Contact

Legal

Privacy Policy

Last updated: 15 August 2026

Who we are

Nure is operated by AI Gen Apps Limited, a company registered in England and Wales (company number 16824575), registered address 3rd Floor, 45 Albemarle Street, London, W1S 4JL. Privacy questions: team@aigenapps.com.

Our two roles

We handle personal data in two distinct roles, and your rights differ depending on which applies:

  • We are the controller for data about our own customers, the businesses who subscribe to Nure. That means account details, login credentials, billing information, and usage records.
  • We are the processor for everything our customers bring into the platform: the messages, calls, contacts and documents belonging to their clients. We handle that data on our customers' instructions. If you are a client of a business that uses Nure, that business is your data controller and you should contact them first; we will support any request they make.

What we collect and why

Account data (controller). Name, work email, hashed password, organisation, role, and subscription and payment records.

Messages (processor). Where a customer connects a channel, we receive and store the message content, sender and recipient identifiers, and timestamps:

  • Email: via the customer's own connected Google account, using access we request from them and which they can revoke at any time.
  • WhatsApp: messages sent to and from a WhatsApp Business number the customer has connected.

WhatsApp chat history and contacts. Where a customer connects an existing WhatsApp Business number using WhatsApp's coexistence onboarding, WhatsApp transfers to us, with that customer's consent given at connection time, up to the previous six months of their one-to-one conversations and their WhatsApp contact list. Group chats and status updates are not included. We import this so the customer's history is available in one place from the day they connect. It is stored and retained on the same basis as any other message.

Phone calls (processor). Where a customer uses a phone number provided through Nure:

  • Call audio recordings. Callers hear an announcement before recording begins. Recordings are encrypted at rest.
  • Written transcripts, including which speaker said what.
  • Call metadata: the numbers involved, time, duration and outcome.
  • Verification codes sent by SMS, where a caller proves their identity. We send these only to a number already held on the customer's records, never to a number supplied during the call.

Contact records (processor). Names, phone numbers, email addresses and messaging handles our customers hold about their own clients, together with records of interactions.

Documents (processor). Files our customers upload, and text extracted from them by automated scanning.

Technical data. IP address, browser type, and security and audit logs.

Automated and AI processing

Nure uses artificial intelligence to draft replies, answer phone calls, summarise conversations, transcribe audio and read documents. This means message and call content is sent to third-party AI providers for processing, under contracts that prohibit them from using it to train their own models.

Where an AI answers a phone call, the caller is told at the start of the call that they are speaking to an automated assistant.

AI-generated actions that have a real-world effect, such as sending a message or raising an invoice, require a human to approve them, unless the customer has explicitly configured otherwise for a specific task.

Decisions with legal or similarly significant effect are not made about you by Nure on a solely automated basis. Because a human reviews and approves consequential actions before they take effect, there is meaningful human involvement in the outcome. Under UK GDPR, as amended by the Data (Use and Access) Act 2025, you have rights in relation to significant decisions based solely on automated processing, including the right to be told about the decision, to make representations, to obtain human intervention and to contest it. Where a customer configures Nure to act automatically on a specific task, that customer is responsible for keeping any such safeguards in place for the people they serve.

AI transparency and the EU AI Act

Nure uses AI to interact with people directly: it drafts replies, answers phone calls, and holds conversations on a customer's behalf. It also generates content such as written summaries, transcripts and suggested messages. We treat the transparency duties in Article 50 of the EU AI Act (Regulation (EU) 2024/1689) as the standard we hold ourselves to, and we apply the same standard in the UK even though the UK has not adopted the EU AI Act.

  • AI interaction is disclosed. Where an AI answers a phone call, the caller is told at the start of the call that they are speaking to an automated assistant, so it is never hidden that the interaction is with AI.
  • A human reviews consequential output. AI-drafted messages and AI-suggested actions that have a real-world effect are reviewed and approved by a person before they are sent or carried out, unless the customer has explicitly configured a specific task to run automatically.
  • AI-generated content can be identified. Summaries, transcripts and drafts produced by AI are presented as such inside the platform, so the people using Nure know what was machine-generated.

We consider Nure to be a limited-risk AI system carrying transparency obligations, rather than a high-risk system. It is a communication and productivity tool: it does not make the kind of automated decision, in areas such as employment, credit, essential services or law enforcement, that the EU AI Act classes as high-risk. This assessment is ours and is kept under review; it is not a determination by a regulator.

The EU AI Act distinguishes the provider of an AI system from the deployer who puts it to use. A business that uses Nure to communicate with its own clients may be acting as a deployer and can have its own obligations under the Act, for example where it uses AI features in a way that reaches people in the EU. Those obligations rest with that business, not with us. The EU AI Act can apply where the output of an AI system is used inside the EU, regardless of where the business is based.

Who else processes this data

We use the following categories of sub-processor.

PurposeProvider
WhatsApp messagingMeta Platforms
Telephone calls, SMS, numbersTwilio
EmailGoogle (customer's own account)
AI language modelsOpenAI, xAI, Groq
Text embedding for search and retrievalGoogle (Gemini)
Speech recognitionDeepgram, Groq
Speech synthesisElevenLabs (via Twilio)
Document text extractionMistral AI
File storageCloudflare

We do not sell personal data, and we do not share it for advertising.

How long we keep it

  • Call recordings: retained according to the retention period set for the customer's account, and deleted on request.
  • Messages, transcripts and contact records: for as long as the customer holds an account, unless they delete them sooner.
  • Raw incoming webhook payloads: 30 days.
  • Account and billing records: for the period required by law after the account closes.

When a customer closes their account we delete their data on request, normally within 30 days of the request, except where we must keep records to meet a legal obligation.

Security

Data is separated per customer at the database level so one customer can never read another's. Stored credentials and call recordings are encrypted. Access is logged and audited.

Hosting and international transfers

Nure's application, database and file storage are hosted on cloud infrastructure located in the United Kingdom. Some of the sub-processors listed above operate outside the UK; where personal data is transferred internationally we rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.

Our website

The aigenapps.com website itself collects a small amount of data, for which we are the controller:

  • Forms. If you contact us, join a waiting list or apply to become a partner, we collect the details you enter — your name, email address, company and message — and use them only to respond to you. Submissions are delivered to our inbox by Mailtrap, our email delivery provider. Your IP address is held briefly in memory to limit automated abuse of the forms and is not stored.
  • Analytics. We use Google Analytics, loaded through Google Tag Manager, to understand how the site is used. This sets cookies in your browser and shares usage data with Google.

Your rights

Under UK GDPR you may request access to your data, correction, deletion, restriction, portability, or object to processing. Contact team@aigenapps.com. See also our data deletion page. You may complain to the Information Commissioner's Office at ico.org.uk.

If a business uses Nure to communicate with you, that business, not Nure, is your data controller. Please contact them first.

Changes

We will post any changes here and update the date above.

This page explains our practices. It is provided for information and is not legal advice. If you have obligations of your own under data protection or AI law, take your own advice on them.