Wiggle

Wiggle App Privacy Notice

Version 2026-09-09

Clarify that the Octopus connection does not provide device control.

Who is responsible

NRB Tech Ltd is the controller of personal information processed for the Wiggle app and service. Company number 11590173; registered office Fairleigh, Coldhill Lane, New Mill, Holmfirth, West Yorkshire, HD9 7JX. Our ICO registration reference is ZC196238. For privacy questions or to exercise your rights, contact nick@nrbtech.io. The website privacy notice separately covers website forms and enquiries.

Account and household information

We collect your name, email address, household names, memberships, preferences and records needed to authenticate your account. Depending on your sign-in method, these include a password hash, passkey public-key information or a Sign in with Apple identifier. We do not receive your Face ID or Touch ID biometric data. We record the versions of the terms you accept and privacy notices you acknowledge.

We use this information to provide and manage the account and household service you request. The lawful basis is performance of our contract with you where the processing is necessary for that service. We use proportionate authentication and security records in our legitimate interests in protecting accounts and preventing misuse.

Information from connected providers

When you connect a supplier, we obtain the information described on its connection screen. This can include supplier account and property or meter identifiers, equipment information, historical and current energy readings, tariffs, billing or cost evidence, and supplier-managed charging plans and activity. We also calculate estimates and modelled energy and cost information, identified as such in the app.

Detailed energy readings can reveal patterns of household activity, including when people may be at home. We use these records to provide the monitoring, history and explanations you request, based on performance of our contract. Your separate provider-connection permission authorises that access; it is not a general permission to use your information for unrelated purposes. Wiggle does not control devices connected through Octopus.

While Octopus OAuth is unavailable, you can submit your API key once over an encrypted connection. We encrypt it for use by the service. The app clears it after submission and does not offer a way to retrieve the stored key. We do not ask for your Octopus password.

Sharing within a household

Other authorised members of your Wiggle household can see its shared energy information. Owners manage membership. People in a different household cannot access your household through their own membership. Your private sign-in credentials are not shared with household members. Household-level readings can concern other occupants as well as the account holder.

Messages, support and diagnostics

We use your email address to send invitations, verification, recovery and other account messages needed to provide or secure the service. If you enable notifications, we process a device notification token, your preferences and limited delivery records. You can turn notifications off in Settings.

When you contact support, we process your message, case status and basic app and operating-system information to investigate and reply. Attaching recent app diagnostic events to a support report is a separate optional choice. Diagnostic data uses bounded technical fields rather than household readings or supplier credentials. Apple may also provide crash or TestFlight feedback under its own settings and privacy information.

Our lawful basis for responding to support requests and maintaining proportionate operational records is our legitimate interest in providing a reliable, secure service. Optional diagnostic attachments use your consent, which you may withdraw by contacting us. We do not require marketing consent to use Wiggle. If we offer marketing updates, they have their own optional sign-up and opt-out.

Where information is held and who helps us

The main application database is hosted by OVHcloud in the UK. Production recovery backups are encrypted before upload to Scaleway storage in Paris, France. We manage the encryption and access controls. Authorised NRB Tech personnel can access information where needed to operate, secure or support the service.

Mailjet processes recipients and account-message contents to deliver transactional email. Apple processes information needed for Sign in with Apple, Apple Push Notification service and TestFlight or App Store distribution. Your connected supplier processes its own account information and our authorised requests under its own privacy notice. Infrastructure providers process limited service and network information to operate their services. We do not sell personal information or share it for third-party advertising.

Some provider processing may take place outside the UK. Where UK transfer rules apply, we use an applicable adequacy regulation or appropriate contractual safeguards, including the UK International Data Transfer Agreement or UK Addendum where required. Contact us for details of the applicable safeguard and how to obtain a copy. UK hosting of the main database does not mean every provider processes all information only in the UK.

How we protect information

Connections to Wiggle are encrypted. The application database is stored on an encrypted volume. Supplier credentials receive additional encryption, with keys kept separately from database records. Passwords are stored as secure hashes. Household permissions restrict access and administrative access is restricted. Routine logs are designed to exclude supplier credentials, energy readings and support-message contents. Our servers process your information to provide the service; it is not end-to-end encrypted between your devices.

Retention and deletion

We keep account and active household history while needed to provide the service you use, including historical comparisons and correction of supplier information. Disconnecting a supplier stops new collection and removes its usable credential, but does not automatically erase the history.

Start account deletion in Settings. We remove your sign-in credentials, sessions and personal account information. Every household you own and its energy history is erased from the active service, including shared households. Households where you are only a member remain. When an owner deletes a household, its other members also have their accounts deleted unless they own another surviving household. The confirmation names the households and accounts affected; remaining accounts retain access only to surviving households. We remove support content attributable to your account. If an older shared-household support record needs review to identify its author, we explain that review and do not describe it as already erased.

Diagnostic batches are normally removed after 30 days and local pending diagnostics after 24 hours. Support cases remain while active and for up to 24 months after closure, unless you request earlier erasure or a specific legal requirement justifies retention. Most completed account-email, notification-delivery and expired session records are removed after 30 days; short-lived authentication attempt records after one day. Disabled notification installations are normally removed after 90 days.

Encrypted production backups expire under a lifecycle schedule beginning after 31 days; object locking, version expiry and provider processing mean removal is not immediate. Backup copies are used for recovery with deletion requests reconciled before restored personal information is made available. We retain only the limited records needed to complete and account for a deletion or a specific legal obligation, and explain any exception that applies to your request.

Your choices and rights

You can correct account information, manage notifications and disconnect suppliers in Settings. The privacy request form at wiggle.energy/privacy-request/ lets you request account deletion, deletion of particular data, or a copy of your information without signing into the app. We send a single-use email verification link, then review the request and any further identity or household authority needed before deleting or releasing information. You can ask us for access to your personal information, correction, erasure, restriction or a portable copy where the right applies. Where we rely on consent, you can withdraw it without affecting earlier lawful processing. Acknowledging this notice is not blanket consent.

You have the right to object to processing based on our legitimate interests. Tell us what you object to at nick@nrbtech.io. You can object to direct marketing at any time.

We respond without undue delay and within one month where the law requires it. Some rights depend on the processing purpose and lawful basis. We do not use your information for solely automated decisions producing legal or similarly significant effects.

You may complain directly to the Information Commissioner's Office at ico.org.uk/make-a-complaint. You do not have to contact us first.

Changes to this notice

When our processing changes, we update this notice and show the new version in the app with a summary. Previous published versions remain available. We ask you to acknowledge the notice so we can record which information you were shown; this does not replace any separate consent needed for optional processing.