← Back to Docs

Privacy Policy

Last Updated: October 20, 2025

Introduction

Nightmare is a free AI self-development app that respects your privacy. This Privacy Policy explains what information we collect, how we use it, and your privacy rights.

We comply with privacy laws globally, including UK GDPR, EU GDPR, CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), PIPEDA (Canada), APPI (Japan), Australian Privacy Principles, and India DPDPA (monitoring for enforcement).

Who We Are

Data Controller:

For UK and EU Users:
This policy complies with UK GDPR and EU GDPR Article 3(2). The data controller operates from the United Kingdom. You can contact us at the correspondence address above.

Information We Collect

We practice strict data minimization and collect only what is necessary to provide our service.

1. Account Information

When you create an account via Apple Sign-In or Google Sign-In:

2. Chat Messages and Usage Data

To provide AI self-development services:

3. Device Fraud Prevention

To prevent abuse and ensure fair access for all users, we implement hardware-based device attestation:

What We Collect:

Purpose:

How It Works:

Retention After Account Deletion:
When you delete your account, the device hash is retained for 1 week to prevent spam account creation and quota abuse. After 1 week of inactivity, the hash is automatically and permanently deleted.

Re-registration:
If you create a new account on the same device within 1 week, the deletion countdown is cancelled and the device quota is reactivated for your new account.

Note: This is NOT device fingerprinting or tracking. We do not collect device identifiers (IDFA, IDFV), device models, operating system versions, or any information that can identify your physical device. The cryptographic hash is pseudonymised and cannot be reversed.

4. Technical Data for Security

For rate limiting and abuse prevention:

How We Use IP Addresses:

Retention: 5 minutes (our rate limiter)

Information We Do NOT Collect

Requirement to Provide Information

Contractual Requirement:
Providing your account information (email, display name) is necessary to create an account and use our service. A unique user identifier is automatically assigned by our authentication system. Device attestation is required to prevent abuse of our free service. Without this information, we cannot provide AI self-development services to you.

Voluntary Information:
All other information (chat messages, usage data) is provided voluntarily through your use of the service.

Consequences of Not Providing Data:

Legal Basis for Processing Your Data

This section provides a comprehensive overview of how we process your personal data, the legal basis for each processing activity, and how long we retain it.

Purpose Personal Data Collected Legal Basis (GDPR) Retention Period
Account Creation & Management User ID, email address, display name, profile picture (if provided), authentication provider, account creation and last sign-in dates Performance of contract (Article 6(1)(b)) - necessary to provide you with an account and access to services Immediate deletion at account deletion
AI Self-Development Services Chat messages (encrypted client-side), chat metadata (titles, dates), message and chat identifiers, message content sent to AI provider Performance of contract (Article 6(1)(b)) - necessary to provide AI self-development responses Immediate deletion at account deletion (our database). Anthropic retention: up to 30 days (messages sent to AI)
Usage Management & Fair Access Daily usage cost tracking, total token usage counter, account activity information (last active timestamp, creation date) Performance of contract (Article 6(1)(b)) + Legitimate interests (Article 6(1)(f)) - enforcing fair daily limits and preventing service abuse Immediate deletion at account deletion
Fraud Prevention & Abuse Protection Device attestation data (Apple App Attest), non-reversible cryptographic hash (SHA-256 of device key), attestation validation timestamps, attestation counter, attestation status (active/revoked), attestation challenges, device quota tracking (current usage cost, daily limit, reset timestamps) Legitimate interests (Article 6(1)(f)) - preventing spam accounts, quota gaming, and ensuring service sustainability for all users. See detailed balancing test below. Attestation data & challenges: deleted immediately at account deletion. Device hash & quota data: retained for 1 week after account deletion, then permanently deleted
Rate Limiting & DDoS Protection IP addresses (in-memory processing only) Legitimate interests (Article 6(1)(f)) - protecting service from API abuse and ensuring availability 5 minutes (our rate limiter)
iCloud Keychain Sync Encryption keys for your messages N/A - Controlled by Apple, not Nightmare. Subject to Apple's Privacy Policy. Optional - can be disabled in iOS Settings. Controlled by Apple (your personal iCloud account)

Understanding Legal Bases

Performance of Contract (Article 6(1)(b)):
This means processing is necessary to provide you with the service you signed up for. For example, we need your email to create your account, and we need to process your messages to generate AI self-development responses. Without this processing, we cannot deliver the service to you.

