Effective 27 August 2026
Privacy Policy
Nudge Money ("Nudge", "we", "us") helps you understand your personal finances. This policy explains how we handle information when you use Nudge.
Information we collect
We collect information you provide, such as your email address when joining the waitlist or contacting us. If you choose to connect Gmail, we request only the read-only Gmail scopegmail.readonlyafter showing an in-product disclosure and receiving your explicit consent.
Nudge checks message metadata first and fetches content only for relevant, allowlisted financial messages—such as card statements and transaction alerts—that pass sender, subject, issuer, and authentication checks. We do not copy or store your entire mailbox, and unrelated mailbox content is not ingested.
How we use Google user data
Gmail messages, selected attachments, and financial facts derived from them are used only to provide your personalized, user-facing financial analysis and present it to you. Nudge does not use Google user data for advertising, resale, data brokerage, creditworthiness or lending decisions, or generalized AI or model training.
Gmail data and derived financial data remain within Nudge-controlled systems. No external AI provider receives them. Nudge does not permit routine human reading of personal email; human access is restricted to exceptional cases allowed by Google policy, such as with specific user consent, for security, or to comply with law.
Nudge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Storage and retention
OAuth credentials, mailbox identifiers, selected provider identifiers, and approved source artifacts are encrypted or cryptographically protected. Selected source artifacts may be retained in encrypted Nudge-controlled storage for processing and reconciliation for no longer than 90 days, then deleted.
Encrypted internal reference records and derived financial records may be retained after a source artifact is deleted when needed to operate the service, maintain security and audit integrity, reconcile your analysis, comply with law, or handle a deletion request. We do not claim that disconnecting Gmail automatically deletes all historical financial records.
Disconnecting and deletion
You can disconnect Gmail from Nudge. Disconnecting stops future collection, stops the Gmail watch, revokes Nudge's Google authorization, and removes stored OAuth token and PKCE material. You can also revoke access at any time from your Google Account permissions.
To request deletion of historical source or derived data, emailnaman@getnudged.moneyfrom the address associated with your Nudge account. We may retain information where required for security, fraud prevention, legal obligations, or dispute resolution, and will explain any applicable exception.
Sharing and service providers
We do not sell personal information. Infrastructure and security providers may process limited data on our behalf under contractual and technical controls, solely to operate Nudge. We may disclose information when required by law or to protect users, Nudge, or the public.
Security and changes
We use HTTPS, encryption, managed keys and secrets, least-privilege access, authenticated service delivery, bounded attachment processing, and operational monitoring. No system is perfectly secure, but we continually review these controls.
Nudge is not intended for children under 18. We may update this policy as the service or law changes. We will post the revised policy here and update the effective date.
Contact
Questions, privacy requests, and support: naman@getnudged.money