The short version
- We process your data to run Nurturi for you. We do not sell it, and we do not use it to train AI models.
- With the desktop agent, your mailbox and connection exports are read on your own computer, and only the distilled result reaches us.
- AI requests from our cloud service only go to providers that do not keep your text for training.
- Your workspace is visible only to the people you invite.
- No advertising trackers and no analytics cookies. One cookie keeps you signed in.
- You can download a copy of your data and delete your account yourself, from inside the product.
1.Who we are
Nurturi is operated by [company name to be confirmed], company number [to be confirmed], registered at [registered address to be confirmed]. For anything about privacy, write to hello@nurturi.app.
2.Our role and yours
Two different situations apply, and the law treats them differently.
- We are the controller of the information we need to run our own business: your account details, billing records, what you send us for support, the website preview, and how the product is used.
- We are also the controller of the business contact data we supply. Where we obtain company and contact information from licensed providers and public sources and make it available to customers, we decide to do that, so we answer for it. A customer who receives it becomes responsible, in their own right, for what they then do with it.
- We are a processor acting for your business for everything inside your workspace: your accounts, the people in them, conversations, notes and research. Your business decides what goes in and why. We follow your instructions, and a data processing agreement is available on request.
3.What we process, and why
| Data | Where it comes from | Why | Legal basis |
|---|---|---|---|
| Account details. Name, work email, workspace and role. Your password is stored only as a salted hash, never in readable form. | You, or the colleague who invited you | To run your account | Contract |
| Website preview. The website address you enter, the results we produce from it, and your email address if you choose to give it. Your IP address is kept for up to two days to limit repeated requests, and is not stored with your email address. | You, and the public website you named | To show you the preview, to follow up if you asked us to, and to prevent abuse | Legitimate interests; consent for follow-up |
| Email. For conversations that need a reply: who it is with, the subject, dates, and short extracts. If you use mail clean-up, the senders in your inbox. | Your mailbox, by one of the two routes in section 4 | Follow-up reminders and drafted replies | Processor, on your instructions |
| Calendar. Meeting title, time, and attendee names and email domains. | Your calendar | Matching meetings to accounts and conversations | Processor, on your instructions |
| LinkedIn. Your conversations with the people you are working, your connections list, and public profile details of people in your account book, including their profile photo. | Your own LinkedIn session, through the desktop agent or browser extension, and the connections export you upload | Conversation tracking, drafts, and showing who on the team knows whom | Processor, on your instructions |
| CRM records. Companies, contacts, deals and owners. | The CRM you connect, such as HubSpot | Building your account book and client pages | Processor, on your instructions |
| Company and contact research. Names, job titles, employers, public profile links, company news, hiring, funding and public tenders. When you ask for a lookup, a business email address or phone number. | Your uploads, public sources, government procurement feeds, and licensed data providers | Account research and deciding who to contact | Processor, on your instructions |
| Your devices. The computer name, version and last check-in time of a desktop agent or browser extension you install. | The agent or extension | Showing whether your setup is working and up to date | Contract |
| Usage. Which features are used and how much AI work a workspace consumes. No message content. | The product | Metering, capacity and improving the product | Legitimate interests |
We do not ask for special category data, such as health or political information about individuals, and our terms ask you not to upload it.
4.Two ways to connect, and what each means
The desktop agent and browser extension
These run on your own computer. Your mailbox, meeting transcripts and connection exports are read there. What reaches our servers is the derived record: the names, companies, dates and the few lines that matter. The mailbox and the recordings do not leave your machine. The agent's logs and data folder are yours to inspect and delete.
A cloud connection
You can instead connect a service directly, for example Microsoft 365 or HubSpot. You approve read-only access on that service's own consent screen. With this route our servers read from the service on your behalf, so message content passes through them while we extract what is needed. We keep the extracts, not a copy of the mailbox. You can disconnect at any time, which removes the stored access token.
Choose the desktop agent if you want raw material to stay on your own machine.
5.How AI is used
Drafts, summaries and research are written by large language models. The text needed for the task, such as the conversation being replied to, is sent to the model for that request.
- AI requests from our cloud service go through OpenRouter, a routing service, to Anthropic's Claude models. Every request tells the routing service to use only providers that do not keep prompts for training.
- We do not train models on your data.
- AI output is a draft for a person to review. Nurturi does not make decisions about individuals that have legal or similarly significant effects.
6.People in your account book who are not our users
Nurturi holds professional information about people your team works with or hopes to: name, role, employer, public profile link and photo, the messages they exchanged with you, and business contact details where you looked them up. Looked-up details come from a licensed data provider and can include a direct or mobile number that the provider lists as a business contact. We do not collect home addresses.
