Local encrypted vault
The current web application stores its journey in the browser using IndexedDB and AES-GCM encryption. The device/browser holds the local encryption material. Moving to another browser or device does not automatically copy the journey.
Private NeXaCoach
Private mode uses local history plus NeXaVirama’s rule-based adaptive engine. It can use recorded triggers, urge intensity and previous intervention outcomes without transmitting the private journal to an external AI service.
AI+
AI+ is optional. When enabled with explicit consent, the selected question and limited behavioural context may be sent to the configured AI provider to generate a more conversational response. Avoid entering names, passwords, IDs or other information you do not want transmitted.
Health information
Health considerations are optional reminders. NeXaVirama does not diagnose. Broad selected considerations are only included with AI+ when the user activates the separate sharing control. The private free-text health note is excluded from the current AI+ request.
Service worker & offline shell
The installable web app may cache public application files for reliability and faster loading. API and AI responses are excluded from the offline cache. Personal journey data remains in the encrypted local vault rather than the service-worker cache.
Delete data
Use Manage focus / Privacy → Delete all NeXaVirama data in the application. This removes the local encrypted journey for that browser/device. Browser settings can also clear the site’s stored data.
What NeXaVirama does not claim
Privacy-first design does not by itself make the product HIPAA-, GDPR-, PDPA-, SOX- or medical-device compliant. Formal compliance depends on the complete operating model, contracts, hosting, security controls, policies, processing purpose and jurisdiction. Those controls should be assessed before any institutional or government deployment.