Privacy Policy
How Nexify collects, uses, stores, and protects your information.
At a glance
Nexify collects information needed to provide and improve the service, operate your account, process subscriptions and payments, operate research and validation features, protect the platform, and communicate with you.
- Your project and research data remain private to your account and are processed only to deliver the features you use.
- Public validation pages you publish may collect visitor interactions and feedback that you choose to request.
- Trusted third-party services process information on Nexify’s behalf to provide AI synthesis, research data, payment processing, and email delivery.
- Privacy questions: hello@thenexify.app
- Support target: We aim to reply to support requests within 24–48 hours.
Table of Contents
1. Information we collect
We collect information in distinct categories depending on how you interact with Nexify:
Account information
When you register an account, we collect only the minimal details necessary to create and secure your login:
- Email address: Used as your primary account identifier and to send service-related notices.
- Password hash: Stored using a one-way cryptographic hash. Your plain text password is never stored or visible to us.
- Account role and timestamps: Your authorization role (e.g. user or admin) and the dates your account was created and updated.
- API token: An optional secure token generated only if you choose to use our API.
We do not collect names, phone numbers, job titles, or physical mailing addresses to create an account.
Payment information
Subscription billing and payment checkouts are managed directly by our Merchant of Record, Creem (creem.io). Creem handles payment card verification and international sales tax/VAT compliance under PCI-DSS Level 1 standards.
Nexify does not receive, process, or store full credit card numbers or bank account details. We receive only transaction confirmations, subscription tier status, and billing emails from Creem.
Project and research information
When you use the platform, we store the content you input to conduct market research and build validation experiments:
- Startup ideas, product descriptions, target customer definitions, and hypotheses you enter.
- Selected target countries and search keywords generated for research runs.
- Validation page drafts, questionnaire configurations, pricing tiers, and branding options you configure.
Validation responses
When you publish a public validation page, visitors may choose to submit responses to your questionnaire. We collect these responses on your behalf as the page owner, including:
- Selected price options and stated willingness to pay.
- Email address, if voluntarily provided by the visitor for project updates.
- Optional written feedback or problem comments submitted through the form.
2. How we use information
We use the information we collect for the following straightforward purposes:
- Provide, maintain, and operate the Nexify platform.
- Run market research workflows and discover relevant public discussions.
- Store, organize, and present your project hypotheses, evidence, and reports.
- Host and publish your public validation landing pages.
- Collect, verify, and report validation visitor responses to project owners.
- Process subscriptions and manage billing via our Merchant of Record.
- Prevent abuse, fraud, spam, and unauthorized access to accounts.
- Maintain platform security, enforce rate limits, and troubleshoot technical errors.
- Communicate critical account notifications, verification links, and support responses.
3. Research and project data
When you submit an idea for research, Nexify processes the information necessary to perform the research. Nexify currently uses public Reddit discussions as its research source via the Zernio API or public Reddit endpoints.
Research results may include links, excerpts, titles, subreddit information, and other information available from public discussions. Nexify does not own third-party Reddit content; public excerpts are retrieved and organized to provide actionable market signals for your project.
Your research runs and hypotheses are private to your account. They are not published in public directories, not shared with other users, and not used to train public AI foundation models.
4. Validation-page visitor data
When you publish a public validation page, visitors from your target audience may view and interact with that page. We collect data necessary to measure interest and deliver response analytics to the project owner:
- Page views: Aggregate visit counts, HTTP referrers, and campaign attribution parameters (such as
utm_source,utm_medium, or custom ref codes). - Form responses: Selected pricing options, voluntary emails, and optional feedback submitted by the visitor.
- Pseudonymous visitor identifier: We may use a pseudonymous visitor identifier (a cryptographic hash of the visitor’s IP address, browser user agent, and a server-side secret) to distinguish repeated visits or responses for analytics and abuse prevention without storing raw visitor IP addresses.
- Email verification: If a visitor submits an email, a single-use verification link may be sent to verify the response. Verification tokens are stored in hashed format and expire automatically.
What we do NOT collect: Public validation pages do not collect precise GPS location, contacts, microphone or camera inputs, or biometric data.
5. Cookies and analytics
Nexify uses a minimal number of first-party cookies necessary for platform operation. We do not use third-party advertising cookies or cross-site tracking pixels.
