Privacy Policy

Last updated: April 2026

NEXORA is built private by default. This policy describes exactly what the product stores, and it matches the behavior of the code — not the other way around.

1. What we store

Account credentials (hashed with scrypt), sessions (random tokens whose hashes are stored), audits and their analysis data, reports you generate, competitor lists you create, contact-message submissions, and usage counters. We do not embed third-party analytics or ad trackers in the product.

2. What we don’t store

We never store plaintext passwords. We do not log full request bodies from analysis endpoints beyond what your report already contains, and we do not sell or share personal data.

3. How data is used

Audit data is used to show you your result, nothing more. If you connect an AI provider (OpenAI-compatible), only the analysis payload you trigger is sent to that provider — and only when you explicitly enable it for a run.

4. Sharing

Reports are private by default. Public share links exist only when you create them and are identified by an unguessable slug. Deleting a report removes the share.

5. Email

When you submit the contact form, we store the message and may reply to the address you provide. If outbound email is not configured on the deployment, messages are retained in the database and no external service receives them.

6. Retention & deletion

You can delete your audits and reports from the account at any time. Contact us to delete your account and its data; removal is honored in full.

7. Cookies

One session cookie (`nexora_session`) is used for signed-in state; it is HttpOnly and SameSite=Lax. The theme preference is stored locally in your browser, not in a cookie.