your device whenever feasible (e.g., trend calculations, insights, and health metrics).
Explicit Consent & Control: You maintain total authority over your data.
Family & Friends Sharing: You can share health data with trusted family members and friends within the Norim ecosystem.
Invitation-Based Acceptance: Data sharing requires double opt-in consent. Sending data requires your explicit approval and receiving shared data requires the recipient to accept your invitation before any data becomes accessible. You can modify, revoke sharing permissions, and/or stop receiving shared data at any time.
Security: End-to-end encryption and passcode/biometric safeguards ensure that physical access to a device does not reveal health records without authorization.
Age Requirements and Children's Privacy
Our Services are not directed to, and we do not knowingly collect personal information from, children under the age of 13. Users younger than 13 are strictly prohibited from creating an account or using this product. If we become aware that we have collected personal data from a child under 13, we will take immediate steps to delete such information.
Teen Accounts (Ages 13-17)
For users between the ages of 13 and 17 ("Teen Users"), we provide a tailored experience that requires parental or legal guardian oversight. Teen Users must have a verified parent or legal guardian to consent to certain feature usages within the product. Guardians of Teen Users hold the right to review, manage, and control the permissions and data associated with the Teen User’s account.
Data Residency and Storage
We are committed to keeping your data local. With the exception of login credentials, all personal data and content generated by a user is stored exclusively on servers located within the country of residency specified in the user’s profile information.
Global Authentication: To ensure you can access your account seamlessly from anywhere in the world, your basic login credentials (such as your username, email address, and cryptographically hashed password) are stored globally. This is strictly necessary to facilitate secure, worldwide authentication. All other personal profile data, usage data, and product-specific data remain strictly within your designated country of residence.
Administrative, Technical & Physical Safeguards
Beyond encryption, Norim Labs, Inc. maintains a broader set of safeguards designed to protect your health data and reasonably limit any incidental use or disclosure:
Administrative Safeguards: We restrict employee access to health data by role, require privacy and security training for anyone who may encounter it, and maintain a documented incident response process.
Technical Safeguards: We use end-to-end encryption, encryption at rest and in transit, secure authentication, and regular security audits, as described throughout this policy.
Physical Safeguards: We restrict physical and network access to the infrastructure that stores and processes health data to authorized personnel only.
Norim System Access & Model Training
Norim Labs, Inc. operates under strict boundaries regarding internal access to user data:
Processing and Model Training: Norim Labs, Inc. will only process or train models on your personal health data if you provide opt-in consent.
Zero Default Training: By default, your health data is never used to train machine learning models, algorithms, or system features without your affirmative, opt-in authorization.
Customer Support Access: Customer support representatives need your consent in order to view your personal data when helping with an issue.
Control and Revocation: If you choose to grant consent for system processing or feature training, you may withdraw your consent at any time in your account settings. Once withdrawn, your data will no longer be a part of any live model within a reasonable timeframe from revoking access.
Electronic Medical Records (EMRs)
EMR Ingestion, Encryption & Key Rotation
Norim Labs, Inc. may gather, sync, and store your Electronic Medical Records (EMRs) at your explicit request and direction (for example, when connecting to a healthcare provider or clinical portal).
Encryption at Rest: All ingested EMR data is encrypted both in transit and at rest using industry-standard cryptographic algorithms.
Restricted Read Access: Your EMR data is cryptographically protected and unreadable by Norim Labs, Inc. or any third party unless you provide explicit, affirmative consent for specific features or sharing workflows.
Encryption Key Rotation: Encryption keys protecting your EMR and health data can be regularly rotated—either automatically on a scheduled cryptographic lifecycle or manually upon user request (e.g., following a device reset, password update, or security event)—ensuring long-term data security without compromising access.
De-Identified Data
When Norim Labs, Inc. uses de-identified health data (for example, to improve product features), we remove or obscure identifying details so the information can no longer reasonably be linked back to you. We do not attempt to re-identify de-identified data, and if data is ever re-identified, we treat it with the same protections as your personal health data.
Periodic Consent Review
6-Month Consent Audit & Reminders
To ensure you retain complete control over who can access your health profile and how your data is used:
Periodic Reminders: Every six (6) months, Norim will prompt you to review all active data-sharing consents (including family/friends sharing permissions and optional system training opt-ins).
Easy Revocation: During this periodic review—or at any other time via your Norim account settings—you can modify, renew, or immediately revoke consent for any shared recipient or data-processing feature.
Consumer Health Personal Data We May Collect
In limited cases, Norim Labs, Inc. may process personal data to deliver services you explicitly request, which may constitute consumer health personal data:
Electronic Medical Records (EMRs): Clinical history, laboratory results, provider notes, and diagnostic records synced from healthcare networks at your direction.
Physical or Mental Health Metrics: Conditions, symptoms, vital signs, or diagnostics you choose to input or sync.
Bodily Measurements & Vital Signs: Sensor data (e.g., heart rate, activity levels) gathered by connected devices or integrated applications at your direction.
Ecosystem & Social Sharing Preferences: Information regarding your designated family and friends contacts, pending sharing invitations, and active data-sharing consents. Norim Labs, Inc. does not share any health records with family or friends without explicit consent and invitation acceptance from both parties.