If you are one of those people, you can ask what is held about you and ask for it to be corrected or deleted. Write to hello@nurturi.app. We will work with the business that holds the record, which is responsible for it, and tell you the outcome.
If your details are in the data we supply
We supply business contact details to customers so that they can contact people about their work. We rely on legitimate interests to do that, and we have weighed it against yours: the data is professional, not private, it is used for business contact, and you can stop it.
To stop it, write to hello@nurturi.app with your LinkedIn profile address or your work email address. We add you to a list of people whose details we do not supply. From then on a customer who looks you up is refused, and if a provider returns your email address anyway, everything it returned about you is withheld. We keep only that identifier, and we keep it for as long as we operate, because forgetting it would mean supplying you again. Where we can tell which customers already received your details, we tell them to stop using them and delete them.
7.Where data lives and who can see it
Production data is stored with Microsoft Azure in the UK South region. Each workspace is separated from every other. Inside a workspace, colleagues see their own conversations, and managers see the team's activity and numbers.
Access by our staff is limited to named people, for support and operations, when needed. Some of the companies in section 8 process data outside the UK. Where that happens we rely on the safeguards the law provides, such as the UK International Data Transfer Agreement or adequacy regulations.
8.Who helps us run Nurturi
| Company | What they do | What they receive |
|---|---|---|
| Microsoft Azure | Hosting and database, UK South | All data stored in Nurturi |
| OpenRouter, routing to Anthropic | AI drafting, summaries and research | The text needed for each request |
| Lusha | Business contact data | The name, company and profile link of a person you ask us to look up, and the company domains and filters of a company search |
| Jina AI | Backup reader for public web pages in the website preview | The public web address only |
| Web fonts on our public and sign-in pages, and company icons in the website preview and inside the app | Your IP address, and the company web domain for an icon |
Services you choose to connect, such as Microsoft 365, HubSpot and LinkedIn, act under your own agreement with them. We also read public government procurement feeds in the UK and EU, which involves no personal data of yours. We will update this list before adding a company that handles customer data.
9.How long we keep it
- Workspace data: for as long as the workspace exists. You can download a copy at any time. When you delete your account, your own data goes straight away, and a workspace goes with you if you were its only member.
- Account signals, such as news and tender notices: 12 months, then removed automatically.
- Deleting your account: immediate, from Connectors, Your data. A request made to us by email instead is carried out within 30 days of our confirming who you are.
- Website preview: the email address you gave us is kept until you ask us to remove it or 24 months pass, whichever comes first.
- Usage records: which pages and features were used, as counts. Individual records for 90 days, daily totals for 13 months. Never the content of a message or a draft.
- Sign-in session: up to 30 days.
- Rate-limit records holding an IP address: two days.
- The do-not-supply list: the identifier only, kept for as long as we operate.
- Backups: held by our hosting provider for a short rolling period and then overwritten. Deleted data leaves the backups as they roll over.
- Billing records: as long as tax law requires, currently six years.
10.Your rights
Under UK GDPR, and EU GDPR where it applies, you can ask to see the personal data held about you, have it corrected or deleted, receive a copy in a portable form, and object to or restrict how it is used. Where we rely on consent you can withdraw it at any time.
Write to hello@nurturi.app. We respond within one month. If your data sits inside a customer's workspace, we will pass your request to that customer and help them answer it. You can also complain to the Information Commissioner's Office at ico.org.uk, though we would like the chance to put things right first.
11.Security
- Traffic is encrypted in transit, and stored data is encrypted at rest by our hosting provider.
- Passwords are stored as salted hashes.
- Each workspace is isolated, and access inside it follows the role each person holds.
- Invite links work once and expire.
- Connections to other services use read-only permissions wherever the service offers them.
No system is perfectly secure. If you think you have found a weakness, tell us at hello@nurturi.app. If a breach affects your data we will tell you without undue delay.
12.Cookies
Nurturi sets one cookie, radar_session, which keeps you signed in for up to 30 days. It is strictly necessary, so it does not need consent. It cannot be read by scripts and is sent only over a secure connection. We use no analytics cookies and no advertising trackers.
Our public and sign-in pages load fonts from Google, and the website preview and the app load company icons from Google. Google receives your IP address when those load, and the company's web domain for an icon.
13.Changes to this policy
When we make a change that matters, we will tell workspace owners by email or in the product at least 30 days before it takes effect. The date at the top shows when the policy last changed.
14.Contact
[company name to be confirmed], [registered address to be confirmed]. Email hello@nurturi.app.