nily

Privacy Notice

We sell health. Not your data. No ads. No data brokers. This notice explains what we collect, why we collect it, how it is protected, and the control you keep over it.

Last updated: July 2026

Who we are

Nily is operated by Annotatory AI Projects Private Limited. For any privacy question you can reach our Data Protection Officer at dpo@nily.health and our Grievance Officer at grievance@nily.health.

  • United States: 849 Olinda Way, Liberty Hill, TX 78642-2616
  • India — engineering & support: Floor 5, Trendz Avenue, Madhapur, Hyderabad, Telangana
  • Estonia: Estohub, Tallinn

What we collect

Information you give us. When you use a free health tool on this site and choose to receive your full report, we ask for your mobile number and your explicit consent to message you on WhatsApp. We also record which tool you used, the result category it produced, the consent you gave, and when you gave it — that record is how we prove your consent was freely given.

Your answers to a health tool. The answers you enter in an assessment are used to produce your result and the report we send you.

Information in the Nily app. If you create an account in the app, the app collects the health information you choose to track there. The app's own in-product notices govern that processing.

Technical information. Standard server and analytics information such as device type and pages viewed, used to keep the site working and understand what is useful.

How we use it, and what we never do

We use what you give us to produce your result, send the report you asked for, respond to you, provide the services you choose, meet legal obligations, and keep the service secure.

We do not sell your personal data. We do not share your health answers with advertising platforms, data brokers, ad networks, or remarketing systems. We do not build advertising audiences out of sensitive health information. Marketing consent is always separate from the consent you give to process a tool response, and you can withdraw either.

We share information only with service providers who help us run Nily (for example, message delivery and hosting), under contract and only for the purpose we engaged them for — and where the law requires us to.

How it is protected

256-bit AES encryption at rest · TLS in transit. Your health data never leaves the people you trust.

  • ISO 27001 — Information security
  • ISO 27701 — Privacy information management
  • ISO 9001 — Quality management
  • SOC 2 — Security & availability

We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as the law requires us to keep it. When it is no longer needed, it is deleted or anonymised.

Your rights

Under India's Digital Personal Data Protection Act, you can:

Access

Ask what personal data we hold about you and get a copy of it.

Correction

Ask us to correct data that is inaccurate, incomplete or out of date.

Erasure

Ask us to delete your personal data where we are not required to keep it.

Withdraw consent

Withdraw a consent you gave — including WhatsApp messages — at any time. Withdrawing does not undo processing already carried out lawfully.

Grievance redressal

Raise a complaint with our Grievance Officer and receive a response.

Nominate

Nominate another person to exercise your rights if you are unable to.

To exercise any right, email dpo@nily.health. If you are not satisfied with our response you may escalate to our Grievance Officer at grievance@nily.health, and thereafter to the Data Protection Board of India.

Children

Nily's tools and services are intended for adults. We do not knowingly collect personal data from children without verifiable parental consent. If you believe a child has given us personal data, contact dpo@nily.health and we will delete it.

Changes to this notice

If we change how we handle personal data we will update this page and change the date above. Where a change materially affects you, we will tell you.

Related: Consent choices · Terms · Medical disclaimer