Privacy Notice
Public privacy notice for Nexus Analysis account, subscription, analysis, and browser data handling.
Effective date: 2026-06-17 Region: English-language international users outside Korea and the EEA/UK, unless local mandatory law requires otherwise Operator: Nexus Privacy contact: support@nexus-analyzer.com
This Global Privacy Notice explains how Nexus Analysis handles personal data for account, analysis, workspace, support, and paid subscription features.
1. Who We Are
Nexus Analysis is a scientific measurement analysis service for converting measurement files into charts, summaries, and analysis outputs.
For privacy questions or rights requests, contact: support@nexus-analyzer.com.
2. Personal Data We Collect
We may collect or process the following categories of data.
| Category | Examples |
|---|---|
| Account data | Email address, display name, Google account identifier, Supabase user ID |
| Authentication data | Login session, OAuth result, authentication provider metadata. We do not directly store plaintext passwords. |
| Subscription data | Plan, subscription status, promotion redemption status, billing cycle, payment processor IDs, invoices, cancellation and refund history |
| Payment data | Payment processor, merchant of record, subscription, invoice, receipt, refund, and cancellation records. Full card numbers are processed by the payment processor. |
| Analysis data | Uploaded file name, sample name, measurement metadata, normalized analysis records, chart data, calculated summaries, workspace and project records |
| Usage data | IP address, access time, device and browser information, language setting, error logs, download quota usage, feature usage events, signed-in tier-based product usage events |
| Browser storage data | Download quota state, plan display state, language setting, session-related browser storage |
At the current product stage, files are primarily processed in the browser. If a user saves a workspace, normalized analysis records and project metadata may be stored in Supabase. If raw file storage is later introduced, this notice should be updated before release.
Product-improvement usage events do not include original file contents, full file names, sample names, measurement values, or chart data. They are limited to the signed-in user's tier, analysis tab, upload success or failure status, export kind, locked feature clicks, and error reason codes needed for service improvement.
3. How We Use Personal Data
We process personal data to:
- create and manage accounts;
- provide login via email/password and Google OAuth;
- convert analysis files into charts and summaries;
- provide workspace save and restore features when enabled;
- manage Guest, Free, and Light plan access;
- validate promotion codes and enforce redemption limits;
- process payments, refunds, invoices, and cancellations;
- prevent abuse and enforce download limits;
- debug errors, secure the service, and improve reliability;
- aggregate product-improvement metrics for signed-in users;
- comply with legal obligations and handle disputes.
4. Legal Basis and Notice for International Users
Depending on your location, we process personal data under one or more of the following grounds:
- to perform a contract with you, such as providing account, analysis, subscription, and support features;
- to comply with legal obligations, such as tax, accounting, fraud prevention, and dispute handling;
- for legitimate business purposes, such as securing the service, preventing abuse, and improving reliability;
- with your consent, such as for optional marketing emails or non-essential cookies where required.
This English global notice is not intended to replace the dedicated Korean notice or the dedicated EEA/UK notice where those regional notices apply.
5. Sharing and Processors
We do not sell personal data. We may share or process data through the following service providers.
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, workspace storage |
| Google OAuth login | |
| Payment processors and merchants of record shown at checkout | Payment processing, subscriptions, receipts, taxes, refunds, and buyer support |
| Vercel or equivalent hosting provider | Web hosting, access logs, technical logs |
We may also disclose information if required by law, to protect rights and security, or as part of a business transfer.
6. International Transfers
The service may involve international transfers of personal data, including transfers to infrastructure or payment providers outside the user's country.
Where local law requires transfer safeguards, we use or require appropriate contractual, technical, or organizational measures from the relevant provider.
7. Retention
We keep personal data only as long as necessary for the purposes described above.
| Data | Retention |
|---|---|
| Account data | Until account deletion, unless retention is legally required |
| Subscription and payment records | As required for accounting, tax, fraud prevention, and disputes |
| Workspace and normalized analysis records | Until the user deletes them or closes the account |
| Product-improvement usage events | Up to 90 days from collection |
| Browser storage data | Until deleted by the user or reset by the service |
| Security and access logs | For a reasonable security and troubleshooting period |
8. Children
Nexus Analysis is not directed to children under 16. Users under 16 may not create an account or subscribe. If we learn that we collected data from a child under 16, we will delete it or take appropriate steps.
9. Cookies and Similar Technologies
We may use cookies, localStorage, sessionStorage, and similar technologies for login, language settings, download quota tracking, security, and service operation.
If we introduce analytics, advertising, or non-essential cookies in a region where consent is required, we will request consent before using them.
10. Your Rights
Depending on your location, you may have rights to:
- access your personal data;
- correct inaccurate data;
- delete your data;
- restrict or object to processing;
- receive a portable copy of data;
- withdraw consent;
- opt out of certain sharing, sale, or targeted advertising where applicable;
- appeal or complain to a privacy or data protection authority.
California users may have rights under the CCPA/CPRA, including rights to know, delete, correct, limit certain sensitive data uses, opt out of sale or sharing, and non-discrimination. Nexus Analysis does not currently sell personal data.
To exercise rights, contact support@nexus-analyzer.com.
11. Security
We use technical and organizational safeguards designed to protect personal data, including authentication controls, database access controls, payment processor separation, and logging for service reliability.
No online service can guarantee absolute security.
12. Changes
We may update this notice as the service, subscription model, processors, or legal requirements change. Material changes will be communicated through the service or other appropriate means.