Last updated: September 7, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells you about Your privacy rights and how the law protects You.
We use Your data to provide and improve Our Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Nudge Care Ltd, registered in England and Wales no. 16418291, 66 Paul Street, London EC2A 4NA, United Kingdom. Contact for anything in this policy: contact@nudge.care.
We are a UK company, and this policy is written to the UK GDPR and the Data Protection Act 2018.
These words mean the same thing everywhere in this policy. They are set out once here so the rest
stays short.
Nudge Care, we, us, our: Nudge Care Ltd, whose details are at the top of this policy
You, your: The person reading this. Which part of the policy applies to you depends on how you use Nudge Care .
Controller: The organisation that decides why and how personal data is used, and is answerable for it. Rights requests go to the controller
Processor: An organisation that handles personal data on a controller's instructions, and may not use it for its own purposes
Your clinic, practice: The healthcare provider that holds your health record and, where relevant, invited you to the patient portal. A separate organisation from Nudge Care.
The app: The Nudge Care mobile app, which you use for your own health
The Clinic Copilot: The Nudge Care application clinicians use alongside the clinical systems they already work in
The patient portal, the portal: The Nudge Care application through which a patient invited by their clinic can see their own information
Your health record: The record of health information held about you. Where a clinic invited you, your clinic holds and controls it
Personal data: Any information that identifies you, or that could be linked back to you
Health data: Personal data about your health. The law calls this "special category" data and protects it more strictly
Anonymised: Stripped of everything that could identify anyone, so that it can no longer be traced back to a person, by us or by anyone else. Anonymised data is not personal data
Our role, and therefore who you go to about your information, depends on how you use Nudge Care. Find your row, then read the parts it points to.
If you:
Signed up to Nudge Care to use the app for your own case, we are the controller. Read sections: A.1–A.2, C, D.
Signed up to Nudge Care as a doctor or clinic staff member, we decide how your data is for your account. Your clinic controls the patient records you work with and manages your access. Read sections: A.1, A.3, B (for the records), C, D.
Did not sign up, your record reached us through your clinic, and you may have been invited to see it in the portal .Your clinic is the controller and we are the processors, we act on their instructions. Read sections: B, C, D.
Are a visitor of our website, read sections: A.6, C, D.
What is in this policy:
Part A. Where we are the controller: what we collect, why, how long we keep it, and the website
Part B .Where your clinic is the controller and we act on their instructions
Part C. How we handle information whichever part applies to you: our suppliers, where it is processed, what we do and never do with AI, how we protect it, the emails we send, and when we may have to disclose it
Part D. Your rights, and where to send a request
This part applies where we decide the purposes, so your rights are exercised directly with us (Part D). It covers two quite different uses, plus visitors to our website.
A.1 Who this part covers
A.1.1. If you signed up to Nudge Care, this policy governs your account, whether you signed up as an individual to look after your own health, or as a doctor or clinic staff member. Your account is between you and us.
A.1.2. That is different from a patient record that reaches us from a clinic. Those records belong to the clinic, we handle them on the clinic's instructions, and the clinic's own privacy notice applies to them. That is Part B.
A.1.3. Two different ways to use Nudge Care:
Using the app for yourself. You download the app, create your own profile, and build a health record you own; your results, your history, and activity data if you connect it. Nothing here involves a clinic unless you choose to share with one. What we collect is in A.2.
Using Nudge Care as a clinician. You use the Clinic Copilot, may be invited into a clinic, and work with your clinic's records inside the systems you already use, such as Semble or Cliniko. You are not building a health record of your own. What we collect about you is in A.3, and it is a short list. The patient records you work with are not yours and not ours: your clinic controls them, which is Part B.
A.1.4. The same person can do both, under one login, based on the application they are accessing each time. They stay separate: the personal health information described in A.2 is not collected for a clinician account, and is not visible in the Clinic Copilot, the patient portal or any clinical tool. If you use the app for your own health as well, that record is yours alone and sits on the app side.
A.2 What we collect if you use the app for yourself
A.2.1 Account data. First and last name, email address, phone number. Your email is used to run your account; sign-in, blocking and unblocking, and handling requests such as data downloads. If you would rather not give us an email that identifies you, you can sign in with Apple, which lets you use a private relay address.
