Skip to main content

Nakama Health · Mobile privacy

Mobile app privacy policy

This policy describes the information handled by the current issued-member mobile app and the controls available in that release.

  • iOS 1.0.0 (113) · Android 1.0.2 (113)
  • Updated July 25, 2026

Scope

This policy applies to the Nakama Health iPhone and Android member-app release identified above. Members sign in with access already issued by a sponsor or organization.

You cannot create an account or membership or enroll through the app. Any coverage purchase or payment setup required by your program takes place outside the app.

Membership, benefit, claim, and record information in the app reflects existing program records. Account, security, privacy, and support actions are available in the app, including password help, data-copy requests, and account deletion.

Information the app handles

  • Account information, such as your name, email address, user identifier, and sponsor or organization association.
  • Issued membership and benefit details available to your account.
  • Existing claim status, claim history, records, and documents made available to your account.
  • Session and security information, including authentication tokens and account-access events.
  • App, device, and service information, including a Firebase installation identifier, similar app or device identifiers, app version, operating system, network and reliability details, and diagnostic information used to protect the service and resolve errors.
  • On Android, app-integrity information and tokens from Firebase App Check and Google Play Integrity used to confirm that requests come from the genuine app on a compatible device.
  • Requests you make for support, a data copy, password help, or account deletion.

This release reads account information returned after sign-in. It does not ask for access to health data stored by your device, the camera, the photo library, or the microphone.

Google and Firebase services

The app and its backend use Google Firebase services. Firebase Authentication manages sign-in; Cloud Firestore stores account and service information; Cloud Functions handles protected account actions; and Cloud Storage stores files made available through the service.

Firebase Installations creates an identifier for an app installation so Firebase services can operate and protect the app. On Android, Firebase App Check uses Google Play Integrity to create app-integrity tokens. Google may process these identifiers, tokens, device or app details, and related diagnostic information to provide, secure, and support those services.

How information is used

  • Authenticate you and display information available to your member account.
  • Protect accounts, prevent misuse, investigate errors, and keep the app reliable.
  • Prepare a requested data copy and process an account-deletion request.
  • Respond to support questions and meet applicable security, recordkeeping, and legal requirements.

Who may receive information

Information may be provided, when needed for the app or a member request, to:

  • Google, which provides Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Firebase Installations, and Android app-integrity services;
  • other service providers supporting hosting, communications, reliability, security, and customer support;
  • the sponsor or organization associated with your access, and authorized people involved with the membership or claim information shown to you;
  • professional advisers or public authorities when required by applicable law or needed to protect people, rights, or the service; and
  • a successor in a lawful corporate transaction, subject to the protections that apply to the transaction.

The current release has no advertising or cross-app tracking, and Nakama does not use the release to sell personal information.

Sensitive information

Claim and record information may include health, identity, or financial details. Access is limited by the signed-in account and the permissions configured for the service.

Use the app or another approved secure process for private records. Do not send medical records or identity documents through ordinary support email.

Retention and deletion

When you schedule account deletion, Nakama keeps the account active for a 30-day cancellation window. A deletion service runs every 24 hours and attempts requests that are due. If a required cleanup step fails, the request remains eligible for a later retry.

A completed deletion removes the Firebase Authentication account, Nakama-controlled account documents and subcollections, user storage, and data-export files. Nakama keeps a minimal record showing that deletion completed. Some financial or economic audit records may remain after account identifiers are replaced with pseudonymous values. Information may also remain when needed for security, fraud prevention, disputes, recordkeeping, backup recovery, or applicable law.

A sponsor, organization, or another service provider may hold separate records under its own notices and requirements.

International processing

Nakama is based in the United Arab Emirates and uses service providers, including Google, that operate in multiple countries. Information may therefore be processed or stored outside the country where you live, where privacy laws may differ. Nakama uses contractual, technical, and organizational safeguards when applicable requirements call for them.

Security

Nakama uses account access controls, authentication, and safeguards intended to protect member information. No online service can promise complete security. Contact support promptly if you believe someone else accessed your account.

Your privacy choices

In the app, open You, then Security and privacy, to request a data copy or schedule account deletion. For another request, contact Nakama Support. Your sponsor or organization can help correct information it provided.

Privacy laws may provide additional choices depending on your circumstances. Nakama may need to verify a request and may retain information when applicable requirements permit or require it.

Changes to this policy

Nakama may update this policy when the mobile app or applicable requirements change. The updated date above identifies this version.

Contact

Email [email protected].

  • OMEGAX HEALTH FZCO
  • Operating as Nakama Health
  • Unit No: UT-12-CO-253
  • DMCC Business Centre, Level 12
  • Uptown Tower
  • Dubai, United Arab Emirates