Privacy Policy

Last updated: 5 October 2026

Private beta draft. This page describes how the product works today. Sections marked “Pending legal review” have not yet been reviewed by a legal adviser.

Marketing Hub by Nexoryx One ("Nexoryx One", "we", "us") is a marketing analytics service. You connect marketing platforms you are authorised to use (such as Google Analytics 4, Google Search Console, Google Ads and Meta Ads), and we turn their data into dashboards, metrics, recommendations and explanations. This policy describes what we collect, how the service uses it, who processes it, and the choices you have. It describes the product as it works today.

Pending legal review: the identity of the data controller, and the lawful bases relied on for each type of processing.

1. Information we collect

1.1 Account information

  • When you sign in with Google (or Apple or Microsoft, where offered) we receive your name, email address and profile picture. Sign-in uses the openid, email and profile scopes only.
  • Your memberships and roles (owner, admin, member) in each workspace.

1.2 Workspace information

  • Workspace profile: company name, website, industry, business model, currency, time zone and reporting preferences.
  • Your objectives, the platforms you use, metric settings and targets, and notification preferences.
  • Invitations you send: the invited email address and role. Invitation links are stored only as a one-way hash.
  • Private beta requests: what you submit in the request form — your name and work email; your business details (company name, optional website, company size, industry and country); your business model; the marketing goals you choose; the platforms you currently use; and, if you add it, a description of your main marketing challenge — plus when you submitted and its review status. We use this only to assess whether the private beta suits you, to contact you about your request, and to support your onboarding if you're approved. We don't use it for unrelated marketing without your separate consent. To limit abuse we keep a one-way hash of your network address for a short period, never the address itself. Deleting your account removes your request.
  • Account access settings: if your access is time-limited or paused, the trial dates, whether access is paused, and which Nexoryx administrator changed it. This never deletes your data.
  • Emails we send you (for example a beta request receipt or approval): the email type, your address, the delivery status and a short failure category. We don't keep copies of the email content. Deleting your account anonymises these records.
  • Internal support notes: Nexoryx administrators may record short notes to help support your account. They are never shown to other customers, must not contain credentials, and are removed when you delete your account.
  • Private beta access list: if you are approved for the beta, your email address, who approved it and when (and if access is later withdrawn). Deleting your account removes your entry.

1.3 Connection information and credentials

  • When you connect a platform, we store the OAuth access and refresh tokens it issues, encrypted at rest (AES-256-GCM). Tokens are used only on our servers to read your data; they are never shown in the app, included in exports, or sent to AI services.
  • Connection status, the account, property or site you select (its ID and name), and error categories from connection checks.

1.4 Marketing data from connected platforms

Once a source is ready, we sync and store daily, aggregated reporting data from it:

  • Google Analytics 4: daily totals such as sessions, users, key events (by event name), transactions, purchase revenue and first-time purchasers. We do not import visitor-level or user-level records.
  • Google Search Console: daily clicks, impressions, click-through rate and average position, plus the top search queries and pages for each day.
  • Google Ads: daily campaign- and ad-group-level metrics (spend, impressions, clicks, conversions, conversion value, impression share), campaign and ad-group names and statuses, campaign settings (type, bidding strategy, budget) and conversion counts by category.
  • Meta Ads: daily account- and campaign-level metrics (spend, impressions, clicks, reach, conversions and actions by type) and campaign names.
  • Shopify (connection preview): if you connect Shopify, we store the store domain and authorisation only. No Shopify data is imported yet.

1.5 Information the service creates

  • Calculated metrics, detected signals, recommendations and scenario estimates (scenarios are calculated on request and not stored).
  • Actions you prepare, approve or confirm, with their audit trail and measured outcomes.
  • Cached AI-generated explanations for the Executive Brief.

1.6 Usage, security and support information

  • Usage events: the type and time of certain actions (for example AI questions, manual syncs and exports), used to apply rate limits and plan limits.
  • Audit records: security and governance events such as exports, deletion requests, ownership transfers and permission checks. These contain IDs, codes and counts, not your marketing data.
  • Server logs kept by our hosting provider, which may include IP address, browser type, pages requested and timestamps. We use them for security and troubleshooting.
  • Beta feedback you send: category, rating, comment and the page you were on. Comments are automatically scanned to remove anything that looks like a password, key or token. Please don't include them.

