Privacy Policy
Draft — Effective date: [NOT YET PUBLISHED] · Version 0.1
Draft — not reviewed by a lawyer.
This document is a starting draft, not a finished legal document. It has not been reviewed by a lawyer, references a legal entity and jurisdiction that don’t exist yet, and must not be treated as binding until reviewed and approved for the jurisdictions NEXORA actually operates in. Questions: legal@onenexora.com.
This Privacy Policy describes how [LEGAL ENTITY NAME — NOT YET INCORPORATED] (“NEXORA,” “we,” “us”) collects, uses and shares information in connection with the NEXORA platform. It describes our actual architecture, not generic boilerplate — each section below reflects what the system genuinely does.
1. Information we collect
Account and identity information. Sign-up and sign-in are handled by our identity provider, Clerk — your name, email address, password (hashed by Clerk, never seen by us), and organisation memberships are stored there, not in NEXORA’s own database. We never store a copy of your password.
Payment information. Subscription payments are processed by Stripe. We do not collect or store your card number, expiry date, or CVC — Stripe handles and stores that directly. We store only the subscription status, plan, and Stripe’s own customer/subscription identifiers needed to know what your organisation is entitled to.
API keys. When your organisation creates an API key, we store a one-way hash of it and a short, non-secret prefix for identification — the plaintext key is shown to you once, at creation, and is never stored or retrievable again.
Usage and audit events. We log events describing what your organisation does within the Service — for example, that a scan completed, or an API key was created — including a timestamp, the organisation and actor involved, and an outcome. This powers billing/usage limits, the Usage and Analytics views in Console, and security auditing. We do not log the content of what you submit to a product (for example, the log sample you paste into Sentinel) as part of this audit trail — only that the action occurred.
Content you submit to a product. Some products (for example, Sentinel and CSPM) accept data you paste in directly — log samples, resource descriptions — to analyse on request. Handling of that content is described on each product’s own page; [TODO(launch): confirm and state each product’s retention period for submitted content here once decided].
2. How we use information
- To provide, maintain and secure the Service;
- To authenticate requests and enforce your organisation’s plan limits;
- To process payments and manage subscriptions;
- To respond to support requests sent to hello@onenexora.com;
- To detect, investigate and prevent abuse, fraud, or security incidents;
- To comply with legal obligations.
We do not sell your personal information, and we do not use content you submit to a product to train any model.
3. Who we share information with
We share information with the following categories of service providers ( “subprocessors”), each acting under its own terms, solely to operate the Service:
- Clerk — identity, authentication and organisation membership;
- Stripe — payment processing and subscription billing;
- Our database host — stores API key hashes, audit events and subscription state (Postgres; [TODO(launch): name the specific host once selected]);
- Our infrastructure/hosting provider — runs the application itself ([TODO(launch): name once selected]);
- The AI provider configured for Gateway — when you use Gateway, your request is forwarded to whichever upstream model provider Gateway is configured with, so that provider processes the content of that specific request under its own terms.
We do not share your information with third parties for their own marketing purposes.
4. Data retention
We retain account and audit data for as long as your organisation’s account is active, and for a limited period afterward as needed for legal, tax, or dispute-resolution purposes. [TODO(launch): specific retention periods per data category not yet decided.]
5. Cookies
We use cookies required for authentication (set by Clerk) and, where used, essential session state. We do not currently use third-party advertising or cross-site tracking cookies. [TODO(launch): update this section if analytics/marketing cookies are added.]
6. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact legal@onenexora.com. [TODO(launch): this section needs jurisdiction-specific detail — e.g. GDPR/UK GDPR and CCPA/CPRA rights and response timelines — once NEXORA’s operating jurisdictions and user base are known.]
7. Security
See our Security Statement for the concrete practices in place. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Children’s privacy
The Service is not directed at children and is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email before taking effect.
10. Contact
Questions about this policy can be sent to legal@onenexora.com. Registered address: [REGISTERED BUSINESS ADDRESS — TBD].