Legal

Privacy Policy

Last updated: 2026-09-19

This policy covers data collected by nexxi.ai, the Nexxi web app, and the Nexxi Model Context Protocol (MCP) server when invoked from Claude (Cowork, Code, Desktop), ChatGPT, Gemini, Perplexity, and other AI clients.

1. What we collect

  • Account data. Email, name, organization, role, and password hash (Better Auth). Optional Google OAuth profile data when a user signs in via Google.
  • Pilot inputs. The goal, niche, ICP, and business context a user supplies when starting a pilot. May include company name, domain, target market descriptions, and competitive context.
  • Pilot outputs.Blueprints, deliverables, worker outputs, and approval decisions stored against the user's session.
  • Tool-call telemetry. Every MCP tool call is logged with timestamp, tool name, calling user/API key, latency, and cost. Tool inputs are stored only when needed to reproduce the call (e.g., a search query); free-text inputs that may contain PII are PII-redacted before persistence.
  • Operational logs. HTTP request method, path, status, IP address (truncated after 30 days), user agent, and OpenTelemetry spans.
  • Affiliate attribution. When a user clicks a tool recommendation, we record visitorId, sessionId, playbookId, toolId, and click timestamp. We do not record real names against affiliate clicks.

2. What we do NOT collect

  • Credit-card numbers, bank accounts, SSNs, or government IDs (Stripe handles payments).
  • Health data (HIPAA / PHI is out of scope for this product).
  • Biometric identifiers, facial images, or voice recordings.
  • Browser history, autofill data, or saved passwords from the AI client.
  • Conversations from your Cowork/ChatGPT/Gemini chats outside of explicit Nexxi tool calls.

3. Data flow when you use Nexxi from an AI client

When you connect Nexxi via MCP to Claude Cowork, ChatGPT, Gemini, or another client:

  1. The AI client sends the tool name, arguments, and your API key (when authenticated) to nexxi.ai/api/mcp/nexxi-cowork over HTTPS.
  2. Nexxi's server processes the call against your tenant-scoped data only — your API key's userId / organizationId is the tenant boundary; cross-tenant access is denied.
  3. Tool outputs are returned to the AI client and rendered to you. Nothing from your other AI conversations is read or transmitted to Nexxi.
  4. For tools that require external research (Perplexity, Serper, Exa), Nexxi forwards your query to those providers. Their privacy policies govern their handling.
  5. For LLM-backed synthesis (Together, Groq, OpenAI, Anthropic), inputs are sent through their APIs with PII redaction applied beforehand.

4. PII detection and redaction

Before any input is sent to a third-party LLM or stored in long-term logs, Nexxi runs it through a PII detector that masks emails, phone numbers, SSNs, and credit-card numbers. Confidence thresholds: SSN 0.98, email 0.95, credit card 0.90, phone 0.85. Redacted values are replaced with sentinel tokens like [EMAIL_REDACTED].

5. How we use data

  • Deliver the pilot you requested (legitimate-interest basis: GDPR Art. 6(1)(b)).
  • Improve worker quality via aggregate, anonymized outcome telemetry (legitimate-interest: GDPR Art. 6(1)(f)).
  • Detect abuse, prevent fraud, and enforce rate limits.
  • Bill subscriptions and usage (Stripe handles cardholder data; we receive only the customer ID and product line).
  • Send transactional email (Resend / Loops) — receipts, security alerts, support replies.

We do not sell personal data, run third-party advertising trackers on logged-in pages, or use customer pilot data to train foundation models without opt-in.

6. Third-party processors

  • Supabase — Postgres database, authentication.
  • Vercel — application hosting, edge runtime.
  • Stripe — payment processing.
  • Together AI, Groq, OpenAI, Anthropic — LLM inference.
  • Perplexity, Serper, Exa — research APIs.
  • Resend / Loops — transactional email.
  • Langfuse, Helicone, OpenTelemetry — observability.
  • Upstash — rate-limit Redis.
  • PostHog — product analytics (logged-in surfaces only; opt-out available in /settings/consent).

7. Data retention

  • Pilot data: retained for the life of your account; deletable on request.
  • Tool-call telemetry: 365 days, then aggregated and source rows deleted.
  • HTTP access logs: 30 days, IPs truncated.
  • Backups: 35 days rolling; the GDPR delete cascade reaches into the latest backup within 35 days.
  • Affiliate event records: 24 months for attribution; then aggregated.

8. Your rights (GDPR / CCPA)

You can:

  • Request a copy of your data (data portability).
  • Correct inaccurate data.
  • Delete your account and all linked data (single-transaction cascade across user_preferences, user_corrections, saved_plays, saved_stacks, saved_tools, pilot_sessions; user record anonymized).
  • Opt out of analytics and non-essential processing in Settings → Consent.
  • Request a creator-content removal via the removal form.

For deletion, hit DELETE /api/user/delete while authenticated, or email privacy@nexxi.ai. We acknowledge within 72 hours and complete within 30 days.

9. Security

  • HTTPS everywhere (TLS 1.2+).
  • Outbound SSRF allowlist on every external HTTP call.
  • API keys hashed at rest; raw key only shown once at generation.
  • Strict Content Security Policy with nonce-based scripts in production.
  • SQL-injection, XSS, and prompt-injection detection at the middleware layer.
  • Disclose vulnerabilities to security@nexxi.ai.

10. Children

Nexxi is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has signed up, email privacy@nexxi.ai and we will delete the account.

11. Changes to this policy

Material changes will be announced via in-product notice and email at least 14 days before taking effect. Each version is timestamped at the top of this page.

12. Contact

Privacy questions: privacy@nexxi.ai
Security disclosures: security@nexxi.ai
Abuse reports: abuse@nexxi.ai
Support: support@nexxi.ai

Open Removal Request →