Privacy Policy
Last updated: May 2026
We have written this policy in plain English. Our goal is to be honest and transparent about what we do — and equally, what we don't do — with your data.
1. Who we are
Nexus (nexusroom.app) is a private video conferencing platform for organisations, groups, and clubs. It is operated as a sole trader business licensed in the United Arab Emirates.
If you have any questions about this policy or want to make a data request, contact us at [email protected] and we will respond within 5 business days.
2. The short version
- Guests who join calls are anonymous. We only know the display name they type — we make no attempt to identify them beyond that.
- We do not sell your data, share it with advertisers, or use it to target you with anything.
- Your calls are not recorded or monitored by Nexus.
- We store the minimum data necessary to run the service.
- You can ask us to delete your data at any time.
- Privacy is not a shield for illegal activity. Where we receive a valid legal request from a competent authority, we cooperate.
3. What data we collect and why
If you are a guest joining a call
Guests do not create accounts. To join a room you enter a display name — that is the only personal data we ask for. We use it to show your name to other participants during the call.
We also record a basic audit log entry when you join and leave a room. This contains your display name, the room you joined, and the times you connected and disconnected. This is used by the room administrator to manage attendance.
We do not collect your email address, phone number, or any other identifying information as a guest. Your display name could be anything — a real name, a nickname, or initials. We make no attempt to link it to a real identity.
If you are a host or administrator
Hosts and administrators sign in using Google Sign-In (OAuth). We receive your Google account email address and use it to verify your identity and grant access to your assigned rooms. We do not receive your Google password, and we do not access any other data from your Google account.
- Your email address is stored in our database and used to manage your access.
- Your room activity — calls started, guests admitted, actions taken — is recorded in an audit log.
- Chat messages you send in rooms with full history enabled are stored and associated with your display name.
If you are a paying customer
When you purchase a Nexus subscription we collect:
- Your name and organisation name
- Your email address — used for your account login and to send receipts, onboarding emails, and service notifications
- Payment is processed entirely by Stripe — we never see or store your card details
Stripe stores your billing information on our behalf. You can read Stripe's privacy policy at stripe.com/privacy.
If you visit nexusroom.app
We may use Google Analytics on our marketing website to understand how visitors find and use the site. Google Analytics collects anonymised data about page visits, referral sources, and general device information. It does not identify you personally.
We use a cookie consent banner — Google Analytics only runs if you accept analytics cookies. You can change your preference at any time by clearing your cookies or using your browser's privacy settings.
4. What we don't do
- We do not sell your data to anyone.
- We do not share your data with advertisers or marketing platforms.
- We do not use your data to build advertising profiles.
- We do not record your video or audio calls. Recordings are a feature available to hosts — they go directly to the host's device and Nexus never receives or stores them.
- We do not use your call content to train AI models or for any other secondary purpose.
- We do not transfer your personal data to third parties except as described in Section 5 below.
5. Lawful disclosure
Nexus is private by design — calls are not recorded or monitored, and we do not share your data with advertisers or for commercial purposes. Privacy, however, is not a shield for unlawful activity.
Where we receive a valid legal request from a competent authority — for example a court order, subpoena, search warrant, or equivalent binding instrument issued under the laws of a relevant jurisdiction — we will comply with our legal obligations and provide the data we hold that is responsive to the request.
The data we are able to produce is limited to what we actually hold, as described in Section 3. Because we do not record video or audio, call content cannot be produced. The information available is generally limited to account details, audit logs of who joined which room and when, IP addresses captured at join time, and chat messages from rooms with full chat history enabled.
Where we are lawfully permitted to do so, we will notify the affected customer of the request before responding. Where the request prohibits notification — for example under a confidentiality order — we will comply with that legal restriction.
We will not disclose customer data in response to informal or undocumented requests. Any request must be a properly issued legal instrument from a recognised authority.
6. Third-party services
Nexus uses a small number of third-party services to operate:
| Provider | Purpose | What they receive |
|---|---|---|
| LiveKit | Video and audio routing | Encrypted media streams. Call content is encrypted in transit — LiveKit cannot read it. LiveKit is GDPR-compliant and a Data Processing Agreement is in place. |
| Stripe | Payment processing | Your billing information when you purchase a subscription. Nexus never sees your card details. |
| Google (OAuth) | Host and admin login | Your Google account email address when you sign in. We do not receive your password or access other Google account data. |
| Google Analytics | Marketing site analytics | Anonymised visit data on nexusroom.app only. Only active if you accept analytics cookies. |
| Hetzner | Server hosting | All Nexus server infrastructure runs on Hetzner data centres in Nuremberg, Germany. Hetzner is GDPR-compliant. |
7. How long we keep your data
Room data, audit logs, chat history, and host account data are retained for as long as your subscription is active.
When a subscription is cancelled, your room data is retained for 30 days. This allows you to reactivate without losing anything. After 30 days, all data associated with that room is permanently deleted.
If you request erasure of your data at any time, we will delete it within 30 days.
Billing records are retained by Stripe in accordance with their legal obligations and privacy policy.
8. Your rights
If you are in the UK, European Economic Area, or another jurisdiction with similar privacy laws, you have the following rights:
| Right | What it means |
|---|---|
| Access | You can ask us what personal data we hold about you and receive a copy of it. |
| Rectification | You can ask us to correct inaccurate data we hold about you. |
| Erasure | You can ask us to delete your personal data. We will do so within 30 days except where we are legally required to retain it. |
| Restriction | You can ask us to stop processing your data in certain circumstances. |
| Portability | You can ask for your data in a structured, machine-readable format. |
| Objection | You can object to us processing your data where we rely on legitimate interests as our legal basis. |
To exercise any of these rights, email us at [email protected]. We will respond within 30 days. There is no charge for making a request.
9. Our legal basis for processing
- Contract performance — we process host and customer data in order to provide the service you have paid for.
- Legitimate interests — we process audit log data to help administrators manage their rooms and maintain security. We have assessed that this does not override your privacy rights.
- Consent — we use Google Analytics on our marketing site only where you have given consent via the cookie banner.
- Legal obligation — we may process and disclose data where required by applicable law or to respond to a valid legal request from a competent authority.
10. Cookies
- Session cookie — keeps you logged in during your visit. This is essential for the service to work and does not require consent.
- Google Analytics cookies — only set if you accept analytics cookies via the consent banner on nexusroom.app. Used to understand how visitors use the marketing site. Not used on the call platform.
You can manage or delete cookies at any time using your browser settings.
11. Children
Nexus is not intended for use by children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it promptly.
12. Changes to this policy
We may update this policy from time to time. When we do, we will update the date at the top of this page. If we make significant changes, we will notify paying customers by email. Continued use of Nexus after changes take effect means you accept the updated policy.
13. Contact us
For any privacy-related questions, data requests, or complaints:
Email: [email protected]
We aim to respond within 5 business days.
If you are in the UK or EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EU it is your national supervisory authority.