Nudge Privacy Policy
Effective date: May 28, 2026
Last updated: July 18, 2026
This Privacy Policy explains what data Nudge ("Nudge," "we," "us") collects when you use the Nudge mobile application (the "App"), where it lives, how long it is kept, who else sees it, and what choices you have. Nudge is operated by Fan Interactive LLC.
For questions or to exercise any right described below, contact contact@fan-interactive.com.
Data we handle
This section describes the categories of information the App handles and where each one lives. The specific providers involved are listed in Third-party providers.
On your device only. Some information never leaves your device:
- Your App Lock password, recovery codes, and the encryption key for the local database.
- OAuth tokens for any third-party service you choose to connect (currently Google Calendar). Reinstalling the App or signing in on another device requires reconnecting.
Synced to our servers so you do not lose it. The personal data you create or log in the App is synced to our servers so it survives device loss and is restored when you sign in on a new device. This covers things like your fitness tracking (workouts, body data, blood pressure, progress photos), nutrition and supplement logs, todos and streaks, journaling-style content, chat conversations with Nudge, the schedules and prompts you write for Heartbeats and Pulses, and your in-app preferences and customizations. We store this in an encrypted database that is isolated per account. We keep it until you delete the data or delete your account.
When you chat with Nudge, the App may include context from this synced data (recent activity, nutrition, body data, notes, and similar) in the prompt sent to our AI provider, so the response is informed by what you have done in-app. The same applies when a Heartbeat or Pulse generates personalized text. See Third-party providers and AI training for how chat content is handled in flight and how it interacts with the optional training corpus.
Other information we hold to run your account.
- Account: email, username, name, password hash. If you sign in with Apple or Google, we also receive the account identifier and email address that service returns to us; we do not receive your password.
- Settings: privacy toggles, notification preferences, your push token (if you have allowed notifications), subscription tier, and referral and reward state.
- Operational logs: short-lived security and abuse-prevention records (for example, recent sign-in attempts), and AI usage counters used to enforce rate limits, monitor costs, and detect abuse.
- Device-identifier hash: a one-way hash of a per-device identifier, used solely to prevent the same device from claiming the same reward more than once. We do not store the raw identifier.
- Anonymous usage analytics: aggregated, anonymized statistics about which features and screens are used, and basic retention, collected so that they are not linked to your account or identity and cannot be traced back to you. Because the data is anonymous, there is no on/off toggle. See Anonymous analytics.
- Marketing consent: a single on-off toggle to receive promotional emails and marketing push notifications, and to have your in-app activity used for ad attribution or recommendation tuning. Default depends on your region: off in the EU/EEA and UK, on elsewhere. You can change it at any time in Settings.
- AI-training corpus (on by default outside the EU/EEA/UK, off by default in the EU/EEA/UK): redacted copies of your chat messages. See AI training.
- Feedback submissions (only when you tap Submit on a thumbs-up or thumbs-down popup): see Feedback you submit.
Sent to providers in real time, not stored by us. When you use a feature that depends on a third-party service, the relevant input is sent to that service to produce the result. This covers chat text and attached photos sent to our AI provider, voice clips sent to our transcription provider, PDF attachments sent to a document-extraction provider, image-generation prompts sent to an image-generation provider with moderation checks before and after, web-search queries (after redaction) sent to a search provider, and food and supplement lookups sent to public nutrition databases. The specific providers are named in Third-party providers.
Held by a third party. A small number of categories are stored by a third party on our behalf: crash reports (if you have crash reporting on), App Lock recovery emails (only if you turn on Email recovery), subscription status held by the relevant app store, by our subscription-management and payment providers. We never receive card details. Provider names and what each receives are in Third-party providers.
Backups and exports you create are saved wherever you put them. We do not get a copy.
What we do not collect. We do not provide data to data brokers. We do not access your contacts, photo library, location history, or browsing history unless you explicitly grant access for a specific feature. We do not collect data for advertising unless you have turned on Marketing communications in Settings.
Third-party providers
For each provider below, we have configured the most privacy-protective setting they offer.
Groq runs our language and vision models. Zero Data Retention is enabled, which is meant to prevent Groq from retaining your prompts or images.
DeepInfra runs additional language models. Zero Data Retention is automatic on DeepInfra's inference endpoints.
Deepgram transcribes voice clips and reads replies aloud. We send mip_opt_out=true on every request, which signals Deepgram not to retain or train on the audio.
Google Calendar (only if you connect it): when you grant access, Nudge reads your calendar events to surface them in chat and create or update reminder events you ask for. The OAuth tokens are stored in your device's secure storage; we do not hold them on our servers. Disconnecting Calendar in Settings (or deleting your account) revokes the grant with Google.
Google (Gemini) extracts text from PDFs you attach.
- What Gemini receives: the PDF's contents (text and page images) plus a fixed instruction to extract and summarize it. No chat history is included.
- How it is sent: inline in a single API request. We do not upload it to Google's file storage, place it in a vector or search index, or store it in cloud storage. Google does not create a persistent copy.
- Retention and use: we use Google's paid API tier. Under those terms, Google does not use your file or the returned text to train its models. Google may retain short-lived logs for abuse and policy monitoring, after which they are deleted.
- What we keep: the request size in bytes and token-usage counts, to enforce rate limits.
Replicate generates images you ask for in chat. Per Replicate's published policy, generated images auto-delete within one hour. We also request immediate deletion as soon as we have fetched the image.
AWS Rekognition attempts a moderation check on each generated image for nudity and celebrity likeness before it is shown to you. If the moderation service is unavailable (for example, an AWS outage), the image is blocked rather than shown unmoderated. We have AWS's AI services opt-out policy enabled, which is meant to exclude submissions from being used to improve AWS models.
Serper performs web searches. Serper logs the queries we send. For chat searches, the AI first rewrites your message into a focused query rather than forwarding your raw text, and our server then runs a redactor that strips common personal-data patterns. For Rhythm prompts the server redactor runs but the AI rewrite step does not. What you type is what gets sent, minus the patterns the redactor catches. Neither step is guaranteed to catch everything; avoid placing truly sensitive information in a search request.
USDA FoodData Central and Open Food Facts. When you look up a food, vitamin, or supplement, by typing a search term or scanning a product's barcode/QR code, the search term or product code is sent to these public databases for nutrition and ingredient data. We send only the search text or product code, never information about you or your account. Barcode lookups may be sent to Open Food Facts directly from your device.
Supabase is our database, file storage, and server functions provider. Supabase hosts both the account and settings data and the synced personal data described in Data we handle. Data is encrypted at rest by Supabase and isolated per account by row-level security policies; in transit it is protected by TLS.
Firebase Crashlytics (Google) handles crash reports, only if you have enabled crash reporting.
Resend sends App Lock recovery emails on our behalf, only when you have turned on Email recovery in App Lock settings. Resend receives the recipient address and the email body. We send a one-time code that expires shortly after it is issued, cannot be reused, and is rate-limited per account.
Apple and Google: sign-in with Apple and sign-in with Google (only if you choose to use them). When you sign in with one of these services, that provider hands us an account identifier and email address so we can create or match your Nudge account; we never see your password for the underlying service. Apple and Google also handle app distribution and in-app purchases.
Expo: app builds, over-the-air updates, and push notification delivery. When we send you a notification you've enabled, the Expo push token your device gave us and the notification payload are passed through Expo's push service to Apple's APNs or Google's FCM for final delivery.
Payments (not active yet, for when paid subscriptions launch). Subscriptions are not currently available to purchase. When they launch: Apple App Store and Google Play will process in-app purchases; Stripe will process web checkouts; RevenueCat will manage subscription status across platforms. None of these will receive your card details from us, because we never see them. We will update this policy before any of these providers begin processing your data.
AI training toggle
Settings contains a toggle called Help train Nudge's AI. When it is on, redacted copies of your chat messages are saved on our servers and may be used to improve our AI. When it is off, no new chat content is sent to the training corpus, and any redacted copies we already hold for your account are deleted.
Default by region. For new accounts created outside the EU/EEA and the UK, the toggle starts on. For new accounts created in the EU/EEA or the UK, the toggle starts off, and you must actively turn it on to participate. You can change it at any time, in either direction.
Redaction. Before any chat content is stored, it passes through two passes of redaction: a local pass on your device that strips emails, phone numbers, addresses, and your own profile name, then a second AI-driven pass that strips other people's names, organizations, locations, and identifiers.
What deletion can and cannot undo. Turning the toggle off deletes our redacted copies of your contributions. We cannot remove data from a model that has already been trained on it, because removing data from trained model weights requires retraining from scratch. This is the same for every AI provider.
Feedback you submit
The chat screen has thumbs-up and thumbs-down buttons. Tapping one opens a popup; submitting that popup sends Fan Interactive the current conversation in full and unredacted, the optional comment you typed, your account ID, the ID of the message and conversation you voted on, whether you voted thumbs-up or thumbs-down, and message metadata (the role and timestamp of each message in the conversation). We use this both to investigate quality issues and as input to improving our AI, including potential inclusion in our training corpus.
Feedback is only sent when you actively tap Submit in the popup. It is not controlled by the "Help train Nudge's AI" toggle and is sent regardless of that toggle's state. Because feedback is opt-in per submission, the conversation snapshot is stored without the PII-redaction pass used for the training corpus. Do not submit feedback if your conversation contains anything you do not want to share unredacted.
What deletion can and cannot undo. Deleting your account removes the raw feedback rows we hold for you. As with the training corpus, we cannot remove data from a model that has already been trained on it, and we cannot undo product changes we made in response to feedback.
Anonymous analytics
We collect usage analytics to understand which features are useful and to improve the App. This data is anonymous: it carries no account identifier, no device identifier, and no precise timestamps, so it cannot be linked back to you or to any individual. We record coarse, aggregated signals only, for example that a feature or screen was used, on which day, and grouped into a temporary session, never the content of your messages, logs, or any personal detail.
