Legal
Effective date: 3 April 2026
Last updated: 3 April 2026
NudgeX ("we", "us", "our") is an email command centre that helps sales and recruitment professionals manage high-volume inboxes. NudgeX surfaces conversations that need attention, prioritises them, and drafts replies for your review. Nothing is sent without your explicit approval.
This Privacy Policy explains what personal data we collect, why we collect it, how we process it, who we share it with, and what rights you have. It applies to all users of nudgex.app and the NudgeX service.
Data controller: NudgeX, a general partnership (VOF) under the laws of the Netherlands
Contact: admin@nudgex.app
We collect data in four categories:
When you connect a Gmail or Outlook account, NudgeX syncs email threads from your inbox. Specifically, we collect:
NudgeX does not store email attachment binary content. When you attach files to outbound replies, the file content is transmitted through our servers to your email provider (Gmail or Outlook) and is not retained after the email is sent. We record attachment metadata (filename, file type, and file size) in your workspace's audit log for your records. Inbound attachment content is not accessed, processed, or stored — only metadata may be displayed for reference.
For Gmail, NudgeX targets your Primary inbox category. For Outlook, NudgeX syncs messages from your inbox folder. The specific messages processed may vary depending on your email provider's inbox configuration and settings.
From your usage of NudgeX, we generate operational metrics that are scoped to your workspace. These include:
These metrics are associated with your workspace and are used solely to improve how NudgeX prioritises and scores your queue. They constitute personal data under GDPR and are subject to the same rights and protections as your other data. When you delete your account, these metrics are deleted along with all other workspace data (see Section 7).
Every data type is tied to a specific product function:
Draft generation: Email body content
Content is sent to our AI provider (Anthropic) to generate a reply draft for your review. You approve, edit, or discard the draft before anything is sent.
Queue prioritisation: Email metadata and thread signals
Subject lines, timestamps, and thread signals are used to calculate which conversations need attention and in what order.
Intelligent prioritisation: Operational metrics
Workspace-scoped outcome data improves how NudgeX scores and ranks your queue over time. This data is not used for advertising or shared with third parties.
Service delivery: Account and workspace data
Required to authenticate you, enforce your preferences, gate your subscription, and tailor AI outputs to your communication style.
Service reliability: Usage and error data
Error logs allow us to identify and fix bugs. Interaction data informs product decisions.
We do not use your data for advertising. We do not sell your data. We do not use your data to train foundational or generalised AI models.
NudgeX accesses your email data through the Gmail API and Microsoft Graph API. Both are subject to their respective platform policies. Our use of Gmail data is subject to Google's API Services User Data Policy. Our use of Outlook data is subject to Microsoft's API Terms of Use.
The specific OAuth scopes requested are:
Gmail: gmail.readonly (read inbox), gmail.send (send replies), userinfo.email (identify your account).
Outlook: Mail.Read (read inbox), Mail.Send (send replies), User.Read (identify your account), offline_access (maintain connection).
NudgeX does not request write or modify access to existing messages on either platform.
We confirm the following:
NudgeX's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our use of Microsoft Graph API data adheres to Microsoft's API Terms of Use and applicable data protection obligations.
We use Sentry for application error tracking. Sentry captures stack traces, error messages, and basic request context. Session replay is disabled — Sentry does not record user screen activity or email content. If we enable session replay in the future, we will update this policy and implement content masking before doing so.
We share data with the following third-party processors and controllers in connection with the Service. Each processes only the data necessary to perform their function.
The following party acts as an independent data controller for data processed through its platform. NudgeX accesses only the scopes explicitly granted by the user.
Microsoft Corporation — Outlook email access
The following third-party processors act under our instruction.
Anthropic PBC — AI draft generation
Supabase — Database
Vercel — Application hosting
Clerk — Authentication
Stripe — Billing
Sentry — Error tracking
Upstash — Rate limiting
We do not share your data with advertising platforms, data brokers, or any entity not listed above.
Database backups are retained for 30 days. Deleted user data becomes unrecoverable after this period.
Operational metrics (see Section 2.2) are associated with your workspace and constitute personal data under GDPR. They are deleted when your workspace is deleted as part of account deletion. The right to erasure applies to this data.
Anonymised billing event records (with no workspace or user association) may be retained after account deletion for financial compliance and audit purposes. These records do not contain email content or personally identifiable information.
Stripe retains billing records as required by applicable financial regulations. This is outside our control.
If your account has been inactive for 12 consecutive months, we will notify you by email that your email content and associated workspace data will be deleted in 30 days unless you log in. If you do not log in within 30 days of this notice, your email content, threads, queue items, actions, operational metrics, and feedback will be permanently deleted. Your account and workspace configuration will be retained so you can reactivate and reconnect your inboxes at any time.
As a user in the European Economic Area or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR:
To request a copy of your personal data, email admin@nudgex.app with the subject line "Data Portability Request". We will compile and deliver your data in a machine-readable format (JSON) within 30 days.
To exercise any of these rights, contact us at admin@nudgex.app. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for NudgeX is:
If you are based in the UK, you may also contact the Information Commissioner's Office (ICO) — ico.org.uk.
We rely on the following legal bases under GDPR Article 6:
NudgeX is a professional tool intended for use in a business context. You must be at least 16 years old to use NudgeX. By creating an account, you confirm that you meet this requirement.
If we become aware that a user is under 16, we will delete their account and associated data immediately.
Your data is primarily stored in the European Union:
Some sub-processors are located in the United States:
Where data is transferred outside the EEA, we ensure appropriate safeguards are in place as required by GDPR Chapter V.
NudgeX uses only technically necessary cookies for authentication and session management (via Clerk). We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
We do not run any analytics beyond error tracking (Sentry). Sentry session replay is disabled — no user screen recordings are made.
No cookie consent banner is required for strictly necessary cookies under the ePrivacy Directive.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this document. For significant changes, we will notify you by email to the address associated with your account at least 14 days before the change takes effect.
Continued use of NudgeX after the effective date of a change constitutes acceptance of the updated policy.
For any questions, requests, or complaints regarding this Privacy Policy or our data practices:
We aim to respond to all privacy-related requests within 30 days.
NudgeX — nudgex.app