noesa

noesa Mobile App Privacy Policy

Policy for the processing of personal data and information in the mobile application noesa

Revision dated July 24, 2026

This document describes the features of processing personal data and other information when using the noesa mobile application for iOS and Android.

Unless otherwise expressly stated in this document, the terms “Operator”, “Company”, “Service”, “User”, “Account”, “Personal Data”, “Personal Data Processing” are used in the meanings defined by the Personal Data and Information Processing Policy noesa and the User Agreement for the use of the service “NOESA”.

In the part directly governing the mobile application, this Policy applies as a special policy. For all issues that are not regulated by this Policy, the main Policy for the processing of personal data and information noesa applies.

1. General provisions

This document defines the specifics of the policy of Individual Entrepreneur Artur Aramovich Berudzhanyan, OGRNIP: 326774600057471, INN: 773771872612, commercial designation “Noesa” (hereinafter referred to as the “Operator”), regarding the processing and confidentiality of personal data and other information of Users of the mobile application noesa.

The mobile application provides the User with access to its functions through a mobile device. All functions of the current version of the application for iOS are provided under the same conditions to all users; Payment data is not collected through the iOS application.

This Policy has been developed in addition to the main Policy for the processing of personal data and information noesa and is applied taking into account the requirements of the Federal Law of the Russian Federation of July 27, 2006 No. 152-FZ “On Personal Data”, other applicable regulations, as well as the rules of the application distribution platforms App Store and Google Play in the part applicable to mobile application.

This Policy applies to personal data processing operations performed by the Operator when using the mobile application, including data provided by the User, data generated when using the mobile application, as well as data necessary for synchronizing the mobile application with the Service.

Ensuring unrestricted access to this Policy is achieved by publishing it at https://api.noesa.ai/legal/mobile/privacy.

2. Basic terms

Personal data (PD) - any information relating to a directly or indirectly identified or identifiable individual.

Processing of personal data - actions (operations) with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, changing), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion and destruction.

Mobile application - software noesa for iOS and Android, through which the User gains access to the functions of the Service.

Push token / device token - a technical identifier of a mobile device or application used to deliver push notifications, calendar reminders and proactive notifications of the Service, if the User has allowed such notifications.

All other terms are interpreted in accordance with the main Policy for the processing of personal data and information noesa, the User Agreement and the current legislation of the Russian Federation.

3. Processing of personal data in the mobile application

### 3.1. Categories of processed data

When using the mobile application, the Operator can process the following categories of personal and other data if they are provided by the User, are generated when using the mobile application or are necessary for the operation of the Service:

1. Account data: email address, name or display name, User ID, login from the Service’s personal account, information about access status, available limits and limit usage history.

2. User content: diary entries, chat messages, calendar events, trackers, tasks, notes, photos, videos, audio, files, attachments, generated content, analytical findings and other materials that the User independently adds to the Service or receives using the Service.

3. Technical data: IP address, information about the mobile device, operating system, application version, language, time zone, technical session identifiers, error information, diagnostic events, downloaded files, videos, tools and other User activity when using the mobile application.

4. Device permission data: information about granting or denying access to the camera, microphone, media library, files, notifications and other system capabilities of the device. The access itself is used only after the User has acted or enabled the corresponding function.

5. Notification data: push tokens / device tokens, notification settings, information about notification delivery, if such information is technically available. This data is used for calendar reminders, proactive Service notifications, as well as service and technical notifications.

6. Integration data: information about connected integrations, external files, calendar reminders, Telegram bot or other functions, if the User independently enables such functions.

7. Access data: information about the current status of the User’s access to the functions of the Service and available limits. The mobile application does not store bank card data.

### 3.2. Purposes, legal basis and processing times

The operator processes personal data in the mobile application for the purposes provided for in the main Policy for the processing of personal data and information noesa, including:

1. Providing the opportunity to use the products, works and services of the Operator, including access to the Service through a mobile application.

Category of subjects: Service User.

PD category: general/other.

List of PD: email address, login from the Service, IP address, technical data of the device and application, Account data, access status information.

Processing time: period of validity of the contract; 5 years after the expiration of the contract; before the withdrawal of consent to processing, if the data is processed on the basis of consent.

Type of processing: mixed.

Legal basis: execution of a contract to which the subject is a party/beneficiary; consent of the subject to the processing of personal data; legitimate interest of the Operator.

2. Identification, registration, authorization and protection of the User Account.

List of PD: email address, protected password, User ID, technical session data, information about logins and actions in the Account.

