All apps

Is Nabla safe with your data?

C
Nabla icon

Nabla

58/100

Partial disclosure · high confidence

Nabla earns a C (58/100) because it discloses its data practices only in part.

Dealbreaker flag

  • D1.1: Nabla may collect, process, and otherwise use de-identified data that is transmitted to Nabla through your use of the Services for training of Nabla's internal artificial intelligence model

#63

of 211 apps ranked

58

score · Healthcare avg 38

+20

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Nabla discloses a strong statutory rights menu, HIPAA BAA safeguards with a named 7-day breach window and SOC 2 audit report, but it reserves de-identified training of its internal AI model with no opt-out and gives no retention number or children's age gate.

What Nabla's privacy policy and terms of service say about your data

De-identified data trains the model with no opt-out

Section 9 of the terms says Nabla "may collect, process, and otherwise use de-identified data... for training of Nabla's internal artificial intelligence model" and may disclose it. Neither document offers any way to opt out.

Child data collected with no age gate

The policy lists "Data from a known child" among the Sensitive Personal Data it collects. It never states a minimum age, an age-verification step or any parental-consent protection.

Concrete HIPAA security commitments

The BAA sets a seven calendar day outer limit for breach notification. It also commits to providing the most recent independent SOC 2 certification report on request.

Retention has no number

Data is kept "for as long as necessary for the purpose for which that data was collected", a formula with no named period. No AI-log retention is disclosed at all.

What the policy is silent or vague on

  • Not stated: keeping user inputs out of model training
  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: shorter retention for AI conversation logs

Nabla privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inAdverse
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsPartial
Data-subject rights5 of 5 disclosed
Grants a right to access your dataDisclosed
Grants a right to delete your dataDisclosed
Offers data portability in a usable formatDisclosed
Grants a right to correct your dataDisclosed
Grants a way to object to or opt out of processingDisclosed
Retention and deletion0 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestPartial
Sets a shorter retention for AI conversation logsSilent
Commits to collecting only the data it needsPartial
Third-party sharing2 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementPartial
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersDisclosed
States a standard for government and law-enforcement accessPartial
Transparency2 of 5 disclosed
Discloses that you are interacting with AIDisclosed
Marks AI-generated or synthetic outputSilent
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesPartial
Is versioned and dated, with change noticePartial
Sensitive data and children2 of 3 disclosed
Discloses automated decisions and a human-review pathDisclosed
Limits the use of special-category dataDisclosed
Governs biometric data specificallyNot applicable
States protections for children's dataSilent
Security and accountability2 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationDisclosed
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
Healthcare
Modalities
text, audio
Processes biometrics
No
Policy last updated
2026-03-25
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Other healthcare apps

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Nabla safe with your data? Grade C | AI App Trust & Transparency Index