Skip to content
Privacy

Privacy Policy

How Nexow, Inc. collects, uses, and protects personal information when you use nexow.ai and the Nexow application.

Last updated: 29 July 2026

This Privacy Policy is provided in English, which is the governing language. Translated summaries, if any, are for convenience only.

1. Who we are

This Privacy Policy describes how Nexow, Inc. (“Nexow,” “we,” “us,” or “our”) processes personal information in connection with our websites (including https://nexow.ai), the Nexow web application (https://x.nexow.ai), and related services (collectively, the “Services”).

Controller / business: Nexow, Inc., 2810 N Church St STE 89080 Wilmington, DE 19802, United States. Email: [email protected]. Web: https://nexow.ai.

If you have questions about this Policy or wish to exercise privacy rights, contact us at the address or email above with the subject line “Privacy Request.”

2. Scope

This Policy applies to personal information we process when you visit our marketing site, create or use a Nexow account, build or share workspaces and widgets, connect third-party services, purchase or manage a plan, or otherwise interact with the Services.

It does not apply to third-party websites, apps, venues, or APIs you choose to connect; those are governed by their own privacy terms. Where a connector runs in your browser against a third party, that third party is typically an independent controller of data you send to them.

3. Information we collect

Account and profile data: email address, display name, authentication identifiers, plan or billing status, preferences, and similar account settings.

Workspace and product data: widgets, prompts, generated code or configurations, versions, logs, library items, sync state, collaboration metadata, and related content you create or upload in the Services.

Connection data: tokens, API keys, or OAuth credentials you supply for third-party connectors (handled as described in “Connections and credentials”), plus technical metadata needed to maintain those connections.

Usage and device data: IP address, browser type, device or OS information, approximate location derived from IP, referrer, pages viewed, feature usage, performance and diagnostic events, and similar telemetry needed to operate and secure the Services.

Communications: messages you send to us (support, privacy, or legal requests), and related correspondence.

Payment data: if you purchase a paid plan, payment method and billing details are typically processed by our payment processor; we receive limited billing metadata (e.g., plan, status, last four digits or similar tokens) rather than full card numbers where the processor allows.

Cookies and similar technologies: see our Cookie Policy for details.

4. How we use information

We use personal information to: provide, maintain, and improve the Services; authenticate users and secure accounts; store and sync workspace content you request; process transactions and send service-related notices; respond to support and privacy requests; monitor reliability, abuse, and security; comply with law; and, where permitted, communicate product updates (you may opt out of non-essential marketing).

We do not sell personal information as “sale” is commonly defined under CCPA/CPRA, and we do not share personal information for cross-context behavioral advertising as those terms are defined under California law, except as disclosed in our Cookie Policy if we introduce advertising cookies (in which case we will update this Policy and provide required opt-outs).

5. Legal bases (EEA / UK / Switzerland)

Where the EU GDPR, UK GDPR, or Swiss FADP applies, we process personal data on one or more of these bases: performance of a contract (providing the Services you request); legitimate interests (securing and improving the Services, preventing abuse, basic analytics), balanced against your rights; consent (where required, e.g., certain cookies or optional marketing); and legal obligation (retaining records or responding to lawful requests).

6. Connections and credentials

Where a third-party service permits it, Nexow may connect directly from your browser so credentials are used primarily to talk to that service. Some services require a proxy or server-side component; in those cases we process only what is needed to fulfill the request and operate the connector.

You are responsible for ensuring you have the right to connect each service and for configuring least-privilege credentials. Revoke access in the third-party service and in Nexow when you no longer need a connection.

7. Generated content and AI features

When you use generation or AI-assisted features, prompts and related context may be processed by us and/or by model or infrastructure providers we use to deliver the feature. We use that processing to generate results for your workspace and to operate and improve the Services, subject to our contracts with those providers.

Do not submit secrets, regulated personal data, or confidential third-party data in prompts unless you have a lawful basis and accept the risk that such content may be processed by subprocessors involved in generation.

8. Sharing and processors

We share personal information with: service providers (hosting, analytics, email, payments, error monitoring, AI/model providers) under contracts that limit use to providing services to us; professional advisors; authorities when required by law or to protect rights and safety; and successors in a merger, acquisition, or asset transfer (with notice where required).

We may also share information you choose to make public or share with other users (e.g., published widgets, community features) according to your settings.

9. International transfers

Nexow, Inc. is based in the United States. If you access the Services from the EEA, UK, Switzerland, or other regions, your information may be transferred to and processed in the United States and other countries that may have different data-protection rules.

Where required, we use appropriate safeguards for transfers (such as Standard Contractual Clauses or successor mechanisms) and take steps we consider reasonable to protect personal information.

10. Retention

We retain personal information for as long as your account is active or as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Workspace content generally persists until you delete it or close your account, subject to backup and legal hold periods. You may request deletion as described below; some residual copies may remain in backups for a limited time.

11. Security

We implement technical and organizational measures designed to protect personal information (access controls, encryption in transit where appropriate, least-privilege practices). No method of transmission or storage is completely secure; you are responsible for safeguarding account credentials and devices.

12. Your rights — Europe and UK (GDPR)

If you are in the EEA, UK, or Switzerland, you may have rights to access, rectify, erase, restrict, or object to certain processing; to data portability; and to withdraw consent where processing is consent-based, without affecting prior lawful processing. You may lodge a complaint with your local supervisory authority.

To exercise these rights, email [email protected] with “Privacy Request” in the subject line. We may need to verify your identity before fulfilling a request.

13. Your rights — United States (including CCPA/CPRA)

Depending on your state of residence (including California under the CCPA/CPRA), you may have rights to know/access, delete, correct, and opt out of sale or sharing of personal information, and to limit use of sensitive personal information where applicable. We will not discriminate against you for exercising privacy rights.

Submit requests to [email protected] (subject: “Privacy Request”) or by mail to 2810 N Church St STE 89080 Wilmington, DE 19802, United States. Authorized agents may submit requests as permitted by law; we may require proof of authorization and identity verification.

If we offer a “Do Not Sell or Share” or similar control (including via Global Privacy Control where we honor it), we will describe it in the Cookie Policy or product settings.

14. Asia-Pacific notes (high level)

If you are in jurisdictions such as Singapore (PDPA), Japan (APPI), South Korea (PIPA), or other Asia-Pacific regions with personal-data laws, we process information as described in this Policy and in accordance with applicable local requirements to the extent they apply to Nexow, Inc. as a U.S. provider of online Services.

You may contact us at [email protected] to inquire about access, correction, or deletion consistent with applicable law. Where local law requires a local representative or additional notices, we will update this Policy or provide region-specific notices.

15. Children

The Services are not directed to children under 16 (or the higher age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.

16. Marketing site

Our marketing website is primarily static and uses limited analytics and cookies as described in the Cookie Policy. We do not sell personal data collected from the marketing site. Outbound links (including to the app) are labelled where practical.

17. Changes

We may update this Policy from time to time. The “Last updated” date will change when we post revisions. Material changes may be highlighted on the site or notified by email where appropriate. Continued use of the Services after an update constitutes acceptance of the revised Policy to the extent permitted by law.

18. Contact

Privacy and data-protection requests: [email protected]

Postal: Nexow, Inc., 2810 N Church St STE 89080 Wilmington, DE 19802, United States

Web: https://nexow.ai