Privacy Policy

Effective date: March 4, 2026

Who we are

NEXA (“we”, “our”, or “us”) operates the website nexa.community and the NEXA professional networking service. Questions about this policy can be sent to zubin@nexa.community.

Information we collect

We collect the following categories of personal information:

  • Identity and contact data - your name and email address, obtained when you sign in with Google.
  • Google profile data - your name, email address, email verification status, and profile photo, provided through Google OAuth at the time of sign-in.
  • Google Contacts data - if you grant permission during sign-in, we access the names, email addresses, and professional details (employer, job title) of people in your Google Contacts and Other Contacts. This data is used exclusively to identify potential warm introductions within your existing network. We do not read the content of any emails or messages. See the “Contact data and permissions” section below for full details.
  • Professional history - job titles, employers, skills, and education retrieved from third-party data providers using your LinkedIn URL, to improve the quality of introductions we make on your behalf.
  • Resume data - if you optionally upload a resume, we extract structured information (current role, skills, work history, education). The file is stored securely on your behalf.
  • Goals and preferences - what you are looking for (e.g. a new role, a cofounder, investors) and any details you provide.
  • Voice conversation data - when you speak with NEXA's AI, the conversation is transcribed. Audio is processed in real time and not stored beyond what is needed to generate a response.
  • Phone contacts - if you grant permission, we access your device's contact list to identify people in your network who may be relevant to your goals. Contacts are used solely for matching and are never sold or shared with third parties for marketing.
  • Usage data - pages visited, features used, and interaction events collected through analytics tools and standard server logs.

We do not collect sensitive personal information such as financial data, government IDs, or health information.

How we use your information

We use your information to:

  • Identify and make relevant warm introductions within your professional network.
  • Personalize the AI conversation so it can ask sharper qualifying questions.
  • Surface relevant contacts from your Google Contacts, phone contacts, and other connected sources.
  • Communicate with you about introductions and service updates.
  • Improve and debug the NEXA product using aggregated analytics.
  • Comply with legal obligations.

We do not use your data to train general AI models, and we do not sell your personal information to third parties.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we share your information

We share personal data only with the service providers necessary to operate NEXA, each bound by data processing agreements. Categories of providers include:

  • Google - identity and profile data is obtained through Google's OAuth API under their Privacy Policy.
  • Professional data enrichment providers - your LinkedIn URL (if provided) is shared with enrichment services to retrieve additional professional context such as work history and skills.
  • AI and voice infrastructure providers - your conversation data is processed by AI providers to power NEXA's matching and conversation features.
  • Cloud infrastructure and database providers - your profile and preference data is stored securely with cloud providers on our behalf.
  • Analytics providers - anonymised usage events are shared with analytics services to help us understand and improve the product.
  • Web hosting providers - our website is served through hosting infrastructure that processes requests on our behalf.

We may disclose data if required by law, to protect the safety of users, or in connection with a merger or acquisition (with prior notice to you).

Data obtained from Google APIs is never shared with third parties for advertising purposes, used to train AI models unrelated to the NEXA service, or otherwise transferred beyond what is necessary to provide NEXA's core functionality.

Contact data and permissions

Access to your Google Contacts, phone contacts, and any other contact sources is always optional and requires your explicit permission. You may revoke Google Contacts access at any time through your Google Account permissions. Revoking permission does not affect previously identified matches, but we will stop accessing new contact data immediately.

Contact data is used exclusively to identify potential introductions within your existing network. We do not contact anyone in your network without your explicit instruction. We do not read the content of emails, calendar events, or messages - only names, email addresses, and professional details (employer, job title) from contact records.

Data retention

We retain your personal information for as long as needed to provide the NEXA service and fulfil the purposes described in this policy, or as required by law. You may request deletion at any time and we will remove your data within 30 days, except where retention is required by a legal obligation.

Cookies and tracking

We use a short-lived session cookie to pass your Google profile data from our sign-in flow back to your browser. It expires automatically within 10 minutes and contains no tracking identifiers.

We use first-party analytics cookies to distinguish unique visitors and understand how the product is used. No third-party advertising cookies are used.

Your rights

Depending on where you are located, you may have the following rights regarding your personal data:

  • Access - request a copy of the data we hold about you.
  • Correction - ask us to correct inaccurate or incomplete data.
  • Deletion - request that we delete your data.
  • Portability - receive your data in a structured, machine-readable format.
  • Objection - object to processing based on legitimate interests.
  • Withdraw consent - where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, email zubin@nexa.community.

GDPR - EU and UK residents

If you are located in the European Economic Area or the United Kingdom, NEXA is the data controller for your personal information. Our legal bases for processing are:

  • Contract performance - processing your data to provide the introductions service you requested.
  • Legitimate interests - product analytics and service improvement, balanced against your rights.
  • Consent - for optional data such as resume upload, Google Contacts access, and phone contacts.

You have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or your national data protection authority in the EU).

CCPA - California residents

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act:

  • Right to know - request details about the categories and specific pieces of personal information we have collected about you.
  • Right to delete - request deletion of your personal information, subject to certain exceptions.
  • Right to opt out of sale - NEXA does not sell personal information. No opt-out is required.
  • Right to non-discrimination - we will not discriminate against you for exercising your CCPA rights.

To submit a request, email zubin@nexa.community with “CCPA Request” in the subject line.

Children's privacy

NEXA is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us and we will delete it promptly.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the effective date at the top and, for material changes, notify you by email or a notice on our website. Your continued use of NEXA after changes take effect constitutes acceptance of the updated policy.

Contact us

For any privacy-related questions, requests, or concerns, please reach out to: zubin@nexa.community