1. Introduction & Scope

This Privacy Policy describes how Nexus AI Coding collects, uses, discloses, and protects personal information when you register for, access, or use our AI coding platform, website (nexus-ai.nexus), and related services (collectively, "Services"). This policy applies to all users worldwide and complies with GDPR, CCPA/CPRA, and other applicable privacy laws.

By using our Services, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use immediately. These Terms are integrated with our Terms of Service, particularly regarding payment processing and data usage rights.

2. Information We Collect

We collect the following categories of personal information:

  • Account Data: Name, email address, username, password, company name, billing address, contact information, and account credentials.
  • Code & Content (User Content): Code snippets, uploaded files, project metadata, prompts, generated outputs, and any content you create, upload, or store using our Services. You retain ownership of your User Content as outlined in our Terms of Service.
  • Transaction Data: Payment records, invoices, purchase history, billing information, subscription details, and transaction metadata. We NEVER store raw credit card numbers (PANs) on our servers—all payment card data is processed securely via tokenized flows provided by our PCI DSS Level 1 compliant payment processors.
  • Usage & Technical Data: Device information, IP addresses, browser type, operating system, access logs, API usage patterns, feature usage data, timestamps, and analytics data collected via cookies and tracking technologies.
  • Communications Data: Support requests, feedback, email correspondence, attachments, and any data you provide when contacting us.
  • Cookies & Tracking Data: Information collected via cookies, pixel tags, web beacons, and similar technologies (see Section 5).
  • Derived Data (for AI improvement): Aggregated and anonymized patterns derived from your usage to improve our Services and AI models (unless you opt out).

3. How We Use Information

We use your personal information for the following purposes:

  • Service Delivery: To provide, maintain, operate, and improve our AI coding platform, including code generation, analysis, and automated reviews.
  • Account Management: To create and manage your account, authenticate your identity, and manage subscriptions.
  • Payment Processing: To process payments, calculate credits/billing, issue invoices, handle refunds, and manage subscription renewals via third-party payment processors.
  • Communications: To respond to support inquiries, send service-related notices (account updates, security alerts, billing notifications), and provide customer support.
  • Fraud Prevention & Security: To detect, prevent, and investigate fraud, abuse, security incidents, unauthorized access, and violations of our Terms of Service.
  • Compliance & Legal Obligations: To comply with legal obligations, respond to lawful requests from authorities, enforce our agreements, and resolve disputes.
  • Analytics & Improvement: To analyze usage patterns, understand user behavior, conduct research, and improve our Services, user experience, and AI models (with your consent or under legitimate interests).
  • Marketing (with consent): To send promotional emails about new features, products, or events. You can opt out at any time via unsubscribe links or email.
  • Legal Bases (GDPR): We process data based on contract performance, legitimate interests, legal compliance, your explicit consent, and other lawful bases as appropriate under GDPR Article 6.

4. Payments & Payment Processor Compliance

✓ Multi-Processor Integration: We partner with trusted payment processors, including a Merchant-of-Record partner, to handle all payment transactions securely and compliantly.

Payment Processors: We use third-party payment processors including Stripe, PayPal, Authorize.Net, Paddle, Whop, and Dodo Payments ("Dodo Payments") to securely process payments. These providers act as data processors and/or independent data controllers and payment facilitators on our behalf, depending on the specific transaction flow.

Authorize.Net
Privacy Policy Link
Paddle
Privacy Policy Link
Dodo Payments
Privacy Policy

Payment Card Data Security:

  • Tokenization: All payment card data is handled exclusively through processor-hosted and tokenized payment flows. We do not store, process, or have access to your full credit card numbers (PANs).
  • PCI DSS Level 1 Compliance: Our payment processors maintain the highest level of PCI DSS certification. We follow PCI best practices and do not directly handle sensitive cardholder data.
  • Secure Payment Flows: Payment processing uses encryption, secure APIs, and hosted payment pages to protect your card information in transit and at rest.

