Nexus · Legal
Privacy Policy Terms of Service Community Guidelines Cookie Policy Moderation & Complaints Data Retention & Deletion Data Processing

Nexus — Privacy Policy

Last updated: 22 July 2026
Effective date: 22 July 2026
Version: 1.0

This Privacy Policy explains how Nexus ("Nexus", "the Service", "we", "us")
collects, uses, stores and protects your personal data when you use the Nexus
messenger at https://nexus-global.space and its associated applications.

This Policy is written to comply with the EU General Data Protection Regulation
(Regulation (EU) 2016/679, "GDPR")
and applicable EU member-state law. It
describes only the data processing that actually takes place in the Service.


1. Data Controller

The data controller responsible for your personal data is:

[CONTROLLER FULL NAME] (individual operator)
Contact e-mail: [CONTROLLER CONTACT EMAIL]
Postal address: [CONTROLLER POSTAL ADDRESS]

Note: These fields must be completed with real, verifiable contact
details before public release in the EU. Under Article 13 GDPR the controller's
identity and contact details are mandatory. Nexus is currently operated by a
private individual; if operation is later transferred to a company, this
section must be updated.

If you have any questions about this Policy or wish to exercise your rights,
contact us at the e-mail above. We aim to respond to all requests within
30 days, as required by Article 12(3) GDPR.


2. What personal data we collect

We collect only the data necessary to operate a messaging service. The
categories below reflect the actual data stored by the application.

2.1 Account and identity data

2.2 Messages and content

2.3 Technical and security data

2.4 Moderation and safety data

2.5 Optional in-app currency data

2.6 Analytics

We do not knowingly collect special categories of data (Article 9 GDPR)
such as health, religion, or political opinions. Please do not share such data
through the Service unless you accept that it will be processed as ordinary
message content.


3. Why we process your data and the legal basis

Under Article 6 GDPR, every processing activity has a legal basis:

Purpose Data used Legal basis (Art. 6 GDPR)
Creating and maintaining your account Identity data Performance of a contract (6(1)(b))
Delivering messages, calls, files Messages, content, presence Performance of a contract (6(1)(b))
Sending one-time login codes (OTP) E-mail / phone Performance of a contract (6(1)(b))
Security, login alerts, fraud/abuse prevention Session, IP, approximate location, rate limits Legitimate interests (6(1)(f))
Moderation, handling reports and appeals Reports, punishments, content snapshots Legitimate interests (6(1)(f)) and legal obligation (6(1)(c))
Push notifications Push subscription Consent (6(1)(a)) — you enable them
Analytics Usage data via Google Analytics Consent (6(1)(a))
Complying with legal requests Relevant data Legal obligation (6(1)(c))

Where we rely on consent, you may withdraw it at any time (for example, by
disabling notifications or analytics). Withdrawal does not affect processing
that already took place.

Where we rely on legitimate interests, we have balanced those interests
against your rights and freedoms. You have the right to object (see Section 10).


4. Who can see your data

We do not sell your personal data. We do not show third-party
advertising inside Nexus.


5. International transfers

Some of the third-party services we rely on may process data outside the
European Economic Area (EEA):

Where data is transferred outside the EEA, such transfers rely on the transfer
mechanisms offered by those providers (for example, Standard Contractual
Clauses or an adequacy decision). Our own servers are hosted with our hosting
provider; the physical hosting location is set out at
[HOSTING LOCATION / COUNTRY] and must be confirmed before release.


6. Third-party services (sub-processors)

Service Purpose Data shared
Google (Sign-In) Optional Google login Google account identifier, e-mail
Google Analytics (gtag.js) Aggregate usage analytics Usage/interaction data, device data
Resend / SMTP provider Sending one-time login codes E-mail address, the code
ip-api.com IP-to-country/city lookup IP address
Hosting provider Running the servers and database All stored data (as processor)

Each provider processes data under its own privacy terms. We recommend
reviewing Google's and your e-mail provider's privacy policies.


7. Security

No system is perfectly secure. If a data breach affecting your rights occurs,
we will notify the competent supervisory authority within 72 hours where
required (Article 33 GDPR) and inform you where required (Article 34 GDPR).


8. How long we keep your data (retention)

Data Retention
Account and messages For as long as your account exists
Account after deletion request Anonymised/deleted after a grace period (during which you can cancel)
Open moderation reports Until resolved + 90 days
Resolved/dismissed reports 180 days after resolution, then content snapshot cleared and record removed
GDPR processing log (Art. 30) Up to 3 years
Approximate location cache (IP) Cached temporarily and refreshed periodically
Session records Until the session expires or is revoked

Automated clean-up routines remove or anonymise expired moderation data. See
the separate Data Retention and Deletion Policy for full details.


9. Cookies

Nexus uses a single strictly-necessary cookie for its core function:

In addition, Google Analytics may set its own cookies for analytics. These
are not strictly necessary and are used based on your consent. See the
separate Cookie Policy for the full list and how to control them.


10. Your rights under the GDPR

You have the following rights. To exercise any of them, contact us at
[CONTROLLER CONTACT EMAIL]. Several are also available directly in the app.

We will not discriminate against you for exercising your rights.


11. Children

You must be at least 13 years old to use Nexus. If the law of your
country sets a higher minimum age of digital consent, that higher age applies.
When you register, you must confirm that you meet this requirement. If you are under the applicable
digital-consent age in your country, please do not use the Service. If we
become aware that we hold data of a child below the applicable age without the
required consent, we will delete it.


12. Changes to this Policy

We may update this Policy to reflect changes in the Service or the law. We will
update the "Last updated" date and, for material changes, provide a notice in
the app. Continued use after changes take effect constitutes acceptance.


13. Contact

For any privacy question or to exercise your rights:

[CONTROLLER FULL NAME]
E-mail: [CONTROLLER CONTACT EMAIL]
Address: [CONTROLLER POSTAL ADDRESS]

You also have the right to contact your national data protection authority.