Privacy Policy for NOWvigation
Last Updated: April 2026
Introduction
This Privacy Policy describes how Smart ID Software Solutions Ltd. (hereinafter "we," "us," or the "Company") collects, uses, retains, and protects information relating to you in connection with your use of the NOWvigation application and related services (the "Application").
Your privacy is important to us, and we are committed to full transparency regarding the manner in which we handle your information. This document constitutes an integral part of the Application's Terms of Use, and use of the Application constitutes your consent to the collection and processing of information as described herein.
If you do not agree to the terms of this policy, you are not permitted to use the Application.
1. Nature of the Application and Information Collection
The Application enables its users to learn and practice meditation and mindfulness independently, by means of a unique methodology involving thumb movement on the device screen synchronized with the user's natural breathing. As part of your use of the Application, we collect various data in order to enable its functionality and present personalized analyses to the user.
Unlike conventional meditation applications, this Application performs the collection and analysis of thumb movement patterns that represent the user's breathing patterns. Such data constitutes physiological-behavioral information, and we afford it a high level of protection.
2. Categories of Information We Collect
2.1 Information You Provide Voluntarily
Account details: username, email address, and password (the password is stored in encrypted form).
Optional details: age and gender, if you choose to provide them. Such details are not mandatory and are not a condition for use of the Application; however, providing them enables better personalization of analyses.
Information from third parties: should you choose to register or log in to the Application through external platforms (such as Facebook or Google), we may receive basic details from them such as name and email address, in accordance with the privacy settings you have selected on those platforms.
Your communications with us: any message, inquiry, or feedback that you transmit to us through email or other communication channels.
2.2 Information Collected Automatically During Practice
The core activity of the Application is based on real-time collection of practice data. During each meditation session, we collect the following data:
Thumb movement data: position coordinates (X, Y) on the device screen and precise timing data, collected several times per second during practice.
Calculated breathing patterns: inhalation timing, exhalation timing, and inter-breath pause timing, derived from thumb movement.
Calculated metrics: breathing rate, rate stability, inhalation-to-exhalation ratio, pause durations, and additional metrics calculated algorithmically from the raw data.
Session data: practice start time, practice duration, number of practice sessions, interruption events or attention drift events during practice.
Personalized analyses: reports and analyses produced based on your practice data, by means of internal algorithms and/or third-party artificial intelligence services.
2.3 Automatic Technical Information
Usage data: Application login times, session durations, features used, and screens visited.
Device information: device type, operating system, Application version, screen resolution.
Technological identifiers: IP address, unique device identifier for purposes of malfunction diagnosis and usage analysis.
Cookies and similar technologies: insofar as a web interface is in use, cookies may be utilized to improve user experience. Cookies may be blocked through browser settings; however, such blocking may impair certain functions of the Application.
3. Purposes of Data Processing
We use the information we collect for the following purposes only:
3.1 Operation of the Application and Provision of Service
Ongoing operation and maintenance of the Application.
Calculation of personal metrics from your practice data.
Display of personalized analyses, practice history, and progress trends.
Personalization of recommendations and analyses to your individual breathing profile.
Management of your account in the Application.
3.2 Improvement and Development of the Application
Aggregate statistical analyses of usage patterns in order to improve the Application's algorithms. Such analyses are conducted on aggregated data that does not identify individual users.
Verification of Application functionality, identification and resolution of malfunctions.
Development of new features and adaptation of the Application to user preferences.
3.3 Communications With You
Sending operational messages relating to your account, such as registration confirmation, password reset, and security updates.
Notifications of material changes to the Application, the Terms of Use, or this Privacy Policy.
Response to inquiries and technical support.
Sending of marketing content, to the extent you have consented thereto, in accordance with applicable law.
3.4 Safety, Security, and Legal Compliance
Protection of the security of the Application and its users.
Prevention of fraud, malicious activity, or breaches of the Terms of Use.
Protection of our legal rights and the rights of third parties.
Compliance with legal, regulatory, and judicial obligations.
4. Use of Third-Party Artificial Intelligence Services
The Application makes use of artificial intelligence services provided by Anthropic, the developer of the Claude model, for the purpose of producing advanced analyses of your breathing and practice patterns. When such an analysis is performed:
Processed data of your breathing patterns and practice is transmitted to Anthropic, without complete personally identifying details (for example, without your full name or email address).
Anthropic processes the data and returns the analysis result to us.
In accordance with Anthropic's policy as of the date of update of this document, Anthropic does not use API data for the purpose of training models; however, it may temporarily retain the data for purposes of service provision, malfunction diagnosis, and compliance with legal obligations.