Essential session cookies
nexify_web_token: Keeps you authenticated to your dashboard across page navigations (30-day lifetime,HttpOnly,SameSite=Lax). Required for dashboard access.nx_csrf: Protects forms against Cross-Site Request Forgery (CSRF). Session-only cookie. Required for secure form submission.
Attribution and measurement cookies
nx_attr_{pageId}: Set on a public validation page when a visitor arrives through a creator’s tracking link. Ensures that return visits within 90 days are attributed to the correct referral source. This cookie stores a campaign reference code, not personal identity.
You can block or delete cookies through your browser settings. Disabling essential cookies will prevent you from signing in to your dashboard, while blocking attribution cookies simply records validation visits as direct traffic.
6. Service providers
We work with trusted third-party service providers who assist in operating specific platform functions. Each provider processes data strictly to deliver its service under its respective privacy terms:
| Service | Purpose | Data Involved |
|---|---|---|
| Google Gemini AI Provider |
Generates idea hypotheses, keywords, evidence clustering, and validation page drafts. | User-submitted idea text, generated search keywords, and public discussion excerpts. |
| Zernio / Reddit API Research Provider |
Retrieves public discussions matching generated keywords. | Search keywords (returns public Reddit thread excerpts, titles, and URLs). |
| Creem Merchant of Record |
Processes subscription checkouts, recurring billing, invoices, and sales tax/VAT. | Customer email, payment card data (processed directly by Creem), and subscription status. |
| Brevo / SMTP Mail Delivery |
Delivers transactional emails, account verification links, and contact inquiries. | Recipient email address and email message text. |
| Hosting Infrastructure Cloud Hosting |
Hosts the web application server and secured relational database. | Encrypted account records, project data, and server request logs. |
We do not sell personal data to third parties, and we never expose internal credentials, API keys, or private configuration.
7. Data retention
We retain your information according to practical operational needs:
- Account data: Retained for as long as your account remains active.
- Project and research data: Stored until you choose to delete the project or close your account. When you delete a project, all associated research runs, cached evidence, and validation pages are permanently deleted.
- Validation responses: Retained within your project until you or your account deletes the project or responses.
- Billing records: Transaction history is retained by our Merchant of Record, Creem, in accordance with legal, accounting, and tax compliance requirements.
- Server logs: Temporary access and rate-limiting logs are retained on rolling server cycles for troubleshooting and abuse prevention, then routinely purged or overwritten.
We retain this information for as long as necessary to provide the service, comply with applicable obligations, resolve disputes, enforce agreements, or protect the service.
8. Your choices and rights
You have direct control over your information within Nexify:
- Access your data: You can review your account information, projects, research runs, and validation responses directly within your dashboard.
- Delete your projects: You can delete any project at any time. Project deletion cascades to remove all associated research runs, stored findings, validation pages, and visitor responses.
- Control validation pages: You can pause or conclude validation pages to stop collecting new visitor responses.
- Manage cookies: You can configure your browser to block or clear cookies at any time.
- Account closure and data requests: You can request an export of your data or complete deletion of your account by emailing us at hello@thenexify.app.
9. Security
We use reasonable technical and organizational measures designed to protect information against unauthorized access, loss, misuse, or disclosure. These measures include:
- Encrypted HTTPS data transport for all web traffic and API calls.
- One-way cryptographic password hashing so passwords cannot be recovered or read.
- Single-use hashed email verification tokens that expire automatically.
- Strict ownership verification on all project and response endpoints to prevent cross-account access.
- Cross-Site Request Forgery (CSRF) token protection on all state-changing forms.
- Rate limiting on authentication, contact, and submission endpoints to protect against brute-force attacks.
- Secure environment-level isolation for credentials and database connections.
While we work continuously to protect user data, no transmission over the internet or electronic storage system can be guaranteed completely secure. If you discover a potential security vulnerability, please report it responsibly to hello@thenexify.app.
10. Children
Nexify is a business tool designed for founders, developers, and product creators. The platform and its public validation pages are not directed to or intended for children under the age of 18.
We do not knowingly collect personal information from children. If you become aware that a minor has provided personal data to Nexify or through a validation page, please notify us at hello@thenexify.app and we will promptly remove the information.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect enhancements to our features, service provider adjustments, or legal obligations. When updates occur, the revised version will be published on this page with an updated date.
For significant material changes, we will provide additional notice through the dashboard or by email where appropriate.
12. Contact us
If you have questions about this Privacy Policy, your personal data, or your account, please get in touch with us.
Questions about your privacy or account?
Contact us directly by email or through our online contact form: