Privacy Policy

Last updated: August 2026.

1. Introduction

Nexa (NexaHub) is an AI knowledge workspace for businesses. Your team puts in the things it already works from every day, whether that is documents, notes, links, or recordings, and Nexa makes all of it searchable and answerable.

This policy sets out what we collect, why, and what you can do about it. It covers the Nexa web app, our API, and any integration you choose to connect. It does not cover the other services you connect Nexa to. Those run under their own privacy policies, and it is worth reading them.

Where this policy says "workspace data", it means the content you and your team put into Nexa. That content belongs to you, not to us.

2. Information we collect

Account information. Your name, email address, and a hash of your password. If you sign in with Google, LinkedIn, or Apple, we receive the basic profile those providers return. We never see your password for any of them.

Workspace and company information. Your workspace name, who you invite, their roles and departments, how you organise collections, and which plan you are on.

Uploaded files and knowledge sources. The documents, notes, links, and audio you add. We also store what we derive from them: extracted text, transcripts, embeddings, search indexes, and the citations that let an answer point back at the page it came from.

Chat conversations and AI interactions. Your questions, the answers, which sources were cited, and any action you approved (creating a reminder, drafting an email, writing a record to a connected CRM).

Integration data. When you connect Google Drive, Slack, a CRM, or WhatsApp Business, we receive whatever that connection is scoped to. If you select three Drive folders, we see those three folders. We also store the access token that keeps the connection alive, encrypted.

Usage and technical information. Which features get used, what gets searched, which jobs run, plus IP address, browser, device type, and timestamps. We keep server logs, and an audit trail of significant actions inside a workspace.

Cookies. Covered in section 9.

3. How we use information

We use it to run the product: store your content, answer questions with citations, transcribe audio, and carry out the automations you set up. That means extracting text, generating embeddings, indexing for search, and assembling the context an answer gets built from.

Beyond running it, we use information to keep the service working and safe. We investigate failures, measure performance, and look at which features get used so we know what to improve. We detect abuse, enforce plan limits, scan uploads for malware, and protect accounts. When you raise a support ticket we look into it, and our staff only open workspace content when solving the ticket actually requires it.

We also use account and usage information for billing and to apply the limits that come with your plan.

We do not sell your personal information. We do not use your workspace data to advertise to you.

4. AI processing

Some of Nexa's features work by sending content to the AI providers that run the underlying models. This happens when you use a feature that needs it: asking a question, transcribing a recording, reading a scanned page, generating a summary.

Only what the operation actually needs gets sent. When you ask a question, what goes out is the handful of passages relevant to that question, not your whole workspace.

We choose providers on the basis that content sent through their APIs is not used to train their general models, and we set our integrations up accordingly.

Quite a lot never reaches a provider at all, because plenty of the processing runs on our own infrastructure. Ordinary text recognition on a clear scan, for example, never leaves it.

You decide what goes in, which sources a question is allowed to draw on, and what gets deleted. An administrator can see which AI operations a workspace has used, and what they cost, from the usage screens.

5. Third-party integrations

Nexa connects to services you authorise, through OAuth where the provider supports it.

You see exactly which permissions you are granting before you approve them, and we only ever ask for the narrowest scope that will make the feature work. Access tokens are stored encrypted and used for nothing beyond the features you turned on, and we reach only the data the connection covers, meaning the folders, channels, or records you picked yourself.

You can disconnect any integration from your workspace settings whenever you want. Disconnecting revokes our access and stops the syncing. Content that was already imported stays in your workspace until you delete it, and you can delete it.

Anything Nexa sends out to another service, such as a Slack message or a CRM record, is covered by that service's policy from the moment it arrives.

6. Data storage and security

Your data lives on managed cloud infrastructure. We apply the security measures you would expect of a business SaaS product:

  • traffic encrypted with HTTPS/TLS, and sensitive stored values such as

integration tokens encrypted at rest;

  • workspace isolation, so a workspace's content is reachable only by its members,

with role and collection permissions inside it;

  • malware scanning on uploads;
  • audit logging of significant actions;
  • internal access restricted to staff who need it for a specific reason.

No system is perfectly secure, and we are not going to claim otherwise. If a breach affects your data, we will tell affected customers without undue delay.

7. Data retention and deletion

We keep your workspace data for as long as your account is active and you keep it there.

Deleting individual content. Remove a file, note, link, or conversation from the app at any time. Deleting a source also removes what we derived from it: the extracted text, the embeddings, the search index entries.

Deleting your account. Go to Settings and choose Delete account. You do not have to email anyone and you do not have to explain why.

You are signed out on every device straight away, but nothing is deleted for 14 days. Your files, chats, notes and CRM stay exactly where they are for that whole period. Sign in again at any point before the 14 days are up and the deletion is simply cancelled. Nothing has to be rebuilt, because nothing was taken apart, so your account is exactly as you left it.

Once the 14 days pass it is permanent. Your files come out of storage, your workspace data is deleted, and your name, email and password are erased from our records.

If you own a company workspace, deleting your account deletes the whole company, including its files, chats, notes and CRM, and everyone in it loses access immediately. The app tells you this and asks you to type the company name before anything is scheduled.

What we keep afterwards, and why. We keep a record that the account existed and closed: the date, how long you were with us, roughly what you used, the plan you were on, and the reason you gave if you gave one. We use it to understand why people leave. Your email and name are removed from that record after 180 days, and what is left cannot be traced back to you. Invoices and payment records are kept, without your identity attached, for as long as tax and accounting law requires. Support conversations are kept in the same anonymised form.

Making a request another way. If you cannot reach the app, email privacy@nexahub.ai from the address on your account and we will handle it.

Integration data. Disconnecting a service stops the syncing. Deleting the imported content removes it from your workspace.

One caveat on timing: backups run on a rolling schedule and get overwritten in the normal course of things, so deleted content can survive briefly in a backup before it cycles out. Server logs are kept for a limited period for security and debugging.

If you connect a service with its own required deletion route, such as Meta/WhatsApp Business, you can ask us to delete the data received through that integration at privacy@nexahub.ai. We handle those requests under this section.

8. Your rights

Depending on where you live, you may have the right to ask us to:

  • give you a copy of the personal information we hold about you;
  • correct anything that is wrong;
  • delete your personal information;
  • export your information;
  • stop or limit certain processing;
  • withdraw your consent, where we relied on it.

Email privacy@nexahub.ai to exercise any of these. We will ask you to confirm who you are first, and we will respond within a reasonable period.

If you use Nexa through your employer's workspace, your employer controls that workspace's data. We may pass your request to them, and we will help them act on it.

9. Cookies and analytics

We use cookies to keep you signed in, to remember preferences such as language and theme, and to understand in aggregate how the product is used so we can improve it. The essential ones are needed for the app to function. You can block cookies in your browser, but parts of Nexa will stop working if you do. We do not use advertising cookies.

10. Changes to this policy

We will update this policy as the product changes. The date at the top always reflects the current version. If a change is significant, we will give you reasonable notice in the product or by email before it takes effect.

11. Contact

Questions about this policy, or a request about your data:

privacy@nexahub.ai

    Privacy Policy · NexaHub