Legal

Privacy Policy

Effective August 5, 2026
1. Scope
This Privacy Policy describes how PixelPad, the operator of NexusHud ("NexusHud", "we", "us"), collects, uses, discloses, and retains personal information in connection with the websites, applications, application programming interfaces, and related services offered at nexushud.org (the "Services"). For the purposes of applicable privacy law, PixelPad is the controller of the personal information described in this Policy.
Capitalized terms not defined here have the meanings given in the Terms of Service.
2. Personal Information We Collect
Information you provide.
  • Account information, including email address, password hash, and display name. Where sign-in is performed through Google, we receive the email address and basic profile associated with the Google account.
  • Customer Content, including workspace configurations, prompts and conversation history, files and reference materials, integration source code, stored memory, and task records.
  • Billing information. Payment is processed by Stripe. We receive billing status, plan, and the card brand and last four digits. We do not receive or store full card numbers.
  • Communications you send to us, including support requests.
Information generated through use of the Services.
  • Usage and metering records, including token counts, model selection, per-run cost, and credit balance.
  • Operational logs, including request identifiers, timestamps, and error output. Logs may incidentally contain fragments of submitted content where an error message includes them.
  • Security records, including IP address, browser user agent, and authentication events.
3. How We Use Personal Information
  • To provide, operate, and support the Services. Legal basis: performance of contract.
  • To transmit requests to the third-party services you connect, within the scopes you authorize. Legal basis: consent.
  • To meter usage, process payment, and maintain accurate billing records. Legal basis: performance of contract and legal obligation.
  • To secure the Services, diagnose faults, and prevent abuse. Legal basis: legitimate interests.
  • To send transactional communications, including receipts and account notices. Legal basis: performance of contract.
We do not sell personal information, and we do not use personal information for cross-context behavioral advertising.
4. Artificial Intelligence Processing
The Services generate Output by transmitting Customer Content, including prompts, conversation history, stored memory, reference files, and integration tool definitions, to third-party Model Providers. Every model offered in the Services is operated by a Model Provider, and the model selected in the applicable workspace determines which Model Provider receives this data.
Model Providers operate in the United States and in other countries. Selecting a model results in the transfer of the data described above to the Model Provider that operates it and to the country in which that provider processes requests, which may be a country other than your own. The current Model Providers, the models each one operates, and the country in which each processes requests are available on request.
We do not use Customer Content to train artificial intelligence models. Our agreements with the Model Providers do not permit the use of Customer Content for model training.
5. Connected Third-Party Services
Where you connect a third-party account to the Services, we store the access and refresh tokens issued by that provider, limited to the scopes presented on the provider's consent screen. Tokens are used solely to perform the API requests the Services carry out on your behalf, including during scheduled operation you configure, and are furnished to an integration only at execution time.
Disconnecting an account deletes the stored token immediately. Deletion of the stored token does not revoke the underlying grant at the provider, which may be revoked in the provider's own account settings. Data transmitted by an integration to an external service is thereafter governed by that service's own terms and privacy policy.
6. Disclosure of Personal Information
We disclose personal information to the following categories of recipients, in each case limited to what is necessary for the stated purpose:
Recipient Purpose
Model ProvidersGeneration of Output for the model you select
Amazon Web ServicesHosting, storage, integration runtimes, scheduling, logging, and email delivery
StripePayment processing
Connected third-party servicesExecution of API requests you authorize
We may also disclose personal information where required by law, to enforce our agreements, to protect the rights, property, or safety of NexusHud, our users, or the public, and in connection with a merger, acquisition, or sale of assets, in which case affected users will be notified before their personal information becomes subject to a different privacy policy.
7. International Data Transfers
Our application, database, object storage, and logs are hosted in the United States. Integration runtimes are hosted in Canada. Email is delivered from the United States. Artificial intelligence processing occurs in the country in which the Model Provider of the selected model processes requests, which may be outside the United States. Where personal information of individuals in the United Kingdom, the European Economic Area, or Switzerland is transferred outside those regions, we rely on standard contractual clauses with the relevant providers.
8. Retention
  • Customer Content is retained until deleted by you or until account closure.
  • Download links issued for generated files expire after seven days.
  • Stored third-party tokens are deleted upon disconnection of the account or deletion of the related integration.
  • Integration code and its deployed runtime are deleted with the integration.
  • Usage and billing records are retained after account closure for the periods required by applicable tax and accounting law.
  • Operational logs are retained for the period necessary for fault diagnosis and security.
9. Security
We maintain administrative and technical safeguards appropriate to the nature of the data processed, including encryption in transit, private storage accessible only through short-lived signed URLs scoped to the requesting account, per-session isolation of integration runtimes, and access to production systems restricted to personnel who require it. In the event of a breach affecting personal data, we will notify affected users and any required regulator without undue delay.
10. Your Rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal information, request restriction of processing, object to processing based on legitimate interests, and request a portable copy of your data. We will not discriminate against you for exercising these rights.
Certain rights may be exercised directly within the Services, including deletion of conversations, workspaces, integrations, stored memory, and connected accounts. Account deletion requests may be submitted to the contact address below.
Residents of the European Economic Area and the United Kingdom may lodge a complaint with their supervisory authority. Canadian users may direct complaints to the Office of the Privacy Commissioner of Canada. California residents: we do not sell or share personal information as those terms are defined in the CCPA.
11. Cookies
The Services set only the cookies necessary for authentication and form security. We do not use advertising cookies or third-party tracking pixels. Because the Services do not track users across third-party websites, browser Do Not Track signals do not alter the Services' behavior.
12. Third-Party Websites and Embedded Deployments
Content submitted to the Services through a deployment embedded on a third-party website is processed in accordance with this Policy. The operator of the third-party website is independently responsible for its own site and disclosures. Where Output contains links to external websites, those websites are governed by their own policies. Content submitted to a workspace made available to other users is accessible to the account holder that operates that workspace.
13. Children
The Services are not directed to individuals under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will delete it.
14. Changes to This Policy
We may revise this Policy from time to time. The effective date above will be updated, and material changes will be notified by email or within the Services before taking effect.
15. Contact
Requests, questions, or complaints regarding this Policy may be directed to hello@pixelpad.io. We aim to respond within 30 days.