Legal
Privacy Policy
Effective March 22, 2026
Overview
NexusBlue LLC ("NexusBlue," "we," "our," or "us") operates the website nexusblue.io and the NexusBlue platform (collectively, the "Services"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you visit our website, create an account, or use our Services.
By using our Services, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use our Services.
Information We Collect
Information you provide directly:
- Account information: name, email address, company name, phone number, and password when you create an account or complete your profile.
- Contact form submissions: name, email, company, phone number, and message content when you submit a contact or scope request.
- Payment information: billing details processed securely by Stripe. We do not store credit card numbers on our servers.
- Communications: emails, chat messages, and other communications you send through our platform, including interactions with our AI assistant ("Blue").
- Business data: information you upload or input into platform modules, including documents, contacts, meeting notes, and other business records.
Information collected automatically:
- Usage data: pages visited, features used, time spent, clicks, and navigation patterns.
- Device information: browser type, operating system, screen resolution, and device identifiers.
- Log data: IP address, access times, referring URLs, and server logs.
- Analytics: we use Google Analytics (GA4) and Google Tag Manager to understand how visitors use our site.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Services.
- Process transactions and send related information, including confirmations and invoices.
- Send administrative messages, security alerts, and support communications.
- Respond to your inquiries and provide customer support.
- Power AI features, including our chat assistant, content generation tools, and business intelligence features. Your inputs may be sent to third-party AI providers (Anthropic, OpenAI) for processing. These providers do not train their models on your data.
- Generate reports, health scores, and recommendations within your account.
- Monitor and analyze usage trends to improve our platform.
- Detect, prevent, and address fraud, abuse, and technical issues.
- Comply with legal obligations.
AI and Data Processing
Our platform uses artificial intelligence to provide features such as chat assistance, content generation, document analysis, and business recommendations. When you use these features:
- Your inputs are sent to AI model providers (Anthropic and OpenAI) for processing. These providers operate under data processing agreements that prohibit training on customer data.
- AI interactions may be logged for quality assurance, debugging, and service improvement through our self-hosted observability system.
- We implement PII detection safeguards to minimize the exposure of sensitive personal information in AI processing.
- AI-generated content is provided as-is and should not be treated as professional legal, financial, medical, or regulatory advice.
Information Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
- Service providers: we share information with third-party vendors who help us operate our Services, including Supabase (database and authentication), Stripe (payment processing), SendGrid (email delivery), Vercel (hosting), Sentry (error monitoring), and Cloudflare (security). These providers are contractually obligated to protect your information.
- AI providers: as described above, inputs to AI features are processed by Anthropic and OpenAI under data processing agreements.
- Business transfers: if NexusBlue is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction.
- Legal requirements: we may disclose information if required by law, regulation, legal process, or governmental request.
- Protection: we may disclose information to protect the rights, property, or safety of NexusBlue, our users, or the public.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide our Services. If you request account deletion, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal, tax, or compliance purposes. Usage logs and analytics data are retained in aggregated, anonymized form.
Data Security
We implement industry-standard security measures to protect your information, including encryption in transit (TLS/HTTPS), encrypted storage for sensitive credentials, row-level security policies on our database, and regular security monitoring. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: request a copy of the personal information we hold about you.
- Correction: request that we correct inaccurate or incomplete information.
- Deletion: request that we delete your personal information, subject to legal retention requirements.
- Data export: request a machine-readable copy of your data.
- Opt-out: unsubscribe from marketing communications at any time using the link in any email.
To exercise any of these rights, contact us at contact@nexusblue.io. We will respond within 30 days.
Cookies and Tracking
We use the following cookies and tracking technologies:
- Essential cookies: required for authentication and security (Supabase session tokens).
- Analytics cookies: Google Analytics (GA4) collects anonymous usage data to help us improve our site. You can opt out using the Google Analytics Opt-out Browser Add-on.
- Bot protection: Cloudflare Turnstile verifies that form submissions come from real users, not bots. This does not track you across sites.
We do not use cookies for advertising or cross-site tracking.
Third-Party Links
Our Services may contain links to third-party websites and services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
Children's Privacy
Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Effective" date. Your continued use of our Services after changes are posted constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy or our data practices, contact us at: