Privacy Policy
This policy explains what personal data Nexus collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers our website, the bot builder, hosted bot runtimes, integrations, billing, and the template marketplace.
Effective July 28, 2026 · Last updated July 28, 2026
Registration details pending. The registered company number and office address for Nexus Bots B.V. are being finalised and will be published here. Until then, reach us at the contact addresses below.
1. Who we are and our role
Nexus Bots B.V. operates Nexus, a platform for building automation flows and deploying them as bots across messaging channels.
Our role depends on whose data is involved, and the distinction determines who you should contact about it:
- We are the controller of account data. For the personal data of Nexus users — your account, workspace memberships, billing records, support requests, and the flows you build — we decide why and how it is processed.
- We are a processor for end-user data. When a customer deploys a bot, the people who message that bot are the customer's end users. The customer decides what data the bot collects and why; we process it on their instructions. If you messaged a bot and want your data removed, contact the operator of that bot. If you cannot identify them, write to us and we will route the request.
Customers acting as controllers are responsible for having a lawful basis to process their end users' data, for giving those people notice, and for honouring their rights.
2. Data we collect
Data you give us
- Account and profile: name, email address, hashed password, profile image, email-verification state, and two-factor secrets and recovery codes if you enable them.
- Workspace: workspace names, memberships and roles, invitations, invite codes, referrals, and single sign-on configuration.
- Product content: bot flows and versions, flow revision history, node configuration, schedules, key-value state your flows write, uploaded media, and marketplace listings you publish.
- Integration credentials: OAuth tokens, API keys, and channel tokens for the services you connect. These are encrypted at rest and are never shown back to you in full.
- Commercial: billing contact details, subscription and plan history, marketplace purchases, refunds, reviews, reports, and payout account references.
- Communications: support tickets and messages, and correspondence you send us.
Data generated by using the service
- Authentication and session records, including sign-in events, active sessions, device and browser identifiers, and rate-limit counters.
- Bot run records: execution logs, per-node outcomes, errors, queue jobs, pending waits, alerts, and daily aggregate statistics.
- Conversation analytics: daily counts and a salted, bot-scoped hash of the channel participant identifier. Analytics tables do not store the raw phone number, session id, or platform user id.
- Conversation state for each channel a bot serves, so a flow can remember where a conversation left off.
- Security and operational logs, including IP address, user agent, request metadata, and audit records of administrative actions.
- Onboarding funnel events that tell us where in setup people get stuck.
Data we receive from connected services
When you connect a channel or integration, that service sends us the data your bot needs to function — inbound message content, platform user identifiers, display names, delivery receipts, and, for the Google integrations you authorise, the spreadsheet, calendar, or live-chat data covered by the scopes you granted. We receive this only for the accounts and channels you connect, and only while the connection is active.
Data we do not collect
We do not buy personal data from data brokers, we do not sell or share personal data for advertising, we do not run advertising or cross-site tracking on our site, and we do not use Google user data or the contents of your bot conversations to train machine-learning models.
3. How and why we use data
- Provide the service: authenticate you, run the builder, execute flows, deliver and receive messages, and keep conversation state.
- Integrations: connect, refresh, and call the third-party services you authorise, on your instruction.
- Billing: process subscriptions, enforce plan limits and quotas, handle marketplace purchases, refunds, and payouts, and calculate tax.
- Support and communication: respond to tickets, send transactional email such as verification, password reset, and operational alerts.
- Safety and integrity: detect and prevent abuse, spam, fraud, and unauthorised access; enforce our Terms; moderate marketplace listings and reports.
- Reliability: monitor errors, capacity, and queue health, and diagnose faults.
- Legal: comply with legal obligations, respond to lawful requests, and establish or defend legal claims.
- Improve the product: understand aggregate usage patterns and where setup fails, and improve the AI flow generator from the prompts and results described in section 8. This never uses the contents of your bot conversations or Google user data.
4. Lawful bases
We are established in the European Union, so the EU General Data Protection Regulation applies to our processing. The UK GDPR applies in addition where we process the data of people in the United Kingdom. Where more than one basis could apply, the primary one is listed.
| Purpose | Lawful basis |
|---|---|
| Creating and operating your account; providing the builder, runtimes, and integrations | Performance of a contract |
| Billing, subscriptions, marketplace payouts | Performance of a contract |
| Transactional email required to operate the account | Performance of a contract |
| Security monitoring, abuse and fraud prevention, audit logging | Legitimate interests in keeping the service and its users safe |
| Reliability monitoring and product improvement from aggregate usage | Legitimate interests in maintaining and improving the service |
| Improving the AI flow generator from builder prompts and their results | Legitimate interests in improving a feature you use, subject to your right to object |
| Optional features you switch on, such as connecting a Google account | Consent, which you may withdraw at any time by disconnecting |
| Tax, accounting, and responding to lawful requests | Legal obligation |
Where we rely on legitimate interests we have balanced those interests against your rights and concluded the processing is proportionate. You can object at any time — see section 13.
