Nudgiefor two people

Privacy Policy

This page describes what Nudgie stores, why, and what we can and cannot see. It reflects what the app actually does; if the two ever disagree, the code is the bug.

What we store

Your account

  • Email address — how you sign in, and where sign-in codes are sent.
  • Display name and avatar emoji — shown to your partner.
  • Public key — so you and your partner can encrypt messages to each other.
  • Status (free, busy, sleeping, thinking) and quiet hours — both set by you.

Your pair

  • Which two accounts are paired, and when the pair was created.
  • Your shared button deck: emoji, label, category and animation for each button.
  • Theme choice and subscription tier.

Nudges

  • Who sent it, who received it, and when it was sent, delivered and acknowledged.
  • Which deck button was used, and the animation style.
  • For composed nudges: the encrypted message and its nonce. We store ciphertext only.
  • Scheduled send time, for scheduled nudges.

Delivery and devices

  • Your per-button loudness rules — silent, normal, or ring through.
  • Push notification tokens for your devices, so notifications can reach them.
  • Sign-in session records, which include the IP address and the device or browser user agent of the sign-in.

Reports

If you report a nudge or a person, we store who reported, who or what was reported, the reason, and any note you write. Operators read these to act on them.

What we cannot see

Composed nudge text is encrypted on your device with your partner’s public key. We hold the ciphertext and no key that opens it.

We can see the metadata around a nudge: that you sent one, to whom, when, and which deck button it used. A deck button label such as "On my way" is stored in plain text, because the two of you edit that deck together. If that distinction matters to you, treat button labels as visible to us and composed text as not.

Who else receives your data

  • Apple and Google, through the Expo push service, to deliver notifications to your devices.
  • Our email provider, to send you sign-in codes.
  • Our hosting provider, which runs the servers and the database.

We do not sell your data, and we do not run advertising or third-party analytics inside the app.

Who at Nudgie can see it

Operators can reach an administration panel that reads account records, pair membership, decks, schedules, delivery rules, and nudge metadata — to answer support requests and act on reports. They cannot read composed nudge text, and they cannot read the session or authentication tokens that would let them sign in as you.

Deleting your account

Deleting your account removes your nudges, push tokens, delivery rules, schedules, sign-in sessions, your half of the pair, and the account itself. Unpairing wipes the shared deck and history for both of you. The account deletion page explains how to start it.

Children

Nudgie is not directed at children and we do not knowingly collect data from anyone under 13.

Changes and contact

We will update this page when what we store changes. Questions, corrections, or a data request: donald.murillo07@gmail.com.

Still to be completed

This policy needs a governing jurisdiction, a legal entity name and postal address, and a data-retention period before the app is submitted to either store. Edit this page in the admin panel to add them.

Privacy Policy — Nudgie