Privacy policy
Last updated: 22 July 2026 — Effective date: 22 July 2026
The French version is the reference version. This English version is adapted for international users and does not limit mandatory rights available under local law.
This policy explains how Nudge processes personal data through the asknudge.app website, the mobile application and support communications.
1. Data controller
Arthur Musso Fournier — sole trader (Entrepreneur individuel, EI)
Trading name: Nudge
Business address: 59 rue de Ponthieu, Bureau 326, 75008 Paris, France
Email: hello@asknudge.app
Nudge has not appointed a data-protection officer because that appointment is not currently required for its activities. Privacy questions may be sent to the email above.
2. How Nudge works
Nudge lets users select a screenshot or text to receive an automated analysis and suggested replies.
Nudge does not create a named user account. Conversations and results are stored locally on the device. Users may voluntarily enable backup to their private iCloud space. Selected content is sent to the AI service only when the user requests an analysis or generation.
Nudge does not sell personal information, display targeted advertising or track users across other companies’ applications or websites.
3. Information processed
3.1 User-selected content
Depending on the feature, Nudge processes selected screenshots, extracted text and messages, writing-style settings, generated analyses and suggestions, and history that the user chooses to keep.
Nudge does not automatically access the user’s entire photo library, messages, contacts or other applications. It processes content selected or entered by the user.
3.2 Technical and security data
Nudge processes random technical identifiers, integrity evidence provided by Apple, usage counters and, temporarily, a pseudonymised representation of the IP address. This information protects the service, prevents abuse, applies usage limits and verifies the application’s authenticity.
When an integrity check fails, Nudge may send a minimal technical diagnostic: the affected stage, an error category and numeric code, and the app and iOS versions. This diagnostic contains no screenshot, conversation, free-form error message or identifier in its payload and is used only to detect and correct security-related failures. Requests remain subject to the service’s technical protections and limits.
3.3 Subscriptions
To activate Nudge Gold and restore purchases, Nudge and its subscription-management provider process a subscription identifier, purchased product, subscription status, relevant dates and general purchase country. Apple processes payments; Nudge does not receive full payment-card or bank details.
3.4 Usage analytics
Nudge may collect limited events about onboarding, features used, operation outcomes, closed error categories, subscription tier and counts grouped into broad ranges.
Analytics are configured without named profiles, conversation content, screenshots, advertising or cross-app tracking. A technical property asks the provider not to enrich events using IP geolocation. Events nevertheless use a technical identifier generated by the SDK for operational purposes.
Users can disable analytics at any time under Settings → Usage analytics, without losing free or paid functionality.
3.5 Bug reports and support
When a user voluntarily submits the “Report a bug” form, the entered text, its length and general technical information may be sent to the tool used by Nudge to receive and analyse reports. The text may contain personal information if the user chooses to include it.
Users should avoid pasting complete conversations and should remove names, contact details or intimate information that is unnecessary to understand the issue.
Emails and technical identifiers voluntarily provided to support are processed to answer the request, diagnose a problem or handle a privacy request.
3.6 Website
The website does not use advertising or non-essential analytics trackers. Its hosting provider generates technical logs containing an anonymised IP address, request date, requested page and browser information to operate and secure the website.
4. Purposes, legal bases and retention
| Processing | Purpose | Legal basis | Retention |
|---|---|---|---|
| Screenshot, text, parameters and AI output | Provide the requested analysis or generation and resume a response after a network interruption | Performance of the requested service | Inputs are not stored in a Nudge application database. The output may be cached in Nudge’s cloud infrastructure only in encrypted form using a random key that is not persisted by the server and is temporarily retained by the app: normally deleted on acknowledgement, replayable for 15 minutes, with fallback deletion within no more than 25 hours. Temporary AI-provider processing remains as described in section 6 |
| Local conversations, screenshots and results | Display the history chosen by the user | Performance of the service | Until deleted in the app or erased from the device |
| Optional iCloud backup | Back up and restore information on the user’s devices | Voluntary activation and performance of the service | Until deleted by the user through Nudge or Apple |
| Technical identifier, counters and integrity evidence | Security, abuse prevention and free-use limits | Nudge’s legitimate interest in protecting the service | Challenges: 5 minutes; security keys and free quotas: 24 months after last activity; short limits: their window plus technical deletion period |
| Minimal integrity-failure diagnostic | Detect and correct an application-verification failure | Nudge’s legitimate interest in securing and maintaining the service | 30 days |
| Pseudonymised IP representation | Prevent attacks and excessive requests | Legitimate security interest | No later than 24 hours after the relevant rate-limit window expires |
| Usage analytics | Understand usage and improve the app | Nudge’s legitimate interest, subject to the right to object and applicable audience-measurement rules | 30 days |
| Voluntary bug report | Receive, understand and correct the issue | Legitimate interest in support and service improvement | 30 days |
| Subscription data | Activate Gold, verify entitlement and restore purchases | Performance of the contract | During the subscription relationship and then as required by the provider and applicable law |
| Support or privacy request | Respond and retain evidence of handling | Legitimate interest and legal obligation | While handling the request, then as needed for evidence and legal obligations |
| Website logs | Website operation and security | Legitimate interest | 8 weeks |
Information is deleted or anonymised when no longer required, subject to technical backups and legal retention obligations.