Data Sharing with Payment Processors:

  • Information Shared: We share necessary transaction information (name, email, billing address, transaction amount, subscription details) with payment processors to complete purchases, issue refunds, and manage billing.
  • Merchant-of-Record Partner (Dodo Payments): For certain products or jurisdictions, we may use Dodo Payments as a Merchant of Record. In those cases, Dodo Payments acts as an independent data controller for buyer and transaction data and processes such data in accordance with its own privacy policy and applicable law. Your contractual and data protection relationship for the payment component is then also with Dodo Payments directly.
  • Data Processing Agreements: We maintain Data Processing Agreements with our payment processors where they act as processors, as required by GDPR and other privacy laws.
  • Processor Privacy Policies: Each processor handles personal information according to their own privacy policies. Payment processor privacy policies are your responsibility to review.
  • Disputes & Chargebacks: We share necessary transaction details with processors and card networks to investigate and resolve payment disputes, chargebacks, and fraud claims.
  • Processor Retention: Payment processors retain transaction records for 7+ years for accounting, tax, and regulatory compliance. We have limited control over processor-retained data.

Your Payment Data Rights: You have the right to access, correct, or request deletion of your payment information. For data controlled directly by payment processors (including Dodo Payments when acting as Merchant of Record), you may need to contact them directly. Contact us at [email protected] for processor contact information.

5. AI Training & Model Improvement Data Usage

⚠ Important: Your User Content (prompts, code) may be used to train and improve our AI models unless you opt out. This is disclosed in our Terms of Service and can be managed via your privacy settings.

AI Model Training:

  • Training Data Use: We may use aggregated, anonymized, and pseudonymized User Content (prompts, code patterns, usage data) to train and improve our AI models, algorithms, and Services.
  • Data Anonymization: Training data is de-identified and processed in aggregate to prevent identification of individual users or reveal confidential information.
  • Third-Party AI Services: If you use our Services with third-party AI APIs (e.g., OpenAI, Anthropic), your data usage is governed by their privacy policies. We recommend reviewing third-party privacy terms.

Opting Out of AI Training:

  • Privacy Settings: You can opt out of using your User Content for AI model training via your account privacy settings.
  • Opt-Out Scope: Opting out prevents your new User Content from being used for training but does not affect past usage or non-anonymized operational data.
  • How to Opt Out: Log into your account, navigate to Privacy Settings, and toggle "Allow AI Training" to OFF. Contact [email protected] for assistance.

Confidential Code: If your User Content contains trade secrets or highly confidential information, we recommend using enterprise privacy features or contacting us about data handling agreements.

6. Cookies & Tracking Technologies

We and our service providers use cookies, pixel tags, web beacons, and similar tracking technologies to collect information about your browsing activity and interactions with our Services.

  • Essential Cookies: Required for authentication, security, user preferences, and core platform functionality. These cannot be disabled without affecting service operation.
  • Analytics Cookies: Used to understand how users interact with our Services, measure feature adoption, and improve performance (e.g., Google Analytics, Amplitude).
  • Marketing Cookies: Used to deliver relevant advertising, measure campaign effectiveness, and retarget users across platforms (with your consent where required by law).
  • Third-Party Scripts: We may use payment processor scripts (Stripe.js, PayPal scripts, Dodo Payments checkout scripts) and analytics tools that collect device, browser, and usage data for security and monitoring.
  • Your Cookie Choices: Most browsers allow you to block or delete cookies. You can manage cookie preferences in your browser settings under "Cookies" or "Privacy." Disabling cookies may affect platform functionality.
  • Do Not Track (DNT): Our systems do not currently respond to DNT browser signals, but you can control tracking via browser settings and explicit opt-outs.
  • CCPA Opt-Out: California residents can opt out of targeted advertising via browser privacy settings or industry opt-out tools (e.g., NAI, DAA).

7. Data Processing Agreements & Subprocessors

We maintain Data Processing Agreements (DPAs) with our subprocessors as required by GDPR, CCPA, and other privacy regulations. Our subprocessors include:

  • Hosting & Infrastructure: Cloud service providers (AWS, Google Cloud, Azure) for data storage, server infrastructure, and backup services.
  • Payment Processors: Stripe, PayPal, Authorize.Net, Paddle, Whop, and where they act as processors, Dodo Payments (for payment processing, billing, and dispute resolution). When Dodo Payments acts as Merchant of Record, it operates as an independent data controller for buyer and transaction data rather than our subprocessor.
  • Analytics & Monitoring: Analytics platforms and monitoring tools for usage tracking, performance analysis, and fraud detection.
  • Support & Communications: Customer support platforms and email service providers for support tickets and communications.
  • Security & Compliance: Security monitoring, vulnerability scanning, and compliance verification providers.

Subprocessor Notification: We notify customers of material changes to our subprocessor list as required by law or contract. You may request our current subprocessor list by contacting [email protected].

Your Rights: You have the right to object to certain subprocessors or request additional safeguards. Contact us at [email protected] to discuss.

8. Data Security & PCI Compliance

We implement industry-standard security measures to protect your data, including:

  • Encryption: TLS/SSL encryption for all data in transit; AES-256 encryption for sensitive data at rest.
  • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and principle of least privilege for all staff.
  • Security Monitoring: Real-time security logging, intrusion detection systems, and continuous security assessments.
  • Secure Backups: Encrypted, isolated backups with restricted access and tested recovery procedures.
  • Employee Training: Annual security and data protection training for all employees handling personal information.
  • Incident Response: Documented incident response procedures and breach notification protocols compliant with GDPR and state laws.
  • PCI Compliance: We do not store cardholder data on our servers. Payment processing is handled entirely by PCI DSS Level 1 compliant processors using hosted, tokenized payment flows.

Security Limitations: While we strive to protect your data, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials. Notify us immediately at [email protected] of any security concerns.

9. Data Retention Periods

We retain personal information only as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods:

  • Account Data: Retained while your account is active. After account closure, retained for 30 days (for billing purposes), then securely deleted.
  • Transaction Records: Retained for 7 years for accounting, tax compliance, and regulatory requirements.
  • Support Communications: Retained for 3 years to address follow-up inquiries and maintain service quality records.
  • Usage Logs & Analytics: Retained for 1 year for security, fraud prevention, and service improvement purposes.
  • Backups: Retained for 90 days for disaster recovery. Backups are not accessible to you after account deletion.
  • Cookies & Tracking: Retained for the duration of your session or per cookie expiration settings (typically 1-2 years).
  • AI Training Data: Aggregated and anonymized data may be retained indefinitely for model improvement unless you exercise your right to deletion.

After Retention Expiry: Upon expiration of retention periods, we securely delete, anonymize, or pseudonymize personal information using cryptographic destruction or secure disposal methods.

10. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Right to Access: Request a copy of all personal information we hold about you in a structured, machine-readable format.
  • Right to Correct: Request correction of inaccurate, incomplete, or outdated data.
  • Right to Deletion: Request deletion of your personal information (subject to legal retention requirements and exceptions).
  • Right to Data Portability: Receive your personal information in a structured, commonly used, machine-readable format (JSON, CSV, etc.).
  • Right to Object: Object to processing of your data, including for direct marketing and profiling activities.
  • Right to Restrict Processing: Request restriction or suspension of processing under certain circumstances (e.g., while disputing accuracy).
  • Right to Withdraw Consent: Withdraw consent for processing based on consent (without affecting prior lawful processing under other bases).
  • Right to Explanation: Request explanation of automated decision-making processes (if applicable).

How to Exercise Your Rights:

Email [email protected] with:

  • Clear statement of which right(s) you're exercising
  • Your account email address or identifying information
  • Proof of identity (if required for verification)
  • Specific data or account information involved

Response Timeline: We will verify your identity and respond within timeframes required by law:

  • GDPR: 30 days from your request (extendable by 2 months for complex requests)
  • CCPA: 45 days from your request
  • Other jurisdictions: Varies by local law

Marketing Opt-Out: Unsubscribe from promotional emails using the "unsubscribe" link in any marketing message. You can also opt out by emailing [email protected]. Processing may take up to 10 business days.

Payment Processor Data: For data controlled directly by payment processors (including Dodo Payments when acting as Merchant of Record), you may also need to contact them directly to exercise your rights.

11. Children's Privacy

Our Services are not intended for individuals under the age of 18 years old (or higher in certain jurisdictions). We do not knowingly collect personal information from children under 18.

  • EEA/UK: Minimum age is 16 years old (or parental consent if 13-15).
  • COPPA (U.S.): Minimum age is 13 years old without parental consent.

If you believe we have inadvertently collected information from a child, please contact us immediately at [email protected] and we will delete it promptly and take appropriate action.

12. International Data Transfers

We and our subprocessors operate globally and may transfer your data to countries outside your residence, including the United States and other jurisdictions. These countries may have different data protection standards than your home jurisdiction.

