Privacy Policy
Effective date: August 26, 2026
Nudge (“we,” “us,” “our”) is operated by Nudge. This policy explains what data we collect, why we collect it, who processes it, and how you can request access, correction, or deletion.
The short version
- Your essays remain yours. We do not sell your personal data or essay content. We process content only as needed to provide Nudge and support the service providers described below.
- Your work is not sent to colleges. We do not send your essays, drafts, questions, context, or account information to colleges, universities, admissions offices, or educational institutions. If a parent sponsors an account, the parent dashboard is limited to activity, progress, and calendar information; it does not show essay body text, drafts, private notes, or coaching.
- AI training is separate from AI processing. Coaching requests send relevant content to OpenAI’s API. OpenAI says API inputs and outputs are not used to train its models by default, unless a customer opts in. OpenAI may still retain content in abuse-monitoring logs for a limited period under its API policies.
- We do not sell your data. We do not sell personal data to advertisers, data brokers, or analytics resellers.
1. What we collect
| Data | Why we need it | How long we keep it |
|---|---|---|
| Account and identity data (name, email, account identifier, sign-in and security information) | Create and secure your account, provide access, and send transactional messages | While your account is active, plus periods required for security, support, legal, or provider records |
| Workspace content (essays, drafts, versions, prompts, context, notes, honors, references, attachments, ideas, questions, diagnostics, brainstorm messages, and related activity) | Store your work, provide coaching and research features, show progress, and avoid repeating work | While needed to provide the workspace. You can delete individual items where controls are available or request account-level deletion through the contact form; backups and provider records may persist for a limited period |
| Billing and purchase data (Stripe customer/subscription identifiers, plan, status, billing period, and payer details) | Activate access, manage subscriptions, process refunds, and provide billing support | Stripe handles payment-method details and may retain transaction records under its own policies and legal obligations |
| Support and contact data (name, email, message, reason for contacting us, and account identifier when available) | Respond to questions, deletion requests, refund requests, and other support needs | As needed to handle the request, maintain support records, and meet legal or security obligations |
| Technical and analytics data (pages, interactions, device and browser information, errors, cookies, local storage, and session activity) | Operate, secure, debug, measure, and improve Nudge | According to the settings and retention practices of the relevant analytics, hosting, and security providers |
| Optional feature data (for example, Google Calendar connection details, calendar events, extracted profile information, and college-research data) | Provide optional calendar, deadline, reminder, and research features that you choose to use | While needed for the feature or until you disconnect or request deletion, subject to provider backups and legal obligations |
2. How we use your essay content
When you request coaching, brainstorming, diagnostics, or college research, we send the relevant draft, prompt, approved context, or research information to OpenAI’s API to provide that feature. Nudge requests OpenAI not to store the API response as application state, but OpenAI’s API policies describe separate abuse-monitoring retention that may apply to API inputs and outputs.
- OpenAI’s API platform states that inputs and outputs are not used to train or improve OpenAI models by default, unless the customer opts in.
- Nudge stores questions, diagnostics, brainstorm messages, and other generated results in your workspace so the service can display history and progress.
- For reliability, usage, and cost monitoring, Nudge also records operator-only AI usage records that can include generated output and model, token, latency, error, and request metadata.
- We use OpenAI for the AI features described here. Infrastructure and analytics providers may process data as described in Sections 1 and 4.
3. How we share data
We do not sell your personal data or license it for another company’s advertising.
- Service providers. We share data with providers that host Nudge, authenticate accounts, process payments, send email, provide AI or optional integrations, or help us analyze and secure the service.
- Colleges and admissions offices. We do not send your essays, drafts, questions, context, or account information to colleges, universities, admissions offices, counselors, or other educational institutions.
- Other users. Your workspace is intended to be private to your account. Parent-sponsored dashboards are limited to the progress and activity information described above.
- Marketing. We do not use your essay content for marketing without your separate written permission.
- Legal and safety reasons. We may disclose information when reasonably necessary to comply with law, enforce our terms, prevent fraud or abuse, protect safety, or defend our rights.
4. Third-party services
We use the following providers or integrations, depending on the features and configuration you use:
- OpenAI — processes relevant content for AI coaching, brainstorming, diagnostics, and research. Its API policies describe default training and abuse-monitoring practices.
- Clerk — authenticates users and manages account identity data such as email and name. See Clerk’s privacy policy.
- Stripe — hosts checkout, processes subscriptions, and handles payment-method details. See Stripe’s privacy center.
- Supabase — hosts the application database and files, including workspace content and internal usage records. See Supabase’s privacy policy.
- Vercel — hosts the application and may provide analytics when enabled. See Vercel’s privacy policy.
- PostHog — may provide product analytics, error capture, and session replay. Signed-in analytics can be associated with your account identifier and may include email or name. Depending on page and configuration, entered text may be captured when it is not masked; we do not describe this data as anonymous.
- Resend — sends transactional and support-related email, including contact-form notifications, using the addresses and message details needed to deliver those messages.
- Google — if you connect Google Calendar, processes the calendar connection and event data needed for syncing. See Google’s privacy policy.
5. Data about minors
Nudge is designed for high school students and, under these terms, users must be at least 13 years old. We do not knowingly offer Nudge to children under 13 without any consent required by applicable law. If you believe a child under 13 provided us personal data, please use the contact form so we can review the situation and delete information where required.
6. Your rights and choices
You can, at any time:
- Request access or a copy of the personal data we hold about you.
- Request correction of inaccurate account or support information.
- Delete individual workspace items using available controls, and request account-level deletion.
- Disconnect optional integrations such as Google Calendar.
Use the contact form for a privacy request. We may need to verify the request. Some billing, support, security, fraud-prevention, legal, and provider backup records may need to be retained for a limited period.
7. Security
We use Clerk authentication, server-side ownership checks, and database access controls, including row-level security where applicable. Data is encrypted in transit using TLS, and we rely on our hosting and service providers’ encryption-at-rest controls where available. No service is perfectly secure. If we discover a security incident that requires notice, we will notify affected people as required by applicable law and may provide additional notice when appropriate.
8. Changes to this policy
We may update this policy as Nudge changes. We will update the effective date and, where required or appropriate, provide notice in the app or by email before a material change takes effect. The updated policy will apply prospectively, except where a different approach is required by law.
9. Contact
Questions, requests, or concerns? Use our contact form.