Privacy Policy

Last Updated: December 10, 2025

This Privacy Policy describes how NUXA, Inc. ("Nuxa", "Company", "we", "us", or "our"), a Delaware corporation located at 2093 Philadelphia Pike 1110, Claymont, DE 19703, USA, collects, uses, discloses, and protects personal data — including data obtained from Google APIs (including Google Workspace APIs) — and your rights and controls regarding that data.

By using or accessing the Service, you confirm that you have read and understood this Privacy Policy, and you consent to the collection, use, and disclosure of your information as described herein.

Interpretation and Definitions

Interpretation

Words with capitalized first letters have defined meanings under the following conditions. The following definitions have the same meaning whether they are written in singular or plural form.

Definitions

For the purposes of this Privacy Policy:

  • Application or Service means the Nuxa web or mobile application or related services.
  • Account means a unique account created for You to access our Service or parts of our Service.
  • Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest, or other securities entitled to vote for election of directors or other managing authority.
  • Business, for the purpose of the CCPA (California Consumer Privacy Act), refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information.
  • Company (referred to as "the Company", "We", "Us" or "Our" in this Agreement) refers to NUXA, Inc., a Delaware corporation. For the purpose of the GDPR, the Company is the Data Controller.
  • Cookies are small files placed on Your computer, mobile device, or any other device by a website, containing the details of Your browsing history on that website among its many uses.
  • Country refers to the United States of America.
  • Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
  • Data Processor means any natural or legal person who processes Personal Data on behalf of the Data Controller.
  • Device means any device that can access the Service such as a computer, a cellphone, or a digital tablet.
  • Do Not Track (DNT) is a concept promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
  • Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual. For GDPR purposes, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity. For CCPA purposes, Personal Data means any information that identifies, relates to, describes, or is capable of being associated with, or could reasonably be linked, directly or indirectly, with You.
  • Google Data means any data, content, or metadata obtained via Google APIs (including Google Workspace APIs).
  • Generalized AI/ML model means an AI or ML model intended to be broadly trained across multiple users, not specific to a single user's data or behavior.
  • User-facing features means features directly visible or used by the individual user through the app UI.
  • Sensitive Personal Data means Personal Data revealing racial or ethnic origin, political opinions, religious beliefs, health information, genetic or biometric data, sexual orientation, or similar categories protected under applicable privacy laws.
  • Sale, for the purpose of the CCPA (California Consumer Privacy Act), means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's Personal Information to another business or a third party for monetary or other valuable consideration.
  • Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service, or to assist the Company in analyzing how the Service is used. For the purpose of the GDPR, Service Providers are considered Data Processors.
  • Third-party Social Media Service refers to any website or any social network website through which a User can log in or create an account to use the Service.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
  • Website refers to Nuxa, accessible from nuxa.ai
  • You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable. Under GDPR, You can be referred to as the Data Subject or as the User as you are the individual using the Service.

1. Information We Collect

Personal Data You Provide

When you sign up, link accounts, or use features, you may provide Personal Data such as:

  • Name and email address
  • Phone number and mailing address
  • Profile picture, settings, and preferences
  • Company name, job title, and business information
  • Content you upload (e.g., documents, files) within Nuxa
  • Any data you explicitly input or connect, including via Google integrations

Google Data via API Scopes

If you choose to connect your Google account (e.g., Google Workspace, Gmail, Drive, Calendar, Contacts), we may request specific scopes. Types of Google Data we may access include:

  • Basic profile (name, email)
  • Drive files and documents
  • Calendar events
  • Contacts
  • Gmail messages (only if explicitly requested for a specific feature)
  • Google Sheets data
  • Other Google Workspace content or metadata as needed per feature

Important: We only request the minimal scopes necessary for the features you enable. We do not request scopes for unimplemented features. You can revoke access to any connected Google account at any time through your account settings.

Usage Data

We may also collect information on how the Service is accessed and used ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers, and other diagnostic data.

Tracking & Cookies Data

We use cookies and similar tracking technologies to track the activity on our Service and hold certain information.

Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service.