2. How we use information

  • To provide the service: sign-in, workspaces and teams, connecting sources, syncing data, dashboards, metrics, recommendations, scenarios, exports and deletion.
  • To calculate metrics. All metrics are calculated by Nexoryx One's own deterministic engine, not by AI.
  • To produce AI-written explanations where that feature is used (see section 4).
  • To keep the service secure and reliable: rate limiting, audit trails, error investigation and support.
  • To respond to your requests and feedback.

We do not sell your data, use it for advertising, or use it to train our own AI models.

3. Google data and permissions

With your authorisation, Nexoryx One reads data from the Google products you choose to connect. Each one is a separate authorisation:

  • Google Analytics 4: https://www.googleapis.com/auth/analytics.readonly (read-only).
  • Google Search Console: https://www.googleapis.com/auth/webmasters.readonly (read-only).
  • Google Ads: https://www.googleapis.com/auth/adwords. Google offers this single scope for Ads access; it technically permits changes. Nexoryx One only reads reporting data and makes no changes to your campaigns, budgets or bids. At most, an owner or admin can run a "permission check only" request, which Google validates without changing anything.

Some Google data can also be connected through an assisted setup, where you share a property or site with our service account instead of signing in. Its access is limited to what you shared, and you can revoke it in Google at any time.

We use Google user data only to provide and improve the user-facing features of the Marketing Hub. Nexoryx One's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Pending legal review: confirming that all handling of Google user data meets the Limited Use requirements, including sending Google-derived marketing evidence to Anthropic to generate explanations (section 4).

You can remove Nexoryx One's access at any time in your Google Account permissions, or by disconnecting the source in the Data Hub.

4. AI explanations (Anthropic)

Where configured, the Executive Brief and Captain AI use Anthropic's Claude models to write plain-language explanations. When this feature is used:

  • We send your question and a selected set of structured marketing evidence: metric names, values and changes, reporting periods, detected signals, recommendations, campaign or ad-group names where relevant, and your workspace's business model, objectives and currency.
  • We never send OAuth tokens, credentials, API keys or raw provider responses.
  • AI does not calculate metrics; it explains numbers our own engine has already calculated, and answers that cite numbers not in the evidence are rejected.
  • AI cannot take actions, change campaigns, budgets or bids, approve recommendations or send messages.
  • If AI is unavailable, you still see the calculated facts without an AI explanation.

Pending legal review: Anthropic's data-retention and model-training terms for API data, and the data processing agreement.

5. Meta data

If you connect Meta Ads, we request ads_read and business_management to read your ad accounts' reporting data. The integration is read-only; Nexoryx One cannot create, edit or pause ads. You can remove access in your Meta Business settings or by disconnecting the source.

Pending legal review: compliance with the Meta Platform Terms and Developer Policies.

6. Service providers (sub-processors)

We use these providers to run the service. They receive only the data needed for their purpose:

ProviderPurposeDataWhen
VercelApplication hosting, serverless functions, scheduled jobs and request logsAll data passing through the application; request metadata such as IP address and user agent in logsAlways
SupabaseDatabaseAccount, workspace, connection and encrypted credential records; synced marketing data; intelligence, actions, audit and feedback recordsAlways
AnthropicAI explanations for the Executive Brief and Captain AIYour question text and structured marketing evidence (metric names, values, changes, periods, campaign or ad-group names, business model and objectives). Never credentials or raw provider responsesWhen AI explanations are used and configured
GoogleSign-in, and the Google Analytics 4, Search Console and Google Ads connectorsSign-in identity; API requests made with your authorisationSign-in with Google, or when you connect a Google source
MetaMeta Ads connectorAPI requests made with your authorisation (read-only)Only if you connect Meta Ads
Apple / MicrosoftSign-inSign-in identity (name, email)Only if you sign in with that provider and it is enabled
ShopifyConnection preview (no data is imported yet)Store domain and authorisationOnly if you connect Shopify
ResendEmail delivery: report emails you request, private beta request receipts and approvals, and account notices (for example access changes or setup help)Recipient email address, name and the email content; for beta requests, the details you submit in the request form (contact, business, goals, platforms and any challenge you describe)When we send you an email, or you request beta access

We may also disclose information if required by law, or as part of a merger or acquisition.

Pending legal review: data processing agreements with each provider, and where each provider processes data.

7. Cookies and similar technologies

We use cookies that are needed for sign-in and security, plus a few preferences. We do not use advertising cookies.

