Privacy Policy
Last updated: April 2026
NEXORA is built private by default. This policy describes exactly what the product stores, and it matches the behavior of the code — not the other way around.
1. What we store
Account credentials (hashed with scrypt), sessions (random tokens whose hashes are stored), audits and their analysis data, reports you generate, competitor lists you create, contact-message submissions, and usage counters. We do not embed third-party analytics or ad trackers in the product.
2. What we don’t store
We never store plaintext passwords. We do not log full request bodies from analysis endpoints beyond what your report already contains, and we do not sell or share personal data.
3. How data is used
Audit data is used to show you your result, nothing more. If you connect an AI provider (OpenAI-compatible), only the analysis payload you trigger is sent to that provider — and only when you explicitly enable it for a run.
4. Sharing
Reports are private by default. Public share links exist only when you create them and are identified by an unguessable slug. Deleting a report removes the share.
5. Email
When you submit the contact form, we store the message and may reply to the address you provide. If outbound email is not configured on the deployment, messages are retained in the database and no external service receives them.
6. Retention & deletion
You can delete your audits and reports from the account at any time. Contact us to delete your account and its data; removal is honored in full.
7. Cookies
One session cookie (`nexora_session`) is used for signed-in state; it is HttpOnly and SameSite=Lax. The theme preference is stored locally in your browser, not in a cookie.