Privacy Policy for Nexa

Last updated: April 22, 2025

1. Agreement To Terms

Nexa ("Nexa", "we", "our", or "us") is a voice‑first personal assistant and reminder application that helps you capture thoughts, tasks, and ideas through natural speech. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Nexa mobile application, our website (https://mynexa.ai), and any related services (collectively, the "Service").

By using Nexa, you agree to the collection and use of information as described here. If you do not agree with this Policy, please do not access or use the Service.

2. Information We Collect

We collect three broad categories of information:

2.1 Information You Provide to Us

  • Account details – email address, display name, password, or Apple Sign‑In credentials.

  • Content – voice recordings, transcriptions, text notes, reminders, to‑dos, and any files you choose to upload.

  • Profile extras (optional) – avatar image or nickname.

  • Payment information – handled securely by Apple In‑App Purchase or Stripe via RevenueCat (we never see your full card number).

2.2 Information We Collect Automatically

  • Device data – device model, operating‑system version, language, and time zone.

  • Usage data – interactions within the app, screens viewed, feature use, and basic event logs.

  • Diagnostic data – crash reports, performance metrics, IP address, and app version.

2.3 Information from Third‑Party Sources

  • Authentication tokens from Apple or Google to enable sign‑in.

  • Subscription status from Apple App Store to verify purchases.

  • AI processing results from OpenAI (e.g., transcriptions and categorization of your voice input).

Note: Nexa is not designed to collect sensitive personal data (e.g., health information or political opinions). Please avoid storing such content in the app.

3. How We Use Your Information

  1. Deliver and operate the Service – save reminders, sync data with Supabase, and send proactive notifications.

  2. Process transactions – manage subscriptions and in‑app purchases.

  3. Transcribe and interpret voice input – leverage OpenAI models to categorize your entries.

  4. Improve and personalize Nexa – troubleshoot, test new features, and understand aggregate usage trends.

  5. Communicate with you – respond to support requests, send updates, and provide security alerts.

  6. Meet legal requirements and enforce our Terms of Service.

4. Legal Bases for Processing (EEA/UK)

We rely on the following legal bases: consent, contract performance, legitimate interests (e.g., improving Nexa, preventing fraud), and legal obligation.

5. Sharing & Disclosure of Information

We disclose information only as necessary:

  • Service providers – Supabase (database & storage), Vercel (backend functions), OpenAI (AI services), RevenueCat/Stripe (billing), and Firebase Crashlytics (analytics/crash reporting).

  • Compliance and safety – to comply with laws, respond to lawful requests, or protect the rights, property, or safety of Nexa and its users.

  • Business transfers – during mergers, acquisitions, or asset sales (we will notify you).

  • Aggregated or de‑identified data – data that cannot reasonably identify you.

We do not sell your personal information.

6. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service and comply with legal obligations. You may delete individual reminders at any time or delete your entire account in app; we erase associated personal data within 30 days, except where a longer retention period is required by law.

7. Security

We use industry‑standard safeguards, including TLS encryption in transit, salted bcrypt hashing for passwords, and role‑based access controls. Nevertheless, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Rights & Choices

Depending on your location, you may have the right to:

  • Access a copy of your data

  • Correct inaccurate data

  • Delete your data ("right to be forgotten")

  • Restrict or object to certain processing

  • Opt out of marketing communications

Most requests can be managed under Settings → Privacy. For others, email privacy@mynexa.ai.

9. California Privacy Notice (CCPA/CPRA)

Nexa does not sell personal information. California residents can request details about data collected, deletion, correction, and disclosure practices. Submit requests via the contact methods below; we will verify your identity as required by law.

10. International Transfers

Our servers reside in the United States. If you access Nexa from outside the U.S., your information will be transferred to the U.S. We rely on Standard Contractual Clauses or equivalent safeguards where required.

11. Children’s Privacy

Nexa is not intended for children under 13. We do not knowingly collect data from children. If we discover such data, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy occasionally. We will post the new version in‑app and on our website and adjust the “Last updated” date. Material changes will be announced by email or in‑app notification at least 30 days before they take effect.

13. Contact Us

If you have questions or concerns about privacy, please contact us:

Nexa Privacy Team
Email: privacy@mynexa.ai

Thank you for trusting Nexa to help you command your day with ease.

