Privacy Policy
Last updated: 30 June 2026
1. Who we are
Nudge.Notes ("we", "us", the "Service") is operated by [Company / Operator name], the data controller for the personal data described in this policy. You can reach us at privacy@nudge-notes.app.
2. Data we collect
- Account data: email, name, password hash (or OAuth identifier), timezone, profile preferences.
- Content: tasks, descriptions, attachments, comments, group memberships, and kiosk pairings you create.
- Billing: Stripe customer ID, plan, subscription status, invoice metadata. Card details are stored only by Stripe — we never see them.
- Auth & security: sign-in timestamps, IP address, user agent, MFA enrolment, and audit events used to detect abuse.
- Operational logs: error reports and webhook failures, scrubbed of secrets and PII, kept short-term for debugging.
3. How we use your data & legal basis (UK/EU GDPR)
- Provide the Service — store, sync, and display your tasks; pair kiosks; deliver notifications. Legal basis: contract.
- Take payment — process subscriptions and refunds via Stripe. Legal basis: contract.
- Send essential service emails — sign-up confirmation, password reset, receipts, security alerts. Legal basis: contract / legitimate interest.
- Protect the Service — rate limiting, audit logs, fraud and abuse prevention. Legal basis: legitimate interest.
- Comply with law — tax records, lawful requests. Legal basis: legal obligation.
We do not sell your personal data. We do not use your task content to train AI models. We do not share your data with advertisers.
4. Sub-processors
We rely on a small set of trusted providers to run the Service:
- Supabase — database, authentication, file storage (EU / US regions).
- Stripe — payment processing and tax compliance.
- Lovable Cloud / Cloudflare — application hosting and edge delivery.
- Lovable Email — transactional email delivery.
- Google & OpenAI (via Lovable AI Gateway) — only when you use AI-assisted features. Task content used for an AI feature is sent to the model only for that request and is not used to train the model.
- Google OAuth — optional sign-in. Only basic profile data (email, name) is received.
5. International transfers
Some of our sub-processors are based in the United States. Where personal data is transferred outside the UK / EEA, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) to provide an adequate level of protection.
6. Data retention
- Account & content: kept for as long as your account is active.
- Deleted accounts: personal data and content are permanently purged within 30 days of account deletion.
- Audit & auth event logs: up to 12 months, then deleted.
- Error logs & webhook failures: 30 days.
- Backups: rolling backups overwrite within 30 days.
- Invoices & tax records: retained for the period required by tax law in our jurisdiction (typically 6–7 years).
7. Your rights
Depending on where you live (UK GDPR, EU GDPR, CCPA, etc.), you have the right to:
- access a copy of your personal data;
- correct inaccurate data;
- delete your account and associated data;
- export your data in a portable format;
- object to or restrict certain processing;
- lodge a complaint with your local data-protection authority (e.g. the UK ICO).
Many of these can be done directly in the app under Settings → Data & Privacy. For anything else, email privacy@nudge-notes.app; we respond within 30 days.
8. Security
We protect your data with row-level security in the database, encryption in transit (TLS), encrypted storage at rest, optional multi-factor authentication, audit logging, and short-lived sensitive-action tokens. No system is perfectly secure — please use a strong unique password and enable MFA.
9. Cookies & local storage
We use only strictly necessary storage to keep you signed in and remember preferences. No advertising or analytics cookies. See Cookies for the full list.
10. Children
Nudge.Notes is not directed to children under 16 (or under 13 in the United States). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will remove it.
11. Changes
We will notify users by email of material changes to this policy at least 30 days before they take effect. Non-material changes (typos, clarifications) take effect when the "Last updated" date changes.
12. Contact
Email: privacy@nudge-notes.app
← Back to home · Terms · Refunds · Cookies · Acceptable Use
Nudge.Notes