Privacy Policy
Effective July 18, 2026
This policy explains how Nexus Bots handles personal data when you use our website, bot builder, hosted runtimes, integrations, billing features, and marketplace.
1. Controller and contact
Nexus Bots controls account, product, marketplace, and operational data described here. Workspace customers may control end-user data processed by their bots. Privacy questions and rights requests can be sent to huseyinmelihcelik@gmail.com.
2. Data we collect
We collect account and profile details; workspace memberships; bot flows and settings; connection labels and encrypted credentials; schedules; execution and alert records; marketplace listings, purchases, installs, reviews, and moderation records; billing and payout references; uploaded or generated media; communications; and device, request, and security logs. Connected platforms may send message and user data selected by your bot.
3. How we use data
We use data to authenticate users, provide and secure the service, run bots, deliver messages, process payments and payouts, enforce plan limits, moderate the marketplace, respond to support requests, prevent abuse, comply with law, and improve reliability.
4. Service providers and disclosures
We disclose only what is needed to processors and connected services, which may include Stripe for payments and payouts; Meta, Telegram, Discord, and Slack for bot delivery; transactional email providers; infrastructure and S3-compatible storage providers; and AI providers when you invoke an AI feature. We may also disclose data for legal process, safety, fraud prevention, or a business transaction.
5. Retention
Raw bot runs are retained for 7 days on Free, 30 days on Pro, and 90 days on Team; aggregate daily statistics may be retained longer. WhatsApp inbound image objects expire after 7 days and generated runtime images after 30 days. Expired temporary objects are pruned daily. Other account and workspace content remains until it is deleted or no longer needed, while transaction snapshots and limited audit records may remain for financial, security, and legal obligations.
6. Your choices and rights
Account settings lets you download a JSON export once every 24 hours and permanently delete your account, subject to workspace ownership and active-subscription safeguards. You may also update workspace access and disconnect integrations. Depending on where you live, you may have rights to access, correct, delete, restrict, object, or receive portable data.
7. Security, transfers, and cookies
We use access controls, encrypted stored credentials, isolated public media delivery, and operational monitoring. No system is perfectly secure. Providers may process data in other countries using legally recognized transfer safeguards where required. Authentication and security cookies are used to keep sessions working; optional analytics should be described here before being enabled.
8. Updates
We may update this policy as the product or law changes. We will revise the effective date and provide additional notice for material changes where required. See our Terms of Service for service rules.