Nexsus Privacy Policy
This policy explains what data Aruni Ishanka Wickramasinghe (ABN 89 335 490 366), trading as Nexsus ("Nexsus", "we", "us") collects when you use the Nexsus service — the memory workspace for AI assistants, including the MCP API, your hosted workspace, the customer dashboard, and our website — how we use and store it, who else touches it, how long we keep it, and the controls you have. It should be read together with the Terms of Service.
1. Data we collect
- Account data — your email address, workspace name, and password. Passwords are stored only as cryptographic hashes, never in plain text. If you enable two-factor authentication we also store your 2FA secret.
- Workspace content — the records, models, relationships, and memory rows your AI assistant (or you) write into your workspace. This is your data; you choose what goes in it.
- Derived search vectors — numeric embeddings computed from your workspace content so your assistant's semantic recall works. They are stored alongside your content, in your workspace.
- Billing data — handled by our payment provider (Stripe). We receive your subscription tier, payment status, and invoice events; full card numbers never reach our servers.
- Operational data — a security audit trail (sign-ins, token mints, denied attempts, with IP addresses), per-workspace tool-call counts used for metering, and standard server logs kept for security, rate limiting, and abuse prevention.
- Cookies — a session cookie to keep you signed in to the dashboard. No advertising or cross-site tracking cookies, and no third-party analytics scripts on the service.
2. How we use and store your data
We use the data above solely to provide and operate the Service: hosting your workspace, generating the embeddings that power semantic recall, metering usage and billing, securing accounts, preventing abuse, sending transactional email (verification, allowance warnings, wind-down notices), and responding to support requests.
We do not sell your data. We do not show advertising. We do not use your workspace content to train AI models.
Each workspace lives in its own isolated database schema with its own database role — one customer's assistant cannot read another customer's workspace. Data is encrypted in transit and at rest on our infrastructure. API keys and access tokens are stored only as cryptographic hashes. Nexsus is not a zero-knowledge system: like the major cloud storage providers, the Service must be able to process your data to serve it, and we access workspace content only to operate the Service, investigate abuse, or as required by law.
3. Your AI assistant and your data
You connect your own AI assistant (for example Claude or ChatGPT) to your workspace, and you authorise that connection yourself — by OAuth consent or an API key you control. Whatever your assistant reads from your workspace is handled by your assistant provider under your agreement with them. Nexsus never pushes workspace content to assistant providers on its own initiative; content moves only when your assistant calls a tool on your workspace.
4. Third parties we share data with
We share data only with the processors we need to run the Service, only for the purposes described here:
- Railway — cloud infrastructure that hosts the Service and its databases, located in the United States.
- Stripe — payment processing and subscription billing.
- Voyage AI — embedding generation: snippets of workspace text are sent to compute the search vectors described above.
- Resend — transactional email delivery (your email address and the notice content).
These providers store and process data in the United States, so personal information we hold is disclosed to overseas recipients located there. We do not share your data with anyone else except as required by law.
5. How long we keep your data (retention)
- Active accounts — workspace content is kept for as long as your account is active. The workspace is append-only by design: archiving a record removes it from lists and search but preserves its history inside your workspace.
- Archive Mode and wind-down — if your subscription ends or a Free workspace stays over its allowance, the retention windows in the Terms of Service apply: 2 years if you have ever paid, 6 months if you never have. We send three warning notices before anything is deleted (roughly one month out, two weeks out, and 48 hours before deletion), and your data stays exportable the entire time. Deletion at the end of the window is permanent.
- After deletion — the email address of a deleted account remains reserved and cannot be re-registered (an integrity property of the append-only design), together with the minimal record that the deletion happened. Workspace content does not survive deletion except in any short-lived infrastructure backups, which cycle out automatically.
- Security audit trail — retained while the account exists, for security and dispute resolution.
6. Your controls and rights
- Export — you can export your workspace data (CSV) from the dashboard at any time, including for the entire wind-down period.
- Correct and delete content — you (and your assistant) can update, archive, and restore records at any time through the dashboard and the MCP API.
- Delete your account — you can cancel and delete from the dashboard; the retention windows above then apply.
- Access, correction, and deletion requests — email us at admin@nexsus.com.au and we will respond within a reasonable period. Australian users have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles; users elsewhere may have rights under their local law (for example the GDPR). If you are not satisfied with our response to a privacy complaint, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
The Service is not directed to children under 16, and we do not knowingly collect personal information from them.
7. Changes to this policy
If we make material changes we will notify you (email or dashboard notice) before they take effect. The current version is always available at the Privacy page, and the version number above changes with any substantive edit.
8. Contact
Privacy questions, requests, and complaints: admin@nexsus.com.au (Aruni Ishanka Wickramasinghe, trading as Nexsus, ABN 89 335 490 366).