Legitimate Interests (Article 6(1)(f)):
This means we have a legitimate reason to process your data, but we must balance our interests against your privacy rights. We use this basis only when:

Right to Object:
Where we rely on legitimate interests, you have the right to object to the processing. Contact support@nightmare.app to exercise this right. Note that objecting to fraud prevention processing may prevent you from using the service.

Detailed Legitimate Interests Assessment (Device Hash Retention)

For the 1-week device hash retention after account deletion, we conducted a thorough balancing test:

1. Our Legitimate Interest:

2. Necessity Test:

3. Balancing Test (Your Rights vs. Our Interest):

Conclusion: The 1-week retention is proportionate, necessary, and includes appropriate safeguards. Your privacy rights are minimally impacted while protecting service sustainability for all users.

How We Use Your Information

We use your information solely to provide and improve our free AI self-development service:

What We Do NOT Do

Encryption and AI Processing

Client-Side Encryption

Your chat messages are encrypted on your device using AES-256-GCM encryption before being stored. Encryption keys are stored securely in your iOS Keychain with hardware-backed security and synced via iCloud Keychain for multi-device access. Our database stores only encrypted messages - we cannot read your stored messages.

iCloud Keychain Sync:

AI Processing

When you interact with our AI self-development assistant:

Third-Party Service Providers

We work with carefully selected processors under data processing agreements with appropriate safeguards:

1. Supabase (Database and Authentication)

2. Anthropic (AI Processing)

3. Railway (Backend Hosting)

4. Apple (Authentication and App Distribution)

International Data Transfers

Your data may be transferred outside your country of residence.

For UK and EU Users:

All transfers comply with GDPR Chapter V requirements, ensuring equivalent protection regardless of processing location.

Geographic Restrictions

Due to technical and legal restrictions imposed by our AI service provider (Anthropic), U.S. export controls, and compliance requirements, the Nightmare App is not available in the following countries and territories:

Restricted Countries and Territories (29 total):

Anguilla, Belarus, Bermuda, Brazil, British Virgin Islands, Cayman Islands, China (mainland), Congo (Democratic Republic of the), Cuba, France, Hong Kong, Iran, Kosovo, Libya, Macau, Mali, Montserrat, Myanmar (Burma), Nicaragua, North Korea, Russia, South Africa, South Korea, Syria, Turkey (Türkiye), Turks and Caicos Islands, Ukraine (Crimea, Donetsk, Kherson, Luhansk, and Zaporizhzhia regions), Venezuela, Yemen

If you are located in or attempt to use the service from these restricted regions, you will not be able to access AI self-development features. This restriction is based on U.S. export controls, OFAC sanctions compliance requirements, technical limitations imposed by our service providers, and regulatory compliance requirements.

AI Transparency (Preparing for EU AI Act)

In preparation for EU AI Act Article 50 (effective 2 August 2026):

AI System Information:

Important Limitations:

User Control:

Data Retention and Deletion

Active Account:

Your data is retained while your account is active and until you delete it.

Account Deletion:

When you delete your account:

Device Quota Retention Period:

After you delete your account, the device hash and device quota data remain in our system for 1 week to prevent abuse. This countdown is automatically cancelled if you create a new account on the same device. After 1 week of inactivity, the hash and quota data are permanently and automatically deleted.

How to Delete Your Account:

  1. In-app: Settings → "Delete Account" → Confirm
  2. By email: Contact support@nightmare.app

Your Privacy Rights

For UK and EU Users (GDPR Rights):

  1. Right to Access - Request a copy of your personal data
  2. Right to Rectification - Correct inaccurate or incomplete data
  3. Right to Erasure ("Right to be Forgotten") - Request deletion of your data
  4. Right to Restriction of Processing - Limit how we use your data
  5. Right to Data Portability - Receive your data in a portable format
  6. Right to Object - Object to certain types of processing
  7. Right to Withdraw Consent - Withdraw consent at any time
  8. Right to Lodge a Complaint - Complain to the ICO (UK) or your local Data Protection Authority (EU)

Response Time: Within 1 month (extendable to 3 months for complex requests)

Data Access Format: JSON format including account information, encrypted messages, device attestation status, and retention information

Note on Device Hash: Due to the pseudonymised and non-reversible nature of the device hash, we cannot provide the original device identifier. We can confirm whether a device hash associated with your account is being retained and when it will be automatically deleted.

