← nudge

privacy policy

nudge is one tap to say you're thinking of someone. it is built to keep almost nothing about you — just enough to deliver that tap to a friend.

last updated: 10 june 2026

the short version

nudge stores a display name you choose, the friend connections you make, and the push tokens needed to deliver a nudge to your devices. there is no email, no password, no message content, no advertising, and no third-party analytics. we never sell your data.

who we are

nudge is built by ogbuilds, a uk-based studio. this policy is governed by uk data-protection law (uk gdpr and the data protection act 2018). ogbuilds is the data controller for the personal data described here.

what we collect

  • a display name. when you join, you pick a first name (or whatever you want to be called). we do not ask for an email address or a password.
  • an invite code. each account gets a short random code so friends can connect to you.
  • friend connections. when you and someone else connect via an invite code, we store that you two are linked, plus a record of the nudges sent between you (who, to whom, and when). nudges carry no message text — there is nothing to write.
  • push tokens. if you enable notifications, we store the web-push subscription (from your browser) and/or the expo push token (from the native app) needed to deliver a nudge to that device.

that is the whole list. we do not collect your contacts, location, browsing activity, or device identifiers beyond the push token.

how we use it

we use this data for one purpose: to run nudge — to identify your account, connect you with friends, and deliver a nudge to their devices. we do not use it for advertising or profiling, and we never sell it.

legal basis (uk gdpr)

we process your display name, connections, and nudge records to provide the service you asked for (performance of a contract). we process push tokens on the basis of your consent — you choose whether to enable notifications, and you can turn them off at any time in your browser or device settings.

third parties / subprocessors

nudge relies on a small set of providers to run:

  • vercel — hosts the nudge web app and its api.
  • neon — the postgres database where your name, connections, nudges, and push tokens are stored.
  • web push services— your browser's push provider (for example apple, google, or mozilla) relays notifications to your browser.
  • expo push service — relays notifications to the native app on ios and android.

these providers process data only to deliver the service. there are no advertising networks and no third-party analytics in nudge.

cookies & local storage

when you join, nudge sets a single session cookie — a signed token that keeps you logged in. it is strictly necessary to use the app and is not used for tracking. the native app stores the same token on your device instead of a cookie. nudge contains no advertising or analytics cookies.

data retention

we keep your data while your account is active. dead push tokens are pruned automatically when a push service reports a device is gone. if you want your account and its data deleted, ask us via the studio link below and we will remove it.

your rights

under uk gdpr you can ask us to access, correct, export, or delete your personal data, and you can withdraw consent for notifications at any time (by disabling them in your browser or device, which stops new tokens, and we prune the old ones). to make a request, reach us via the ogbuilds studio. you also have the right to complain to the uk's information commissioner's office (ico).

international transfers

some of our providers (such as vercel, neon, and the expo push service) operate from the united states. where data is transferred outside the uk, it is protected by appropriate safeguards such as the uk international data transfer addendum or equivalent standard contractual clauses.

children

nudge is not intended for children under 13. we do not knowingly collect data from anyone under 13.

security

all traffic to nudge is encrypted in transit (https). your session token is signed, stored in an http-only cookie on the web, and your data is held in a managed postgres database with access restricted to the service. because there is no password and no message content, there is little sensitive data to expose.

changes

if this policy changes, we'll update the date above and, for material changes, note it on this page.

contact

questions? reach out via ogbuilds, the studio behind nudge.