A.2.2 Profile data used to make the service work. Date of birth and sex at birth (used to select the right reference ranges and prevention checklist), and optionally height and weight (used for BMI).
A.2.3 Health data you choose to give us, all of it optional, and all of it deletable by you at any time:
documents you upload, such as laboratory and diagnostic reports, and the biomarker values extracted from them;
history you enter: diagnosed conditions, surgeries, family history, medication, allergies, and lifestyle information such as smoking and alcohol;
activity and physiological measurements synced from Apple Health or Google Health Connect where you grant access: respiratory rate, blood oxygen, blood pressure, body temperature, weight, body fat, heart rate, steps, sleep, VO2 max, cycling distance;
the analysis, insights and checklists we generate from the above.
A.2.4 Usage and device data. IP address, device and browser type, operating system, device identifiers, pages visited, time spent and interaction logs, and diagnostic data.
A.3 What we collect if you are a clinician or work for a clinic
A.3.1 We collect only what is needed to run your professional account:
your full name, email and role;
which clinic or clinics you belong to;
sign-in records and how you use the product;
the fact that you have connected an external record system, and the API credential that makes the connection work if you are the owner of the clinic.
A.3.2 We use it to run your account, keep the service secure, support you and bill your practice. We also use it, and statistics derived from it, to understand how the product is used, find and fix faults, and decide what to build next. That is our legitimate interest in running and improving a product you rely on. It is not used to assess you individually, to report on your performance to your clinic, or to make any decision about you. If you would rather we did not use your account activity this way, write to us at contact@nudge.care and tell us. We will stop unless we have compelling grounds not to.
A.3.3 Your clinic manages your access to its workspace. It does not control your account. A clinic can add you, remove you, and end your access to its patient records at any time; that is access management, and it is theirs to do. What we hold about you, why we hold it and how we look after it is set out in this Part A and is a matter between you and us. If you leave the clinic, your Nudge Care account remains yours, and you can close it under Part D.
A.3.4 We do not build a health record for you. We do not ask for your date of birth or sex at birth, we do not collect activity or wearable data from you, and none of the health information in A.2 is collected for a clinician account. The patient records you work with belong to your clinic and are covered by Part B, not this part.
A.4 Why, and on what legal basis
A.4.1 Everything we do with your information has to rest on a legal basis. Here is what we do, and why:
Create and run your account, and provide the app, to give you the service you asked for
Process your health data to build your record, to analyse results and generate insights, this is the service
Keep the service secure, prevent abuse, fix faults, to run it safely and reliably
Review a sample of questions asked of the assistant, and the answers given, to catch unsafe or wrong answers and improve them, based on our legitimate
interest in a safe and accurate serviceCollect anonymized analytics to understand how the service is used, in aggregate, and improve it and make the product better, safer and better performing
Send you service emails: sign-in and security, planned maintenance, changes to our terms or this policy, replies to your requests, to use the service safely, and some are required by law
Send you our mailing list, news and product updates , to learn what's new, only if you asked for it
Meet our legal obligations, and establish or defend legal claims
A.4.2. Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and you can object at any time (Part D).
A.4.3. Your explicit consent to health-data processing is separate from accepting our terms. We ask for it before we process health data, we record it, and you can withdraw it, after which we stop and you can delete the data. Withdrawing it means we cannot provide the parts of the service that depend on it.
A.5 How long we keep it
A.5.1. We keep data for the following periods:
Account and health data, while your account is open. Delete your account and it is permanently deleted from live systems, and copies age out of encrypted backups within 90 days
Data you delete inside the app, removed from live systems on deletion, and from backups within 90 days
Usage and diagnostic data, 36 months
Records we must keep by law (for example financial records), for the period the law requires, and no longer
A.5.2. Deletion is irreversible. We cannot restore data after it is deleted.
A.6 Website and cookies
A.6.1. Cookies are small files placed on your device that let a site work, remember your choices, or measure how it is used. We use three kinds:
Strictly necessary: needed for the site or the apps to work and to keep you signed in. These are always set; without them the site does not function.
Preference: remember choices you make, including your cookie settings, so you are not asked again each visit.
Analytics: tell us, in aggregate, how the site is used so we can improve it.