For California Residents (CCPA/CPRA Rights):

  1. Right to Know - Request disclosure of personal information collected and shared
  2. Right to Delete - Request deletion of your personal information
  3. Right to Correct - Request correction of inaccurate information
  4. Right to Opt-Out - (Not applicable - we do NOT sell or share data for advertising)
  5. Right to Non-Discrimination - Exercise rights without discriminatory treatment

Response Time: Within 45 days (extendable to 90 days if needed)

Important: We do NOT sell your personal information and have NOT sold personal information in the preceding 12 months. We do NOT share your information for cross-context behavioral advertising.

For Virginia, Colorado, and Connecticut Residents:

  1. Right to Confirm - Confirm whether we process your personal data
  2. Right to Access - Access your personal data
  3. Right to Delete - Delete your personal data
  4. Right to Data Portability - Obtain a portable copy of your data
  5. Right to Opt-Out - (Not applicable - we do NOT engage in targeted advertising or data sales)
  6. Right to Appeal - Appeal our decision regarding your request

Appeal Process: Reply to our response email within 30 days. We will respond to appeals within 60 days.

For Utah Residents:

  1. Right to Confirm - Confirm whether we process your personal data
  2. Right to Access - Access your personal data
  3. Right to Delete - Delete your personal data
  4. Right to Data Portability - Obtain a portable copy of your data
  5. Right to Opt-Out - (Not applicable - we do NOT engage in targeted advertising or data sales)

Note: Utah law does not provide a right to appeal denied requests.

For Canadian Users (PIPEDA Rights):

  1. Right to Access - Access your personal information
  2. Right to Correct - Correct inaccurate or incomplete information
  3. Right to Withdraw Consent - Withdraw consent for data processing
  4. Right to Complain - File a complaint with the Privacy Commissioner of Canada

For Japanese Users (APPI Rights):

  1. Right to Disclosure - Request disclosure of your personal information
  2. Right to Correction - Request correction of inaccurate data
  3. Right to Deletion - Request deletion in certain circumstances
  4. Right to Stop Use - Request suspension of use or provision to third parties

For Australian Users (Privacy Act Rights):

  1. Right to Access - Access your personal information
  2. Right to Correction - Correct inaccurate or out-of-date information
  3. Right to Complain - Complain to the Office of the Australian Information Commissioner

How to Exercise Your Rights:

Email: support@nightmare.app

In-App (Account Deletion): Settings → "Delete Account"

No Fee: Exercising your privacy rights is free (unless requests are manifestly unfounded or excessive)

Data Security

We implement robust security measures to protect your information:

Encryption:

Access Controls:

Limitations:

No system is 100% secure. We cannot guarantee absolute security of data transmitted over the internet. You are responsible for maintaining the confidentiality of your account credentials and protecting your device.

Data Breach Response:

In the event of a data breach that poses a risk to your rights:

Children's Privacy

Nightmare is NOT intended for children.

Age Restrictions:

Parental Notice:

If you believe your child has provided us with personal information, contact support@nightmare.app. We will delete such information immediately upon verification.

Do Not Track Signals

We do NOT track you across websites or apps, use cookies, or engage in behavioral advertising. We honor Do Not Track (DNT) signals by default because we don't track in the first place.

Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements.

Notification of Changes:

We encourage you to review this policy periodically. Previous versions available upon request.

Complaints and Supervisory Authorities

If you believe we have not handled your personal information properly, you have the right to lodge a complaint with the relevant supervisory authority:

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:

Email: support@nightmare.app

Data Controller:
Ilya Tsymbal (Individual Developer)

Correspondence Address:
Room 1603F, Block A White Rose View
16 Merrion Way
Leeds LS2 8PT
United Kingdom

Response Time:

We are committed to resolving privacy concerns promptly and transparently.