Processing terms: period of use of the Account; terms necessary to ensure safety, fulfillment of the contract and compliance with legal requirements.

Type of processing: mixed.

Legal basis: execution of the contract; legitimate interest of the Operator; compliance with legal requirements.

3. Operation of the functions of the mobile application and the Service: diary, chat, calendar, trackers, analytics, attachments, voice input, content generation, file processing and other functions noesa.

List of PD: user content, technical data, device permission data, integration data and other data necessary to perform the corresponding function.

Processing terms: period of use of the Account; until the relevant data is deleted by the User; until the purpose of processing is achieved or there is no longer any need to achieve such a purpose.

Type of processing: mixed.

Legal basis: execution of the contract; consent of the subject to the processing of personal data; legitimate interest of the Operator.

4. Processing of User requests using artificial intelligence technologies, including analysis of text, images, files, audio and other data that the User transmits to the Service.

List of PD: user messages, diary entries, files, photographs, audio, calendar data, tracker data, other attachments and user content, technical request data, processing results.

Processing time: the period required to complete the request and store the interaction history in the Account; before the User deletes the data; until processing is terminated on the grounds provided by law.

Type of processing: automated or mixed.

Legal basis: execution of the contract; subject consent; legitimate interest of the Operator.

5. Technical support and consultations.

List of PD: email address, Account information, content of the request, diagnostic data, error information.

Processing time: period of validity of the contract; the period required to process the request and protect the rights of the Operator and the User.

Type of processing: automated or mixed.

Legal basis: execution of the contract; legitimate interest of the Operator.

6. Analysis of user experience in order to improve the Service, mobile application, ease of use and development of new functions.

List of PD: technical and aggregated usage data, IP address, device and application information, information about errors and diagnostic events.

Processing time: 14 or 24 months depending on the type of analytics, unless a different period is established by applicable documents or the consent of the User.

Type of processing: automated.

Legal basis: legitimate interest of the Operator; consent of the subject to the processing of personal data; processing for statistical and other research purposes.

7. Delivery of push notifications, service, technical and information messages, including calendar reminders, proactive Service notifications and notifications about Service events.

List of PD: push token / device token, notification settings, Account information, notification content to the extent necessary for delivery.

Processing time: until the User disables notifications; before removing the push token; before withdrawing consent if notifications require consent.

Type of processing: automated.

Legal basis: consent of the subject; execution of the contract; legitimate interest of the Operator.

8. Compliance with legal requirements, processing User requests for export, clarification, blocking, deletion or destruction of data, as well as protecting the rights of the Operator and Users.

Processing terms: terms established by law, agreement, consent or necessary to protect the rights of the Operator.

Type of processing: mixed.

Legal basis: performance of functions, powers and duties assigned to the Operator by law; legitimate interest of the Operator.

### 3.3. Certain processing restrictions

The Operator does not process biometric personal data unless a separate function directly provides for such processing and the User has provided the consent required by law.

The operator does not intentionally process the personal data of minors. Independent use of the Service is permitted by Users who have reached the age established by the User Agreement noesa. Responsibility for the actions of minors and their provision of personal information lies with their legal representatives in accordance with applicable law.

The Operator generally does not verify the accuracy of the personal information provided by the User and does not exercise control over his legal capacity. The risk of providing false personal data, including providing data of third parties as their own, is borne by the User.

If the subject of personal data is a citizen of the European Union or a citizen of other states, temporarily or permanently residing in the territory of the EU countries and accesses the Service from European countries, the Operator takes reasonable measures to ensure compliance with the requirements of the legislation on the protection of personal data. To do this, the subject of personal data is obliged to notify the Operator about the existence of a special regime for the protection of his personal data by contacting the address privacy@noesa.ai.

4. Principles, methods of processing and transfer of data to third parties

The operator processes personal data on a legal and fair basis.

When processing personal data, their accuracy, sufficiency and relevance in relation to the purposes of processing are ensured.

The operator processes personal data using and without automation tools. The operator fulfills the requirements for automated and non-automated processing of personal data provided for by law and regulations adopted in accordance with it.

The operator may entrust the processing of personal data to other persons. At the same time, the Operator fulfills the requirements for ordering the processing of personal data provided for by law.

The operator does not disclose or distribute personal data to third parties, except in the following cases:

1. The subject of personal data has expressed his consent to such disclosure in advance.

2. The transfer is necessary for the execution of an agreement to which the subject of personal data is a party or beneficiary or guarantor, as well as for concluding an agreement on the initiative of the subject of personal data.

