Privacy Policy
Last Updated: August 2026
1. The short version
This policy covers the Nammu iOS app and the nammu.finance website. It explains what we collect, why, who helps us run the service, and how to get your data removed. If anything is unclear, email us. A human will reply.
2. Who we are
Nammu is built and operated by Damgar s.r.o., a company based in Prague, Czech Republic. Our servers run in the United States, and the app is offered in the United States. When this policy says "we," it means Damgar s.r.o. operating as Nammu.
3. What we collect in the app
Your account
You sign in with your email address or with Sign in with Apple. Our login and wallet partner, Privy, handles the sign-in and creates your self-custody wallet. We store your email address and a link to your wallet.
Your profile
During onboarding you can tell us your first name, a goal you're working toward (its name, a symbol, and a target amount), how much you plan to add and how often, the causes you care about, how much of your earnings you want to send to conservation, and your date of birth. We use your date of birth for one thing: confirming you are 18 or older. None of this is identity verification, and we never ask for a government ID.
Later, if you make a pledge in the app, you can attach an optional note to your future self. We store that note with the pledge.
Your wallet and its activity
We keep a record of your wallet address, your USDC activity, your balance, your earnings, and your giving history. We need this to show you your money, keep our books straight, and send your chosen share of earnings to conservation.
Adding funds and cashing out
Card payments and bank transfers happen inside Coinbase's own flow, on Coinbase's pages, under Coinbase's privacy policy. Your card number and bank login go to Coinbase, never to us. To open that flow we send Coinbase your wallet address, the amount, your country and region, your device's IP address, and a reference number so Coinbase can report the result back to us. The reference is a fresh random ID each time, not your identity. For cash-outs we also send the payout currency and the payout method type, like card or bank transfer. Afterward Coinbase tells us the amount, the fees, and whether it went through.
Small diagnostic reports
If something breaks in the app, it sends us a tiny report: which step failed and what kind of error it was. That's the whole report. It contains no email, no wallet address, and no account identifiers. We also keep standard server logs to run and debug the service, and our logging is built to scrub secrets and URLs before anything is written down.
4. What we deliberately don't do
- No advertising or tracking SDKs in the app. None.
- No selling or renting your data. To anyone. Ever.
- No access to your location, contacts, photos, camera, or microphone. The app never asks.
- No storing card numbers or bank credentials. Coinbase handles payment details on their side.
- No government ID collection. If Coinbase runs an identity check for a purchase, that happens with Coinbase directly.
5. Your money lives on a public ledger
USDC runs on Base, a public ledger. Transactions to and from your wallet address are visible to anyone, by design. That's what makes your balance checkable by you instead of taking our word for it. The ledger shows wallet addresses and amounts. It does not show your name or email, and we don't publish anything that links the two.
6. What we collect on the website
The nammu.finance website is a separate surface from the app, and it collects more than the app does:
- Waitlist signup: your email, name, country, device type, browser, how you found us, and, if you share it, the rough amount you plan to start with.
- Umami analytics: page view counts, without cookies.
- Microsoft Clarity: how visitors move through the site, including session replays and heatmaps. Clarity sets cookies.
- Country lookup: we use your IP address to look up your country, so we know where signups are coming from.
- Welcome email: when you join the waitlist, we send you one confirmation email through our email provider, Resend.
- Cloudflare: the website sits behind Cloudflare, so your visits pass through it, like most of the modern web.
- Fonts and icons: the site loads its font from Google Fonts and icons from a public CDN. Like any server you load a file from, they see your IP address.
7. Cookies
| Where | What | Purpose |
|---|---|---|
| App | Login session | Keeping you signed in to your account |
| Website | Microsoft Clarity cookies | Site analytics and session replay |
You can block cookies in your browser. The website still works without them.
8. Who helps us run Nammu
We don't run everything ourselves. These companies process data for us, and each one gets only what it needs to do its job:
- Privy runs sign-in and your self-custody wallet. They see your email or Apple sign-in.
- Coinbase handles card and bank payments in their own flow, under their own policy.
- Alchemy and Base network providers are the plumbing we use to read the public ledger. They see wallet addresses, which are already public.
- Apple delivers push notifications to your device.
- Railway hosts our servers.
- Sentry receives error reports from our servers, with secrets and URLs scrubbed first.
- Resend sends the waitlist welcome email.
- Umami and Microsoft Clarity provide website analytics, as described above.
- Telegram carries our internal team alerts. When someone joins the waitlist, our team channel gets their signup details, like email, name, and country. System failure alerts are scrubbed before they're sent.
- Cloudflare sits in front of the website and sees visitor traffic.
We share data with authorities only if the law requires it. We don't share your information with data brokers or advertisers.
9. Push notifications
Notifications are optional, and you choose whether to allow them. If you turn them on, we store your device's push token and an installation ID so Apple can deliver them. The title is always generic, like "Achievement unlocked." The detail line names the milestone you reached, and for money milestones that can include the threshold you crossed, like your first $100. If you'd rather keep amounts off your lock screen, leave notifications off.
10. How long we keep things, and how to delete your account
We keep your information while your account is active. You can delete your account any time in the app, under Profile. When you do, we delete your email, your profile, and your sign-in identity with Privy, and the app wipes its local data from your device.
Three honest caveats. First, we keep transaction records for as long as accounting and legal rules require, because money moved and the books have to stay true. Second, a few of those signed records hold a sealed copy of your onboarding answers and any pledge note, because they're part of the evidence that keeps our books provable. Third, the public ledger is permanent. Nobody, including us, can erase past transactions from it.
Before deleting your account, you'll need to cash out your balance. The app walks you through it.
11. Your choices
- Ask us what we have about you.
- Ask us to correct it.
- Delete your account in the app, or email us and we'll do it with you.
- Want off the waitlist? Email us and we'll remove you.
Email [email protected] for any of these. We'd rather answer a hundred questions than have one person feel unsure.
12. Age
Nammu is for adults, 18 and up. We check your date of birth at signup, and we don't knowingly collect information from anyone under 18. If you think a minor has an account, tell us and we'll remove it.
13. Where your data is processed
Our servers and database are in the United States, and the app is offered in the United States. If you visit the website from somewhere else, your data will be processed in the United States.
14. Changes to this policy
When we change this policy, we update the date at the top. If a change is significant, we'll tell you in the app or by email before it takes effect.
15. Contact
Questions about privacy: [email protected]
Anything else: [email protected]