01Who we are
Nexa (“Nexa,” “we,” “us”) provides the Nexa AI-native code editor (the “App”), the website at nexa-ai.xyz, and the associated account, sign-in, and cloud services (together, the “Services”). This policy applies to all of them, including the App distributed through the Microsoft Store and other channels.
02Information we collect
We collect only what we need to run the Services. That includes:
Account information
When you sign in with Google, we receive your email address, name, and profile picture from Google (via your consent on Google’s sign-in screen). We use this to create and identify your account and to issue your personal API key. We do not receive your Google password.
Your API key
Each account has a personal Nexa API key that unlocks the AI agent. The key is stored in your account and, on your device, in your operating system’s secure secret store. It is sent with your requests so we can authenticate and meter them.
Prompts and code context you send to the agent
When you ask the AI agent to do something, the App sends the content needed to fulfil that request — your prompt and the relevant portions of your code, files, or selection for that task — to our backend, which relays it to our AI model provider to generate a response. We send only the context needed for the request, not your entire project.
Usage and metering data
To enforce fair-use limits and quotas we record request counts and token counts per account, along with timestamps. We do not use this to build advertising profiles.
Cloud memory & chat history
If enabled, the App can sync a small set of project “memory” notes and your chat sessions to our cloud so they follow you across machines. This is tied to your API key and can be turned off or deleted (see Your rights & choices). Your chats and memory are scoped per project.
Technical & log data
Our servers keep standard operational logs (e.g. request status, timing, IP address for rate-limiting and abuse prevention). These are used for security and reliability and are not used to identify you beyond your account.
03How your code is handled
Your code stays on your machine. The App reads and edits files locally. Code is transmitted only when you ask the agent to act, and then only the context needed for that request.
We do not use your code or prompts to train AI models. Content you send is used only to produce your result and is not sold or used for advertising.
Destructive actions (deleting files, overwriting work) always require your explicit approval inside the App. You remain in control of what the agent changes.
04How we use information
- To provide the Services — authenticate you, run the AI agent, and return results.
- To operate and secure the Services — enforce quotas, prevent abuse, diagnose problems, and keep the system reliable.
- To sync your memory and sessions across your devices, when you enable that feature.
- To communicate with you about your account, security, or important changes to the Services.
- To comply with law and enforce our terms.
We do not sell your personal information, and we do not use your code or prompts for advertising or model training.
05Sharing & third parties
We share information only with the service providers needed to run Nexa, and only as described here:
| Recipient | Purpose | What is shared |
|---|---|---|
| AI model provider | Generate the agent’s responses to your requests | Your prompt and the code context needed for that request, transmitted encrypted |
| Sign-in (OAuth) | We receive your email, name, and picture; we do not send your data to Google beyond the sign-in exchange | |
| Hosting / infrastructure | Run our servers and store account data | Account records, usage counts, and any cloud memory/sessions you enable |
We may also disclose information if required by law, to protect our rights or users’ safety, or as part of a business transfer (e.g. merger), in which case this policy will continue to govern your information.
06Data retention
We keep account information for as long as your account is active. Usage/metering records are kept for operational and abuse-prevention purposes and then aggregated or deleted. Cloud memory and chat sessions are kept until you delete them or close your account. Operational logs are retained for a limited period and then rotated out. When you delete your account, we remove your personal data within a reasonable period, except where we must retain it to comply with law.
07Security
Data is encrypted in transit (HTTPS/TLS). Your API key is stored in your operating system’s secure secret store on your device. We restrict administrative access to authorized personnel and publish SHA-256 checksums for every App release so you can verify your download. No system is perfectly secure, but we work to protect your information and to fix issues quickly.
08Your rights & choices
- Access & view your account, key, and usage anytime on your dashboard.
- Delete cloud memory / sessions from within the App or your dashboard.
- Turn off cloud sync so memory and sessions stay only on your device.
- Regenerate or clear your API key at any time.
- Delete your account and associated personal data by contacting us (see below).
Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA — including the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, contact us and we will respond as required by law. We do not sell personal information.
09Children
Nexa is a developer tool intended for users aged 13 and over (or the minimum age of digital consent in your country). It is not directed to children, and we do not knowingly collect personal information from children under that age. If you believe a child has provided us information, contact us and we will delete it.
10International transfers
Our Services and providers may process data in countries other than yours. Where we transfer personal data internationally, we take steps to ensure it remains protected consistent with this policy and applicable law.
11Changes to this policy
We may update this policy as the Services evolve. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the Services after an update means you accept the revised policy.
12Contact us
If you have questions about this policy or your data, or want to exercise your rights, contact us at:
Email: privacy@nexa-ai.xyz
Website: https://nexa-ai.xyz