3. The transfer is necessary to protect the rights and legitimate interests of the Operator or third parties.

4. The transfer is initiated by the subject of personal data.

5. The transfer is necessary for the administration of justice, the execution of a judicial act, an act of another body or official, or in other cases provided for by the current legislation of the Russian Federation.

6. The transfer is necessary for the proper fulfillment by the Operator of its obligations to the User to provide access to the Service, mobile application, services, works and goods of the Operator.

Entities that may be involved in data processing during the operation of a mobile application include providers of cloud infrastructure, data storage, push notification delivery, email sending, error analytics, artificial intelligence infrastructure, access control infrastructure, as well as Apple and Google as operators of application distribution platforms.

When using AI functions, the data recipients are backend noesa and OpenAI OpCo, LLC (USA, hereinafter referred to as “OpenAI”) through the OpenAI API as an external AI provider. The following can be transmitted to the OpenAI API: the text of the User’s specific AI request; photographs, files or audio that the User himself selected and attached to this request; diary entries, calendar events, tracker data and other context only when the User has explicitly selected such context or requested an AI function for which it is required. This data is used to generate a response, analyze, process a file, image, audio or other AI function specifically requested by the User, and by OpenAI to ensure security and prevent abuse within the terms of the OpenAI API.

Before transmitting data to the OpenAI API for the first time, the mobile application identifies OpenAI as the recipient on a separate screen, lists the categories of data being transferred and the purpose of the transfer, and requests explicit permission from the User. Registration, login to an Account, acceptance of the User Agreement or general consent to the processing of personal data do not in themselves constitute permission to transfer data to OpenAI. The user can select “Continue without AI”: in this case, no data is transferred to OpenAI, AI functions are not executed, and non-AI application functions remain available. Permission can be revoked in the mobile application settings; The next time you access the AI ​​function, the application will ask for permission again. The transfer is carried out only when the User uses the corresponding AI function and only to the extent necessary to fulfill a specific request or function.

According to OpenAI's documentation for the OpenAI API, data submitted to the OpenAI API is not, by default, used to train or improve OpenAI models unless the organization has explicitly enabled data transfer for such purposes. noesa does not include voluntary submission of user content for training OpenAI models. Depending on the feature used, OpenAI may retain abuse prevention logs and individual API state for periods of time as specified by the OpenAI API terms and settings.

The relationship between the Operator and OpenAI regarding data processing is governed by the terms of the OpenAI Services Agreement and the OpenAI Data Processing Addendum. The Operator engages OpenAI as a processor only if it provides contractual, organizational and technical measures to protect personal data that are no less stringent and comparable to the protection measures that the Operator is required to provide under this Policy and applicable law. The Operator remains responsible to the User for the proper selection and control of the involved processor within the limits provided by law.

To deliver push notifications, technical services of platforms and notification delivery intermediaries may be used, including Apple Push Notification service, Google/Firebase and Expo, if they are used in the corresponding version of the mobile application.

The operator engages suppliers on the condition that they use the received data only for the purpose of providing the relevant technological services, unless otherwise provided by applicable law, contract or rules of the relevant platform.

The Operator does not sell Users’ personal data and does not use mobile application data to track Users in third-party applications and third-party websites without a separate legal basis or consent, if such consent is required. If a particular version of the Application uses an advertising device identifier or other tracking technology within the meaning of the platform rules, it will only be used after obtaining the required system permission from the User.

5. Device permissions, push notifications and artificial intelligence

A mobile application can request system permissions of the device: camera, microphone, media library, files, notifications and other permissions required for individual functions. The user can allow or deny access in the device's system settings.

The camera is used to create photographs and videos that the User himself attaches to a recording, message or other object of the Service.

The media library is used to select and save photos or videos based on User action.

The microphone is used for voice input, audio recording or speech recognition based on User action.

Files are used to download and open documents that the User himself selects or receives in the Service.

Push notifications are used only with the User's permission and can be disabled in the device settings or in the Service settings, if such a setting is available. Push token / device token is used to deliver calendar reminders, proactive Service notifications, as well as service and technical notifications.

noesa uses artificial intelligence technologies to process User requests, analyze records, help with a diary, calendar, trackers, files, images and other functions. To perform such functions, the data listed above may be transmitted to the backend noesa and to OpenAI OpCo, LLC via the OpenAI API only after the separate informed permission of the User, only when using the appropriate AI function and only to the extent necessary to fulfill a specific request.

Artificial intelligence responses are informational and supportive in nature. They do not constitute medical, psychological, legal, financial or other professional advice.