Privacy Policy for Nexa

Last updated: April 22, 2025

1. Agreement To Terms

Nexa ("Nexa", "we", "our", or "us") is a voice‑first personal assistant and reminder application that helps you capture thoughts, tasks, and ideas through natural speech. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Nexa mobile application, our website (https://mynexa.ai), and any related services (collectively, the "Service").

By using Nexa, you agree to the collection and use of information as described here. If you do not agree with this Policy, please do not access or use the Service.

2. Information We Collect

We collect three broad categories of information:

2.1 Information You Provide to Us

  • Account details – email address, display name, password, or Apple Sign‑In credentials.

  • Content – voice recordings, transcriptions, text notes, reminders, to‑dos, and any files you choose to upload.

  • Profile extras (optional) – avatar image or nickname.

  • Payment information – handled securely by Apple In‑App Purchase or Stripe via RevenueCat (we never see your full card number).

2.2 Information We Collect Automatically

  • Device data – device model, operating‑system version, language, and time zone.

  • Usage data – interactions within the app, screens viewed, feature use, and basic event logs.

  • Diagnostic data – crash reports, performance metrics, IP address, and app version.

2.3 Information from Third‑Party Sources

  • Authentication tokens from Apple or Google to enable sign‑in.

  • Subscription status from Apple App Store to verify purchases.

  • AI processing results from OpenAI (e.g., transcriptions and categorization of your voice input).

Note: Nexa is not designed to collect sensitive personal data (e.g., health information or political opinions). Please avoid storing such content in the app.

3. How We Use Your Information

  1. Deliver and operate the Service – save reminders, sync data with Supabase, and send proactive notifications.

  2. Process transactions – manage subscriptions and in‑app purchases.

  3. Transcribe and interpret voice input – leverage OpenAI models to categorize your entries.

  4. Improve and personalize Nexa – troubleshoot, test new features, and understand aggregate usage trends.

  5. Communicate with you – respond to support requests, send updates, and provide security alerts.

  6. Meet legal requirements and enforce our Terms of Service.

4. Legal Bases for Processing (EEA/UK)

We rely on the following legal bases: consent, contract performance, legitimate interests (e.g., improving Nexa, preventing fraud), and legal obligation.

5. Sharing & Disclosure of Information

We disclose information only as necessary:

  • Service providers – Supabase (database & storage), Vercel (backend functions), OpenAI (AI services), RevenueCat/Stripe (billing), and Firebase Crashlytics (analytics/crash reporting).

  • Compliance and safety – to comply with laws, respond to lawful requests, or protect the rights, property, or safety of Nexa and its users.

  • Business transfers – during mergers, acquisitions, or asset sales (we will notify you).

  • Aggregated or de‑identified data – data that cannot reasonably identify you.

We do not sell your personal information.

6. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service and comply with legal obligations. You may delete individual reminders at any time or delete your entire account in app; we erase associated personal data within 30 days, except where a longer retention period is required by law.

7. Security

We use industry‑standard safeguards, including TLS encryption in transit, salted bcrypt hashing for passwords, and role‑based access controls. Nevertheless, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Rights & Choices

Depending on your location, you may have the right to:

  • Access a copy of your data

  • Correct inaccurate data

  • Delete your data ("right to be forgotten")

  • Restrict or object to certain processing

  • Opt out of marketing communications

Most requests can be managed under Settings → Privacy. For others, email privacy@mynexa.ai.

9. California Privacy Notice (CCPA/CPRA)

Nexa does not sell personal information. California residents can request details about data collected, deletion, correction, and disclosure practices. Submit requests via the contact methods below; we will verify your identity as required by law.

10. International Transfers

Our servers reside in the United States. If you access Nexa from outside the U.S., your information will be transferred to the U.S. We rely on Standard Contractual Clauses or equivalent safeguards where required.

11. Children’s Privacy

Nexa is not intended for children under 13. We do not knowingly collect data from children. If we discover such data, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy occasionally. We will post the new version in‑app and on our website and adjust the “Last updated” date. Material changes will be announced by email or in‑app notification at least 30 days before they take effect.

13. Contact Us

If you have questions or concerns about privacy, please contact us:

Nexa Privacy Team
Email: privacy@mynexa.ai

Thank you for trusting Nexa to help you command your day with ease.