NEXUS MARKETING OS
Preparing your workspace
Restoring saved state without generating content or taking any action.
NEXUS MARKETING OS
Preparing your workspace
Restoring saved state without generating content or taking any action.
How NEXUS collects, uses, and protects data, and the rights you may request under applicable law
Information you provide directly: • Name and email; Supabase Auth handles the password and stores a secure derived value • Payment information (processed by Stripe — we do not store card data) • Campaign data and content you enter Operational information: • Technical logs needed to operate and secure the service • IP address and browser type as processed by hosting and security services • Optional usage and performance analytics after consent
We use your information solely to: • Provide and improve our services • Process payments and manage subscriptions • Send technical notices and support messages • Review optional usage and performance telemetry when you consent • Prevent fraud and abuse • Comply with legal obligations
• AI-generated content based on your inputs is provided for your use under the applicable terms • We do not use your specific inputs to train a NEXUS-owned AI model • OpenAI API processes inputs under its terms, policies, and the service settings in use (see: openai.com/privacy)
• Core application data is stored on Supabase, media files are stored on Cloudinary, and the service interface runs on Vercel. • Service connections use HTTPS/TLS and infrastructure providers apply storage encryption under their configurations; sensitive OAuth tokens are additionally encrypted by the application with AES-256-GCM. • We use access controls and operational logs to isolate workspace data and investigate failures. • Data is retained while an account is active or as needed to provide the service and meet legal obligations.
We do not sell, trade, or rent your personal information to third parties. Service providers in use: • Supabase — authentication and data storage • Stripe — payment processing • OpenAI — AI text and image generation • fal.ai — image generation when that provider is enabled • Cloudinary — media hosting • Resend — operational email delivery • Vercel — hosting and optional usage/performance analytics • Sentry — application error monitoring and incident diagnostics when monitoring is enabled • Google Fonts — delivery of site interface fonts • Meta, LinkedIn, TikTok, Pinterest, Google/YouTube, and X/Threads — only when you connect a supported account or request an eligible platform action Each provider's processing is governed by its terms and the service settings in use.
We use essential storage for sign-in state, security functions, operating preferences, and continuity of drafts you requested. You can opt into Vercel Web Analytics/Speed Insights from the consent banner. Choosing “Essential only” prevents optional analytics components from loading.
Depending on the law applicable to you, you may have rights to: • Access — request a copy of your personal data • Correction — update inaccurate information • Deletion — request deletion of the account and data eligible for deletion • Restriction — request restriction of processing • Portability — request a machine-readable copy where applicable • Objection — object to specific processing, including direct marketing We may retain limited billing, security, fraud-prevention, legal, and backup records under applicable retention periods. We will explain the deletion scope and any exceptions when verifying a request. To submit a request: privacy@nexus-grow.com
Rights, response periods, and exceptions vary by your location and the law applicable to you and the Service operator. You may submit an access, correction, deletion, restriction, portability, or objection request to privacy@nexus-grow.com; we will verify identity and respond under applicable requirements. We do not sell personal information. This section is not a claim of blanket certification or compliance under every privacy regime.
The Service is not directed at individuals under 16. We do not knowingly collect information from children under 16. If we discover any unintentional collection, we will delete the data immediately.
We may update this policy when the product, providers, or applicable requirements change. We will update the policy date and provide additional notice when the nature of the change or applicable law requires it.
When you connect a Facebook Page, NEXUS uses Meta permissions to: • List the Pages you manage (pages_show_list) • Read engagement on your own posts (pages_read_engagement) • Publish posts you create (pages_manage_posts) When you connect a Meta Ads account, NEXUS may use Marketing API permissions to: • Read ad accounts and business context you can access (ads_read, business_management) • Create campaign, ad set, ad creative, or ad draft objects in a paused state only after explicit confirmation (ads_management) • Read paid campaign performance after real platform data exists (ads_read) • NEXUS never publishes merely because an account is connected. Immediate publishing requires your explicit Publish action; scheduled API publishing is limited to a post you reviewed, approved, scheduled, and placed in AUTO mode. • NEXUS does not launch paid ads or start budget spend just because an account is connected or a plan exists. Platform creation is paused-draft only, and activation requires separate final approval for launch, budget, and spend. • Access tokens are encrypted inside the application with AES-256-GCM and removed from NEXUS when you disconnect the account. • We never see or store your Facebook password — connection uses Meta's official OAuth. • To delete data associated with a Meta connection, disconnect in Connections or use our Data Deletion process (/data-deletion). • The Instagram path is implemented, but it is not shown as ready until Business-account and publishing-permission verification succeeds.
Privacy request email: privacy@nexus-grow.com