Privacy
Privacy Policy
Effective from 25 August 2026.
This privacy policy explains how Seaglass Projects Ltd (“we”, “us”, “our”) collects, uses, stores, shares and protects your personal information when you use the Nova fertility companion mobile application and the Nova website (together, “Nova” or “the Service”). Nova is a fertility patient experience platform that helps people track treatment cycles, record their journey, connect with supporters, and review fertility clinics.
Nova processes health data — specifically, information about fertility treatment. Under UK data protection law this is special category data. Under Australian law it is sensitive information. Under Washington State law it is consumer health data. We treat all of it at the highest level of protection, regardless of where you are.
Data controller: Seaglass Projects Ltd, registered in England and Wales (company number 17396371), registered office 16 Eastchurch, Margate, CT9 3EN, United Kingdom. You can reach us at privacy@heynova.org.
1. What we collect and why
We collect only what is needed to provide and improve Nova. We do not collect data for advertising or sale to third parties. We have no advertising SDKs and no third-party trackers in the app. We collect limited, anonymised usage analytics to improve the app’s design — these are never joined with your health data. See section 1.2 for details.
1.1 Information you provide directly
| Data | Purpose | Lawful basis (UK GDPR) |
|---|---|---|
| Name, email address | Account creation, communication | Contract (Art. 6(1)(b)) |
| Treatment protocol (e.g. IVF, FET, egg freezing, IUI) | Personalise your experience to your treatment type | Explicit consent (Art. 9(2)(a)) |
| Cycle dates, stages, outcomes, donor arrangement, transfer details | Track your current and past treatment cycles | Explicit consent (Art. 9(2)(a)) |
| Medications: drug name, dose, form, injection site, schedules, dose tracking | Medication management and reminders | Explicit consent (Art. 9(2)(a)) |
| Appointments: dates, times, clinic locations, attendance, notes | Appointment tracking | Explicit consent (Art. 9(2)(a)) |
| Treatment milestones: trigger, transfer, progesterone timing and instructions | Track key treatment dates and changes | Explicit consent (Art. 9(2)(a)) |
| Treatment events: stage moves, results (e.g. blood test results, scan results) | Record and review treatment progress | Explicit consent (Art. 9(2)(a)) |
| Journal entries: mood, symptoms, free-text personal writing | Private reflective journalling | Explicit consent (Art. 9(2)(a)) |
| Symptoms | Track physical symptoms during treatment | Explicit consent (Art. 9(2)(a)) |
| Embryo records: grade, PGT result, storage location, renewal date | Manage embryo bank across cycles | Explicit consent (Art. 9(2)(a)) |
| Egg batches: counts, maturity, method, age at freezing, storage, consent dates | Manage frozen egg inventory | Explicit consent (Art. 9(2)(a)) |
| Clinic contact details (phone, email) | Your personal reference | Contract (Art. 6(1)(b)) |
| Clinic call and result notes | Your personal reference | Explicit consent (Art. 9(2)(a)) |
| Clinic reviews: ratings across dimensions, treatment type, outcome, free-text comments | Publish clinic reviews to help other patients | Explicit consent (Art. 9(2)(a)) |
| Support network: who you invite and what categories you share with them | Allow chosen people to follow parts of your treatment | Contract (Art. 6(1)(b)) |
| Display name you choose | Publish your review under a name you choose, and your community posts when those features open | Consent (Art. 6(1)(a)) |
1.2 Information we generate or collect automatically
| Data | Purpose | Lawful basis (UK GDPR) |
|---|---|---|
| Push notification subscription (device endpoint, encryption keys) | Deliver medication reminders you have enabled | Consent (Art. 6(1)(a)) |
| Timezone | Schedule reminders at the correct local time | Legitimate interest (Art. 6(1)(f)) |
| Security events (connect, disconnect, rate-limit events) | Protect your account from unauthorised access | Legitimate interest (Art. 6(1)(f)) |
| Deletion receipts (table names and row counts only, never content) | Prove that account deletion was carried out completely | Legal obligation (Art. 6(1)(c)) |
| Invite codes (multiple per account) | Enable partner linking | Contract (Art. 6(1)(b)) |
| Rate-limit records | Prevent abuse of the linking system | Legitimate interest (Art. 6(1)(f)) |
| App usage patterns: screens visited, time spent, feature interactions, drop-off points. Never joined with your health or treatment data. Collection is off by default; you choose whether to enable it. | Understand how people use Nova so we can improve its design and usability | Explicit consent (Art. 9(2)(a)) |
1.3 What we deliberately do not collect
- Date of birth, home address, phone number or national health identifier (e.g. NHS number, Medicare number)
- Payment card or bank details (payments are handled entirely by Apple or Google as merchant of record)
- Precise geolocation — we do not access your device’s GPS or location services
- Device identifiers beyond a push notification endpoint
- Third-party analytics services (e.g. Google Analytics, Mixpanel), advertising SDKs, or cross-app tracking of any kind. The anonymous usage patterns we collect (section 1.2) are processed entirely within our own infrastructure and are never shared with third parties.