A.6.2. Some cookies are session cookies, deleted when you close your browser. Others are persistent and stay until they expire or you delete them.
A6.3. Only strictly necessary cookies are set without asking. Everything else is set only if you accept it in the cookie banner, and you can change or withdraw that choice there at any time. You can also block or delete cookies in your browser settings, though parts of the site may stop working if you do.
A6.4. The tools that set non-essential cookies, or that we use to run the site, are PostHog, Firebase, Brevo and Framer; each is listed in C.1.
This part applies to patient records that reach us through a clinic, imported from the record system the clinic already uses, such as Semble or Cliniko, or entered by its clinicians, and to the people those records are about, including anyone the clinic invites to see their own record in the portal.
If you signed up to Nudge Care yourself, Part A applies to your account instead; this part still describes the records you work with as a clinician.
B.1 Your clinic decides; we act on their instructions
B.1.1. Your clinic is the controller of your health record, however it reached us; imported from their record system or entered by their clinicians. They decide what is recorded, why, and how long it is kept, under a written agreement that requires us to process it only on their instructions and to keep it secure. Nudge Care does not decide what happens to your record, and does not use it for its own purposes.
B.1.2.Your clinic is responsible for giving you its own privacy information. This policy tells you what we do as their processor.
B.2 What we do with your record, and what we do not
B.2.1 What we do. We store it, extract structured information from uploaded documents, generate analysis and insights, make it available to the clinicians your clinic authorises and to you through the portal upon clinical staff's validation, and keep it secure.
B.2.2 Three further things are covered by our agreement with your clinic, and are limited in what they allow:
Statistics that identify no one. We produce aggregated, anonymised figures, like how often something is used, how well it performs, where it fails, and use them to improve the service and to build features. We do not attempt to reverse it, and no clinic or patient is identifiable in anything we publish or share.
Analysis your clinic asks for. Your clinic may use features that analyse its own records to show how the practice is performing and where there are gaps. We produce that for your clinic, from your clinic's own data, and give the result back to them. It is not used to serve another clinic.
Fixing faults. Occasionally we need to look at real data to diagnose a problem, an extraction that failed, a report that did not render. We do that only when anonymised or test data would not answer the question, only to the minimum extent needed, only by named staff bound by confidentiality, only inside our EU environment, and never to build something for another customer.
B.2.3 What we never do: train AI models on it (C.3), sell it, use it for our own marketing, or share it with anyone other than the suppliers in C.1 who help us run the service.
B.3 How long it is kept
B3.1. Your clinic decides. Retention of your health record is their decision, and they may have professional or legal duties to keep medical records for a period. Ask your clinic how long they keep records. We hold the data for as long as your clinic instructs, and delete or return it when their agreement with us ends.
B.4 Where your requests go
B.4.1. Your clinic is the controller, so requests about your information go to your clinic; access, correction, erasure, objection, a copy. We are not permitted to answer them ourselves, or to confirm to anyone else that we hold information about you. Part D sets out the detail.
B.4.2. Ending your access works the same way: ask your clinic and they will close your profile. Your clinic gave you the access, so your clinic removes it; and whether your health record is deleted as well is their decision.
C.1 The systems and suppliers we use
C1.1. Suppliers. The same systems serve both the app and the portal.
Microsoft Azure (Microsoft Ireland Operations Ltd): hosting, database, storage of uploaded documents, and the AI processing described in C.3.
Receives: All platform data, including health data. Where: EU
PostHog: error monitoring, performance and product analytics.
Receives: Pseudonymised technical and usage data. No health data, no screen capturing. Where: EU
Brevo: our mailing list, news and product updates.
Receives: Your email address and name. No health data, and no data from the app or the portal. Where: EU
Google Drive: used to handle internal collaboration, but also contact form inputs from the website. No user, no health data stored. Where: EU
Google Firebase: signing you in and keeping your account secure.
Receives: Your account identifier, email address and sign-in records. No health data. Where: USA
Apple Login: sign in with Apple, if you choose it.
Receives: Authentication, and a relay email address if you use one. No health data. Where: USA
Twilio SendGrid: service emails, including sign-in, security, maintenance notices, changes to our terms.
Receives: Your email address and the content of the message. No health data. Where: USA (with EU sub-processors)
Framer: our public marketing website.
