Who runs Grudgy
Grudgy is a joke app for holding grudges, operated by Nicolás Rodrigues. Questions about this policy go to hello@grudgy.app.
Grudgy keeps what it needs to hold your grudges and nothing for advertising. There are no ads, no analytics and no data sales, in the app or on this website.
What we collect
On your account we store:
- Your email address, and a hash of your password (argon2id). The password itself is never stored.
- The name you put on your certificates.
- Your sign-ins: a hash of each session token, when it was created and last used, and when it expires or you signed out. A session lasts 30 days.
- Each grudge: the offender’s name as you typed it, what they did, how bad it was, the certificate design, and its dates: when you started holding it, when its term started and ends, how many times you renewed it, and when you forgave it.
- Moru’s verdicts: the name and what happened as you described them, the severity, the ruling, and whether it came from the AI model or the built-in rulings. That includes requests that got the fixed safety answer instead of a ruling.
- For a grudge you served: the random token in its link, when you first served it, and whether and when the page was reported.
- Apologies and appeals left on your served pages: which one it was, any message the other person wrote (up to 280 characters), Moru’s ruling on an appeal, when it arrived, and when you saw it.
- What you have unlocked, Grudgy Pro and certificate designs, with a record of each unlock and its date.
We do not collect your location, contacts or photos, and the app does not register for push notifications.
Kept in memory only
To stop abuse, the server counts requests per IP address, per install id (see below), and per email address when someone signs in. Those counts live in the server’s memory for at most an hour, are gone when it restarts, and are never written to the database.
The server writes errors to its logs so faults can be found and fixed.
On your phone
- The app keeps your sign-in and account details in the iPhone Keychain, together with your appearance setting and an install id.
- The install id is a random value the app makes up the first time it runs. It is not tied to your phone’s hardware, and it is sent with each request only so rate limits can apply per phone instead of per network. It is not stored on the server.
- Expiry reminders are local notifications, scheduled on your phone. Their text, including the offender’s name, is created on the phone and does not go through a push service.
- Share as image makes the picture on your phone. It leaves only if you send it.
Moru and OpenAI
When AI rulings are switched on for the service, asking Moru the Judge sends the offender’s name and what you say they did to OpenAI, to write the verdict. When they are off, verdicts come from Grudgy’s built-in rulings and that text is not sent anywhere.
Before any model is asked, a safety check reads the text. Anything that reads as violence, abuse, threats, stalking, sexual violence or self-harm gets a fixed answer and is not sent to OpenAI. Only asking Moru sends text to a model: holding, serving, apologies and appeals never do.
Served pages
Serving a grudge creates a link with a long random token in it. Anyone who has the link can see the name on your certificates, the offender’s name, what they did, how bad it was, its term and whether it is still held, and can apologize, appeal or report it. The page asks search engines not to index it. Grudges are never anonymous: a grudge cannot be served until your account has a name.
The person who opens the page does not need an account. Nothing identifies them in what we store: an apology keeps only what they wrote and when, an appeal only Moru’s ruling and when, and a report only that the page was reported and when. Their IP address is used only in memory, for the rate limits above.
A reported page stops being shown to anyone and cannot be served again. The grudge itself stays in the holder’s list.
Who else sees it
- Hetzner, which hosts the Grudgy API and its database on a server in Nuremberg, Germany.
- Cloudflare, which runs the DNS for grudgy.app, serves this website, passes requests for served pages on to the API, and forwards mail sent to hello@grudgy.app to our inbox.
- OpenAI, only while AI rulings are switched on, as described above.
- Apple, when you buy Grudgy Pro or a certificate design through the App Store, under Apple’s own terms. Purchases are not live yet.
We do not sell this data. We do not use it for advertising.
How long we keep it
For as long as your account exists. Deleting a grudge removes it together with its apologies and appeals, and its link stops working; a verdict you asked for stays on your account until the account is deleted.
Deleting your account removes the account, its sessions, grudges, verdicts, apologies, appeals and unlocks from the database in the same request, and every link you served stops working.
How to delete it
In the app: open You, tap Delete account, then Delete everything. There is no waiting period and nothing to cancel.
Or write to hello@grudgy.app from the address on the account, and we will delete it the same way. More detail is on Support.
Children
Grudgy is not meant for children. We do not knowingly collect data from anyone under 13. If you think a child has an account, write to us and we will delete it.
This website
grudgy.app is a static site. It sets no cookies, runs no analytics, and needs no account. Fonts are served from this same site. There is no sign-up form: if you email us, we keep that email only to reply to it.