- Cookies (the app does not use cookies)
2. How we use your data
We use your data for the following purposes and no others:
- To provide the Nova service: tracking your treatment cycle, managing medications, recording results, and displaying your journey
- To deliver discreet reminders you have opted into (medication reminders via push notification)
- To enable your chosen supporters to see the categories of information you have explicitly shared with them
- To publish clinic reviews you have submitted
- To display aggregated clinic scores (individual reviews are attributed to a name you choose, or to no name at all)
- To understand how people use Nova in aggregate (e.g. which features are used most, where users encounter difficulty) so we can improve the app — only if you have opted in to share usage data in Settings. This analysis uses anonymous usage patterns only and is never combined with your health data.
- To produce anonymised, aggregated statistical reports about platform-wide trends (e.g. treatment-type distributions, cycle progression rates). These reports contain no individual-level data and can never identify any individual. No statistic is produced from fewer than 5 data points.
- To protect account security (detecting and rate-limiting abuse)
- To comply with legal obligations (e.g. responding to data access requests, maintaining deletion records)
We do not use your data for: serving you advertising, profiling you for third-party marketing, automated decision-making, or training machine learning models. We never sell or share your individual personal data with third parties.
3. Who we share your data with
We share your data only with the following parties, and only to the extent necessary to operate Nova:
| Recipient | What they receive | Why |
|---|---|---|
| Supabase (database and hosting provider, a subsidiary of Supabase Inc.) | All data stored in Nova and server-side functions. Supabase processes data on our behalf under a data processing agreement. | Database hosting, authentication |
| Browser push service (Google FCM, Mozilla Push Service, or Apple Push Notification Service) | Encrypted notification payload and device endpoint | Delivering medication reminders you have enabled. The payload is encrypted end-to-end; the push service cannot read the reminder content. |
| Google or Apple (if you use social sign-in) | Your email address | Authentication only. We receive a token confirming your identity; no health data is shared with Google or Apple through sign-in. |
| Your chosen supporters | Only the specific categories you have enabled (e.g. medications, appointments) — never journal entries, which have no sharing toggle and cannot be shared | The support network feature you control. You can revoke access at any time. |
| Healthcare organisations, researchers, or fertility industry partners | Anonymised, aggregated statistics only — never individual-level data, never data derived from fewer than 5 data points | To support fertility research and improve industry understanding of patient experience. No recipient can identify any individual from these reports. |
We do not sell your personal data. We have never sold any individual’s personal data and will never do so. We do not share data with advertisers or data brokers. We may produce anonymised, aggregated statistical reports about platform-wide trends and make these available to healthcare organisations, researchers, or fertility industry partners. These reports contain only aggregate numbers (e.g. average cycle counts, treatment-type distributions) and can never identify any individual user.
4. Where your data is stored
Your data is stored on Supabase’s infrastructure, which runs on Amazon Web Services (AWS). The specific region is eu-north-1 (Stockholm, EU). Data is encrypted at rest using AES-256 encryption and in transit using TLS 1.2 or higher.
Cross-border transfers. Supabase Inc. is headquartered in the United States. Where data is processed outside the UK or Australia, it is protected by standard contractual clauses (UK International Data Transfer Agreement) and Supabase’s data processing agreement, ensuring a level of protection equivalent to UK GDPR and the Australian Privacy Principles. Under the Australian Privacy Principles (APP 8), we take reasonable steps to ensure overseas recipients handle your data in accordance with the APPs, and we remain accountable for their compliance.
5. How we protect your data
Given the sensitivity of fertility treatment data, we apply the following safeguards:
- Row-level security on every database table — your data is isolated to your account at the database level, not just the application level
- Encryption at rest (AES-256) and in transit (TLS)
- Journal entries have no sharing category and cannot be shared through any setting — there is no toggle to get wrong
- Medication reminders are discreet by default: the notification says “You have something due” without naming the medication. Detailed notifications are opt-in.
