Privacy policy
Last updated: October 4, 2026
Who are the controllers
NEXA is a service operated by its two partners, who are joint controllers of the data: Anderson David Salazar Guzmán, an individual residing in Colombia, and Miguel Ángel Lis Medina, an individual residing in Venezuela. NEXA has not yet been incorporated as a company. Contact for any privacy matter: nexa.iaa@gmail.com
What NEXA is and its role regarding the data
NEXA is a platform that businesses hire to run artificial intelligence agents on their own business data: a web panel, a mobile app for the owner and their staff, and an agent that serves their customers over WhatsApp.
When a client business uses NEXA to serve its end customers, that business decides what data is collected and why, and NEXA processes it following its instructions. If you are an end customer of a business that uses NEXA and want to exercise your rights over your data, you can contact that business or write to us and we will pass it on.
NEXA is directly responsible for the data of the people who use the platform (the web panel and the NEXA mobile app) and of those who try the app's demo.
What data is processed
From the people who use the platform:
- Your email address, which you use to sign in.
- Your name, if the business records it; your role (owner or staff), what you can do with the agent, and the business you belong to.
- What you write in the app or in the panel chat: entries (sales, expenses, inventory…), questions to the agent, and what you confirm or cancel.
- The order in which you want to see the cards on your home screen and, if you are an owner, the goals you set for the business.
- Technical data: your session, when you signed in, and how many requests your business makes to the agent (without their content).
From end customers who message a business that uses NEXA over WhatsApp:
- The content of the messages exchanged with the agent.
- The name the person voluntarily gives when placing an order or making a booking.
- The details of the booking or order itself: date, time, number of people, items.
- The phone number, only during the active conversation.
About the phone number
The phone number is not stored in our database. Inside it, each conversation is identified by a code cryptographically derived from the number, from which the original number cannot be recovered.
The number exists in plain form only in two temporary places: in the memory of the ongoing conversation, which is deleted automatically 24 hours after the last message, and in a cache for the day's bookings panel, which is deleted after 25 seconds.
The NEXA mobile app
The NEXA mobile app is used by the owner of a client business and their staff to record sales, expenses and inventory movements, ask the agent questions, and see how the business is doing. This section describes what the app does with your data.
Access. Accounts are created by NEXA or by the business owner; there is no open sign-up. To sign in you enter your email and receive a one-time code, which expires after 15 minutes. There is no password. The code is generated by the authentication service (Supabase), sent by the email service (Resend) and checked on our server: the app does not connect directly to the database.
What you record or ask. The text is sent to our server and stored together with its status, the date, and what the system understood. The business owner sees all of the business's entries; each staff member sees only their own, and never the business's money figures except the amount they themselves dictate.
To understand it, the text is processed by a language model: OpenAI's for businesses outside Venezuela and Google's (Gemini) for businesses in Venezuela. The same model writes the sentences that summarize your figures on the home screen. The result of an entry is written to the business's Google spreadsheet, which belongs to the client business.
The app does not record audio or ask for microphone access, and NEXA does not store voice recordings.
The app only uses the internet connection and checks whether there is signal. It does not access your location, contacts, camera, photos or microphone, and it does not use the phone's advertising identifier.
The phone stores, in the system's encrypted storage (Keychain on iPhone, Keystore on Android): the credential that keeps your session open; your profile (name, email, role and business); the latest daily summary, so you can see it offline; and whatever you recorded that has not yet reached the server. Signing out deletes all of it. If the session ends on its own (for example, because your access was removed), everything is deleted except what is pending, which is sent when that same person signs in again on that phone.
Error reports. If the app fails, it sends Sentry a technical report with the error, the app version, your internal user identifier, your role and the business identifier. It does not send your name, your email, what you write or the content of your communications with the server, and before leaving the phone any email addresses and credentials that might appear in the report are removed. The screen is not recorded and no screenshots are taken, performance is not measured, and Sentry is configured not to store the IP address. The start and end of each use of the app are also sent, without personal data, to know which versions fail.
The app demo
From the sign-in screen you can try the app without an account, with a fictional business. To start, you type the name of a business (it can be made up) and choose a type of business; the app also sends the language, your region's currency and the phone's time zone, to show you figures and times that make sense.
The app randomly generates its own identifier for the demo (it is not the advertising identifier or a hardware identifier). We store it encrypted (as a sha256 fingerprint) to count visits and limit how many questions can be asked; for the same purpose we also store the IP address, encrypted, for 24 hours.
