nak

Privacy Policy

Your stillness stays yours.

Last updated 17 August 2026

nak measures how still you sit using your phone's camera — and the camera feed never leaves your device. This page explains, plainly, what nak sees, what it keeps, and what it never does.

The one thing to know

No photo or video of you is ever uploaded, stored, or sent anywhere. The camera is read on your device only. What leaves your phone is a stream of numbers — posture, stillness, whether your eyes are closed — never an image.

01 The camera

During a sit, nak uses the front camera with on-device machine learning to estimate a few things: whether you're in frame, how still you are, your posture, and whether your eyes are closed. This all happens locally, in real time, on your phone.

Only the derived measurements — a low-rate timeseries of those numbers — are sent to our server to score the session fairly. Individual camera frames are never transmitted, never saved, and never seen by us or anyone else. When a session ends, the camera stops.

02 Face data

Because Apple asks apps to be explicit about this, here is exactly what nak does with face data.

What is collected. While a session is running, an on-device machine-learning model (Google MediaPipe, bundled with the app) reads the front-camera preview and computes, several times per second: an eye-closed likelihood (0–1), the approximate tilt and turn of your head in degrees, and the position of your shoulder line. That is the whole of it. nak does not build a face template, a faceprint, or any biometric identifier; it cannot recognise or identify a person, match one face to another, or tell two users apart by their faces.

Where it happens, and what leaves the device. All face processing happens locally on your device, in memory, in real time. Camera frames, face images, face meshes, and landmark coordinates are never uploaded, never written to storage, and never leave your device. They are discarded frame by frame as the session runs. What is transmitted to our server is only a low-rate list of plain numbers derived from the above — for example “eyes closed: 0.94, head tilt: 3°, movement: 0.02” once or twice per second — which the server uses to decide how long you actually sat with your eyes closed and to score the session fairly.

Storage and retention. The derived numeric session trace is stored in our Google Cloud Firestore database (asia-southeast1 region) attached to your account, for as long as you keep your account, so that your minutes, streaks and leaderboard standing remain accurate. No face data of any kind is stored, because none is ever transmitted. Deleting your account (Profile → Delete account, in the app) permanently erases the stored session traces along with everything else, immediately.

Sharing. Face data is not shared with anyone, because it never leaves your device. The derived numbers are not sold, not shared with advertisers, data brokers, or analytics companies, and are not used for advertising or tracking. They are held by Google Firebase, which hosts our database and sign-in on our behalf (see §6). The stored numeric trace itself is never sent anywhere else; a short summary of a finished sit — its date, its length in minutes, and the percentage of it you spent with your eyes closed — is sent to the assistant described in §7. No face data is provided to Google beyond the on-device model that runs inside the app itself.

Uses. The face-derived measurements are used for exactly one purpose: to run the meditation timer (which only advances while your eyes are closed) and to score a completed session. They are not used for any other purpose, now or planned.

03 What nak stores about you

To keep your progress and run the leaderboard, nak stores:

04 The leaderboard is public

nak has a leaderboard. If you're signed in and appear on it, other people using nak can see your display name, profile photo, and standings (minutes, points, streak). If you'd rather not appear that way, don't set a real name or photo — an auto-generated handle is used by default. Your journal notes are never on the leaderboard.

05 Signing in

You can use nak anonymously. If you want your sits to follow you across devices, you can sign in with Apple, Google, or LINE. When you do, that provider tells nak a basic profile (typically a name and an identifier) so we can attach your history to you. We don't receive your password.

06 Who processes the data

nak runs on Google Firebase (Authentication, Firestore, Cloud Functions, and Storage), which stores and processes the data above on our behalf so the app can work. Our database is in Google's asia-southeast1 region.

Two other companies process something for us, and nothing else:

We don't use advertising networks or analytics SDKs that track you across other apps and websites.

07 The assistant

nak has a built-in assistant — the round face in the bottom bar. It is a large language model, run by Google's Gemini API. This section says exactly what it is given, because some of it is your own writing.

What is sent to Google. Each time the assistant speaks, we send it a hidden brief about you so its answer is about your practice and not generic. That brief contains: your display name; your totals (sessions, minutes, points, current and best streak); whether you hold a pass; your five intake answers; a list of your last 12 sits (date, minutes, eyes-closed percentage, and whether each was verified); and the text of your last 6 journal entries, in your own words. Your messages to the assistant are sent along with it.

This happens even if you never open the chat. Two things the app does on its own also go through the assistant, and both carry the same brief: the short remark nak writes when you save a journal entry, and the come-back reminder lines it writes after each sit so your phone can show them while offline. If you are signed in and you finish a sit, that brief has been sent.

What is not sent. No camera image, no video, no face data, ever — see §1 and §2. Not your email address, and not your sign-in credentials.

What is kept. We do not store your conversations on our servers. The only record we keep is a daily count of how many messages you sent. Your chat history lives on your own device (the last 20 messages), and clearing the app's storage or reinstalling erases it. Google processes what we send in order to generate the reply. We pay for the Gemini API on a paid tier, under which Google does not use what we send — your messages or your journal — to train or improve its models. Its handling is governed by Google's terms for the Gemini API.

It is not a professional. The assistant is not a doctor, therapist, or counsellor, and nothing it says is medical advice. If you are in crisis, please talk to a real person — in Thailand, the Department of Mental Health hotline is 1323.

If you'd rather it saw none of this. Don't write journal entries, and don't use the chat. The come-back lines are only written for signed-in accounts, so a sit taken while signed out sends nothing to the assistant at all.

08 What nak never does

09 Your control

You can edit your name and photo in the app at any time. You can delete your account and the data tied to it — including your stats and journal — from Profile → Delete account in the app, or by emailing us. You can also stop appearing on the leaderboard by clearing your display name and photo.

10 Children

nak is a general-audience app and is not directed at children under 13. We don't knowingly collect data from children.

11 Changes

If this policy changes, we'll update the date at the top and, for anything significant, note it in the app. Continuing to use nak after a change means you accept the updated policy.

17 August 2026. Added §7, describing the assistant and what is sent to Google's Gemini API — including your journal entries. This was already how the app worked; the policy had not said so, and it should have.

12 Contact

Questions, or a request to delete your data? Email palapol.c@icloud.com and we'll help.