We use the following types of cookies:

  • Essential Cookies: Required for the Service to function properly (authentication, security, load balancing)
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how visitors interact with the Service (require consent where applicable)
  • Marketing Cookies: Track visitors across websites for advertising purposes (require consent)

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

2. How We Use Your Information

We use the collected data for various purposes:

  • To provide, operate, and maintain our Service
  • To notify you about changes to our Service
  • To allow you to participate in interactive features of our Service when you choose to do so
  • To provide customer care and support
  • To provide analysis or valuable information so that we can improve the Service
  • To monitor the usage of the Service
  • To detect, prevent, and address technical issues
  • To manage Your Account and provide you with access to features
  • For the performance of a contract
  • To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication regarding updates, security alerts, and administrative messages
  • To enable and support user-enabled integrations with Google services (e.g., syncing files or calendar) and provide personalization, suggestions, and user-specific automation for that individual user
  • To detect and prevent fraud, abuse, or security incidents and to comply with legal obligations

Critical AI/ML Commitment: Any Google Data used within Nuxa is used only for features tied to that specific user (user-facing features), and never for generalized AI/ML training or shared model improvement across users. We do not use any Personal Data, including data received through any third-party services, for developing, improving, or training AI and/or ML models.

3. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following legal bases to process your Personal Data:

  • Contract: Processing necessary to perform our contract with you (providing the Service)
  • Consent: Where you have given explicit consent for specific processing activities
  • Legitimate Interests: Processing necessary for our legitimate business interests, provided these do not override your rights and freedoms
  • Legal Obligation: Processing necessary to comply with applicable laws and regulations

You may withdraw consent at any time where we rely on consent as our legal basis.

4. Transfer of Data

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

Primary Data Location: Our primary data storage and processing facilities are located in the United States. If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States and process it there.

International Transfer Safeguards: For transfers of Personal Data from the EEA, UK, or Switzerland to countries not deemed to provide an adequate level of protection, we implement appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission and UK Information Commissioner's Office
  • EU-U.S. Data Privacy Framework certification (where applicable)
  • Additional technical and organizational measures to protect data in transit

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

5. Disclosure of Data

Service Providers

We may share your Personal Data with third-party service providers who perform services on our behalf. These service providers have access to your Personal Data only to perform specific tasks and are obligated to protect your information. Our key service providers include:

  • Cloud Infrastructure: Amazon Web Services (AWS), for hosting and data storage
  • Payment Processing: Stripe, for subscription and payment processing
  • Email Communications: Resend, for transactional emails
  • Analytics: PostHog, for product analytics and usage insights
  • Error Monitoring: Sentry, for application error tracking
  • AI Model Providers: OpenAI, Anthropic, Google, and others as selected by users

Important: We do not sell your Personal Data to third parties. We do not share your Personal Data with third parties for their own marketing purposes without your explicit consent.

Business Transactions

If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law Enforcement & Legal Requirements

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).

Nuxa may disclose your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of Nuxa
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users of the Service or the public
  • Protect against legal liability

6. Data Retention

We retain data only as long as necessary for the purposes disclosed or as required by law:

  • Account Data: Retained during active account + 30 days after deletion request to allow for data export
  • Google API Data: Retained during feature use + 7 days after revocation or account deletion
  • Usage Logs: 90 days for analytics purposes; up to 1 year for security investigations
  • Transaction Records: Up to 7 years for legal, tax, and compliance purposes
  • Communications: Customer support correspondence retained for 3 years after resolution

When you revoke access, delete your account, or stop using a feature, we remove associated data within the timeframes above. Data may be anonymized and retained indefinitely for analytics purposes in a form that cannot be linked back to you.

7. Security of Data

The security of your data is important to us. We implement appropriate technical and organizational measures to protect your Personal Data, including:

  • Encryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Access Controls: Role-based access controls and least-privilege principles
  • Authentication: Multi-factor authentication for administrative access
  • Monitoring: Continuous security monitoring, logging, and alerting
  • Secure Development: Security testing and code review practices
  • Vendor Management: Security assessments of third-party service providers

OAuth tokens and credentials are stored securely using encrypted vault systems and secure key management practices.

However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

8. Analytics

We may aggregate or anonymize non-Google data (not tied to personal identity) for internal analytics, product improvement, usage trends, or performance monitoring. This data cannot be tied back to individual users and is not used for generalized AI/ML training with Google Data.

We use PostHog for product analytics. PostHog processes usage data to help us understand how users interact with our Service and to improve the user experience.

