Back
NexmetryNexmetry

Privacy Policy

Last updated: April 2026

1. Who We Are

Nexmetry Inc. ("Nexmetry", "we", "us"), 263 Hull Street, Apt 412, Brooklyn, New York, USA, is the data controller for personal data processed through this platform. For any privacy question, or to exercise the rights described below, contact us at [email protected].

2. Information We Collect

Account data you provide (name, email, organization, password — stored only as a bcrypt hash). Technical data created by using the service (IP address, browser/user agent, timestamps, audit records of significant actions). And the content you upload — datasets, survey responses, documents, images and the analyses you build from them, which may itself contain personal data about other people.

3. Why We Process It, and on What Legal Basis

To provide the platform to you (contract). To keep it secure — authentication, abuse prevention and audit logging (legitimate interests). To send transactional email such as verification, password reset and team invitations (contract). To send marketing or product-news email (consent, which you can withdraw at any time). To meet tax and legal obligations (legal obligation). We do not use your data for automated decision-making that produces legal effects.

4. Data Storage & Security

Data is encrypted in transit (TLS) and at rest. Passwords are hashed with bcrypt and never stored or logged in plaintext. Access is controlled by a server-enforced role hierarchy with strict organization isolation — every tenant-scoped query is filtered by organization. Sessions use short-lived 60-minute access tokens plus 30-day refresh tokens with rotation, so a stolen token cannot be replayed; signing out revokes all sessions. Organizations can additionally enforce multi-factor authentication.

5. AI Features

AI features are processed by our AI sub-processor, Anthropic (Claude API). For dataset analytics, only aggregated statistics are sent — never your raw dataset rows. For text features (NLP, qualitative coding, literature screening), the relevant text content itself is sent, because the feature cannot work otherwise. Anthropic does not use API submissions to train its models. You can opt out of AI features at any time in account settings.

6. Who We Share It With

We do not sell your data and we run no advertising. Our core sub-processors, each under a data processing agreement, are: Amazon Web Services (hosting and storage), Anthropic (AI features), Resend (email delivery) and Cloudflare (DNS, TLS, CDN and bot protection). Depending on your configuration and the features you use, data may also be processed by: OpenAI (a second AI provider for image generation and some AI fallbacks); Sentry (error monitoring, which can include request context); Cloudflare Web Analytics (privacy-preserving page analytics); Google, Microsoft or GitHub (only if you sign in with them); Google Drive or Sheets (only if you connect them as a data source); and hCaptcha or reCAPTCHA (bot protection on sign-in and public forms). Billing (Stripe) and SMS (Twilio) apply only if you enable those features — card details go directly to Stripe and we never receive or store them. Separately, your browser contacts a few services directly when you use certain features: Have I Been Pwned (a k-anonymity check that rejects breached passwords at sign-up — only a partial hash is sent, never your password), map tile providers (CARTO/OpenStreetMap/ArcGIS) when a map renders, and the jsDelivr CDN for the formula editor. The full, current register is available on request. We disclose data to authorities only where legally required, and will notify you of a personal-data breach as required by law.

7. Where Your Data Is Processed

Our infrastructure runs in Amazon Web Services in the United States (region us-east-2, Ohio). If you are in the EU, UK or Switzerland, using Nexmetry involves transferring personal data to the United States. Where required, such transfers rely on Standard Contractual Clauses together with a transfer-risk assessment.

8. How Long We Keep It

Account and project data are kept for the life of your account or organization. Access tokens last 60 minutes and refresh sessions 30 days. Audit logs are retained under the audit-retention policy set for your organization for security and legal purposes, and are exempt from the general retention setting. When you delete your account, personal data is erased immediately from our live systems; copies may persist in encrypted backups until those backups age out, within 30 days.

9. Cookies

Cookies we set are strictly necessary for signing in. Two of them — nx_access_token and nx_refresh_token — are HttpOnly (unreadable by JavaScript), Secure and SameSite=Lax. A third, auth_token, holds your session token so the app can authorize you during server-side page routing; it is SameSite=Lax and, unlike the other two, is readable by JavaScript running in the app. It mirrors the session token the app also keeps in your browser local storage to authenticate your API requests. We use no analytics, advertising, tracking or session-replay cookies. Other preferences (language, theme) are stored locally in your browser and never sent to us. Blocking these cookies will prevent you from staying signed in.

10. Your Rights

You can access and export your data (Settings → Data & Export), correct it in-app, and erase it (Settings → Danger Zone → Delete my account, which requires your password). You may also object to or restrict processing, withdraw consent — including opting out of marketing email from Settings or the unsubscribe link in any such message — and request portability. If you are in the EU/UK you have the right to lodge a complaint with your local supervisory authority.

11. Health Data (HIPAA)

Nexmetry supports imaging and clinical workflows, but protected health information must not be uploaded unless a Business Associate Agreement is in place with us and our relevant sub-processors. Medical-imaging ingress is disabled by default for this reason.

12. Children

Nexmetry is not directed to children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children; if you believe we have, contact us and we will delete it.

13. Changes to This Policy

We may update this policy periodically. Material changes will be communicated by email and in-app notification. Continued use after an update constitutes acceptance of the revised policy.

Privacy questions? Contact our Data Protection Officer at [email protected]