Transfer Safeguards: To ensure adequate protection, we use legally approved transfer mechanisms:

  • Standard Contractual Clauses (SCCs): EU-approved model clauses for transfers from the EEA/UK to non-adequate countries.
  • Data Privacy Framework: We rely on the EU-U.S., UK-U.S., and Swiss-U.S. Data Privacy Frameworks where applicable and certified.
  • Adequacy Decisions: We may rely on adequacy findings by the European Commission or UK ICO for transfers to certain countries.
  • Supplementary Measures: We implement supplementary technical and organizational measures to protect transferred data.

Your Rights: You may request details about transfer mechanisms and safeguards by contacting [email protected]. If you believe a transfer violates your rights under GDPR, you may lodge a complaint with your data protection authority.

13. State-Specific Privacy Rights (U.S.)

California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA):

Residents of these states have additional privacy rights under state law:

Your Rights:

  • Right to Know: Request categories and specific pieces of personal information collected, sources, purposes, and third parties with whom we share data.
  • Right to Delete: Request deletion of your personal information collected directly from you (subject to exceptions for legal compliance, fraud prevention, etc.).
  • Right to Correct: Request correction of inaccurate personal information we hold.
  • Right to Opt-Out: Opt out of the "sale" or "sharing" of personal information and targeted advertising based on your activity.
  • Right to Limit Sensitive Data Use: Limit our use of sensitive personal information (SSN, financial info, health data) to purposes necessary to provide services.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights through denial of service, price differences, or reduced service quality.
  • Opt-Out of Automated Decision-Making: Request that we not use automated decision-making that produces legal or similarly significant effects on you (not applicable to AI code generation tools).

Categories of Personal Information We Collect: Identifiers (name, email), commercial information (transaction history, subscription details), internet/network activity (usage logs, IP address), geolocation data, professional information, and inferences (derived from usage patterns).

Categories We Disclose: We disclose identifiers, commercial information, and internet/network activity to payment processors, analytics providers, and service providers.

Sale/Sharing of Personal Information:

  • We do NOT sell personal information for monetary compensation.
  • We MAY share certain data (identifiers, usage data) with analytics and advertising partners for targeted advertising purposes, which may constitute "sharing" under CCPA.
  • We do NOT sell or share sensitive personal information or data of individuals under 16.
  • You can opt out: Toggle "Opt Out of Sharing" in your account settings or use the NAI / DAA industry opt-out tools.

Sensitive Personal Information Use: We use sensitive personal information (SSN, financial info) only for purposes authorized by law: service delivery, security, fraud prevention, legal compliance, and debug purposes. We do not use sensitive data for secondary purposes.

Automated Decision-Making: Our AI Services involve automated code generation and analysis. These are provided as tools under your direction and do NOT involve automated decisions that produce legal or similarly significant effects concerning you (as that term is defined in state law).

To Exercise State Rights:

  • Email [email protected] with a clear statement of your request
  • Provide your account email and any identifying information
  • We will verify your identity and respond within 45 days (extendable by 45 days for complex requests)
  • Authorized Agents: You may submit requests through an authorized agent with proper power of attorney

California "Shine the Light" (CA Civil Code §1798.100): California residents may request information about disclosures of personal information to third parties for direct marketing purposes. Contact [email protected] for details.

14. Contact Us & Privacy Inquiries

Privacy Team
Email: [email protected]
Website: nexus-ai.nexus
Physical Address: [No.10 Spg 185-3, Wasai Limuru RPN Kg.Meragang BT2725 Brunei Darussalam]

For Specific Inquiries:

EU & UK Representations (if applicable):
EU Representative: [Insert EU Representative Name, Address, Email] UK Representative: [Insert UK Representative Name, Address, Email]

Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights:

Changes to This Policy: We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, and other factors. Material changes will be communicated via email to your registered account address or prominent notice on our website. Your continued use of the Services after changes constitutes acceptance of the updated policy.

Effective Date: November 3, 2025
Last Updated: November 4, 2025
Compliance Status: ✓ GDPR • CCPA/CPRA • Multi-Processor • PCI DSS Level 1

This policy is provided for informational purposes and does not constitute legal advice. For compliance guidance specific to your jurisdiction and circumstances, consult qualified legal counsel.

Related Documents: Terms of ServiceData Processing Agreement