CookieTypePurposeDuration
next-auth.session-token (or __Secure-next-auth.session-token)EssentialKeeps you signed inUp to 30 days
next-auth.csrf-token / next-auth.callback-url (and __Host- / __Secure- variants)EssentialProtects and completes the sign-in flowSession
oauth_state_<provider>, oauth_return_<provider>, oauth_shop_<provider>EssentialProtects the data-source connection flow and returns you to the right page10 minutes
nx_workspacePreferenceRemembers which of your workspaces is activeUp to 1 year
nexoryx_demoPreferenceEnables Demo Mode with sample data1 day
Google Tag Manager tagsAnalytics (if enabled)Loaded only if a tag container is configured for the site; cookies depend on the tags in that containerDepends on the tag

The app also keeps some preferences in your browser's local storage (these aren't sent to us with each request):

  • dashboard_period: Your selected reporting period
  • nx_first_value_dismissed: Hides the setup-complete card after you dismiss it
  • sidebar_section_*: Which navigation sections are expanded
  • kpi_template, ga4_selected_property, marketing-intelligence_alerts: Legacy dashboard and demo preferences
  • nx_invite_token (session storage): Holds an invitation token during sign-in; removed after you accept

Pending legal review: whether consent is required for any non-essential cookie or tag, particularly if Google Tag Manager is enabled.

8. Retention, export and deletion

8.1 Export

A workspace owner can download a copy of the workspace's data at any time (Settings → Data & privacy). The download link works once and expires after 15 minutes. Exports never include tokens or credentials, and we don't keep a copy of the export file.

8.2 Workspace deletion

  • The workspace owner requests deletion and confirms it. Deletion is then scheduled after a 7-day grace period, during which the owner can cancel it.
  • After the grace period, final deletion requires approval by a Nexoryx One platform administrator. The owner can still cancel until it's approved.
  • Once approved, we delete the workspace's configuration, connections and encrypted credentials, synced data, recommendations, actions, outcomes, feedback and usage records.
  • We keep a minimal governance record: the request, its dates and row counts, and audit events containing IDs and codes. It contains no marketing data.
  • Deleting the workspace removes our stored credentials but does not revoke the access you granted inside Google or Meta. You can remove that in your Google or Meta account settings.

8.3 Account deletion

  • You can delete your account in Settings → Data & privacy. If you are the only owner of a workspace that has other members, you must first transfer ownership or delete that workspace.
  • Workspaces where you are the only member are scheduled for deletion (the same process as above). You are removed from other workspaces.
  • Your user record is anonymised (name, email and picture removed) rather than erased, so audit records keep only an anonymous ID.
  • Accounts that have data from an earlier version of the product need a manual deletion step; contact us.

8.4 Retention

We keep data while your workspace is active, or until it is deleted as described above. We have defined retention periods for operational records (for example sync history, usage events and cached AI explanations), but automatic cleanup is not yet switched on, so these records are currently kept until their workspace is deleted. Sign-in sessions expire after up to 30 days.

Pending legal review: final retention periods and when automatic cleanup will be enabled.

9. Security

  • Encryption in transit (HTTPS) and encryption of stored OAuth credentials (AES-256-GCM).
  • Workspace isolation: every request is checked against your workspace membership and role.
  • Role-based permissions, rate limits, one-time links for exports and invitations, and audit trails for sensitive actions.
  • Changes to ad platforms are disabled. Meta access is read-only, and Google Ads is used for reading only.

No system is perfectly secure. Please protect the accounts you sign in with, including using two-factor authentication.

10. Your choices and rights

  • Export your workspace data, delete a workspace, or delete your account in the app.
  • Disconnect any data source in the Data Hub, and revoke access in Google or Meta.
  • Ask us for access to, correction of, or deletion of your personal data, or object to processing: email sub17h4@gmail.com.

Pending legal review: the statutory rights that apply (for example under UK or EU data protection law), response timelines, and how to complain to a supervisory authority.

11. International processing

Our providers may process data in countries other than yours. The specific regions depend on each provider's configuration.

Pending legal review: provider regions and the transfer safeguards relied on.

12. Children

The service is for businesses and is not directed to children. We do not knowingly collect information from children.

13. Changes to this policy

We will update this page when the product changes how it handles data, and change the "Last updated" date. Where a change is material, we will also tell workspace owners in the app or by email where appropriate.

14. Contact

Questions or requests: sub17h4@gmail.com.