Legal

Privacy Policy

1. Who We Are

1.1 This Privacy Policy explains how Nibbler ("Nibbler", "we", "us", or "our") collects, uses, shares, and protects your personal data when you use the Nibbler mobile application, the website at getnibbler.com, and related services (together, the "Service").

1.2 For the purposes of the EU General Data Protection Regulation (GDPR) and applicable Swedish data protection law, Nibbler is the data controller of your personal data.

1.3 Contact details:

1.4 This Policy should be read together with our Terms and Conditions.


2. Scope

This Policy applies to personal data we process about users of the Service and visitors to our website. It does not apply to third-party services that have their own privacy policies (see Section 8 and Section 16).


3. The Personal Data We Collect

We collect the following categories of personal data:

3.1 Identity and account data
Your email address, password (stored in hashed form), and, if you sign in with Google or Apple, the identifiers and basic profile information those providers share with us (such as your name or email). On Apple Sign-In you may choose to hide your email, in which case we receive a private relay address.

3.2 Profile and preference data
The information you provide during the conversational onboarding and in your editable "growth profile" — for example your learning goals and aspirations, what you are working on, how you like to learn, your preferred read length (5, 10, or 15 minutes), your daily delivery time, and your mascot and app settings.

3.3 User Content
The content you upload, paste, link to, or submit — including PDFs, documents, pasted text, URLs, and notes — and the data we derive from it to operate the Service, such as numerical representations of the content ("embeddings") used to match content to your profile.

3.4 Activity and usage data
How you use the Service — for example bites delivered and read, reflections you write, bites you save or favourite, quiz responses, your chat messages with Nibbler, streaks, reading history, and weekly recap data.

3.5 Device and technical data
Your device model, operating system, app version, language settings, IP address, device identifiers, push-notification tokens, and diagnostic or crash logs.

3.6 Subscription and transaction data
Your subscription tier and status, free-trial status, and purchase identifiers. Payments are processed by the App Store (Apple or Google); we do not collect or store your full payment card details.

3.7 Analytics data
Aggregated and event-level analytics about how features are used, retention, and conversion, collected to help us understand and improve the Service.


4. How We Collect Your Data

We collect personal data:


5. How and Why We Use Your Data (Purposes and Legal Bases)

We process your personal data on the following legal bases under GDPR Article 6:

PurposeData usedLegal basis
Create and manage your account and authenticate youIdentity and account dataPerformance of a contract (Art. 6(1)(b))
Build your growth profile and personalise your daily contentProfile and preference data; User ContentPerformance of a contract (Art. 6(1)(b))
Process your uploads to generate bites, quizzes, and chat responsesUser Content and derived embeddingsPerformance of a contract (Art. 6(1)(b))
Deliver daily bites and send push notificationsPreference data; push tokensContract (Art. 6(1)(b)); Consent for notifications (Art. 6(1)(a))
Track streaks, history, reflections, and recapsActivity and usage dataPerformance of a contract (Art. 6(1)(b))
Manage free trials and subscriptionsSubscription and transaction dataContract (Art. 6(1)(b)); Legal obligation for records (Art. 6(1)(c))
Understand usage and improve the ServiceActivity, device, and analytics dataLegitimate interests (Art. 6(1)(f)), or Consent where required (Art. 6(1)(a))
Keep the Service secure and prevent fraud or abuseDevice and usage dataLegitimate interests (Art. 6(1)(f))
Provide support and respond to your requestsIdentity data and the content of your requestContract and/or Legitimate interests
Comply with legal obligationsRelevant data as requiredLegal obligation (Art. 6(1)(c))
Measure and optimise our advertising campaigns (e.g. on Meta, TikTok, and Google)Device, usage, and advertising identifiers; conversion and install eventsConsent where required (Art. 6(1)(a)); otherwise Legitimate interests (Art. 6(1)(f))
Send marketing communications, if anyIdentity and contact dataConsent (Art. 6(1)(a)), withdrawable at any time

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing as described in Section 12.


6. User Content and AI Processing

6.1 Nibbler's core features rely on automated and artificial intelligence ("AI") processing. To generate your personalised insights, quizzes, and chat responses, your User Content and profile are processed by AI and related providers (see Section 8).

6.2 Your uploaded files are stored using cloud storage located in the European Union. Content is converted into embeddings and stored in a vector database to match relevant material to your profile.

6.3 We use your User Content to provide the Service to you. We do not use the content of your private uploads to train our own foundation models, and we do not publish or share your User Content with other users.

6.4 Some AI and infrastructure providers are located outside the EU/EEA; see Section 9 on international transfers.


7. Sensitive ("Special Category") Data

7.1 We do not ask you to provide special category data (such as data revealing health, religion, political opinions, or sexual orientation).

7.2 However, because you choose what to upload and what to write in your profile and reflections, your User Content could contain such information. If you include special category data, you do so on your own initiative, and you consent to it being processed as part of providing the Service to you. Please avoid uploading sensitive information you do not wish to be processed.


