Nudge/Privacy Policy
Privacy Policy
Last updated: July 23, 2026
Overview
This Privacy Policy describes how Sam Ships (“we”, “us”) handles information in connection with the Nudge iOS app and related websites (collectively, the “Service”).
Nudge is built for stuck moments — turning a messy brain dump into one small next step. It is a wellness and productivity tool, not medical care, therapy, or an emergency service. We designed the product so raw thoughts are processed to help you start, not stored as a long-term diary of everything you typed.
This policy reflects how Nudge is designed and implemented. It is not legal advice. Practices may evolve as we ship; we will update this page when they do.
Who we are
Operator: Sam Ships
Contact: support@samships.com
Mailing address: Contact support@samships.com for operator mailing details
No traditional account
Nudge does not require you to create an email or password account to use the core rescue flow. The app creates an anonymous device credential (a random device identifier and session token) stored in the iOS Keychain so we can enforce free weekly limits, rate limits, and security controls on our servers. We do not use advertising identifiers (IDFA) for this purpose.
Information we process
Depending on how you use Nudge, we may process:
- Content you provide — typed or dictated “brain dumps,” and related rescue inputs. Text is sent over HTTPS to the Nudge API so the AI can choose one task and a tiny step. Raw dumps are not saved into your Starts history and are not intended to be retained by Nudge after the rescue is processed.
- Derived rescue data — selected task labels, tiny steps, shrink/next-step results, and short-lived rescue session state needed to continue an active rescue. On the device, “starts” you choose to keep live locally so you can look back kindly.
- Voice (optional) — if you use Voice, the microphone captures audio so on-device / system speech recognition can turn speech into text for the dump field. Nudge does not keep an audio library and does not send raw audio to the Nudge AI backend. Depending on Apple’s speech APIs and settings, audio or transcription may be processed by Apple. Typing always works if you deny mic or speech permission.
- Device & service identity — anonymous account/device IDs and session tokens used for authentication, quotas, and abuse prevention.
- Usage & quota data — free rescues used in the current week, Pro entitlement flags, rate limits, and related operational counters.
- Purchase information — App Store / StoreKit transaction and entitlement data needed to unlock Nudge Pro. Payments are processed by Apple; we do not receive your full payment card details.
- Preferences (on device) — timer defaults, reminders, onboarding state, optional display name, and privacy choices for system surfaces (widgets, notifications, Live Activities). These stay local unless needed to provide a feature you turned on.
- Operational diagnostics — technical logs such as request route, status code, latency, model or prompt version, and safety outcome labels. We design logging so raw dump text and personal free-text content are not written to application logs.
How we use information
We use the information above to:
- Provide the rescue flow (dump → one chosen task → tiny step)
- Shrink steps, advance to the next item, and show safe fallbacks
- Enforce free weekly limits and Pro access
- Prevent abuse, spam, and automated quota farming
- Route high-risk content to fixed safety responses (not ordinary task advice)
- Operate widgets, reminders, and Live Activities you enable
- Respond to support requests you send us
- Comply with law and protect the Service
We do not sell your personal information. We do not use your brain dumps to build a long-term personal profile or AI memory of you across rescues.
AI and model processing
When you run a rescue, the text of your dump (and related step context for shrink/next) is sent securely to Nudge’s servers and then to our contracted AI provider — currently OpenAI — to generate structured results (chosen task, tiny step, optional rationale, and related fields). The OpenAI API key lives only on the server; it is never embedded in the iOS app.
Nudge uses the model as a narrow transformation service, not as a general chatbot or clinical advisor. If input suggests crisis, immediate danger, or other high-risk categories, the Service may return fixed safety copy instead of ordinary task steps.
Provider processing is subject to that provider’s terms and data policies for API customers. We configure the integration for product use (generating steps), not so that Nudge can train its own models on your dumps. We do not claim zero retention by every subprocessor unless a specific zero-retention arrangement is in place and verified.
When AI is unavailable or free limits are exhausted, Nudge may offer an on-device or deterministic fallback so you still get a useful micro-step without sending additional text to the model.
Sharing of information
We may share information with:
- AI provider (OpenAI) — dump and step text needed to generate rescues
- Hosting & infrastructure — servers that run the Nudge API (e.g. cloud hosts such as Railway)
- Apple — for App Store distribution, in-app purchases, and system features you use (speech recognition, notifications, widgets, Live Activities)
- Professional advisors or legal authorities when required by law or to protect rights and safety
We do not use ad networks or cross-app tracking in the Nudge MVP. If we add product analytics later, events will use coarse product state only — not dump, task, step, notification, or widget free text.
System surfaces (widgets, notifications, Live Activities)
By default, Nudge aims to show neutral copy on shared or lockable surfaces (for example, “Nudge is with you” rather than your task text). More detailed step text on widgets, notifications, or Live Activities is only intended when you opt into showing details on those surfaces. You can change related preferences in the app under You → Voice & privacy (or equivalent settings).
Data retention
- Raw dumps — processed to create a step; not stored in Starts; not intended for long-term Nudge retention after processing
- Starts & preferences — kept on your device until you delete them or remove the app
- Active rescue session state — kept as needed to power shrink, next step, and continue during a rescue, then discarded according to normal session lifecycle
- Anonymous identity & quota — retained while needed to operate free limits and security; may be deleted on request or when no longer needed
- Purchase records — retained as required for entitlement checks and legal/accounting obligations (often via Apple’s systems)
- Operational logs — short technical retention (on the order of weeks for MVP diagnostics), without raw user free text
Your choices and rights
You can:
- Use Nudge without granting microphone or speech permission
- Deny or later change notification permission in iOS Settings
- Control what appears on system surfaces via in-app privacy settings
- Delete local history and preferences by clearing app data or deleting the app
- Email support@samships.com to request deletion of server-side device identity and quota records associated with your use of Nudge
- Manage or cancel Nudge Pro in iOS Settings → Apple ID → Subscriptions
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. Contact us to exercise those rights. See also Support.
Children
Nudge is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact support@samships.com and we will take appropriate steps to delete it.
International transfers
We may process information in the United States and other countries where our service providers (including hosting and AI providers) operate. Those locations may have different data protection laws than your home country. Where required, we rely on appropriate safeguards offered by our providers and applicable law.
Security
We use HTTPS for network traffic to the Nudge API, store device session secrets in the iOS Keychain, and design the app so the AI provider key never ships in the client. No method of transmission or storage is 100% secure; please use the Service with that understanding.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date.
Contact
Questions about privacy? Email support@samships.com.