Privacy Policy

Last Updated: March 11, 2026

1. Introduction

This Privacy Policy explains how Nudget ("we," "us," or "our") collects, uses, discloses, and safeguards your information when you access our AI-powered content subscription and monitoring service ("Service"). By using the Service, you consent to the data practices described in this policy.

2. Information We Collect

Personal Information

We collect your name, email address, and account credentials when you sign in via Google OAuth. If you subscribe to a paid plan, payment details are processed securely via Polar.

Content and Sources

We process content from your subscribed sources, including websites, YouTube channels, RSS feeds, social media profiles (Twitter/X, Threads, LinkedIn, Medium, Substack), and any other URLs you choose to monitor. We obtain read-only access to publicly available content solely for fetching and summarizing your subscriptions.

Usage Analytics

We use Mixpanel and Sentry to track user interactions, feature usage patterns, error logs, and device information to improve the Service.

Automatically Collected Information

When you access the Service, we may automatically collect certain information, including your IP address, browser type, operating system, referring URLs, and interaction data with the Service.

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract performance: Processing necessary to provide the Service you subscribed to (account management, content summarization, digest delivery)
  • Legitimate interests: Service improvement, analytics, fraud prevention, and security
  • Consent: Marketing communications and optional data processing where you have given explicit consent
  • Legal obligation: Compliance with applicable laws and regulations

4. How We Use Your Information

We use collected data to:

  • Provide and maintain the Service
  • Process content through AI services (OpenAI, Google Gemini) for summarization
  • Deliver personalized email digests
  • Manage your account and subscriptions
  • Improve service quality and user experience
  • Provide customer support
  • Detect, prevent, and address technical issues or abuse
  • Comply with legal obligations

5. Third-Party Services

We share data with the following categories of third-party providers:

AI Processing: Content is sent to OpenAI and Google Gemini solely for summarization purposes and is not used for training their AI models.

Payments: Polar handles payment processing securely. We do not store credit card details on our servers.

Authentication: Google OAuth and Supabase are used for secure user authentication.

Analytics & Error Tracking: Mixpanel (usage analytics) and Sentry (error monitoring) receive anonymized usage data and error reports.

Customer Support: Crisp is used for live chat support. Your name and email may be shared with Crisp when you initiate a conversation.

6. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States and other jurisdictions where our third-party service providers operate (e.g., Google Cloud Platform, OpenAI, Supabase). These countries may have data protection laws that differ from those in your jurisdiction.

Where required by applicable law, we ensure appropriate safeguards are in place for international data transfers, such as standard contractual clauses or reliance on the recipient's participation in recognized data protection frameworks.

7. Cookies and Tracking

We use cookies and similar tracking technologies to operate and improve the Service.

  • Essential cookies: Required for authentication, session management, and core functionality
  • Analytics cookies: Used by Mixpanel to understand usage patterns and improve the Service
  • Error tracking: Sentry uses cookies to capture error context and session replay data (only during errors)

You can control cookie preferences through your browser settings. Disabling essential cookies may impair the functionality of the Service.

8. Data Retention

Content is retained for up to one year for re-summarization capabilities, then automatically deleted. Account information persists while your subscription remains active. Upon account deletion, personal data is removed within 30 days, except where retention is required by law. You can request expedited deletion by contacting us at admin@nudget.app.

9. Data Security

We implement appropriate technical and organizational safeguards to protect your information, including encryption in transit (TLS) and at rest, access controls, and regular security reviews. However, no method of transmission over the Internet or electronic storage is 100% secure.

10. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your personal data
  • Portability: Request export of your data in a machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Restriction: Request restriction of processing in certain circumstances
  • Withdraw consent: Where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at admin@nudget.app. We will respond to your request within 30 days.

11. Region-Specific Disclosures

European Economic Area (GDPR)

If you are located in the EEA, you have the right to lodge a complaint with your local data protection authority. Our legal bases for processing are described in Section 3 above.

California (CCPA/CPRA)

California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell your personal information to third parties.

Republic of Korea (PIPA)

Korean residents have the right to access, correct, delete, and suspend processing of their personal information under the Personal Information Protection Act (PIPA).

12. Children's Privacy

The Service is not intended for users under 13 years of age (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child, we will take steps to delete it promptly.

13. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users via email within 72 hours of becoming aware of the breach, along with details of the breach and recommended protective measures. Where required by law, we will also notify the relevant supervisory authority.

14. Content and Copyright

We process only publicly available content. We do not claim ownership of any content submitted by users. For copyright-related concerns, please refer to our Terms of Service (Section 7, Copyright Complaints).

15. Do Not Track

The Service does not currently respond to "Do Not Track" browser signals. However, you can manage your tracking preferences through the cookie and analytics controls described in Section 7.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email and by posting the updated policy on the Service. Your continued use of the Service after such changes constitutes acceptance of the updated policy.

17. Contact

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at admin@nudget.app.