Privacy Policy
The short version
Guddle is local-first. The Android app has no ads or third-party analytics, advertising or automatic crash-reporting SDK. When you use sharing, encrypted backups, public publishing, membership, cloud media or AI generation, data needed for that feature leaves your device. Features available to you depend on your app version and service availability.
Request deletion of your Guddle service account and associated data · Contact us
Notes, sharing and cloud media
- Private notes stay on your device by default. Uninstalling the app or clearing its data removes the local copy. Export anything you need first.
- Close-friend messages and encrypted backups are encrypted on your device before being sent to Nostr relay servers used by you or your friends. Relays cannot read the encrypted content, but network operators may see IP addresses, connection times and protocol metadata.
- Private cloud media, including images, GIFs, videos and profile backups, is encrypted before upload. Hosting services process ciphertext, ownership authorization, hashes, file types, sizes, references and usage records.
- Public notes, profiles and media are published for others to read. Anyone may copy or redistribute them. Removing an original cannot guarantee removal from independent relays, search engines, caches or other devices.
Identity, keys and service access
Your Nostr public key identifies you when adding friends, publishing or using membership services. A public identifier is not anonymous. Guddle services may process this key, app-generated device authorization identifiers or proofs, service claims and security status to authorize access. Your private key and recovery code are not sent to Guddle, Google Play, OpenAI or Cloudflare. Keep your recovery material safe; we cannot reconstruct your private key from server records.
Membership and purchases
When you purchase, restore or verify membership, Google Play provides purchase credentials, product and plan identifiers and purchase status. The app sends these and your current Nostr public key to Guddle's membership service for verification. Service records include entitlement, expiry, claimed services, AI and media usage, refunds, disputes and necessary security records. Google handles payments under its own privacy policy; Guddle does not receive your full payment-card details.
AI page generation
When you start generation, your input text, reference URL and public information read from that URL go to page.guddle.me and OpenAI. Reference screenshots are analysed on your device: layout, colour, dimensions and the current filename are sent, not the original image. Profile details and selected public notes supplied separately by Android are applied to the local draft after generation; information you include yourself in the prompt or reference URL is still sent.
The membership generation path does not persist full prompts, model responses or generated pages in Guddle's generation service or its review queue. Usage records are separate. OpenAI does not use API data for training by default. Its default abuse-monitoring retention is up to 30 days, with legal and safety exceptions; prompt caching can retain temporary data for up to 24 hours. This is not a promise of zero retention. See OpenAI's data controls.
Diagnostics and privacy requests
The app keeps error and operational logs locally; more detailed logging is optional. Logs leave your device only when you choose to send them through your email app. They may include device model, system and app versions, relay addresses, connection state and errors. Review attachments before sending. Ordinary feedback also opens your email app instead of submitting automatically.
If you email us, we process your sender address, message, attachments and correspondence to handle your request. Cloudflare forwards the privacy mailbox to the responsible person's NetEase mailbox. Your email provider also handles the message. Do not send private keys, recovery codes, recovery shares or complete purchase tokens.
Service providers and this website
- Nostr relays carry encrypted messages, backups and public events, with connection metadata.
- Cloudflare hosts Guddle pages, membership and media infrastructure, processing request metadata, service records, encrypted objects and public content.
- Google Play processes purchases, renewals, refunds and purchase verification.
- OpenAI processes user-initiated generation inputs and model outputs.
- Email providers, including Cloudflare forwarding and NetEase, process privacy correspondence.
Providers may retain request metadata for security and operations under their own policies. Turning off an application's logs does not mean the hosting provider retains nothing.
This website uses browser language settings and a local language preference. Its deployed pages also load Cloudflare Web Analytics for page-view and performance measurements. This is distinct from the Android app's SDKs. See Cloudflare's collection explanation.
Retention
You control local copies. Cloud objects are kept while referenced and during recovery and deletion windows; membership expiry alone does not delete existing objects. Membership, billing, usage, dispute and security records are retained as needed for those purposes and applicable obligations. AI provider retention is described above. Any identifiable older AI review records are handled separately from the membership generation path.
We explain the scope, expected completion time and any records that must be retained when handling a deletion request. We do not promise immediate erasure of every record or of copies outside our control.
Delete your Guddle service account and associated data
To request deletion, email privacy@guddle.me with the subject “Guddle account and data deletion”. Include your public identity code if available and describe the services or data concerned. You can send a request without reinstalling Guddle. We verify control of the relevant identity or membership before acting; we never ask for your private key or recovery code.
The request covers service-account records and associated data controlled by Guddle, not just disabling access. Necessary billing, dispute, fraud-prevention or legally required records may be retained; we explain those exceptions. A locally controlled Nostr identity and independent public copies cannot be erased globally by Guddle.
Deleting local app data is not a server-data deletion request. Deleting a service account does not itself cancel a Google Play subscription: manage that subscription in Google Play to stop future renewals.
Permissions explained
- Network (INTERNET / ACCESS_NETWORK_STATE) — relay, membership, AI, page and media connections and network-state checks.
- Biometric (USE_BIOMETRIC) — to gate app entry behind fingerprint or face and to protect your key. Authentication happens entirely on the Android system; we receive only a yes / no result.
- Camera (CAMERA) — only requested when you scan an identity code or half-share QR. Frames are processed in memory and discarded.
- Notifications (POST_NOTIFICATIONS) — messages and background-sync notices; change this in Android settings.
- Background connection (FOREGROUND_SERVICE / FOREGROUND_SERVICE_SPECIAL_USE) — keeps relay subscriptions active when you choose continuous connection. The notification and Network page let you switch to periodic sync.
- Startup and battery settings (RECEIVE_BOOT_COMPLETED / REQUEST_IGNORE_BATTERY_OPTIMIZATIONS) — restore your chosen connection policy after restart and let you request reduced battery restrictions.
- Wake lock (WAKE_LOCK) — Android's background-work library may keep the processor awake while scheduled work runs.
- Legacy storage (WRITE_EXTERNAL_STORAGE, Android 9 only) — save a QR code to your gallery when you choose to export it.
Children
Guddle is not designed for children under 13. Guardians can contact us if a child has submitted data to a Guddle-controlled service without permission.
Changes to this policy
We update this page and the in-app explanation when data flows, providers or retention change materially. Enabling an optional sharing or cloud feature is not a blanket permission to upload unrelated local content.
Contact
For privacy questions, requests or complaints, email privacy@guddle.me.