Legal
Privacy Policy
Last updated: 30 June 2026
This Privacy Policy explains how NEXA ("we", "us") collects, uses, and protects your personal data when you use our service. We process data in accordance with the EU General Data Protection Regulation (GDPR). The data controller is the operator of NEXA; contact details are at the end of this page.
Data we collect
- Account data: your name, email address, and authentication credentials.
- Brand Memory: the brand information, voice, audience, and assets you provide to personalize generation.
- Generated content: the copy, images, and videos you create, plus your prompts and instructions.
- Billing data: subscription plan and payment status (card details are handled by Stripe, never by us).
- Connection tokens: OAuth access tokens for social accounts you connect, encrypted with AES-256 at rest and used only to publish and read results on your behalf. See Data deletion to remove them.
- Usage data: credits consumed, feature usage, and technical logs needed to operate and secure the service.
How we use your data
- To provide the service: generate on-brand content, schedule, and publish it.
- To meter usage and bill your subscription.
- To secure the service, prevent abuse, and comply with legal obligations.
- To contact you about your account and important service changes.
We do not sell your personal data, and we do not use your Brand Memory or generated content to train shared AI models.
Subprocessors
We share data with the following processors strictly to operate NEXA:
- Supabase — database, authentication, and storage.
- Vercel — application hosting.
- Stripe — subscription payments (PCI-DSS compliant).
- Anthropic and Google — AI generation engines for text, image, and video. Your prompts and Brand Memory are sent to these engines to produce your content.
- Meta and LinkedIn — only when you connect those accounts, to publish content you schedule.
Data retention
We keep your data for as long as your account is active. You can delete your account at any time from Settings → Danger zone, which permanently erases your brands, content, automations, and connections. Some records may be retained where required by law (e.g. invoicing).
Your rights
Under the GDPR you have the right to access, rectify, export, restrict, and erase your personal data, and to object to processing. You can exercise erasure directly via account deletion, or contact us for any other request. You also have the right to lodge a complaint with your local data protection authority.
Security
Data is encrypted in transit (TLS) and at rest. Access tokens and secrets are stored server-side and never exposed to the browser. Access is restricted to what is necessary to operate the service.
Contact
For any privacy request, contact us at legal@nexamarketing.app.