Stored to operate the service
Operational records stay intentionally narrow.
NexFade stores encrypted payloads, encrypted metadata envelopes, workspace ownership, expiration details, billing state, and lifecycle records needed to operate the service.
Intentionally not stored in readable form
The service is designed to stay out of the readable content path.
Readable notes, file contents, and the decryption fragment are not stored as part of normal service operation. That boundary is part of the product design itself.
Integration identity and hosts
Marketplace sign-in and host display add specific data flows.
NexFade uses Auth0 to process an OAuth subject, verified email, profile data, scopes, and token metadata for marketplace sign-in. ChatGPT, Codex, or Claude displays the NexFade component, so information entered into that component is also subject to the host platform's privacy terms. NexFade does not request host chat history, memory, unrelated attachments, or raw host conversation identifiers.
Recipient verification
Recipient email is used only when the sender enables verification.
When recipient-email verification is enabled, NexFade processes the recipient address to deliver and verify the access code and to enforce that link's assurance setting. It is not placed in model-visible tool results or analytics.
Providers and subprocessors
A focused vendor set supports the product.
Providers such as Auth0, Stripe, PocketBase, Cloudflare, Vercel, Upstash, Fastmail, and Sentry may process the limited identity, payment, infrastructure, mail, rate-limit, and error data needed to operate NexFade. Support and billing questions are handled through support@nexfade.com. Security reports can be sent to security@nexfade.com.
Operational logging
Logs and abuse controls stay measured.
Application logs are kept limited and redacted. Abuse controls lean on validation, rate limiting, and hashed request signals rather than broad raw activity storage.
Retention and deletion
Lifecycle records and account requests follow defined operational needs.
Encrypted objects expire, burn, or are revoked according to their configured lifecycle, while narrow account, billing, security, and audit records may be retained as needed for service operation, fraud prevention, legal obligations, and dispute handling. Request account access, correction, deletion, or identity-mapping revocation through support@nexfade.com. NexFade verifies the requester and explains any record it must retain.
United States privacy rights
US residents can exercise applicable state privacy rights.
Depending on your state, you may have rights to access, correct, delete, or obtain a copy of personal data, or to appeal a denied request. Contact support@nexfade.com. NexFade does not sell personal data or use marketplace integrations for cross-context behavioral advertising.