- Error logs carry no row data — an error records the shape of the problem, never the content, so health information cannot leak into logs
- Deletion receipts hold counts and table names only, never the content of deleted records
- Security events (account linking, rate limiting) contain no health information — this is verified by automated tests
- Partner access is granular and default-off: each sharing category (medications, appointments, cycle updates, mood) must be individually enabled by the patient
- The service-role database key is never exposed to the browser — all client access uses the anon key with row-level security enforcement
- Usage analytics are stored in a separate schema with no foreign key to treatment data, ensuring they cannot be joined with health information by construction
- If we produce anonymised aggregate reports, the anonymisation process is irreversible — individual records cannot be reconstructed from the published statistics. Reports are never generated from cohorts smaller than 5 to prevent re-identification through small sample sizes.
6. How long we keep your data
We retain your data for as long as your account is active. Treatment journey records (past cycles, embryo records, egg batches) are retained indefinitely while your account exists because their value to you grows over time — fertility treatment can span years, and a complete history is clinically useful.
When you delete your account, we delete all of your data. This is not an archive or a soft delete — it is a real, cascading deletion across every table. Specifically:
- All treatment records (cycles, medications, schedules, doses, appointments, milestones, events, journal entries, symptoms, embryos, egg batches, clinic contacts, clinic logs) are permanently deleted
- Your authentication identity is deleted — you cannot sign back in
- Any active partner links are severed — your supporter immediately loses access
- Push notification subscriptions are removed
- A deletion receipt is created recording that the deletion occurred, which tables were affected, and how many rows were removed. The receipt contains counts only, never the content of what was deleted
- Your individual usage analytics events are permanently deleted. Any anonymised, aggregated statistics that were already computed from platform-wide data are retained — these contain no record of any individual and cannot be traced back to you.
- Clinic reviews you have written are deleted, published or not. Clinic scores are recalculated without them.
- Any display name used for writing reviews or taking part in the community is deleted.
Backups. Supabase maintains automated database backups for disaster recovery. Deleted data may persist in backups for up to 7 days before those backups are rotated out. We do not access backups to retrieve deleted data, and we will not restore deleted data on request.
7. Your rights
You have the following rights regardless of where you are located. Where a specific law grants additional rights, those are noted.
7.1 Rights available to all users
- Access: You can request a copy of all personal data we hold about you.
- Correction: You can correct inaccurate personal data at any time through the app, or by contacting us.
- Deletion: You can delete your account and all associated data at any time from within the app. Deletion is immediate and permanent. You can also request deletion by contacting us.
- Withdraw consent: Where processing is based on your consent (which includes all health data processing in Nova), you can withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. The simplest way to withdraw consent for all health data processing is to delete your account.
- Data portability: You can export your data in a machine-readable format from within the app.
- Usage analytics: Usage data collection is off by default. You can enable it in Settings to help us improve Nova, and disable it again at any time. This does not affect any other part of the service.
7.2 Additional rights under UK GDPR
- Right to restrict processing: You can request that we limit how we use your data in certain circumstances.
- Right to object: Where processing is based on legitimate interest, you can object. We will stop processing unless we have compelling legitimate grounds.
- Right to complain: You can lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.
7.3 Additional rights under the Australian Privacy Act
- Access and correction: Under APPs 12 and 13, you can request access to your personal information and ask us to correct it. We will respond within 30 days.
- Right to complain: You can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
7.4 How to exercise your rights
You can exercise most rights directly in the app (account deletion, data export, sharing controls, usage analytics toggle). For anything you cannot do in the app, email us at privacy@heynova.org. We will verify your identity before acting on a request. We will respond:
- UK: within one month. We may extend this by up to two further months if the request is complex or if you have made several; we will tell you within the first month if we need longer.
- Australia: within 30 days.
- Washington State: within 45 days, extendable once by a further 45 days.
If a request is manifestly unfounded or excessive — for example, because it repeats one we have already answered — we may charge a reasonable fee based on our administrative costs, or decline to act. We will explain why and tell you how to complain. If you ask for further copies of information we have already given you, we may charge a reasonable fee for those copies.
8. Consent
Because Nova processes special category health data, we rely on your explicit consent as the lawful basis for processing fertility treatment information under UK GDPR Article 9(2)(a). Under the Australian Privacy Act, we obtain express consent before collecting sensitive information (APP 3).
You provide consent when you create an account and enter your treatment information. Consent is:
- Informed — you have read this policy and understand what data is collected and why
- Specific — consent applies to the purposes stated in this policy and no others
- Freely given — use of Nova is voluntary
- Unambiguous — you take an affirmative action (entering data) to provide it
You may withdraw consent at any time by deleting your account or by contacting us. If we wish to collect or use your data for any new purpose not described in this policy, we will seek your consent before doing so.
Anonymised, aggregated statistical reports are derived from data that has been irreversibly anonymised and do not constitute personal data. The production of such reports does not require individual consent. Usage data collection is off by default; if you have enabled it, you can disable it again at any time in Settings or by contacting us at privacy@heynova.org.