8. Who We Share Your Data With

8.1 We do not sell your personal data.

8.2 We share personal data with trusted third-party providers who process it on our behalf to operate the Service, and with others where necessary. The main recipients are:

ProviderPurposeLocation
Google (Firebase Authentication)Account sign-in and authenticationUSA
RailwayBackend application hosting and database (PostgreSQL)United States (US East, Virginia)
Amazon Web Services (S3)Storage of your uploaded filesEuropean Union (Stockholm)
Anthropic (Claude API)AI generation, personalisation, onboarding conversationUSA
Voyage AIConverting content into embeddingsUSA
PineconeVector database for matching content to your profileUSA
MixpanelProduct analytics and retention measurementUSA
RevenueCatSubscription managementUSA
Apple App Store / Google PlayApp distribution, sign-in, and payment processingGlobal
Apple Push Notification service / Firebase Cloud MessagingDelivering push notificationsUSA
Meta Platforms (Facebook, Instagram)App-install and conversion advertising and measurementUSA
TikTok (ByteDance)App-install and conversion advertising and measurementGlobal
Google (Google Ads, Google Analytics, Google Tag Manager)Advertising, conversion measurement, and website analyticsUSA
AppsFlyerAttributing app installs and measuring ad performance across networksUSA
AdjustAttributing app installs and measuring ad performance across networksGermany (EU)

8.3 We may also disclose personal data: (a) to comply with a legal obligation, court order, or lawful request from authorities; (b) to enforce our Terms or protect the rights, safety, or property of Nibbler, our users, or others; and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this Policy.

8.4 The App Stores and authentication providers may act as independent controllers for the data they process for their own purposes (for example, payment processing and their own account systems), under their own privacy policies.

8.5 The list of providers in 8.2 may change as the Service evolves. We will keep this Policy up to date and may maintain a current list of sub-processors on request.


9. International Data Transfers

9.1 Some of our providers are located outside the European Economic Area (EEA), including in the United States and, in some cases, other countries that may not have been recognised as offering an equivalent level of data protection. When we transfer personal data outside the EEA, we ensure an appropriate level of protection through a valid transfer mechanism, such as the European Commission's Standard Contractual Clauses, an adequacy decision (for example, the EU–US Data Privacy Framework where applicable), or other lawful safeguards.

9.2 You may request more information about the safeguards we use by contacting us at privacy@getnibbler.com.


10. How Long We Keep Your Data

10.1 We keep your personal data for as long as your Account is active and as needed to provide the Service.

10.2 When you delete your Account, we delete or anonymise your personal data, including your User Content, within a reasonable period, except where we must retain certain data:

10.3 Aggregated or anonymised data that can no longer identify you may be kept for longer.


11. How We Protect Your Data

11.1 We use reasonable technical and organisational measures to protect your personal data, including encryption in transit, access controls, hashed passwords, and use of reputable infrastructure providers.

11.2 No system is completely secure. While we work to protect your data, we cannot guarantee absolute security, and you share information with the Service at your own risk. If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, you, in line with our legal obligations.


12. Your Rights

12.1 Under the GDPR, you have the following rights regarding your personal data:

12.2 Exercising your rights. You can manage much of your data directly in the app, or contact us at privacy@getnibbler.com. We will respond within the time limits required by law (generally one month). We may need to verify your identity before acting on a request.

12.3 Supervisory authority. If you are in Sweden, you may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY"). If you are elsewhere in the EU/EEA, you may contact your local supervisory authority. We would, however, appreciate the chance to address your concerns first.


13. Children's Privacy

13.1 The Service is intended for users who meet the minimum age set out in our Terms and Conditions. We do not knowingly collect personal data from children below the applicable minimum age without appropriate consent.

13.2 Where we permit users below the age of digital consent in their country to use the Service, we require verifiable consent or authorisation from a holder of parental responsibility and will make reasonable efforts to verify it, in line with GDPR Article 8.

13.3 If you believe a child has provided us with personal data without the required consent, please contact us at privacy@getnibbler.com and we will take appropriate steps to delete it.


14. Cookies and Similar Technologies

14.1 Website. Our website may use cookies and similar technologies for functionality and, with your consent where required, for analytics. Where applicable, a separate cookie notice or banner will provide details and choices.

14.2 Mobile app. The app uses software development kits (SDKs) and device identifiers (for example, for analytics, authentication, and push notifications) rather than browser cookies. You can control some of these through your device settings.


15. Automated Processing and Personalisation

15.1 Nibbler personalises your experience by analysing your growth profile and content to select and generate the insights most relevant to you. This involves automated processing and profiling for the purpose of personalisation.

15.2 This personalisation does not produce legal or similarly significant effects on you within the meaning of GDPR Article 22. If you have questions about how personalisation works, contact us at privacy@getnibbler.com.


16. Third-Party Links and Services

The Service may reference or link to third-party content or services (for example, a URL you choose to add). We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.


17. Changes to This Policy

17.1 We may update this Policy from time to time. When we make material changes, we will update the version number and effective date and, where required, notify you through the Service or by other reasonable means.

17.2 Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy, except where additional consent is required by law.


18. Contact Us

If you have questions about this Policy or how we handle your personal data, contact us at: