Privacy Policy — naggingissue.com
This policy explains what naggingissue.com ("the Site", "we", "us") collects, why, and what you can do about it. 2morrow.ai, LLC, a Colorado limited liability company, of 2730 S Wadsworth Blvd Ste B #1013, Denver, CO 80227, United States, is the operator responsible for this data (the "controller" under EU/UK data protection law).
1. What we collect
| Data | When | Why |
|---|---|---|
| Email address | When you submit a nag | To verify it's a real person, notify you of status, and credit you if picked |
| The nag text and any optional context | When you submit a nag | To publish it (if approved) and to assess it |
| IP address | Every submission, and every "me too" | Abuse prevention, provenance evidence, coarse location |
| Device and browser type, operating system + version | Every submission, and every "me too" | Abuse prevention, provenance evidence, debugging |
| Coarse, IP-derived location (city/region/country only — never precise GPS) | Every submission, and every "me too" | Abuse prevention, provenance evidence, understanding where the board is used |
| A scrambled, one-way fingerprint of your visit (see Section 2) | Every page view and every "me too" | Counting unique views and "me too"s without cookies or logins |
| Terms-of-Use version and timestamp you agreed to | When you submit a nag | Proof of consent (clickwrap record) |
We never ask for precise/GPS location, and we never ask people under 16 to use the Site (see Section 8).
2. Cookieless view counting
To count how many different people view a nag or say "me too" — without tracking you individually or asking for cookie consent — we generate a one-way scrambled value (a "hash") from your IP address, your browser's user-agent string, and a random value that we throw away and replace every day ("daily-rotating salt"). This lets us tell "the same visitor today" from "a different visitor" without storing your IP address in a form that is tied back to you long-term, and without placing a tracking cookie on your device. Because the salt changes daily, the same visitor produces a different hash tomorrow, so the hash cannot be used to follow someone across days. This approach is used by privacy-focused analytics tools such as Plausible.
3. Why we're allowed to process this (legal basis)
- IP address, device, OS, and coarse location, for abuse prevention and provenance: we rely on legitimate interest — we need this to stop fraud, spam and duplicate abuse, and to have evidence of who first submitted an idea if that is ever disputed. We believe this interest is not outweighed by your privacy rights given the limited, non-precise data involved, but you can object (Section 6).
- Email address, submission content, and clickwrap record: we rely on performance of a contract with you (running the board you asked to participate in) and legitimate interest (keeping records of consent).
- Cookieless view-count hash: legitimate interest in measuring engagement, using the least intrusive method we could find.
4. Who else sees your data (processors)
We use outside service providers ("processors") to run the Site:
- Supabase — database, authentication, and storage.
- Google (Gemini API, paid tier) — automated review/moderation of nag text, generating AI replies and effort estimates. Only the nag text (and minimal context needed for the request) is sent; we do not knowingly send your email, IP, or device details to this API. Google does not use paid-tier content to train its models.
- Cloudflare (Turnstile) — invisible bot/abuse check used on "me too" and submissions. Cloudflare processes some technical signals from your device/browser as part of this check.
- Amazon Web Services (Amazon SES) — sends verification and status-update emails.
- Vercel — hosts the Site.
We only give processors the data they need to do their job, and we expect them to protect it. We work to have a data-processing agreement in place with each processor that handles personal data.
5. How long we keep it (retention)
- Published nag text and credited submitter name: kept indefinitely while it remains on the public board or archive, as the board is historical/public by design.
- Submitter email address: kept for 24 months after last activity, then deleted or anonymized.
- IP address, device/OS details, and coarse location tied to a specific submission: kept for 12 months for abuse-prevention and provenance purposes, then deleted or anonymized.
- Declined/held nag records (including AI category and confidence score): kept for 12 months to track false-positive rates and tune moderation, then deleted or anonymized.
- Clickwrap acceptance record (Terms version + timestamp): kept for 7 years after the relevant activity, to preserve evidence of consent for as long as a legal claim could reasonably arise.
- Cookieless view-count hash: never stored beyond the rotating day it was generated for; only the resulting aggregate counts are kept.
6. Your rights
If you are in the EU or UK, under GDPR / UK GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to be forgotten"), subject to legal exceptions (for example, we may need to keep abuse-prevention or provenance records for a period even after a deletion request, per Section 5).
- Restrict or object to certain processing, including processing based on legitimate interest.
- Port your data to another service, where technically feasible.
- Complain to your local data protection authority.
To exercise any of these, contact us at stefan@2morrow.ai.
If you are a California resident, under the CCPA/CPRA you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to not be discriminated against for exercising these rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We give this notice proactively, regardless of whether the Site currently meets the CCPA/CPRA's applicability thresholds. To exercise your rights, contact stefan@2morrow.ai.
7. International transfers
Our processors (Supabase, Google, Cloudflare, Amazon Web Services, and Vercel) may process your data in the United States and other countries where they operate. Where a transfer requires a safeguard under EU/UK data protection law, we rely on Standard Contractual Clauses or the processor's equivalent safeguards.
8. Children
You must be at least 16 to use the Site. We do not knowingly collect personal data from anyone under 16. If we learn that someone under 16 has submitted data to us, we will delete it. If you believe a child has used the Site, contact us at stefan@2morrow.ai.
9. Security
We use reasonable technical and organizational measures designed to protect the personal data we hold, including encrypted connections (HTTPS/TLS) between your device and the Site, and we rely on our processors (Supabase, Vercel, Amazon Web Services, Google, Cloudflare) to maintain their own security programs. No online service can guarantee absolute security, and we cannot promise the Site will never be compromised.
10. Changes to this policy
We may update this policy from time to time. We will update the
last_updated date above when we do, and if the change is material, we
will make that clear on the Site.
11. Contact
Questions about this policy, or to exercise your rights: stefan@2morrow.ai.