Legal

Privacy Policy

Nerve is designed to route encrypted operational signals and protect access to trusted infrastructure workflows.

Effective date: June 30, 2026

Overview

Nerve is a secure operational signaling application. This Privacy Policy explains what information we process, how we use it, and how users can contact us about privacy or data requests. Nerve is operated by TC Infra.

Data we process

Nerve may process account identifiers, sign-in information, device push tokens, encrypted operational message envelopes, delivery status, app interaction metadata, diagnostics, and security logs needed to operate, protect, troubleshoot, and improve the service.

Depending on how you use Nerve, this may include email address, user ID, display name, app account identifiers, mobile device identifiers, push tokens, device model, operating system version, app version, IP address, request metadata, timestamps, pipe and sender identifiers, delivery metadata, encrypted message envelopes, agent connection metadata, webhook metadata, payment or app-store entitlement metadata, support messages, and abuse prevention records.

Account and sign-in data

If you sign in using a Google Account, Apple Account, or another supported authentication method, we may process basic account identifiers required to authenticate you and provide access to the app. This may include your account ID, email address, display name, and authentication session metadata.

Encrypted operational content

Nerve is designed so operational signal and command payloads are encrypted before they are routed through the service. The hosted relay is intended to route encrypted payloads and should not receive plaintext operational content.

Encryption does not remove all metadata. We may still process routing metadata, delivery metadata, device metadata, timestamps, sender identifiers, pipe identifiers, webhook request metadata, and other information required to operate, secure, debug, and prevent abuse of the service.

Push notifications

Nerve may use device push tokens, including Firebase Cloud Messaging tokens on Android and Apple Push Notification service tokens on iOS, to deliver app notifications. Push tokens are used only to provide notification functionality and maintain reliable delivery.

Push delivery depends on Apple, Google, device settings, operating systems, networks, and carriers. Notification previews, badges, and delivery behavior may be controlled by your device and platform settings.

Diagnostics and security logs

We may process technical logs, app diagnostics, crash information, device information, operating system version, timestamps, request metadata, and security events to monitor service reliability, investigate issues, prevent abuse, and protect the service.

Support and communications

If you contact us, we may process your email address, message content, attachments, diagnostic details, and related communications. Do not send sender DSNs, agent tokens, private keys, Apple or Google credentials, server secrets, regulated data, or unnecessary personal information in support requests.

How we use data

We use data to provide app functionality, authenticate users, deliver encrypted operational signals, send notifications, maintain service reliability, troubleshoot problems, prevent abuse, and comply with applicable legal and security requirements.

We may also use data to maintain accounts, sync app state, validate subscriptions or app-store entitlements, detect misuse, enforce rate limits, investigate security events, respond to support requests, comply with legal obligations, and improve reliability and usability.

Data sharing

We do not sell user data. We may share limited data with service providers needed to operate the app, such as hosting, authentication, analytics, diagnostics, security, and notification infrastructure providers. These providers process data only as needed to support the service.

Service providers may include hosting, storage, DNS, CDN, authentication, push notification, app distribution, crash reporting, analytics, payment, fraud prevention, security, email, and support providers. We may also disclose information if required by law, to protect rights and safety, to investigate abuse, or as part of a merger, acquisition, financing, or sale of assets with appropriate notice where required.

No sale of personal data

We do not sell personal data. We do not use encrypted operational payloads for advertising. If this changes, we will update this policy and provide any notices or choices required by law or platform policy.

App store disclosures

App store privacy labels and data safety disclosures summarize data practices for app review and user-facing store listings. This Privacy Policy is intended to provide the more complete disclosure. If you notice a conflict between an app store label and this policy, contact us so we can review and correct it.

Data security

We use technical and organizational safeguards designed to protect data in transit and at rest. Operational payloads are intended to be encrypted before they reach the hosted relay. No system can be guaranteed completely secure, but Nerve is built with security as a primary design goal.

You remain responsible for device security, account security, sender DSN rotation, webhook secrecy, agent token protection, local agent configuration, infrastructure permissions, and avoiding sensitive plaintext in fields that may be logged or displayed by your own tools.

Data retention

We retain data only as long as needed to provide the service, maintain security, troubleshoot issues, comply with legal obligations, and support operational requirements. Retention periods may vary depending on the type of data and the reason it is processed.

We may retain security logs, abuse-prevention records, support records, billing or entitlement records, and limited backup records for longer periods where reasonably necessary for security, legal, accounting, operational, or dispute-resolution purposes.

User choices and deletion requests

Users may contact us to request access, correction, or deletion of their data. Some information may need to be retained where required for security, fraud prevention, legal compliance, or legitimate operational purposes.

To request account deletion or deletion of data associated with your account, email [email protected] from the email address associated with your account and include "account deletion" in the subject. We may ask for information needed to verify the request and protect the account from unauthorized deletion.

You can reduce data processed by removing devices, rotating or deleting senders, disabling webhooks, deleting pipes, disconnecting agents, changing notification settings, and limiting what your scripts send to Nerve.

Regional privacy rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal data. You may also have the right to appeal a decision or contact a local data protection authority. To exercise privacy rights, contact us at [email protected].

International processing

We may process and store information in the United States and other countries where we or our service providers operate. Those countries may have data protection laws that differ from the laws where you live.

Legal bases

Where a legal basis is required, we process data to provide the service, perform our agreement with you, comply with legal obligations, protect the service and users, prevent abuse, and pursue legitimate interests such as security, reliability, support, and product improvement.

Children

Nerve is not intended for children. The app is intended for users who are 18 years of age or older.

Changes to this policy

We may update this Privacy Policy from time to time. When we make changes, we will update the effective date on this page.

Contact

For privacy, support, or data requests, contact us at [email protected]. Nerve is operated by TC Infra.