Anthropic's full privacy policy is available at: https://www.anthropic.com/privacy
The use of Anthropic's services is necessary for the functioning of certain advanced features of the Application. To the extent that you do not consent to the processing of your data by Anthropic, please refrain from using such features. We are working on providing more granular control over the transfer of data to third parties in future updates of the Application.
5. Research Use of Anonymized Data
We believe in the advancement of scientific knowledge in the field of meditation and contemplative health. To this end, we may collaborate with academic research institutions by sharing anonymized data from the Application.
5.1 The Anonymization Process
Prior to sharing data for research purposes, we conduct a complete anonymization process that includes:
Complete removal of personally identifying details: name, email address, password, user identifiers, and device identifiers.
Obfuscation of details that may enable identification: precise age is converted to an age range, and precise timestamps are converted to date only.
Creation of a new anonymous identifier that cannot be reversed back to the original identity.
Complete deletion of any link between the anonymized data and the original account.
5.2 Conditions for Sharing With Research Institutions
Research data shall be transferred only in cases where all of the following conditions are met:
The collaboration is with a recognized research institution (university, public research institute, or similar academic institution).
A formal Data Sharing Agreement has been concluded, defining the purpose of use, its scope, and limitations.
The research institution undertakes not to attempt to identify users from the data.
The collaboration has been approved by the ethics committee (IRB) of the research institution.
The data shall be retained by the researchers in accordance with accepted security protections.
5.3 Your Right to Decline Research Use
Even where data is fully anonymized, we respect your right to choose not to be included in research collaborations. The option "Do not include my data in academic research" may be activated through the account settings at any time.
Activation of this option shall not impair your regular use of the Application.
5.4 Transparency Regarding Collaborations
We are committed to transparency regarding research collaborations. An updated list of active collaborations shall be displayed on the Application's website, and any research publication based on data from the Application shall be referenced on the website.
6. Sharing of Information With Third Parties
We do not sell, lease, or trade in personal data of users. We share information with third parties only in the limited cases set forth below:
5.1 Essential Service Providers
We work with limited service providers who provide us with infrastructure for the operation of the Application:
Amazon Web Services (AWS): our information is stored on the cloud infrastructure of AWS, in a server region in Europe. AWS is committed to high security standards, and an appropriate data processing agreement has been concluded with it.
Anthropic: as described in Section 4 above, for the purpose of producing advanced analyses.
Additional operational service providers: such as systems for managing communications and customer service, to the extent operated in the future.
These providers are bound by appropriate agreements to process the information solely for the purpose of providing the service for us, and to maintain the security and privacy of the information.
5.2 Legal Obligations and Investigations
We may disclose information if we believe in good faith that doing so is necessary in order to:
Comply with provisions of law, judicial order, or binding regulatory requirement.
Protect our rights, property, or safety, or those of other users or the public.
Prevent fraud, criminal activity, or material breaches of the Terms of Use.
Enforce the Terms of Use or other agreements concluded with users.
5.3 Change of Control of the Company
In the event of a merger, acquisition, sale of assets, or liquidation proceeding of the Company, information regarding users may be transferred to the receiving entity. In any such case, we shall notify users and shall ensure that the receiving entity is bound by privacy terms no less protective than the terms set forth in this document.
7. Information Security
The security of your information is a high priority for us. We employ reasonable technical and organizational security measures in accordance with accepted standards, including:
Encryption at rest: all personal data is stored in encrypted form in our database.
Encryption in transit: all information transmitted between the Application and our servers is encrypted by means of TLS/SSL protocols.
Access control: access to personal information is limited to authorized personnel only, on a "need-to-know" basis.
Monitoring and supervision: we conduct ongoing monitoring of our systems for the detection of unusual activity.
Environment separation: development and production environments are separated, and development environments do not contain actual personal data.
Automated backups: periodic encrypted backups of the information are performed.
Notwithstanding the foregoing, it is important to know that no system is entirely immune from intrusion. You acknowledge and accept the risk inherent in the transmission of information over the Internet, and we cannot absolutely guarantee the security of the information.
In the event of a material security breach having implications for your privacy, we shall notify you thereof as soon as practicable, in accordance with applicable law.
8. Data Retention Period
We retain your information for as long as your account is active in the Application. Retention periods vary in accordance with the type of information:
Account data and personal information: for as long as your account is active. Upon deletion of the account, the information shall be deleted within 30 days.
Practice data and breathing patterns: for as long as your account is active. Deletion may be requested without account deletion.
Aggregate and anonymous data: may be retained for a longer period for purposes of improving the Application, regardless of account deletion.
Information we are required to retain by law (such as for tax purposes, transaction proof, or legal proceedings): shall be retained for the period required by law.
In any case of deletion, we act for the secure deletion of the information from all of our systems, including from backups, within a reasonable period of time.