6. User rights, storage and deletion of data

The subject of personal data has the following rights:

1. The right to receive information regarding the processing of his personal data by sending a written request to the email address privacy@noesa.ai in the manner prescribed by law.

2. The right to clarify, block or destroy data if personal data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated purpose of processing.

3. The right to revoke previously provided consent to the processing of personal data by sending a corresponding notification to the email address privacy@noesa.ai marked “Withdrawal of consent to the processing of personal data.” Termination of processing of personal data by the Operator may make it impossible to further use goods, works and services.

To fulfill requests, the Operator may require confirmation of the identity of the subject of personal data in any form that does not contradict the law.

The user can request data export and initiate Account deletion directly in the mobile application in the Account management section: “Profile” / “Settings” → “Account” → “Delete Account”, and also contact support to clarify the status of the request.

The operator stops processing personal data:

1. upon expiration of the established deadlines;

2. upon achievement of the purposes of their processing or in case of loss of the need to achieve these purposes;

3. at the request of the subject of personal data, if the data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated purpose of processing and it is impossible to ensure the legality of processing;

4. in the event that the subject of personal data withdraws consent to the processing of his personal data in relation to data processed on the basis of consent;

5. in case of termination of activities by the Operator.

Destruction of personal data is carried out in cases of unlawful processing, redundancy of data for the stated purpose, withdrawal of consent, achievement of the purpose of processing or loss of the need to achieve such a goal, expiration of storage periods established by regulatory legal acts of the Russian Federation, recognition of the unreliability of personal data or their receipt by illegal means.

Deleting an Account leads to the deletion of user content, including records, messages, files, photographs, audio, calendar data, tracker data and other User materials, in the manner and within the time limits provided for by applicable law, the User Agreement and technical processes of the Service. Some technical logs, backup copies, security information, data necessary to comply with legal requirements, resolve disputes or protect the rights of the Operator may be retained for a limited time after Account deletion.

7. Security and privacy

To ensure the fulfillment of the obligations provided for by the Federal Law of the Russian Federation “On Personal Data” No. 152-FZ of July 27, 2006 and the regulatory legal acts adopted in accordance with it, the measures specified in the main Policy for the processing of personal data and information noesa have been taken.

The Operator applies legal, organizational and technical measures to ensure the security of personal data, exercises internal control over the compliance of the processing of personal data with the requirements of the law, Policy and local regulations of the Operator, and also limits access to personal data to persons who need such access to fulfill contractual obligations.

Information related to personal data that has become known to the Operator is confidential information and is protected by law.

The Operator's employees and other persons who have access to the processed personal data sign an obligation of non-disclosure of confidential information and are warned of liability in case of violation of the requirements of the legislation of the Russian Federation in the field of personal data processing.

Authorization tokens in the mobile application are stored using secure device storage, if such means are available on the User’s device.

8. Responsibility of the parties and dispute resolution

An operator who fails to fulfill its obligations is liable for losses incurred by the User in connection with the unlawful use of personal data, in accordance with the legislation of the Russian Federation.

In the event of loss or disclosure of confidential information, the Operator is not responsible if such information became public knowledge before its loss or disclosure, was received from a third party before it was received by the Operator, or was disclosed with the consent of the User.

In the event of a leak of personal data of the subject of personal data, the Operator notifies the relevant government authorities about the leak of personal data and the results of the investigation of such a leak within the time limits provided for by the current legislation of the Russian Federation.

Before filing a claim in court regarding disputes arising from the relationship between the User and the Operator, it is mandatory to submit a claim. The recipient of the claim within 10 (ten) calendar days from the date of receipt of the claim notifies the claimant in writing of the results of consideration of the claim.

The current legislation of the Russian Federation applies to this Policy and the relationship between the User and the Operator.

9. Additional conditions and contact with the Operator

This Policy applies to any action or set of actions performed with personal data using automation tools or without the use of such tools.

The operator has the right to make changes to this Policy without the consent of the personal data subjects. The new edition comes into force from the moment it is posted at this address, unless otherwise provided by the new edition.

The invalidity of individual provisions of this Policy, if recognized by a court or other authorized government body, does not entail its invalidity as a whole.

Regarding the processing and protection of personal data, requests are accepted at privacy@noesa.ai.

For questions regarding the operation of the mobile application and support, requests can be received at help@noesa.ai.

Operator details:

IP Berudzhanyan A.A.

INN: 773771872612

OGRNIP: 326774600057471

Responsible for the processing of personal data is Berudzhanyan A.A.