Privacy Policy
Last updated: July 1, 2026
This Privacy Policy explains how Nex-Nex, operated by Liviu Stoica (“we”, “us”, or “our”), collects, uses, stores, and shares your personal data when you use the Nex-Nex platform at nex-nex.com and its related services (web dashboard, Telegram Bot, API).
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR, EU 2016/679).
1. Data Controller
The data controller responsible for your personal data is:
Liviu Stoica
Operating as Nex-Nex
Romania
Email: [email protected]
2. Data We Collect
2.1 Account Information
When you register, we collect: name, email address, and profile picture (via Google OAuth or email/password). If you sign in with Google, we receive the information your Google account shares according to your Google privacy settings.
2.2 Organization and Brand Data
Information you provide when creating an organization or brand: organization name, brand name, brand description, tone settings, target languages, and brand kit assets (logo, color palette, font preferences, identity documents).
2.3 Social Account Connections
When you connect a social media account (Facebook, Instagram, LinkedIn, X/Twitter, Discord, etc.), we store OAuth access tokens and refresh tokens, the platform account ID, and display name. These credentials are stored encrypted and used solely to publish content on your behalf.
2.4 Content You Create
Posts, captions, images, and other content you create or upload through the Service, as well as the AI-generated outputs produced for your account.
2.5 Billing Information
Payment processing is handled entirely by LemonSqueezy (our Merchant of Record). We do not store or have access to your credit card numbers. We receive transaction identifiers, subscription status, and billing email from LemonSqueezy.
2.6 Usage Data
We collect data about how you use the Service: pages visited, features used, credit consumption, publish times, error events, and general interaction logs. This data is used to improve the Service and for analytics.
2.7 Telegram Bot Data
If you use the Nex-Nex Telegram Bot, we collect your Telegram user ID and the messages you send to the bot. Telegram user IDs are linked to your Nex-Nex account via a secure pairing token. We do not store the full conversation history beyond what is necessary for session context and audit logs.
2.8 Technical Data
IP addresses, browser type, operating system, and session identifiers collected automatically for security, fraud prevention, and debugging purposes.
3. How We Use Your Data
- Providing the Service: generating content, scheduling and publishing posts to your connected social accounts, managing your campaigns and calendar.
- Personalization: storing your brand voice, RAG context, and preferences to improve AI output quality for your specific account.
- Billing and account management: processing payments, sending invoices, managing subscriptions and credit balances.
- Communication: sending transactional emails (account confirmation, publish notifications, billing receipts) and important service updates.
- Security and fraud prevention: detecting abuse, protecting against unauthorized access, enforcing the anti-abuse rules described in the Terms of Service.
- Analytics and improvement: understanding how users interact with the Service to fix bugs and develop new features.
- Legal compliance: meeting our obligations under applicable laws, including responding to lawful requests from public authorities.
4. Legal Basis for Processing (GDPR)
We process your personal data on the following legal grounds:
- Contract performance (Art. 6(1)(b) GDPR): processing necessary to provide the Service you signed up for (account management, content generation, publishing, billing).
- Legitimate interests (Art. 6(1)(f) GDPR): security, fraud prevention, abuse detection, product analytics, and improving the Service.
- Consent (Art. 6(1)(a) GDPR): marketing communications, where we rely on your explicit consent. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c) GDPR): where required by law (e.g., tax records, law enforcement requests).
5. Third-Party Services We Use
We rely on trusted third-party providers to operate the Service. Each processor handles your data only as instructed by us and under appropriate data protection agreements:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting (servers, databases) | EU (Germany) |
| Cloudflare, Inc. | CDN, DDoS protection, DNS, SSL | USA (SCCs) |
| LemonSqueezy | Payment processing, subscriptions, invoicing (MoR) | USA (SCCs) |
| OpenAI, Inc. | AI text generation (GPT-4o-mini) | USA (SCCs) |
| Fal.ai | AI image generation (FLUX) | USA (SCCs) |
| Google LLC (Gemini) | AI image generation (Gemini) | USA (SCCs) |
| Cloudflare R2 | Media storage (campaign images, brand assets) | EU |
| Resend | Transactional email delivery | USA (SCCs) |
| Telegram Messenger Inc. | Bot interface (messages and commands) | UAE / Dubai |
SCCs = Standard Contractual Clauses (EU-approved transfer mechanism for data transfers outside the EEA).
AI prompt data (your content and brand context) sent to OpenAI, Fal.ai, and Gemini is processed under their respective API data processing agreements. We have opted out of AI training where such options are available. Prompts are not used to train shared models.
6. Data Retention
- Account data: retained for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where retention is required by law (e.g., financial records: 5 years).
- Published content and campaign data: retained for the duration of your subscription plus 90 days after account deletion, to allow for any disputes or data export requests.
- Media files (Cloudflare R2): campaign media is automatically moved to infrequent-access storage after 6 months and deleted after 24 months or upon account deletion.
- Audit logs and security logs: retained for 12 months.
- Billing records: retained for 5 years as required by Romanian accounting law.
7. Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate data.
- Right to erasure: request deletion of your data (“right to be forgotten”), subject to legal retention obligations.
- Right to restriction: request that we limit how we use your data while a dispute is resolved.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at dataprotection.ro.
8. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include:
- TLS encryption for all data in transit (HTTPS);
- Encryption of OAuth tokens at rest;
- Multi-tenant isolation — each organization’s data is logically separated at the database level using organization IDs enforced on every query;
- Restricted access to production systems;
- Regular security reviews.
Despite our efforts, no system is 100% secure. If you believe your data has been compromised, contact us immediately at [email protected].
9. Cookies
The Service uses the following types of cookies and similar technologies:
- Essential cookies: required for authentication sessions and basic functionality. Cannot be disabled.
- Preference cookies: remember your theme (light/dark), language, and other UI preferences.
- Analytics cookies: help us understand how users navigate the platform. These are first-party analytics only — we do not use Google Analytics or other third-party tracking scripts on the authenticated dashboard.
The marketing site (nex-nex.com home page and public pages) may use minimal analytics to measure page visits. We do not use advertising cookies or sell your data to advertisers.
10. Children
The Service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it promptly.
11. International Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States. Where such transfers occur, we ensure appropriate safeguards are in place — primarily the European Commission’s Standard Contractual Clauses (SCCs) or adequacy decisions. See Section 5 for the specific providers and their locations.
12. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or an in-app notice at least 14 days before they take effect. The date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact
For any privacy-related questions, requests, or complaints, contact our privacy team at:
We aim to respond to all requests within 30 days. For complex requests, we may extend this period by a further 60 days and will notify you accordingly.
