Legal
Privacy Policy — Codra
- Last updated
- 19 September 2026
- Applies to
- Codra 1.0.0
- App
- Codra
- Platform
- Android
- Developer
- Nainnie Labs
- Contact
- hello@nainnielabs.com
Before anything else
Codra is a reference tool. It is not a medical device, it does not diagnose, treat, cure or prevent any medical condition, and it does not tell you which code to assign. Always consult a qualified healthcare professional for medical advice, and verify every code against the current official guidelines and your payer's rules.
Codra never asks you for patient information, and you should never enter any. No patient names, no dates of birth, no medical record numbers, no claim or account numbers — not in notes, not in list names, not anywhere. The app has no field intended for it and the notes editor says so.
The short version
There is no account, no sign-in and no profile. Every code lookup, every favourite, every list and every note stays in the app's own storage on your phone. None of it is sent to us, because there is nowhere for it to be sent — we run no servers and we have no database with your name on it.
Two things do involve Google, and only two:
- Ads, on the free tier only. Google AdMob serves them, and Google receives data to do that.
- Subscriptions, if you buy Codra Pro. Google Play processes the payment.
Everything below is the detail.
1. Who we are
Codra is published by Nainnie Labs.
Privacy questions, requests and complaints: hello@nainnielabs.com. We answer within 30 days.
2. What stays on your device and never leaves it
All of this is written to Codra's private app storage, which no other app on your phone can read:
| What | Where it lives |
|---|---|
| Favourited codes | codra-user.db |
| Lists you create, and their contents | codra-user.db |
| Notes you write on a code | codra-user.db |
| Theme choice (light / dark / system) | app preferences |
| Whether you have seen onboarding, and when you accepted the disclaimer | app preferences |
| Counters used to decide when to offer a review prompt | app preferences |
| Your subscription status, cached so the app works offline | app preferences |
| Time remaining on a rewarded-ad unlock | app preferences |
| PDF and CSV files you export | the app's own cache directory |
None of it is transmitted anywhere. It is not synced, not analysed, not backed up to the cloud, and not visible to us.
Codra has allowBackup="false" and excludes itself from Android's device-to-device transfer, so your favourites, lists and notes are not copied to Google Drive or to a new phone either. That is deliberate — it is the price of being able to say "nothing leaves this device" without an asterisk. The consequence is real and you should know it: if you uninstall Codra, factory reset, or move to a new phone, your favourites, lists and notes are gone. Use Export PDF or Export CSV on a list first if you want to keep it.
An exported file goes to Codra's own cache. It is shared with another app only at the moment you tap Share and pick one — and then it is that app's privacy policy that governs it, not ours.
The ICD-10-CM data itself
The entire code set ships inside the app. Searching, browsing the tabular list, reading the alphabetic index and opening a code's full entry all work with the phone in aeroplane mode, and none of them makes a network request. We do not and cannot see what you look up.
3. Ads (free tier only)
Codra's free tier is supported by ads from Google AdMob. To serve them, the Google Mobile Ads SDK collects and processes:
- your device's advertising ID (a resettable identifier — you can reset or delete it in Android's Settings → Privacy → Ads), along with the app set ID and any identifiers tied to a signed-in Google account
- your IP address, from which an approximate, city-or-region-level location is inferred
- device and app information: model, operating system version, language, screen size, Codra's package name and version
- ad interactions: which ads were shown, whether you viewed or tapped them, and whether a rewarded ad was completed
- diagnostics: crash and performance information from the ads SDK itself, used by Google for reliability and fraud prevention
Google states that it collects this for advertising, analytics and fraud prevention, and that it is encrypted in transit with TLS. Google's own disclosure guidance for the Mobile Ads SDK is at developers.google.com/admob/android/privacy/play-data-disclosure.
This data goes to Google, not to us. We receive only anonymous, aggregated performance figures — impressions, clicks, revenue — that identify no one. How Google uses it is governed by the Google Privacy Policy and the Google Advertising Policies.
Your controls
- In the European Economic Area, the United Kingdom and Switzerland, Codra shows a Google-certified consent form before a single ad is requested, and before the ads SDK is initialised at all. Your choice is remembered, and you can change it at any time from Settings → Ad privacy options.
- Anywhere in the world, Codra Pro removes ads entirely. With an active subscription no ad is ever requested and the ads SDK is not used.
- Android-level controls apply too: resetting or deleting your advertising ID, or opting out of ad personalisation, works on Codra like it does on any app.
Codra requests the com.google.android.gms.permission.AD_ID permission for this and no other reason.
