Privacy Policy
Effective date: September 28, 2026
This policy explains how Nexia Cloud OS handles information for its public website, Nexia Developers, and related account services. Customer workspace data is also subject to the customer’s agreement and the instructions of the organization that operates that workspace.
1. Information we process
We process the name, email address and account information you provide, developer project memberships, invitations, and information submitted through support requests. Service requests may produce IP addresses, browser information, timestamps and security logs. A customer organization controls the business records and personal information it enters into its workspace.
2. Google and GitHub sign-in
When you choose Google or GitHub sign-in, we request your basic profile and verified email address. We use the provider’s account identifier, name and email to create or authenticate your developer account and link the sign-in method you selected. Sign-in does not request access to Gmail, Google Drive, contacts, calendars or GitHub repositories. Provider access tokens are used during sign-in and are not stored as a continuing integration in your developer account. Google account data is not used for advertising or to train general-purpose AI models.
3. Why we use information
We use information to provide accounts and requested services, manage project access, send verification and invitation messages, respond to support requests, and investigate security incidents or misuse. Where applicable, processing relies on providing the service you request, consent for optional analytics, legitimate service-security interests, or legal obligations. You can decline optional analytics without losing access to the service.
4. Cookies and analytics
Session and security cookies support authentication and protect requests. On supported public and developer pages, Google Analytics is enabled only after you consent. It receives permitted page and interaction events, such as page views and sign-in or project actions, along with device and network information processed by Google. Our event payloads exclude email addresses, project or tenant identifiers, URL query strings and referrers. Production and developer analytics use separate streams. You can change your choice through Analytics settings on the website; withdrawing consent stops future collection in that browser but does not automatically erase previously collected information.
5. Service providers and sharing
Hosting, network, authentication, email and analytics providers process information needed to operate the selected features. These include Laravel Cloud for hosting, Cloudflare for network and service infrastructure, and Google for sign-in, email delivery and consented analytics; GitHub processes its own sign-in flow. Infrastructure and support processing may take place outside your country. We do not sell Google account information. We disclose information when needed to provide the requested service, protect accounts, comply with a lawful obligation, or follow an authorized customer instruction.
6. Retention and deletion
Account and project information is retained while needed to provide the service and manage authorized access. Security, billing and audit records may need to be retained for their operational purpose or applicable legal obligations. Retention of customer workspace records depends on the customer’s configuration and agreement. To request account deletion or details about applicable retention, contact support@nexia.to. After verifying your identity, we explain what can be removed and any records that must be retained; removing a sign-in connection alone does not delete your account or a customer’s workspace records.
7. Your choices and requests
You can review account settings, disconnect a Google or GitHub identity when another sign-in method remains available, and revoke access in your provider’s account settings. Contact support@nexia.to to request access, correction, deletion, a copy of your information, or to object to or restrict processing where applicable. For information controlled by an employer or another customer organization, contact that organization’s administrator. We may verify identity and authority before acting on a request.
8. Security, updates and contact
We use authentication, access controls and service safeguards to protect information. No online service can guarantee absolute security. This service is intended for professional and organizational use, not for children. Material changes to this policy will be communicated through the service or appropriate account channels. Contact the Nexia Cloud OS team at support@nexia.to with privacy questions.