Receives: Nothing, only Cookies for operational reasons. No health data, and nothing from the app or the portal. Communication goes to Google Drive. Where: EU / global CDN
C1.2. Every supplier here is bound by written data protection terms, may use the data only to provide the service to us, and is reviewed before we engage them.
C.2 Where your information is processed
C.2.1 Your health data does not leave the European Union. Your account, the documents uploaded, the results, the AI processing performed on them, and our backups are all held and carried out in the EU. That includes the AI, see C.3.
C.2.2 Some account and website data is processed outside the EU. Health data never is. Specifically: your account identifier and email address, held by our sign-in provider; an authentication assertion, if you sign in with Apple or Google; your email address and the content of any service email we send you; and visit data from our public website. None of these involves your health record, your documents or your results.
C.3 AI: what it does, and what we never do with your data
C.3.1 Where the AI runs. All AI processing happens inside our own Microsoft Azure environment in an EU region. We use more than one model, and which models and versions we use changes over time as better ones become available.
Some of those models are built by other companies. That does not mean those companies get your data. The model runs in our environment.
C.3.2 What we never do:
We do not train AI models on your data, ours or anyone else's, and neither do the developers of the models we use.
We do not send your data to a third-party AI service to be processed.
We do not sell your data, and we do not use it for advertising.
C.3.3 If this ever changes, it changes only by agreement obtained first. Any new use of your data for training, or any AI service that would process it outside the EU, would need agreement in advance: from you, and where a clinic is the controller of the record from that clinic as well. We would ask you before it happened, update this policy first, and not proceed for anyone who had not agreed.
C.3.4 This does not restrict the use of anonymised data. Models can be built and tested on data that identifies nobody, and that is not personal data.
C.3.5 We may use aggregated, anonymised statistics, which cannot identify anyone, to operate and improve the service, communicate progress to the board and investors (candidate or existing ones), or to prospects.
C.4 How we protect it
C4.1. Encryption of everything we send across a network and everything we store, including backups; role-based access on least privilege; separation of each clinic's data; encrypted backups in the same EU region; logging, monitoring and a documented incident response process; confidentiality obligations and training for everyone with access; and and written data protection terms with every supplier in C.1. We keep this summary short on purpose; we can provide more detail on request, and clinics receive the full description of our security measures with their agreement.
C4.2. No online service can be completely secure, but if a breach affects your data we will act on it and notify whoever the law requires, within the deadlines it sets.
C.5 Emails we send you
C.5.1 Your email address is never passed to anyone else. It is used to run your account and to send you the messages below. The sign-in and email providers in C.1 handle it only on our instructions, only to deliver those functions, and may not use it for anything of their own. We do not sell it, rent it, or share it with any third party for their own purposes.
C.5.2 Service emails: you cannot turn these off while you have an account. They are how we run the service and tell you things you need to know: sign-in and security messages, planned maintenance and interruptions, changes to our terms or to this policy, and replies to requests you have made. They are not marketing, we keep them to what is necessary, and some of them are notices we are required to send. If you do not want them, close your account.
C.5.3 Our mailing list: you can stop at any time. News, product updates and similar. You subscribe deliberately, every message carries an unsubscribe link, and unsubscribing has no effect on your account or on the service emails above. This is sales and marketing, not part of the product.
C.5.4 If your clinic invited you to the portal, you receive service emails and nothing else, unless you choose otherwise. If we offer product updates to portal users in future, they will be opt-in: nothing is sent unless you have asked for it, and you can stop at any time. Your clinic cannot ask on your behalf.
C.5.5 We never use your details to sell to someone else. We do not use contact details from the portal for prospecting, we do not pass them to anyone marketing to clinics or clinicians, and we never add you to a list because your clinic signed up.
C.6. When we may have to disclose information
C.6.1. Where we are the controller, we may disclose your information where it is necessary to:
comply with a legal obligation, a court order, or a valid request from a public authority;
establish, exercise or defend legal claims;
enforce our terms, or protect our rights, property or safety;
prevent or investigate wrongdoing connected with the service;
protect the personal safety of a user or of anyone else, including where there is a risk to someone's life; or
carry out a sale, merger or reorganisation of our business, in which case we will tell you before your information becomes subject to a different privacy policy.