5. Google user data
Nexus can connect to Google Sheets, Google Calendar, Gmail, and YouTube so your flows can act on your behalf. These connections are entirely optional. We request access only when you start a connection, only for the scopes that specific integration needs, and you can revoke access at any time.
Limited Use disclosure
Nexus's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes we request and why
| Scope | Google product | Classification | Why we request it |
|---|---|---|---|
openid, email | Google Sign-In | Basic | Identify the Google account being connected and label the connection in your workspace. Also used when you choose to sign in to Nexus with Google. |
https://www.googleapis.com/auth/spreadsheets | Google Sheets | Sensitive | Read and append rows in the specific spreadsheets your flow references, so a Sheets node can look up or record data while a bot runs. |
https://www.googleapis.com/auth/calendar.events | Google Calendar | Sensitive | Create, read, and update calendar events on your behalf when a flow contains a Calendar node — for example booking an appointment a bot user requested. |
https://www.googleapis.com/auth/gmail.send | Gmail | Restricted | Send an email that your flow composes. This scope grants send-only access: it does not permit Nexus to read, search, delete, or modify any message in your mailbox. |
https://www.googleapis.com/auth/youtube.readonly | YouTube | Sensitive | Detect when a connected channel is live and read the live chat associated with that broadcast, so a bot can respond during a stream. |
https://www.googleapis.com/auth/youtube.force-ssl | YouTube | Sensitive | Post the replies your flow generates into the live chat of your own connected channel. |
How we handle Google user data
- Use is limited to providing the user-facing integration features you invoked. Data obtained through these scopes is not used for any other purpose.
- We do not transfer or sell Google user data to third parties, including advertising platforms, data brokers, or information resellers, and we do not use it for advertising, retargeting, credit assessment, or lending decisions.
- We do not use Google user data — raw, aggregated, anonymised, or derived — to develop, improve, or train generalised artificial-intelligence or machine-learning models.
- No human at Nexus reads your Google user data, except where you have given specific affirmative agreement for us to look at particular data to support you, where it is strictly necessary for security purposes such as investigating abuse or a specific bug, or where the law requires it.
- OAuth access and refresh tokens are encrypted at rest with a dedicated application key and are only decrypted in memory at the moment a flow calls the relevant API.
- Google user data is transmitted over TLS and is not written to our general application logs.
- The Gmail scope we request is send-only. It does not permit us to read, search, delete, or modify anything in your mailbox.
Revoking access and deletion
You can disconnect a Google integration from Settings → Connections in Nexus, which deletes the stored tokens immediately. You can also revoke access directly from your Google Account at https://myaccount.google.com/permissions. Once access is revoked we stop calling the API, and we delete cached Google user data associated with the connection within 30 days.
Google's own handling of your data is governed by the Google Privacy Policy. Our use of Google APIs is governed by the Google API Services User Data Policy.
6. YouTube API Services
The YouTube integration uses YouTube API Services. By connecting a YouTube channel to Nexus, you agree to be bound by the YouTube Terms of Service.
- We use YouTube API Services to detect when your connected channel goes live, read the live chat for that broadcast, and post the replies your flow generates into your own channel’s live chat.
- Data obtained through YouTube API Services is handled in accordance with the Google Privacy Policy.
- You can revoke our access to your YouTube data at any time through the Google security settings page at https://myaccount.google.com/permissions, or by disconnecting the channel in Settings → Connections.
- We store live-chat data only for as long as needed to run the flow that responds to it, and we delete stored YouTube data within 30 days of a deletion request or of you revoking access.
- We do not use YouTube data to derive independent metrics, we do not combine it with data from other sources, and we do not make it available to any third party.
7. Meta and other messaging channels
When you connect WhatsApp, Messenger, Instagram, Telegram, Discord, Slack, Twitch, or a Twilio phone number, we receive inbound messages and platform identifiers for the accounts you connect, and we send the outbound messages your flow produces. We process this material as your processor, for the purpose of running your bot.