Longer-term measures such as retention (how many people keep using the App over time) are computed on your device and reported only as anonymous, aggregated counts. We never receive a per-person timeline. To avoid singling anyone out, very small groups are not reported.
Because this data is anonymous and cannot identify you, it is not personal data under the GDPR and similar laws.
Your rights and choices
You can:
- Export your data via the in-app Export feature.
- Correct your data in the App, or by email.
- Delete your account in Settings, then Account, then Delete Account. We wipe what we have within 30 days, except records we are legally required or permitted to keep (a small number of records such as tax-relevant transaction history).
- Withdraw consent for crash reporting, marketing, or AI training at any time.
How to make a request. Email contact@fan-interactive.com. We respond within one month of receiving your request. Where a request is particularly complex or where we receive a high volume of requests, we may extend the response period by up to two further months and will tell you within the first month if we need to do so.
In-app controls. In Settings you can turn Crash reporting on or off (it starts off in the EU, EEA, and UK, and on elsewhere), turn off Help train Nudge's AI, and turn off Marketing communications.
If you live in a country with a data protection authority, you may lodge a complaint with it. If you live in California, the rights above apply; we do not sell or share personal information.
Security
- Data on your device is encrypted at rest using industry-standard encryption. The key is held only in your device's secure storage and is never transmitted to us.
- The cloud copy of your data is encrypted at rest by our database provider and isolated per account, so one account cannot read another's data. Our servers can read this data so the App can sync across devices, restore after reinstall, and let you recover via a normal password reset. We may ship an opt-in "advanced data protection" mode in the future that adds end-to-end encryption, with the trade-off that losing your recovery material would make the encrypted data unrecoverable.
- Data in transit between the App and our servers is encrypted.
- The App offers an optional App Lock with a password and/or biometric primary, plus required recovery: a set of three recovery codes (any two of which can unlock), and any of the optional account-based recovery paths you turn on: Account password recovery, Email recovery (one-time code sent to your account email), or having both password and biometric enrolled (each recovers the other). We do not hold a copy of your App Lock password or recovery codes. If you lose every recovery path you set up, we cannot restore access.
- Breach notification. If we become aware of a personal-data breach that is likely to result in a risk to your rights or interests, we will notify the relevant supervisory authority within 72 hours of becoming aware, and we will notify affected users without undue delay where required by law.
Children
Nudge is for users 13 and up. We do not knowingly collect anything from children under 13. If you believe a child under 13 has created an account, email us and we will investigate and remove the account if we determine it belongs to a child under 13.
If you are under 18 and using the App from California, we periodically show a reminder during long chat sessions that Nudge's responses are generated by AI, not by a person, and that taking a break is a good idea. The reminder is shown on your device based on time spent on the chat screen; we do not record when it appears.
Legal requests and safety
We may access, preserve, or disclose information we hold about you (a) to comply with applicable law, regulation, subpoena, court order, or other valid legal process, and (b) where we believe in good faith it is necessary to enforce our Terms; to detect, prevent, or address fraud, abuse, or security issues; or to protect the rights, property, or safety of our users, the public, or us.
Disclaimers
Medical. Nudge is not a medical service and is not a HIPAA-covered entity. The data you log and the responses the AI gives are for general information and motivation only. They are not a diagnosis, treatment, prescription, or professional recommendation. Talk to a licensed healthcare professional before starting or changing an exercise program, changing your diet, taking supplements, or acting on anything the App tells you, especially if you have a medical condition, are pregnant, or take medication.
AI output. AI output can be wrong, incomplete, biased, or fabricated. Generated images can fail to match what you asked for, and web search can surface unreliable sources. Do not rely on AI output for decisions that materially affect your health, finances, relationships, or safety without independent verification.
Crisis and safety limitations. Nudge is not a crisis service, a suicide-prevention line, or a substitute for emergency help, therapy, or professional care. The App includes a basic safeguard that tries to recognize messages suggesting a crisis (such as self-harm, suicidal thoughts, disordered eating, substance crises, or abuse) and, when it does, encourages you to contact appropriate professional help or a crisis line. This detection is automated, imperfect, and may miss a real crisis or respond to one that is not there. Never rely on the App in an emergency. If you are in danger or thinking about harming yourself or others, contact your local emergency services or a crisis line right away (in the US, call or text 988 for the Suicide and Crisis Lifeline).
Changes to this policy
We may update this policy as the App and the law evolve. For material changes, such as collecting a new category of personal data, using your data for a new purpose, sharing it in a materially less protective way, or reducing your rights, we will give reasonable advance notice (typically 30 days) through the App or by email before the change takes effect. Other updates take effect when posted.
The following are not, by themselves, material changes: expanding what we collect within an already-disclosed category, routine retention adjustments, swapping or adding a provider that serves the same purpose with comparable protections, and editorial clarifications. We may make these without advance notice.
Continued use of the App after a change takes effect means you accept the updated policy.