9. Behavioral Remarketing

The Company uses remarketing services to advertise on third-party websites to You after You visited our Service. We and Our third-party vendors use cookies to inform, optimize, and serve ads based on Your past visits to our Service.

Google Ads (AdWords)

Google Ads remarketing service is provided by Google Inc. You can opt-out of Google Analytics for Display Advertising and customize the Google Display Network ads by visiting the Google Ads Settings page.

You may opt out of interest-based advertising by visiting the Digital Advertising Alliance opt-out page.

10. Payments

We may provide paid products and/or services within the Service. In that case, we use Stripe for payment processing.

We will not store or collect Your payment card details. That information is provided directly to Stripe whose use of Your personal information is governed by their Privacy Policy. Stripe adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which helps ensure the secure handling of payment information.

11. Use of Google / Workspace APIs & Data — Limited Use

Affirmative Statement & Compliance

Nuxa's use, storage, processing, and transfer of Google Data (raw or derived) strictly adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Workspace API user data policy (when applicable). We explicitly affirm that:

  • Nuxa does not use, transfer, or allow Google Data to be used to train, improve, or develop generalized or non-personalized AI/ML models.
  • Any processing of Google Data is limited to providing or improving user-facing features visible in the app UI.
  • We do not allow third parties to access Google Data for purposes of training or model improvement.
  • Transfers of Google Data are disallowed except in limited permitted cases as described below.

Permitted Transfers & Data Use

We may only transfer Google Data (raw or derived) to third parties under the following limited conditions and always aligned with user disclosures and consent:

  • To provide or improve user-facing features (with the user's explicit consent)
  • For security, abuse investigation, or system integrity
  • To comply with laws or legal obligations
  • As part of a merger, acquisition, divestiture, or sale of assets, with explicit user consent

Human Access Restrictions

We restrict human review of Google Data strictly. No employee, contractor, or agent may view Google Data unless one of the following is true:

  • The user gave explicit, documented consent to view specific items (e.g., "Let customer support view this email/file").
  • It is necessary for security, abuse investigation, or legal process.
  • Data is aggregated, anonymized, and used for internal operations only (without re-identification).

Scope Minimization & Justification

We only request scopes essential to features you opt into; we do not request broad or unused permissions. For each Google API scope we request, we maintain internal documentation justifying why that scope is needed and why narrower scopes are insufficient. Where possible, we follow incremental authorization and request additional scopes only when needed in context.

Secure Handling & Storage

  • Google Data is encrypted in transit (TLS/HTTPS) and at rest (AES-256).
  • Access controls, role-based permissions, logging, and auditing protect data.
  • OAuth tokens and credentials are stored securely (encrypted vault, secure key management).
  • We regularly review security practices and infrastructure.
  • If a security incident affects Google Data, we will notify Google as required and cooperate fully.

Retention & Deletion

When you revoke access, delete your account, or stop using a feature, we remove associated Google Data within the timeframes specified in Section 6 (Data Retention). You may request deletion via in-app settings or by contacting us; we will comply promptly.

12. Links to Other Sites

Our Service may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

13. Children's Privacy

Our Service does not address anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18.

If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

If we need to rely on consent as a legal basis for processing your information and your country requires consent from a parent, we may require your parent's consent before we collect and use that information.

14. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top.

For material changes, we will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective. Material changes include changes to how we use your Personal Data, changes to our data retention practices, or changes to third-party data sharing.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

15. Your Data Protection Rights Under GDPR

If you are a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, you have certain data protection rights. Nuxa aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.

In certain circumstances, you have the following rights:

  • Right of Access: The right to access, update, or delete the information we have on you.
  • Right of Rectification: The right to have your information rectified if it is inaccurate or incomplete.
  • Right to Object: The right to object to our processing of your Personal Data.
  • Right of Restriction: The right to request that we restrict the processing of your personal information.
  • Right to Data Portability: The right to be provided with a copy of the information we have on you in a structured, machine-readable, and commonly used format.
  • Right to Withdraw Consent: The right to withdraw your consent at any time where Nuxa relied on your consent to process your personal information.
  • Right to Lodge a Complaint: The right to lodge a complaint with a supervisory authority.