- Message content and platform user identifiers are stored only as needed to maintain conversation state and to produce the run records described in section 11.
- Platform data is not used for advertising, is not sold, and is not used to train models.
- Inbound images are fetched from the platform while the flow runs and are not stored by us. Images your flow generates are stored for 30 days and then pruned automatically.
- Delivery and event receipts used to deduplicate webhook traffic are kept for 24 hours (Slack) and 7 days (WhatsApp) and then deleted.
- Each platform also processes data under its own terms — for Meta products, see the Meta Privacy Policy.
- For instructions on deleting data associated with a Meta channel, see our data deletion page.
8. AI features
Nexus uses AI in two places, and they work differently in a way that matters for your data — in particular, whose account pays for the call determines who is responsible for the data afterwards.
Generate with AI — runs on our account
The flow generator in the builder drafts or modifies a flow from a prompt you write. It runs on our own OpenAI account, and is available on Pro and Team. We are the controller for this processing.
- Your prompt, and the existing flow if you asked for a modification, are sent to OpenAI under our account.
- Prompts are screened for values that look like secrets and rejected before they are sent. Do not paste credentials or other people’s personal data into a prompt.
- Generated flows are never saved, run, or deployed automatically — nothing happens until you review and save it.
AI nodes — run on your account
When a deployed flow reaches an AI node, the request is sent using the API key from a connection you configured, directly to that provider. We do not fund or route these calls through our own provider account.
- Your own agreement with that provider governs what they do with the data, including whether they retain it or use it to improve their models. We are not a party to that agreement and cannot make commitments on their behalf. Review their terms and their data controls.
- If a flow has no AI connection configured, no request is made and the node returns placeholder text instead. Nothing leaves our systems.
- We never use the content passed to an AI node to improve our own features — see the exclusions below.
- Your stored credentials are decrypted only in memory at the moment of the call and are never sent to any other party.
Model output can be wrong in both cases. Do not rely on it for decisions that need to be correct without checking it first.
Improving the flow generator
We use material from Generate with AI, the server-funded flow generator in the builder to evaluate and improve how well it works. This is on by default for accounts that have access to that feature. Specifically, we may use:
- the prompt you write describing the bot you want
- the existing flow you submit when you ask for a modification or explanation
- the flow structure the model returns
- whether you accepted, edited, regenerated, or discarded the suggestion, and any validation errors it produced
Free accounts have no flow-generation allowance and therefore contribute nothing. Where this processing relies on our legitimate interest in improving the service, you have the right to object under Article 21 of the GDPR — email privacy@hmcelik.com and we will exclude your workspace, without affecting your access to the feature.
What we never train on
The following are excluded from any use in developing or improving AI models, on every plan and in every feature:
- data obtained through Google APIs, including Sheets, Calendar, Gmail, and YouTube
- the content of conversations between your bots and their end users, including anything processed by AI nodes at run time
- data received from Meta, Telegram, Discord, Slack, Twitch, Twilio, or HubSpot
- integration credentials, API keys, and OAuth tokens
- billing, payment, and payout details
The exclusion of Google data is required by the Limited Use terms in section 5. The exclusion of bot conversation content follows from our role: that data belongs to the customer who operates the bot, and we hold it only as their processor.
This material is shared with OpenAI, which processes it under our account so that we can evaluate and improve the generator. OpenAI may also use it to improve its own models. If you would rather that did not happen to your prompts, object using the address above and we will exclude your workspace. We do not sell this material, and we do not share it with any other third party.
10. International transfers
We are established in the Netherlands, and several of our sub-processors are located outside the European Economic Area, principally in the United States. Where we transfer personal data out of the EEA to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented by the UK International Data Transfer Addendum for transfers of UK personal data. In each case we carry out a transfer impact assessment and apply technical measures including encryption in transit and encryption of stored credentials at rest. Some US recipients are certified under the EU–US Data Privacy Framework, which we rely on where it applies.
You can request a copy of the safeguards applying to a specific transfer by writing to privacy@hmcelik.com.