Support Interactions: Information you voluntarily provide if you contact Norim Labs, Inc. Customer Support for assistance with health-related features.
Sources of Consumer Health Personal Data
Norim Labs, Inc. collects consumer health personal data:
Directly from you when you enter information or enable health tracking features.
From connected healthcare providers, EHR systems, connected hardware, or third-party apps integrated into the Norim platform at your explicit direction.
From other Norim users only when they send you an invitation to share health data and you choose to accept it.
How Norim Labs, Inc. Uses Consumer Health Personal Data
Norim Labs, Inc. uses consumer health personal data solely as necessary to operate the features you explicitly enable. This includes:
Powering interactive health dashboards, EMR management, and insights.
Facilitating authorized data sharing between you and accepted family/friends connections.
Communicating critical security or service updates regarding your account.
Norim Labs, Inc. does not sell your consumer health personal data.
How Norim Labs, Inc. Discloses Consumer Health Personal Data
Norim Labs, Inc. discloses health data only in the following controlled scenarios:
Family & Friends Sharing: Disclosed strictly to specific users you explicitly authorize via an invitation-and-acceptance flow.
Service Providers & Business Associates: Disclosed to verified service providers who process data strictly on our behalf under contractual confidentiality and security commitments that require them to safeguard your data, use it only for the purposes we authorize, notify us promptly of any security incident, and return or delete your data when the relationship ends. Where a connected healthcare provider or clinical portal requires it, these agreements meet HIPAA's business associate requirements.
Legal Requirements: Disclosed when required by applicable law, search warrant, or court order.
Your Rights & Controls
You retain full control over your consumer health personal data within the Norim ecosystem:
Invitation & Sharing Control: You choose whether to send or accept family/friends sharing requests. No data flows automatically without mutual consent.
System Access & Training Control: You decide whether your data may be processed or used for system training, with the ability to opt in or opt out at any time.
Key & Security Management: You maintain authority to trigger key rotation or update cryptographic credentials protecting your stored PHI (such as EMRs).
Revocation: You can revoke sharing access for any family member or friend at any time in your Norim settings.
Access, Correction, & Deletion: You have the right to request access to, correction or amendment of, or complete deletion of your personal health data held by Norim Labs, Inc.
Restriction Requests: You can ask us to further restrict how a specific piece of your health data is used or shared, and we will accommodate the request where feasible.
Accounting of Disclosures: You can request a record of certain disclosures of your health data made by Norim Labs, Inc.
Confidential Communications: You can request that we contact you about your health data through an alternative method.
Consent Withdrawal: Where sharing and processing relies on consent, you may withdraw it at any time.
Complaints & Non-Retaliation
If you believe your privacy rights have been violated, you can file a complaint with our Data Protection Officer using the contact information below. Norim Labs, Inc. will not retaliate against you, and will not condition your access to the Norim platform, for filing a complaint or exercising any right described in this policy.
HIPAA
Policy Adoption
Norim Labs, Inc. shall, in cooperation with relevant stakeholders, develop and adopt necessary and appropriate HIPAA Policies designed to comply with the HIPAA Privacy Rule. Norim Labs, Inc. shall implement, document, and update these policies and procedures as necessary to comply with changes in the law or its privacy practices, and shall retain such documentation in accordance with the Documentation and Retention section of this policy. All relevant Norim Labs, Inc. stakeholders shall cooperate in the development and implementation of the HIPAA Policies.
Privacy Officer
The Privacy Officer is responsible for the development and implementation of the HIPAA Policies and for the oversight of Norim Labs, Inc.’s privacy compliance program. The Privacy Officer may create, modify, or revise the HIPAA Policies as necessary to incorporate changes to the HIPAA Privacy Rule or to improve compliance.
The Privacy Officer is: Grace Haley, Member of Founding Team - Operations, privacy@norim.com.
Workforce Training
Norim Labs, Inc. trains all workforce members on its privacy and breach-notification policies and procedures as necessary and appropriate for them to carry out their functions, including new workforce members within a reasonable time after joining and existing workforce members whose functions are affected by a material change in the policies or procedures. Norim Labs, Inc. documents that training has been provided.
Safeguards
Norim Labs, Inc. has in place appropriate administrative, technical, and physical safeguards to protect the privacy of PHI in all forms and reasonably safeguards PHI to limit incidental uses and disclosures. These safeguards are implemented through Norim Labs, Inc.’s information security and data privacy policies and through operational practices that limit incidental disclosure of PHI.
Documentation and Retention
Norim Labs, Inc. maintains its HIPAA Policies and any required communications, actions, activities, or designations in written or electronic form, and retains such documentation for six years from the date of its creation or the date when it last was in effect, whichever is later.
Disciplinary Action
Failure to comply with any provision of this policy may result in disciplinary action, including, but not limited to, termination. Norim Labs, Inc. applies and documents appropriate sanctions against workforce members who fail to comply with its privacy policies and procedures or the Privacy Rule.
Reporting
All suspected violations or potential violations of this policy, no matter how seemingly insignificant, must promptly be reported to privacy@norim.com.
Contact & Privacy Questions
If you have questions regarding this Privacy Policy or privacy practices at Norim Labs, Inc., including how to exercise your privacy rights or trigger key rotations, please contact our Data Protection Officer at privacy@norim.com or through the Privacy & Security settings in your Norim app.