We don't sell your data, we don't train models on it, and we let you export it any time. Here's how we handle it, in full.
Nudgile (“Nudgile”, “we”, “us”, “our”) is a collaborative sprint retrospective tool available at nudgile.com, including our web application, API, MCP server, and command-line interface (together, the “Service”).
This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
Beta notice: Nudgile is currently in beta. Features, data practices, and this policy may change as the product develops. We will update this page and, where changes are significant, notify you by email or in-app notice.
The data controller for personal data processed through the Service is Nudgile, a business based in the United Kingdom.
For any privacy-related questions or to exercise your rights, contact us at privacy@nudgile.com.
When you create an account, we collect:
If you sign in with Google, we receive your name, email address, and profile picture from Google in accordance with the permissions you grant. We do not receive your Google password. Google’s processing of your data is governed by Google’s Privacy Policy.
The core of the Service is the content you and your team create: boards, columns, notes, votes, comments, discussion outcomes, and action items (“Retro Content”). Retro Content may include personal data — for example, notes that mention colleagues by name, or action items assigned to a named owner.
Notes are anonymous to other board members during the brainstorm and voting phases and become attributed to their author once the discussion phase opens. Attribution data (who wrote what) is stored throughout, even while a note is displayed anonymously.
If you mint a personal access token (PAT) to use the API, MCP server, or CLI, we store the token (hashed), its scopes, and metadata about its use. We log API activity — including the actor, action, and timestamp — to provide the audit trail that is part of the Service.
When you use the Service we automatically collect technical data such as IP address, browser type, device information, pages visited, and timestamps. We use this to operate, secure, and improve the Service.
We use cookies, browser local storage, and server-side sessions to keep you signed in, remember your preferences, and keep the Service secure. See section 7 for details.
Under UK GDPR we must have a lawful basis for each use of your personal data:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and managing your account; providing the Service | Account data, Google sign-in data, Retro Content, tokens | Contract (Art. 6(1)(b)) — necessary to provide the Service you signed up for |
| Authentication, session management, and security | Account data, technical data, cookies/sessions, token logs | Contract and legitimate interests (Art. 6(1)(f)) — keeping the Service and your account secure |
| AI-powered insights (see section 4) | Retro Content | Contract — insights are a core feature of the Service; and legitimate interests in improving team retrospectives |
| Audit trail of board and API activity | Account data, API activity logs | Legitimate interests — providing the accountability and audit features the Service advertises |
| Service emails (e.g. security alerts, important changes) | Email address | Contract and legitimate interests |
| Product news and marketing emails (if any) | Email address | Consent (Art. 6(1)(a)) — you can opt out at any time |
| Improving and debugging the Service | Technical and usage data | Legitimate interests |
| Complying with legal obligations | Any relevant data | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can object to processing based on legitimate interests (see section 10).
Nudgile includes AI-powered analysis of your team’s Retro Content. The AI runs once per retrospective and analyses your team’s boards over time to surface recurring themes, sentiment trends, and stale action items. This means Retro Content — which may include personal data such as names mentioned in notes — is processed by the Azure OpenAI Service, provided by Microsoft within our Azure environment.
We do not use your Retro Content to train AI models, and Microsoft does not use data submitted to the Azure OpenAI Service to train its models. Insights are only shown to members of the relevant team (or, on applicable plans, organisation).
We do not sell your personal data. We share it only with:
All processors act under contracts that meet UK GDPR Article 28 requirements.
We use the following technologies:
ai_user and ai_session) and collects telemetry to help us understand how the Service is used and to monitor performance and errors. These are not used for advertising.We do not use advertising or cross-site tracking cookies.
You can clear cookies and local storage through your browser settings; doing so will sign you out and may reset your preferences.
Your data is stored on Microsoft Azure in the West Europe (Netherlands) region. This means your data is transferred from the UK to the European Economic Area, which is permitted under the UK’s adequacy regulations recognising the EEA as providing adequate protection.
Some of our processors may process data outside the UK and EEA — for example, Resend is a US company. Where this happens, we ensure an adequate level of protection through UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
Under UK GDPR you have the right to:
To exercise any of these rights, email privacy@nudgile.com. We will respond within one month.
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO) — ico.org.uk or 0303 123 1113. We would appreciate the chance to address your concerns first.
We take security seriously. Measures include: passwords stored as salted hashes; encryption in transit (TLS) and at rest; scoped, revocable personal access tokens; automatic revocation of leaked tokens via GitHub secret scanning; and access controls and audit logging across the Service. No system is perfectly secure, so please use a strong, unique password and protect your tokens.
If we become aware of a personal data breach that risks your rights and freedoms, we will notify the ICO and, where required, affected users in line with our UK GDPR obligations.
The Service is intended for use at work and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
We may update this policy from time to time, particularly during the beta. We will post the updated version on this page with a revised “Last updated” date and, for material changes, notify you by email or in-app notice.
Nudgile
Email: privacy@nudgile.com
Mint a token in 30 seconds. No credit card.