5. Information about other people
A screenshot may include another person’s messages, name, photograph, profile or other information. Nudge receives this information from content selected by the user, not from that other person.
Users must have legitimate access to imported content, limit submission to what is useful and, where reasonably possible, hide unnecessary names, photographs, contact information, sensitive data and intimate details.
Nudge must not be used to monitor, harass, threaten or impersonate another person, or otherwise infringe their rights.
6. Artificial intelligence
When an analysis or generation is requested, Nudge sends Microsoft, through Azure OpenAI Service, the screenshot or messages selected by the user, together with the writing-style or tone settings needed for generation. Microsoft processes this information to provide and secure the requested service.
Nudge does not use user screenshots, conversations or suggestions to train its own model. Under the commitments applicable to the professional service used, inputs and outputs are not used to train the provider’s general models.
The current configuration uses the provider’s standard abuse-monitoring system. Inputs and outputs undergo automated real-time review. Where content or behaviour is flagged as potentially abusive, a sample may be retained temporarily within the provider’s environment and reviewed by authorised personnel under its applicable documentation and terms. Nudge does not enable an AI-service feature intended to maintain a persistent conversation history.
Before the first transmission, the app identifies the information being sent and Microsoft Azure OpenAI, then asks for the user’s permission. Users may decline without any information being sent and may later withdraw permission in the app’s privacy settings. AI outputs may be inaccurate, incomplete, awkward or unsuitable. They are not professional advice and do not make legal or similarly significant decisions about users.
7. Local storage and iCloud
Conversations, screenshots and results retained in the app are encrypted in local device storage.
iCloud backup is disabled by default. If enabled, the information listed on the activation screen is synchronised to the private iCloud database associated with the user’s Apple Account. Structured content uses CloudKit protection mechanisms, and Nudge encrypts image files before upload.
Nudge has no interface allowing it to browse the user’s private iCloud space. Users can disable backup, delete the remote copy, or erase local and remote information through the app. Disabling backup without choosing deletion does not necessarily remove an existing iCloud copy.
8. Recipients and providers
Information is disclosed only as needed to Microsoft through Azure OpenAI Service for the requested analysis and its security, the usage-analytics and bug-reporting provider, the subscription-management provider, Apple for App Store, security and iCloud functions, the website host, and legally authorised authorities.
Providers are selected with regard to available safeguards and are governed by their contractual terms or data-processing agreements. They must provide protection for shared information that is at least equivalent to the protection described in this policy and may process it only for the relevant services, subject to their own legal obligations.
9. International transfers
Some providers or subprocessors may process information in the United States or other countries outside the European Economic Area.
Where required by the GDPR, transfers rely on an adequacy decision, the recipient’s participation in the EU–US Data Privacy Framework where applicable, European Commission standard contractual clauses, or another recognised safeguard. Further information may be requested at hello@asknudge.app.
10. Security
Nudge uses measures appropriate to the information involved, including encrypted communications, protected local storage, encrypted iCloud screenshot backups, integrity controls, pseudonymisation of certain technical data, retention limits and access controls.
No system can guarantee absolute security. Suspected incidents involving Nudge may be reported to hello@asknudge.app.
11. Privacy rights
Subject to applicable conditions, individuals may request access, correction, deletion, restriction, portability of information they provided, objection to legitimate-interest processing, withdrawal of consent where relevant, and information about international-transfer safeguards.
Much of the information remains under the user’s direct control in the app or iCloud account. Because Nudge has no named account, locating some technical records may require the support identifier shown in the app. Identity evidence will be requested only where reasonably necessary and proportionate.
Requests may be submitted to hello@asknudge.app. Nudge responds within the legally required period, generally one month under the GDPR, subject to permitted extensions for complex requests.
Individuals in the European Economic Area may complain to their local supervisory authority or the French Commission Nationale de l’Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.
12. Children
Nudge is intended only for people aged 16 or older and is not designed for younger children. Nudge does not seek to knowingly collect their information.
A parent or guardian who believes that a person under 16 submitted information to Nudge may request deletion at hello@asknudge.app.
13. Changes
This policy may change to reflect updates to the service, providers or law. The date at the top will be updated. Material changes will be communicated in the app or by another appropriate method before taking effect where required.
14. Contact
Privacy questions and requests: hello@asknudge.app.