Please note that we may ask you to verify your identity before responding to such requests. We will respond to your request within 30 days, or within the timeframe required by applicable law.

You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).

To exercise any of these rights, please contact us at privacy@nuxa.ai or use the data subject request form available in your account settings.

16. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: The right to know what personal information we collect, use, disclose, and sell about you.
  • Right to Delete: The right to request deletion of your personal information.
  • Right to Correct: The right to request correction of inaccurate personal information.
  • Right to Opt-Out: The right to opt-out of the sale or sharing of your personal information.
  • Right to Non-Discrimination: The right not to be discriminated against for exercising your privacy rights.

Do Not Sell or Share My Personal Information

We do not sell your personal information for monetary consideration. However, some data sharing practices (such as certain analytics or advertising services) may be considered a "sale" or "share" under CCPA/CPRA. You have the right to opt-out of such data sharing.

To exercise this right, contact us at privacy@nuxa.ai or use the "Do Not Sell or Share My Personal Information" link in your account settings.

Global Privacy Control (GPC)

We recognize and honor Global Privacy Control (GPC) signals. When your browser sends a GPC signal, we will treat it as a valid request to opt-out of the sale or sharing of your personal information.

Categories of Personal Information

In the preceding 12 months, we have collected the following categories of personal information:

  • Identifiers (name, email, IP address)
  • Commercial information (transaction history, subscription status)
  • Internet or electronic network activity (browsing history, search history, usage data)
  • Geolocation data (derived from IP address)
  • Inferences drawn from the above (preferences, characteristics, behavior patterns)

Shine The Light Law

California Civil Code Section 1798.83 permits California residents to request information about categories of personal information we disclosed to third parties for direct marketing purposes in the preceding calendar year. To make such a request, please contact us using the information provided below.

17. Canadian Privacy Rights

If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial privacy legislation:

  • Right to Access: The right to access your personal information held by us
  • Right to Challenge: The right to challenge the accuracy and completeness of your personal information
  • Right to Withdraw Consent: The right to withdraw consent, subject to legal or contractual restrictions

To exercise these rights or for questions about our privacy practices in Canada, please contact us at privacy@nuxa.ai.

18. Do Not Track Signals

Some browsers have a "Do Not Track" feature that signals to websites that you visit that you do not want your online activity tracked. Currently, there is no uniform technology standard for recognizing and implementing DNT signals.

However, we do honor Global Privacy Control (GPC) signals as described in the California Privacy Rights section above. If your browser sends a GPC signal, we will treat it as an opt-out of the sale or sharing of your personal information.

19. Vulnerability Disclosure Policy

Introduction

Nuxa is dedicated to preserving data security by preventing unauthorized disclosure of information. This policy provides security researchers with instructions for conducting vulnerability discovery activities and information on how to report vulnerabilities.

Guidelines

We request that you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Provide us a reasonable amount of time to resolve the issue before you disclose it publicly.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability's presence.
  • Stop your test immediately upon encountering any sensitive data and keep any discovered data strictly confidential.
  • Do not submit a high volume of low-quality reports.

Scope

This policy applies to:

  • nuxa.ai website
  • Nuxa web application
  • Nuxa API services

The following test types are not authorized:

  • Network denial of service (DoS or DDoS) tests
  • Physical testing, social engineering (phishing, vishing), or any other non-technical vulnerability testing

Reporting

To report any security flaws, send an email to security@nuxa.ai. We will acknowledge receipt within one business day and keep you updated on our progress. Reports can be anonymously submitted.

Security research carried out in conformity with this policy is deemed permissible, and Nuxa will not suggest or pursue legal action in connection with your research.

20. Data Protection Officer

While not currently required by law, we have designated a point of contact for data protection matters. For questions about our privacy practices, data processing activities, or to exercise your data protection rights, please contact:

  • Email: dpo@nuxa.ai
  • Address: NUXA, Inc., Attn: Data Protection, 2093 Philadelphia Pike 1110, Claymont, DE 19703, USA

21. Contact & Dispute Resolution

If you have questions, requests, or complaints regarding this Privacy Policy or our data practices, you may contact us at:

We will respond to your request within a reasonable timeframe, typically within 30 days. For complex requests, we may extend this period by an additional 60 days with notice.

If you are not satisfied with our response to your complaint, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.