What you write in the demo is processed by Google's model (Gemini) and stored only in your demo session, which nobody else sees. The session lasts 24 hours; if you tap "Leave the demo", it is deleted right away together with everything you recorded.
If at the end you choose to book a meeting, Cal.com's booking page opens with the business name you typed, the type of business and the number of times you have tried the demo already filled in, so we know what to talk about. What you enter there (your name, your email) is received by Cal.com, and the meeting is created in NEXA's Google Calendar with its Google Meet link.
How long data is kept
- WhatsApp conversations (message content): 90 days from the last message, after which they are deleted automatically.
- Panel and app notifications: 90 days, deleted automatically.
- App entries: the text you wrote, what the system understood and the card you asked from are cleared automatically after 30 days. The rest of the entry (status, dates and, if it could not be recorded, the reason) is kept as long as your account exists.
- The agent's answers to your questions in the app: 24 hours.
- The data that allows undoing an entry: discarded in the first automatic cleanup after the undo window (at most, about an hour later).
- Audit log of actions: kept indefinitely, as a record of what was written to the business's spreadsheet. It contains no phone numbers or end-customer names.
- Agent usage log (how many requests and their size, without their content): kept indefinitely.
- Technical execution log of the automation flows: 72 hours.
- Encrypted fingerprints of the email address and IP address used to limit attempts and abuse: from minutes to 24 hours.
- Demo sessions and what was recorded in them: 24 hours, or until you tap "Leave the demo". Demo visit count: 90 days.
- Your account (email, name, role): as long as it exists. If you delete it, it is erased after 30 days (see below).
Who processes the data and where
NEXA relies on these providers, which process data on our behalf. Each receives only what it needs for its function, and data travels encrypted (HTTPS):
- Supabase — database and authentication (generates the sign-in codes). United States (Virginia).
- Vercel — hosting for the web panel and for the server the app talks to. United States.
- Railway — hosting for the automation engine (n8n). Netherlands (Amsterdam).
- Upstash — temporary conversation memory and usage limits. United States (Virginia).
- OpenAI — language model for businesses outside Venezuela. United States. We use it without it storing the conversations on its platform; under its API terms it does not use this data to train its models, although it may retain it for up to 30 days for abuse monitoring.
- Google (Gemini) — language model for businesses in Venezuela and for the demo. United States. We use the paid service, under which Google does not use the data sent to train or improve its models.
- Google (Sheets) — the business's spreadsheet, owned by the client business, where entries are recorded.
- Meta (WhatsApp) — messaging channel with end customers. United States.
- Resend — sending the emails with the sign-in code. United States.
- Sentry — technical error logging for the panel and the app, without the content of what you write. United States.
- Cal.com — page for booking a meeting from the demo; the meeting is created in Google Calendar and Google Meet (Google) on NEXA's account. United States.
We do not sell personal data or share it with anyone. We do not show advertising, we do not use third-party analytics tools, and we do not track anyone across other companies' apps or websites.
Interaction with artificial intelligence
The agent's replies are generated by an artificial intelligence system. On WhatsApp, the agent says so at the start of each conversation. The figures the agent gives come from the business's spreadsheet; even so, it can make mistakes when interpreting what it is told.
Cookies
The web panel uses only the strictly necessary cookie to keep you signed in. We do not use advertising, analytics or tracking cookies.
Your rights
You can request access to, correction or deletion of your data, or object to its processing, by writing to nexa.iaa@gmail.com. We will reply within 30 days at most.
Deleting your account and your data
From the app: under "More", "Delete my account". Once you confirm, your access is cut off immediately and all your sessions are closed, on all your devices. Your data is erased after 30 days.
By email: write to nexa.iaa@gmail.com from the address you sign in with, stating the business you belong to. We will reply within 30 days at most.
Deleting your account erases your access, your profile, your app entries, your notifications and your preferences. The audit log and the usage log are kept, but are no longer associated with you. What has already been written to the business's spreadsheet belongs to the client business, and deleting your account does not delete the business.
If you are the only owner of your business on NEXA, your access is cut off all the same, and we will contact you to settle what happens to the business before erasing your data.
What is stored on your phone is deleted when you sign out. In the demo, "Leave the demo" deletes the trial session right away.
Changes
We may update this policy. The date of the last update appears at the top.