9. Children
Nova is for people aged 18 and over. When you create an account you confirm that you are 18 or over. We do not verify age beyond that declaration.
We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us personal data, email privacy@heynova.org and we will delete it. We will confirm once we have.
10. Clinic reviews
When you submit a clinic review you are choosing to publish your assessment of a clinic’s care. Reviews are rated across six dimensions — communication, waiting times, cost transparency, feeling informed, dignity and respect, emotional support — each scored from 1 to 5.
Your treatment outcome is not part of the calculation. A clinic’s score is the average of your six ratings. We do not incorporate your treatment outcomes into the clinic’s overall score. You can choose to have your treatment outcome published alongside your review, which will also allow a clinic’s reviews and scores to be broken down by outcome once a category has enough reviews. You may also decide not to publish your treatment outcome.
You choose whether your review carries a name. You can publish a review under a display name you choose, or with no name at all, and you decide separately for each review. We never publish your email address or your treatment profile. Your review shows the information you provide in the review submission flow — the treatment type, the year of treatment, your six ratings, your title, what you wrote, the outcome where you chose to publish it, and, if you recorded a cycle at that clinic in Nova, a badge reading Tracked in Nova. That badge is not verification: we have not checked the record with the clinic, and the sentence saying so is published beneath every review that carries it. We hold a link between your account and your review internally, so that you can edit or withdraw it and so we can act if someone reports it. That link is never published.
A display name also links your reviews to each other: somebody reading one can find the others you have published under the same name.
Your written review is published in full on the Nova website and in the app, and search engines can find it. Please write about your own care. Anything you write about somebody else, such as a partner, a donor or a child, is published too. Leave out their names, dates and anything else that would identify them, and please do not identify a donor. This applies to your outcome as well: if you write about the outcome in your review body, it will be published as part of the review, regardless of what you chose for the outcome question.
A person reads every review before it appears. We may ask you to change something, or decline to publish. Every published review carries a link to report it and a link to our moderation policy, and the clinic is always given a right of reply, shown directly beneath the review it answers. You can edit your review for 30 days after it is published, and withdraw it at any time.
Small samples are suppressed. A clinic’s headline score is not published until it has at least 5 moderated reviews, and an outcome breakdown is not published until that category has at least 8 moderated reviews. Below the threshold, reviews will not be published.
11. Support network and data sharing
Nova allows you to invite supporters (partners, family members, friends) to follow parts of your treatment. Sharing is controlled entirely by you:
- Each sharing category (including medications, appointments, cycle updates, doses, mood/today) must be individually enabled
- All categories default to off until you toggle them on to share
- Journal entries cannot be shared — there is no sharing category for them
- You can revoke a supporter’s access at any time, and it takes effect immediately
- If you delete your account, all supporter access is severed immediately
Supporters see only what you have explicitly chosen to share. They cannot see your full profile, your journal, your embryo records, your egg batches, or any category you have not enabled.
12. Push notifications and reminders
If you enable medication reminders, we store a push notification subscription (device endpoint and encryption keys) so we can deliver reminders when the app is closed. Reminders are:
- Opt-in only — they are never enabled by default
- Discreet by default — the notification says “You have something due” without naming the medication
- Detailed notifications (showing the medication name) are available but require you to opt in separately
- You can disable reminders at any time, and we immediately mark the subscription as revoked
Reminder delivery records note whether a reminder was sent, failed or skipped, and why. They never contain the name of a medication or the content of the reminder — a record refers to your medication by an internal reference, and the reason is an operational code such as “already sent” or “no device accepted”. Only you can see your own delivery records.
13. Data breaches
In the event of a personal data breach that poses a risk to your rights, we will:
- Notify the ICO within 72 hours of becoming aware of the breach (UK GDPR)
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights
- Notify the OAIC as soon as practicable where the breach is likely to result in serious harm (Australian Notifiable Data Breaches scheme)
- Take immediate steps to contain and remediate the breach
14. Changes to this policy
We will update this policy if our data practices change. If we make material changes — particularly any change to the categories of data we collect, who we share data with, or the purposes of processing — we will notify you within the app before the changes take effect and, where required, seek your renewed consent.
The effective date at the top of this policy reflects the most recent revision.
15. Contact us
If you have any questions about this privacy policy, want to exercise your rights, or have a complaint about how we handle your data:
Email: privacy@heynova.org
Post: Seaglass Projects Ltd, 16 Eastchurch, Margate, CT9 3EN, United Kingdom
If we have not resolved your concern, you have the right to complain to your local supervisory authority:
- UK: Information Commissioner’s Office (ICO) — ico.org.uk
- Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
Terms of use · Medical information disclaimer · Delete your account · support@heynova.org