Privacy Policy
Effective Date: 01 July 2026
Contents
- Who We Are
- What This Policy Covers
- Personal Data We Collect
- How We Use Your Data
- Legal Bases for Processing (GDPR)
- Data Sharing & Third-Party Service Providers
- International Data Transfers
- Data Retention
- Data Security
- Your Rights Under the GDPR
- Children's Privacy
- Cookies & Tracking Technologies
- Push Notifications
- Changes to This Policy
- Contact Us
1. Who We Are
AM I NUTS B.V. ("we", "us", or "our") is the data controller responsible for your personal data. We are incorporated under the laws of the Netherlands and our registered address is Prinseneiland 43, 1013 LL Amsterdam, the Netherlands.
If you have any questions about this Privacy Policy or our data practices, you may contact us at: contact@aminuts.app.
2. What This Policy Covers
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use the Am I Nuts mobile application (the "App"), available exclusively through the Apple App Store and Google Play Store.
Am I Nuts is a native mobile application — it is not a website or web app. This distinction is relevant because certain web-specific data practices (such as cookies) do not apply.
3. Personal Data We Collect
3.1 Data You Provide at Registration
To create an account, you must provide the following:
| Data | Purpose |
|---|---|
| Email address | Primary account identifier, login credential, and communications |
| Full name (first & last) | Display name within the App (e.g., within Circles) |
| Password | Account authentication (stored as Argon2 hash only - we never access your plaintext password) |
If you register using Google Sign-In, we receive your email address, first name, last name, and a unique Google account identifier from Google. We do not receive or store your Google password, nor do we request access to any other Google services.
3.2 Optional Profile Data
After registration, you may optionally provide:
- Date of birth
- Gender
- Country of residence
- City of residence
- Profile photo
Country and city are self-reported text fields. We do not access your device's GPS or location services.
3.3 Data Generated Through Your Use of the App
| Data | Description |
|---|---|
| Poll answers | Your selected option for each daily poll question |
| Favourites / Likes | Poll questions you have "liked" |
| Circles membership | Which social groups you belong to |
| Circle activity | Actions within Circles (e.g., answering polls, joining or creating a Circle) |
| Points & levels | Gamification points earned through actions (answering, referrals, profile completion) |
| Streak | Count of consecutive days you completed daily polls |
| Affiliation code | A unique 6-character code auto-assigned to you for referral purposes |
| Share codes | Unique codes generated when you share a question set |
3.4 Data Collected Automatically
| Data | Purpose |
|---|---|
| IP address | Rate limiting, abuse prevention, referral verification, and security |
| API request logs | Each authenticated request is logged with: session token, client IP, request path, sanitised request body (passwords redacted), and response status. Used for rate limiting and anti-abuse monitoring. |
| Timestamps | Account creation, last update, and session activity times |
| Session tokens | Unique, server-generated identifiers for session management |
| Network connectivity status | Whether your device is online or offline - stored in device memory only, never sent to our servers |
3.5 Data Stored on Your Device
The App stores certain data locally on your device:
- General cache (via SharedPreferences): cached profile, poll questions, results, Circle data, points, preferences, and onboarding state. Not sensitive; used for performance.
- Authentication token (via secure storage - iOS Keychain / Android EncryptedSharedPreferences): your session token only.
- Temporary image cache: profile photos cached in device's OS-managed temporary directory; may be cleared by the OS at any time.
4. How We Use Your Data
We use your personal data for the following purposes:
- Providing the service: delivering daily polls, calculating your Nuts Score, managing your account, and enabling social features (Circles, leaderboards, activity feeds).
- Authentication & security: verifying your identity, managing sessions, preventing abuse, rate limiting, and protecting against unauthorised access.
- Communications: sending transactional emails (password resets, password-change confirmations, and referral invite verifications).
- Gamification: tracking points, levels, and streaks to power the in-app reward system. Points have no monetary value.
- Aggregate analytics & AI insights: generating anonymised, aggregate-level textual assessments of poll results using AI. No personally identifiable information is sent to the AI provider.
- Content moderation: AI-based review of user-submitted questions before publication.
- Referral system: facilitating invitations and verifying referral completions.
4a. Automated Decision-Making and Profiling
Please note: Your poll answers are processed by an automated algorithm to calculate your Nuts Score. Whilst this constitutes profiling under Article 4(4) GDPR (automated processing to evaluate aspects of your behaviour and preferences), we note that the Nuts Score does not produce legal effects or similarly significant effects within the meaning of Article 22(1) GDPR. It is an entertainment metric only, with the limited purpose of displaying your score within the App. You may choose to delete your data at any time by terminating your use of the App.
5. Legal Bases for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we rely on the following legal bases:
| Legal Basis | Applicable Processing Activities |
|---|---|
| Performance of a contract (Art. 6(1)(b)) |
Account creation and management, delivering the core service (polls, results, Circles), session management, gamification features, and referral processing. |
| Consent (Art. 6(1)(a)) |
Optional profile data (date of birth, gender, location, photo). Push notifications (when activated - you will be asked to opt in via your device's OS prompt). |
| Legitimate interests (Art. 6(1)(f)) |
Security measures (rate limiting, IP logging, abuse prevention, DDoS protection), API request audit logging, fraud detection, and profiling for the Nuts Score entertainment feature (see Section 4a). It is our legitimate interests to maintain the security, integrity, and availability of the service; and to provide an engaging entertainment product. |
| Legal obligation (Art. 6(1)(c)) |
Retaining certain records where required by applicable Dutch or EU law. |
Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
6. Data Sharing & Third-Party Service Providers
We do not sell your personal data. We share data with third-party service providers (sub-processors) only as necessary to operate the App:
| Provider | Purpose | Data Shared | Location / Transfer Mechanism |
|---|---|---|---|
| Google LLC | OAuth 2.0 authentication (Google Sign-In) | Auth request; Google ID token (email, name, Google user ID) verified on our servers | Standard Contractual Clauses |
| OpenAI, L.L.C. | AI-generated poll assessments; AI content moderation; poll option illustrations | No PII - only anonymised, aggregate poll statistics | Standard Contractual Clauses |
| Mailgun (Sinch) | Transactional email delivery | Recipient email, name, email content | Standard Contractual Clauses |
| BunnyCDN (BunnyWay d.o.o.) | Profile photo storage & delivery | Profile photo files (anonymised UUID filenames) | N/a (EU) |
| OneSignal, Inc. | Push notification delivery | Device push token, notification content | Standard Contractual Clauses |
| Apple / Google | App distribution | Standard store listing data. Apple and Google collect their own analytics per their respective policies. | Standard Contractual Clauses in Appstore standard terms. |
We may also disclose your data if required by law, court order, or governmental authority, or to protect our rights, safety, or property.
7. International Data Transfers
Some of our sub-processors are located outside the European Economic Area (EEA), specifically in the United States. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Reliance on the EU-U.S. Data Privacy Framework, where the recipient is certified; or
- Other lawful transfer mechanisms as applicable.
You may contact us at contact@aminuts.app to obtain further details about the specific safeguards applied to any transfer.
8. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes described in this Policy, or as required by law:
- Active accounts: Your data is retained for the duration of your account.
- Deleted accounts: soft-deleted and excluded from all active queries. Retained for 3 months to enable recovery and comply with legal obligations, then permanently and irreversibly anonymized so it can no longer be linked to you.
- API request logs: Retained for 12 months for security and anti-abuse purposes, then deleted.
- Session tokens: Revoked immediately upon logout or password reset.
- Device-local data: Deleted from your device upon logout, except for your last-used email address (for login convenience) and onboarding completion status.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit: All communication between the App and our servers is encrypted via HTTPS/TLS.
- Password hashing: Passwords are hashed using Argon2. We never store or access plaintext passwords.
- Secure credential storage: Authentication tokens use iOS Keychain / Android EncryptedSharedPreferences.
- Rate limiting: Exponential back-off rate limiting protects against brute-force attacks.
- DDoS protection: Dynamic thresholds automatically reject excessive traffic.
- Session management: Only one active session permitted per user; previous sessions revoked on new login.
- Dual-layer API authorisation: Static app-level bearer token + per-user session token required.
- Input sanitisation: Server-side HTML sanitisation, parameterised SQL, and client-side input formatters.
- IP validation: Requests without a valid client IP are rejected.
While we take reasonable precautions, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
10. Your Rights Under the GDPR
If you are located in the European Economic Area (EEA), you have the following rights with respect to your personal data:
- Right of access (Art. 15): You may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You may update or correct your data at any time through the App profile settings (name, date of birth, gender, country, city, and profile photo).
- Right to erasure - right to be forgotten (Art. 17): You may delete your account through the in-app account deletion feature. Upon deletion, your data will be soft-deleted immediately and permanently and irreversibly anonymized after the retention period described in Section 8, so it can no longer be linked to you.
- Right to restriction of processing (Art. 18): You may request that we restrict processing of your data under certain circumstances.
- Right to data portability (Art. 20): You may request a machine-readable copy of the data you have provided to us. To exercise this right, please contact us at contact@aminuts.app.
- Right to object (Art. 21): You may object to processing based on legitimate interests, including profiling for the Nuts Score. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)): Where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at contact@aminuts.app. We will respond within one month of receipt of your request. In cases of complexity or high volume, this period may be extended by up to two further months; we will inform you within one month of receipt and explain the reasons.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority of your EU Member State of residence.
11. Children's Privacy
Am I Nuts is not intended for individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have inadvertently collected data from a person under 18, we will take steps to delete that data promptly. If you believe that a minor has provided us with personal data, please contact us at contact@aminuts.app.
12. Cookies & Tracking Technologies
Am I Nuts is a native mobile application. It does not use cookies, web beacons, pixel tags, browser-based local storage, or any other web-based tracking technologies. There are no first-party cookies, third-party cookies, analytics cookies, or advertising cookies.
We do not use any advertising SDKs or ad networks, and we do not engage in behavioural advertising or cross-app tracking.
13. Push Notifications
We offer push notifications to inform you when daily results are available and for other service-related updates. Push notifications are delivered via OneSignal.
- You will be asked to grant permission through your device's operating system prompt. No push notifications are sent without your prior opt-in consent.
- If you opt in, your device push token will be shared with OneSignal to deliver notifications.
- You can opt out at any time through your device's notification settings (iOS: Settings > Notifications; Android: Settings > Apps > Am I Nuts > Notifications). Withdrawing consent does not affect the lawfulness of notifications sent prior to withdrawal.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you through the App or by other appropriate means. The "Effective Date" at the top of this page will be updated accordingly.
Your continued use of the App after any changes take effect constitutes your acceptance of the revised Policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please contact us:
- Data Controller: AM I NUTS B.V.
- Address: Prinseneiland 43, 1013 LL Amsterdam, the Netherlands
- Email: contact@aminuts.app
© 2026 AM I NUTS B.V. All rights reserved.