4. Subscriptions
If you subscribe to Codra Pro, the purchase is handled by Google Play Billing. Google processes the payment.
We never see your card number, bank details, billing address or full name. Codra receives from Google only what it needs to unlock the app: whether a subscription is active, whether it renews, and an opaque purchase token. That is cached on your device so Pro keeps working offline.
Google's handling of the transaction is covered by the Google Payments Privacy Notice. Manage or cancel a subscription at play.google.com/store/account/subscriptions.
5. Other Google Play services
- In-app review — if Codra offers a review prompt, Google Play draws it and handles the review. We never see who reviewed or what they wrote, beyond what is public on the store listing.
- In-app updates — Google Play tells the app when a newer version exists.
Both are Google Play components. Neither receives anything about your codes, lists or notes.
6. Permissions, and why each one exists
| Permission | Why |
|---|---|
INTERNET | Ads, and Google Play billing and update checks. Never for code lookups. |
ACCESS_NETWORK_STATE | Lets the ads SDK avoid requesting an ad with no connection. |
com.google.android.gms.permission.AD_ID | The advertising ID, for ads. Irrelevant once you are on Pro. |
Codra requests no runtime permissions at all. No storage, no camera, no microphone, no contacts, no calendar, no GPS location, no phone state, no health or fitness data, no Health Connect.
7. What Codra does not do
We think the absences are the point, so here they are explicitly. Codra has:
- no account, sign-up, login or password
- no analytics or usage-tracking SDK
- no crash-reporting SDK of our own — the only crash and performance data leaving the device is the ads SDK's own, described in section 3
- no advertising SDK other than Google AdMob
- no social-network SDK, no third-party login
- no data broker, no data sale, no data sharing for cross-context behavioural advertising beyond the AdMob processing described in section 3
- no server of ours that your device ever talks to
8. HIPAA and patient data
Codra is a reference tool for looking up published code sets. It is not designed for protected health information (PHI), it does not receive PHI, and Nainnie Labs is neither a HIPAA covered entity nor a business associate. We do not sign Business Associate Agreements for Codra.
If you enter patient information into a note anyway — against the app's own warning — that text stays in the app's private storage on your phone and is never transmitted to us. But it is then sitting on a phone, subject to your employer's policies and your device's own security, which is exactly why you should not do it.
9. Children
Codra is a professional reference tool for adults working in healthcare and medical billing. It is not directed at children, we do not knowingly collect data from children, and Codra is not enrolled in Google Play's Families programme.
10. Retention and deletion
We hold no personal data about you, so there is nothing for us to retain or delete.
On your device: delete a note, a list or a favourite in the app at any time. Uninstalling Codra erases everything it stored, permanently. Because backup and device transfer are switched off (section 2), there is no copy anywhere else.
At Google: ad data is retained per the Google Privacy Policy; purchase records per Google Play's terms. Those are Google's to hold and Google's to delete — request deletion through your Google Account, not through us.
11. Your rights
Because we hold no personal data, there is usually nothing for us to produce, correct or erase. The rights below are still real, and are exercised against Google for the ad and purchase data Google holds — we will help you work out where to direct a request.
- EEA / UK (GDPR, UK GDPR). Access, rectification, erasure, restriction, portability and objection. Our lawful basis for personalised advertising is your consent, collected through the form in section 3 and withdrawable at any time from Settings → Ad privacy options. Withdrawing it does not make past processing unlawful. You may complain to your national supervisory authority.
- California (CCPA / CPRA). The right to know, delete, correct, and to opt out of sale or sharing. We do not sell personal information and never have. AdMob's personalised advertising may constitute "sharing" under the CPRA; opt out through Settings → Ad privacy options, or subscribe to Pro, which stops ad requests altogether. We will not discriminate against you for exercising any of this.
- Elsewhere. Write to hello@nainnielabs.com and we will apply the same standard.
12. International transfers
We transfer nothing, because we receive nothing. Google operates globally and may process ad and payment data outside your country under its own safeguards; see the Google Privacy Policy.
13. Security
The data Codra stores is held in Android's private per-app storage, which the operating system isolates from other apps and, on a device with a screen lock, encrypts at rest. Codra adds no network layer of its own, so there is no transmission of your data to secure and no account of yours to breach.
14. Changes to this policy
If this policy changes we will update the date at the top and publish the new version at the same URL before the change takes effect. Material changes will also be called out in the app's release notes.
15. Contact
Nainnie Labs
Email: hello@nainnielabs.com
Web: https://nainnielabs.com