Suno Na

Privacy, in plain language.

This policy explains what Aastik Labs collects through Suno Na, why we need it, who can see it, and how you can control or delete it.

Effective and last updated: 28 August 2026

The short version: we do not sell personal data, run behavioural advertising, or use HealthKit, Health Connect, messages, photos or voice notes for advertising or tracking.

1. Scope and who we are

This policy applies to the Suno Na mobile application and the Aastik Labs website. “Aastik Labs”, “we”, “us” and “our” refer to the developer and operator of Suno Na.

Suno Na is a wellness reminder and private care-circle app. It does not provide diagnosis, prescriptions, dosing decisions, medical treatment or emergency services.

2. Data we handle

Account and profile

  • Your email address, used for passwordless sign-in and account notices.
  • Your chosen display name and account identifier.
  • Your private care-circle membership, invitation codes and sharing permissions.

Routines and activity

  • Reminder names, schedules, goals and completion records for medicine, hydration, walking and routines you create.
  • Reports derived from those reminders and check-ins.
  • Your chosen walking goal and, when you grant health permission, daily step totals used to show progress.

Private communication and media

  • Messages, photos and voice notes you choose to share with a care partner.
  • Encrypted message content and the minimum delivery information needed to send it to the intended partner.
  • Photos you choose for a partner profile or reminder.

Device and service data

  • A push-notification token and platform type so reminders and care updates can reach your device.
  • Notification permission and app settings stored on your device.
  • Basic security and operational records produced by our service providers when requests fail or abuse is detected. We design app logs not to include message content, health values, authentication codes or media.

The Aastik Labs website does not use advertising cookies or analytics at launch.

3. How we use data

We use personal data only to:

  • create and protect your account;
  • send email sign-in codes;
  • schedule, sync and report the routines you choose;
  • deliver notifications and the escalation settings you enable;
  • connect you to a partner through an invite you explicitly accept;
  • deliver private messages and media;
  • honour sharing, export, retention and deletion choices;
  • secure, maintain and troubleshoot the service; and
  • comply with applicable law and enforce safety requirements.

4. Partner sharing and service providers

Your care partner

Joining a care circle does not automatically share everything. You choose which categories a partner may see, and you can turn a permission off. A partner may see only the information covered by an active permission or information you directly send to them.

Service providers

  • Supabase provides authentication, database and private media storage. The primary application data region is Mumbai, India.
  • Resend delivers email authentication codes and processes the email delivery information required for that purpose.
  • Firebase Cloud Messaging and Apple Push Notification service deliver notifications and process device push identifiers and delivery metadata.
  • Hetzner hosts the public Aastik Labs website.

These providers process data for us under their terms and security controls. Some limited delivery or service metadata may be processed outside India depending on the provider’s infrastructure.

We do not sell or rent personal data. We do not permit service providers to use Suno Na health data or private communications for advertising.

5. Health and step data

Step access is optional. On iPhone, Suno Na requests read-only access to step count through Apple HealthKit. On supported Android devices, it requests read-only step access through Health Connect. We do not write health data.

When permission is granted, Suno Na reads step totals to show progress toward a walking goal you selected. A current daily total may sync with your account so progress and reports work across the app. It is shared with a care partner only when the relevant permission is active.

We do not use health or fitness data for advertising, marketing, profiling, insurance decisions or data mining. You can withdraw health permission at any time in your device settings and use a time-based walking goal instead.

6. Security and encryption

Messages, voice notes and chat photos are encrypted on the device before upload. The private key is kept in the device’s secure storage and is not uploaded to us. Losing the device or reinstalling the app can therefore make earlier encrypted communication unrecoverable.

Reminder names, schedules, completion records, account details, sharing permissions and step progress are not end-to-end encrypted. They are protected in transit and by server access controls, but our service must be able to process them to provide reminders, reports and approved care sharing.

No online service can promise absolute security. We limit access, avoid putting personal information in URLs or ordinary logs, and review our controls as the product changes.

7. Retention and deletion

  • One-time chat photos expire within 24 hours.
  • Voice-note audio expires after 90 days by default. Its conversation record may remain without the audio.
  • Reminder history, account information and encrypted text messages remain while the account or related care circle is active, unless you delete them sooner through available controls.
  • Email delivery and push providers may keep limited delivery records according to their own retention requirements.

When in-app account deletion succeeds, we remove the account from active systems, including its profile, reminders, check-ins, permissions, messages, push tokens and uploaded media. A surviving care partner keeps their own independent data. Limited residual copies may remain temporarily in protected provider backups until those backups rotate, or longer where retention is legally required; they are not used for ordinary product activity.

See the account deletion instructions.

8. Your choices and rights

Depending on applicable law, you may ask to access, correct or delete your personal data, withdraw consent, stop partner sharing, object to certain processing or raise a grievance.

  • Change sharing permissions in the in-app Consent Center.
  • Withdraw notification, photo, microphone or health permission in device settings.
  • Delete the account inside Suno Na under Privacy & trust.
  • Contact us for an access, correction, deletion or privacy request.

Never send an email OTP, password, private key, medical document or chat content to support.

9. Children

Suno Na is intended for adults aged 18 and over. It is not directed to children, and a child should not create an account. If you believe a child has provided personal data, contact us so we can investigate and delete it.

10. Changes to this policy

We may update this policy when the product, providers or legal requirements change. We will change the effective date above and provide an in-app notice when a change materially affects how personal data is used.

11. Contact and grievance requests

For privacy questions, rights requests or grievances, contact Aastik Labs at support@aastiklabs.com. Include the email address associated with the account and a description of the request, but do not include authentication codes, passwords or sensitive health details.