Data Deletion Instructions
Every route to having your data removed from Nexus — deleting your account yourself, disconnecting a single integration, removing data tied to a specific messaging platform, or asking us to do it for you.
Effective July 28, 2026 · Last updated July 28, 2026
Registration details pending. The registered company number and office address for Nexus Bots B.V. are being finalised and will be published here. Until then, reach us at the contact addresses below.
Delete your account yourself
The fastest route is self-serve, and it needs no request to us. Sign in and go to Settings → Account:
- Export first, if you want a copy. Download a complete JSON export of your data. Deletion is permanent, and the export is available once every 24 hours — take it before you delete.
- Delete account. Confirm with your password. Your account, personal data, flows, and stored credentials are removed.
- Delete a workspace. From workspace settings, type the workspace slug to confirm. This removes the workspace and its bots, flows, connections, and conversation state.
If deletion is blocked
Two safeguards can stop a deletion, so that you do not lose access to something you are still paying for or strand your collaborators:
- An active subscription. Cancel it in billing settings first, then retry.
- Sole ownership of a team workspace. Transfer ownership or add another owner in Settings → Members, or delete the workspace, then retry.
Disconnect a single integration
If you only want to revoke one connection rather than delete your account, go to Settings → Connections and remove it. The stored credentials for that connection — access tokens, refresh tokens, and API keys — are deleted immediately, and we stop calling that service. Flows that referenced the connection will stop working until you reconnect or point them elsewhere.
Google and YouTube data
You can remove our access to your Google data in two independent ways:
- In Nexus: Settings → Connections → remove the Google Sheets, Google Calendar, Gmail, or YouTube connection.
- In your Google Account: go to https://myaccount.google.com/permissions, find Nexus, and choose Remove access. This revokes our tokens at Google regardless of anything on our side.
Either action stops all further API calls. Any Google or YouTube user data we cached to run your flows is deleted within 30 days. To confirm deletion in writing, email privacy@hmcelik.com from the address on your account.
Meta platform data (WhatsApp, Messenger, Instagram)
To delete data associated with a Meta platform — a WhatsApp Business number, a Facebook Page connected to Messenger, or an Instagram professional account:
- Remove the connection in Nexus under Settings → Connections, or delete the bot that uses it. This deletes the stored page and channel tokens, the conversation state for that channel, and the associated media objects.
- Remove Nexus from your Meta account's business integrations, in Facebook Settings & Privacy → Settings → Business Integrations, to revoke the permission at Meta.
- For a written confirmation, or to request deletion without signing in, email privacy@hmcelik.com with the subject Data deletion request and tell us which platform account or page ID is involved.
We confirm receipt within 5 business days and complete deletion within 30 days. If you email us, we will reply with a confirmation you can retain as a record.
If you messaged a bot built on Nexus
When you chat with a bot built on Nexus, the business or person who built that bot decides what it collects and why. They are the controller of your data; we only process it on their instructions.
- Contact that business directly — they can delete your conversation data themselves and are the ones obliged to answer your request.
- If you cannot identify or reach them, email privacy@hmcelik.com with the platform, the bot's name or handle, and roughly when you interacted with it. We will identify the operator and pass the request on, and we will tell you we have done so.
Request deletion by email
If you cannot sign in, or want something deleted that the account tools do not cover, email privacy@hmcelik.com. To let us act quickly, include:
- the email address on the account, or the platform account ID if the request concerns a connected channel;
- what you want deleted — the whole account, one workspace, one connection, or a specific conversation; and
- the subject line "Data deletion request".
We may need to verify your identity before acting, so that we do not delete someone else's data on a stranger's say-so. We acknowledge within 5 business days and complete the request within 30 days, telling you if a lawful extension is needed. There is no charge unless a request is manifestly unfounded or excessive.
What gets deleted, and when
| Action | What is removed | Timing |
|---|---|---|
| Disconnect an integration | Access tokens, refresh tokens, and API keys for that connection | Immediately |
| Revoke access at Google | Our ability to call the API; cached Google and YouTube user data | API access immediately; cached data within 30 days |
| Delete a bot | Its flow, versions, channel credentials, conversation state, queued jobs, and media | Immediately |
| Delete a workspace | All bots, flows, connections, conversation state, and workspace membership | Immediately |
| Delete your account | Your profile, credentials, sessions, and personal data; shared workspace rows are transferred or removed | Immediately |
| Email request | Whatever the request covers, once verified | Acknowledged within 5 business days, completed within 30 days |
| Backups | Deleted data persists in rolling backups until they cycle out and is never restored into production | Within the backup rotation window |
Automatic expiry, without any request
Some data ages out on its own: raw bot run records after 7 days on Free, 30 days on Pro, and 90 days on Team; runtime-generated images after 30 days; unclaimed marketplace screenshots after 24 hours; Slack event receipts after 24 hours; and WhatsApp delivery receipts after 7 days. Inbound images are never stored — they are fetched from the platform while the flow runs.
What we must keep
A small set of records survives deletion because the law requires it or because removing them would undermine the safety of the platform:
- Billing, invoice, tax, and payout records, retained for up to 7 years to meet accounting and tax obligations.
- Limited security and audit records where they are needed to investigate abuse, fraud, or a security incident, or to establish or defend a legal claim.
- Aggregate statistics that contain counts rather than message content or identifiers, which cannot be traced back to an individual.
- Records we are under a legal hold or a court order to preserve.
Full detail on retention is in section 11 of our Privacy Policy.