Skip to content

Legal

Privacy Policy

What Nova Security collects, what it does not, and what you can ask us to do about it.

Last updated May 2026

Introduction

This notice explains how PeraSoft handles personal information in the Nova Security mobile application. It covers the app and the services behind it, and nothing else: other products and third-party sites you reach from the app have their own policies.

We revise this notice as the product changes. Material changes are announced in the app or by email before they take effect, and the date above always reflects the version you are reading.

Information we collect

We collect the least we can and still run a security product. In practice that is:

  • Registration data: the email address and password you sign up with.
  • Device data: operating system and version, device model, and IP address.
  • Application metadata: which features you use and when, and the version of the app you are running.
  • Wi-Fi scan data: the name, security type and characteristics of networks the app assesses.
  • Threat data: URLs and QR code destinations that are checked against our threat database, and the verdict returned.
  • Breach-check data: a cryptographic hash of the email address you ask us to monitor, together with the result of the comparison.
  • Analytics and diagnostics: aggregated usage and crash information used to find and fix problems.

Nova does not collect your general browsing history, and it does not access your emails, text messages, photos or videos. It does not ask for the permissions that would make any of that possible.

How we use it

  • Detecting malicious applications, links and QR destinations.
  • Assessing the security of networks you are connected to or about to join.
  • Telling you when an address you have asked us to watch appears in a known breach.
  • Providing, maintaining and improving the service, including diagnosing faults.
  • Sending you service messages, and product announcements you have not opted out of.

We do not use your information to build an advertising profile, and we do not sell it.

How we disclose it

We share personal information only in the following circumstances:

  • Service providers who operate parts of the service on our behalf, including Firebase for application infrastructure and RevenueCat for subscription management. They are bound by contract to use the data only for the work we have asked them to do.
  • Payment processing, which is handled entirely by Apple and Google. We never receive your card details.
  • Law enforcement or regulators, where we are legally required to respond and the request is valid.
  • A buyer or successor, if the business or the relevant part of it is sold, merged or reorganised.
  • Pseudonymised, aggregated threat reporting, which cannot be used to identify you or your device.

Your choices

Scanning, notifications and monitoring can be turned on and off in the app's settings at any time. You can unsubscribe from promotional email from any message we send; you will still receive transactional messages about your account and your subscription, because those are part of the service rather than marketing.

Data retention

We keep information only as long as is reasonably necessary to provide the service, to meet a legal or regulatory obligation, or to resolve a dispute. When none of those applies any longer, the data is deleted or irreversibly anonymised.

Security

Data is encrypted in transit and at rest, access to production systems is authenticated and restricted, and infrastructure is segmented and monitored. No system is perfectly secure, and the part we cannot do for you is your password: keep it confidential and do not reuse it elsewhere.

Users under 16

Nova Security is not directed at children. We do not knowingly collect or store personal data about anyone under the age of 16. If you believe a child has provided us with personal information, write to info@pera.software and we will delete it.

International transfers

We operate internationally, so your information may be processed in a country other than the one you live in. Where it leaves the EEA, the UK or Switzerland, the transfer is covered by Standard Contractual Clauses or another safeguard recognised under applicable law.

California and other US state residents

If you live in California, Colorado, Connecticut, Utah or Virginia, you have the right to know what personal information we hold about you, to have it corrected or deleted, to receive a copy of it, and not to be treated differently for exercising any of those rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

EEA, UK and Swiss residents

We process personal data on one of three bases: because it is necessary to perform our contract with you, because we have a legitimate interest in operating and securing the service that is not overridden by your rights, or because you have given consent, which you may withdraw at any time.

Your rights over your data

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data deleted.
  • Receive your data in a portable format.
  • Object to, or ask us to restrict, certain processing.
  • Complain to your local data protection authority.

To exercise any of these, write to info@pera.software. We may need to verify your identity first, and we will respond within the period the applicable law allows.

Contact us

Questions about this notice, or about anything above, go to info@pera.software.