Privacy Policy
Effective date: 1 June 2026 Data controller: Riverbank Solutions Ltd, registered in Kenya. Trade name: Nudgey. Contact: legal@nudgey.app (or postal address: Riverbank Solutions Ltd, Silverpool Office Suites, Suite B31, Jabavu Lane, Hurlingham, P.O. Box 50633-00100, Nairobi, Kenya)
1. What we collect
On your device (never leaves your phone)
Nudgey learns how your money moves from your phone, on-device — nothing leaves it. To do that, on your device only it reads and processes:
- Your M-Pesa, bank, and sacco messages — the content + sender address of the financial messages your providers send you (read and processed entirely on-device; never uploaded).
- Your in-app activity (which cards you swipe, when you open the app).
- Your salutation preferences + first name (you provide these at onboarding).
- Encrypted local database holding everything Nudgey infers from the money activity it reads on your phone.
In our cloud
- Your phone number (for OTP-verified sign-in).
- Your email address (if you choose to provide one).
- Your Mode 2 chat messages (only if you've opted into AI Cards / Premium).
- Anonymized money insights (we'll explain below).
- Audit-log entries when admin actions happen on your account (e.g., a DSAR delete).
2. What "anonymized money insights" means
When Nudgey's local AI surfaces an insight ("you spent KSh 5,200 on food this week"), the insight itself can cross to our cloud — but ONLY in a form that strips identifying detail:
- No raw message body.
- No raw transaction amount (categories like "food this week" are passed; raw amounts are stripped).
- No counterparty names or phone numbers.
- No date precision finer than week.
The full list of what is allowed to cross is in our public Foundation Privacy Boundary spec (S0 §4.2).
3. How we process
- On your phone: Nudgey learns how your money moves from your phone, on-device — nothing leaves it. Your financial messages are classified by an on-device classifier (no cloud), then read by an on-device LLM (Gemma 3 1B running locally via LiteRT-LM — nothing leaves the device for this parsing), producing insights cached in an encrypted local SQLite database (SqlCipher).
- In our cloud: anonymized insights aggregate to weekly Sunday Drops + Salary Period Stories (if you've opted in). Mode 2 chat messages route to our LLM endpoint via Firebase only with your explicit consent (the AI Cards / Premium opt-in).
4. Sub-processors
- Clerk (USA) — authentication for our internal operations console. https://clerk.com/legal/privacy
- Vercel (USA) — hosting our marketing site, OTP endpoint, and operations console. https://vercel.com/legal/privacy-policy
- Firebase / Google Cloud (USA) — Firestore for cloud-side state, Firebase Auth for user sign-in, Remote Config for feature flags, Firebase Cloud Messaging for kill-switch broadcasts. https://policies.google.com/privacy
- Resend (USA) — sending OTP emails + DSAR confirmation emails. https://resend.com/legal/privacy-policy
- Upstash (USA) — Redis for OTP-pending state. https://upstash.com/static/trust/privacy.pdf
- Twilio (USA) — phone-number OTP delivery. https://www.twilio.com/legal/privacy
- ZED Kenya (Kenya) — M-Pesa STK push processor for Premium subscription payments. Receives your phone number + payment amount when you start a Premium subscription; returns payment confirmation via webhook to nudgey-api. The only Kenyan sub-processor in our stack (matters for ODPC data-sovereignty review). Privacy policy at https://www.zed.co.ke/privacy (verify URL at publish time).
5. Your rights
You can:
- Access: see what we hold about you (email legal@nudgey.app).
- Delete: request full erasure (data subject access request — DSAR). We wipe Firestore, Firebase Auth, Upstash OTP keys, Twilio Verify sessions, and confirm via email. Your device wipes its local Drift database on next launch.
- Object to processing: stop using AI Cards / Mode 2 at any time. Your local Nudgey continues to work without them.
- Lodge a complaint: to the Office of the Data Protection Commissioner (ODPC) of Kenya.
6. Data retention
- User data: deleted on DSAR; deleted automatically on account deletion.
- OTP records: 5-minute TTL.
- Anonymized insights in cloud: retained while you have an account; deleted on DSAR.
- Admin audit log: retained indefinitely (required for ODPC investigation support).
7. Security
- Encrypted local database (SqlCipher with device-keystore-derived key).
- HTTPS-only for all cloud calls.
- Clerk-managed admin session security.
- Firebase Security Rules + admin-SDK-only paths for sensitive collections.
- No raw PII stored in audit logs.
8. Data breach notification
If we discover a data breach affecting your personal data, we will notify:
- The Office of the Data Protection Commissioner (ODPC) within 72 hours.
- You directly via email + in-app notification within a reasonable timeframe given the nature of the breach.
9. Changes to this policy
We may amend this policy. Material changes will be announced via in-app notification + updated effective date. Continued use after a change indicates acceptance.
10. Contact
- Email: legal@nudgey.app
- Postal: Riverbank Solutions Ltd, Silverpool Office Suites, Suite B31, Jabavu Lane, Hurlingham, P.O. Box 50633-00100, Nairobi, Kenya
- ODPC complaints: https://www.odpc.go.ke/
This policy reflects Nudgey V1.0 (effective date 1 June 2026).