Norsk English

Privacy Policy

Last updated: February 2026

1. Introduction

This Privacy Policy describes how Nova ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the Nova app and related services (the "Service").

We are committed to protecting your privacy in accordance with:

2. What Personal Data We Collect

2.1 Information You Provide Directly

CategoryExamplesPurpose
Account InformationName, email, password (encrypted)Create and manage your account
Profile InformationProfile photo, bio, municipality, genderPersonalize service and trainer matching
Training GoalsGoals (strength, weight loss, etc.), experience levelRecommend suitable trainers and programs
CommunicationsMessages, images, audio files in chatEnable communication with trainer

2.2 Health-Related Information (Special Categories)

CategoryExamplesLegal Basis
Training DataExercises, weight, repetitions, durationConsent (GDPR Art. 9(2)(a))
Body MeasurementsWeight, height, body measurementsConsent (GDPR Art. 9(2)(a))
Progress PhotosPhotos to track physical changesConsent (GDPR Art. 9(2)(a))

2.3 Automatically Collected Information

We do NOT collect: GPS location, contact lists, call logs, or other data from your device without explicit consent.

3. Legal Basis for Processing

We process your personal data based on the following legal grounds (GDPR Article 6):

BasisApplication
Contract (Art. 6(1)(b))Deliver the service you registered for
Consent (Art. 6(1)(a))Health data, marketing, progress photos
Legitimate Interest (Art. 6(1)(f))Improve service, prevent fraud, security
Legal Obligation (Art. 6(1)(c))Retention per accounting and tax laws

4. How We Use Your Information

5. Sharing of Personal Data

5.1 Sharing with Trainers

When you connect with a personal trainer, the following is shared:

Progress photos are NOT shared with trainers unless you explicitly choose this.

5.2 Third-Party Providers (Data Processors)

ProviderPurposeLocation
Google FirebaseAuthentication, database, storageEU (eur3)
Google Cloud PlatformHosting and infrastructureEU
Stripe/RevenueCatPayment processingEU/USA (SCC)

All data processors are bound by Data Processing Agreements (DPA) per GDPR Article 28.

5.3 We NEVER Sell Your Data

Nova does not sell, rent, or trade your personal data to third parties for marketing purposes.

6. Storage and Security

6.1 Where Data is Stored

All personal data is stored on servers within the EU/EEA (Google Cloud, region eur3). For transfers outside EU/EEA, we use EU Commission Standard Contractual Clauses (SCC).

6.2 Security Measures

6.3 Retention Period

Data TypeRetention Period
Account InformationUntil account deletion + 30 days
Training HistoryUntil account deletion
Chat MessagesUntil you or the other party deletes the chat
Progress PhotosUntil you delete them
Payment Information5 years after last transaction (accounting law)

7. Your Rights

Under GDPR, you have the following rights:

How to Exercise Your Rights

We respond to all requests within 30 days.

8. Children

Nova is not intended for persons under 13 years of age. We do not knowingly collect personal data from children under 13. If you are between 13 and 16 years old, you need parental consent to use the Service.

9. Cookies

The Nova app does not use cookies. Our web application only uses necessary technical cookies for authentication and security.

10. Changes to Privacy Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you via email or in the app at least 30 days before the changes take effect.

11. Complaint to Supervisory Authority

If you believe we are processing your personal data in violation of regulations, you can file a complaint with the Norwegian Data Protection Authority:

12. Contact Us

For questions about this Privacy Policy or our processing of your personal data:

© 2026 Nova Fitness. All rights reserved.