9. Your Rights Regarding Information
In accordance with applicable privacy protection laws, you have various rights regarding your information. We respect all such rights and act to enable you to exercise them with ease:
8.1 Right of Access
You are entitled to receive confirmation from us as to whether we are processing personal information regarding you, and if so, to obtain access to the information and additional details on the manner of its processing.
8.2 Right of Rectification
You are entitled to request the correction of inaccurate or incomplete information relating to you.
8.3 Right of Erasure
You are entitled to request the deletion of your personal information, as well as the complete deletion of your account. A deletion request shall be executed within 30 days, except for information that we are required to retain by law.
8.4 Right of Restriction
You are entitled to request the restriction of processing of your information in certain situations, for example when you contest the accuracy of the information.
8.5 Right to Data Portability
You are entitled to receive the information you have provided to us in a structured, commonly used, and machine-readable format, and to request its transfer directly to another entity insofar as technically feasible.
8.6 Right to Object and to Withdraw Consent
You are entitled to object to the processing of your information in certain circumstances, and to withdraw your consent to processing at any time. Withdrawal of consent shall not affect the lawfulness of processing performed prior to withdrawal.
8.7 Right to Lodge a Complaint
To the extent you believe that our processing of information does not comply with the provisions of law, you are entitled to lodge a complaint with the Privacy Protection Authority in Israel or with a corresponding authority in your country.
8.8 How to Exercise Your Rights
You may contact us at nowvigation@gmail.com for the purpose of exercising any of these rights. We shall endeavor to respond to all inquiries within 30 days. We may need to verify your identity before performing certain actions.
10. Transfer of Information Outside Israel
The Application stores information with service providers operating primarily in Europe (AWS in the Frankfurt region). When using Anthropic's services, certain information may also be processed on servers in the United States.
Transfer of information outside Israel is conducted in accordance with the privacy protection regulations, and appropriate agreements have been concluded with the providers ensuring an adequate level of protection of the information.
11. Third-Party Services and External Links
The Application may contain links to websites or services of third parties. This Privacy Policy does not apply to such websites or services, and we recommend reviewing their privacy policies separately. We do not bear responsibility for the manner in which third parties handle your information.
12. Minors and Family Use
The Application is intended for users aged 18 years and above. The account in the Application shall be opened only by an adult, who shall be the contracting party with the Application and shall bear responsibility for any action related to such account.
Parents and legal guardians may use the Application together with their minor children, as part of joint family practice. In such case, the account shall remain registered in the name of the adult, who shall be responsible for all information collected under such account and for consent to its processing.
We do not knowingly collect information directly from users under the age of 18, and we do not maintain separate accounts for minors. To the extent we become aware that a minor has independently opened an account in violation of the Terms of Use, we shall delete the account and information immediately.
If you are a parent or guardian and have discovered that a minor in your custody has independently opened an account or provided information without your permission, please contact us and we shall address the matter promptly.
12.1 "Practice With Child" Mode
The Application offers a special mode that enables a minor child to experience practice under the parent's account, without any personal information being collected about them.
In this mode, the Application does not collect or retain the child's practice data:
The child's thumb movements are not retained.
Breathing patterns are not calculated or retained.
No data is transmitted to Anthropic or any third party.
No artificial intelligence analyses are performed.
No metrics, analyses, or history are displayed.
The only information retained in this mode is an anonymous record of the practice session itself, including:
A randomly generated unique identifier created for the practice session, having no link to the account or user identifier.
The date and time of the practice session.
The duration of the practice session.
This record cannot be linked to a specific account, a specific user, or to the identity of the child. It is used solely for purposes of operational statistics of the Application (such as: how many child practice sessions were conducted on a given day). The bell function, activated if the finger does not move for a certain period of time, is performed locally on the device and does not involve any collection or transmission of information.
13. Changes to the Privacy Policy
We may update this Privacy Policy from time to time in order to reflect changes in our activities, in law, or in technology. In the event of a material change, we shall notify you thereof by means of a notice in the Application or by email, prior to the entry into force of the change. Continued use of the Application following an update of the policy shall constitute your consent to the updated terms.
It is recommended to periodically review the Privacy Policy available on the website and in the application stores.
14. Contact Us
For any question, request, complaint, or for the exercise of your rights pursuant to this Privacy Policy, you may contact us by means of the following:
Email: nowvigation@gmail.com
Smart ID Software Solutions Ltd.
We shall endeavor to respond to all inquiries within a reasonable time and in any event within 30 days from receipt of the inquiry.
15. Governing Law and Jurisdiction
This Privacy Policy is subject to the laws of the State of Israel. Exclusive jurisdiction in any dispute relating to this policy shall be vested in the competent courts of the Central District in Israel.