11. Retention
We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires.
| Data | Retention period |
|---|---|
| Account, workspace, and flow content | Until you delete it, or until the account is deleted |
| Raw bot run records | 7 days on Free, 30 days on Pro, 90 days on Team |
| Aggregate daily statistics | Retained after the underlying runs expire; these contain counts, not message content |
| Hashed analytics participant state | Until the bot or workspace is deleted; the raw participant identifier is not stored in analytics tables |
| Inbound images from a messaging platform | Not stored — fetched from the platform during the run and discarded |
| Runtime-generated images | 30 days, then pruned automatically |
| Unclaimed marketplace screenshots | 24 hours |
| Slack event receipts | 24 hours |
| WhatsApp delivery status receipts | 7 days |
| Google user data cached to run a flow | Deleted within 30 days of disconnection, revocation, or a deletion request |
| Integration credentials | Deleted when you disconnect the integration or delete the workspace |
| Billing, invoice, and payout records | Up to 7 years, to meet tax and accounting obligations |
| Security and audit logs | Up to 12 months, or longer where needed for an active investigation |
| Backups | Rolling backups are overwritten on a schedule; deleted data persists in backups until they cycle out, and is not restored into production |
12. Security
- Transport encryption (TLS) for all traffic to the application and to third-party APIs.
- Integration credentials and OAuth tokens encrypted at rest with a dedicated application key, separate from the database.
- Passwords stored using bcrypt; optional two-factor authentication with recovery codes.
- Workspace-scoped access control on every data path, with tenant isolation enforced server-side rather than in the UI.
- Signed, expiring state for OAuth flows; signed webhook verification for inbound platform traffic; rate limiting on authentication and webhook endpoints.
- Public media served from a separate, cookie-free origin, with uploads validated by magic bytes and SVG never hosted.
- Audit logging of administrative actions, including every emergency access use.
- Operational alerting on error spikes, dead-lettered jobs, and quota thresholds.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to security@hmcelik.com rather than disclosing it publicly, and give us a reasonable opportunity to fix it. We will not pursue legal action against good-faith security research conducted under those terms.
13. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have data deleted, subject to obligations that require us to keep some records;
- restrict or object to processing, including processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.
Exercising them yourself
Account settings lets you download a complete JSON export of your data once every 24 hours, and permanently delete your account. Deletion requires your password, and is blocked while you are the sole owner of a team workspace or hold an active subscription, so that you do not lose access to something you are still paying for or strand your collaborators. Resolve those first, then retry. You can also disconnect integrations and manage workspace access at any time.
For anything you cannot do yourself, write to privacy@hmcelik.com. We respond within 30 days, and will tell you if we need an extension. We may ask you to verify your identity before acting. We do not charge for these requests unless they are manifestly unfounded or excessive.
Step-by-step deletion instructions, including for data tied to a specific messaging channel, are at /legal/data-deletion.
14. Regional disclosures
European Economic Area
Our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), at www.autoriteitpersoonsgegevens.nl. You may lodge a complaint with it, or with the supervisory authority in your country of residence or work, or where you believe the issue occurred. We would appreciate the chance to address your concern first.
We have assessed that our processing does not require a data protection officer under Article 37 of the GDPR, because it does not involve large-scale monitoring or large-scale processing of special-category data as our core activity. Privacy questions still reach a named owner at the address below.
United Kingdom
Where the UK GDPR applies, you may complain to the Information Commissioner's Office (ico.org.uk).
California
In the past 12 months we collected the categories of personal information described in section 2 — identifiers, commercial information, internet activity, and the contents of communications you route through the service — for the business purposes in section 3, from the sources in section 2, and disclosed them to the service providers in section 9.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not knowingly collect or sell the personal information of anyone under 16. You have the right to know, delete, correct, and to be free from discrimination for exercising these rights. Use the account tools above or write to privacy@hmcelik.com. An authorised agent may submit a request with written proof of authorisation.
Other US states
Residents of states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana — have comparable rights to access, correct, delete, and obtain a portable copy of their data, and to appeal a refused request. To appeal, reply to our decision and we will review it and respond with our reasoning.
16. Children
Nexus is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 (or under 13 where that is the applicable threshold). If you believe a child has provided us with personal data, write to privacy@hmcelik.com and we will delete it. If your bot may interact with children, you are responsible for the additional obligations that creates for you.
17. Changes to this policy
We update this policy when the product or the law changes. We revise the "last updated" date on every change. For material changes — a new category of data, a new purpose, or a new type of recipient — we give notice by email or in the application before the change takes effect, and where a change affects data obtained through Google APIs we will prompt you to consent before accessing that data in the new way.
18. Contact
Privacy questions and rights requests: privacy@hmcelik.com
Legal notices: huseyinmelihcelik@gmail.com
Security reports: security@hmcelik.com
Nexus Bots B.V.
See also our Terms of Service, sub-processor list, and data deletion instructions.