← Back to NEXUS
legal draft

Privacy Policy

Version 2026-09-11-draft-1 · Draft — not yet in effect

Draft — requires UAE legal review. Draft requiring UAE legal review. This document has not been reviewed by a lawyer qualified in the United Arab Emirates, is not legal advice, and makes no claim of compliance with any law or regulation. Every item shown in a red box below is a launch-blocking placeholder that must be replaced before launch.
Legal operator
[LEGAL BUSINESS OR LICENCE HOLDER NAME — REQUIRED BEFORE LAUNCH]
Dubai, United Arab Emirates

1. Who controls your data

[LEGAL BUSINESS OR LICENCE HOLDER NAME — REQUIRED BEFORE LAUNCH], Dubai, United Arab Emirates, decides how your data is used in NEXUS. Privacy questions: [SUPPORT EMAIL — REQUIRED BEFORE LAUNCH].

2. What we collect and why

  • Account details — email address, display name, avatar, and (if you sign in with Google) the basic profile Google returns. Needed to create and secure your account.
  • Age band and consent record — whether you are 11 to 17 or 18 or over, the time you accepted the Terms and this Privacy Policy, which versions you accepted, and where you accepted them (sign-up, an in-app prompt, or checkout). Used to apply the age policy and to prove what you agreed to. We do not store an exact date of birth.
  • Onboarding answers — interests, skill level and goals. Used to generate project ideas that fit you.
  • Project and build data — projects, layers, steps, checkpoints, notes and completion state. This is the product.
  • Memory and activity events — a record of actions you take in Forge and Pulse (project started, step completed, deployment, reflections). Used to build your timeline, weekly digests, Builder DNA and to give the Wren companion context.
  • AI conversations — messages you send to Wren, the mentor and other AI features, plus the replies. Used to answer you and to keep conversation history.
  • Usage counts — number of AI messages and projects per month. Used to apply plan limits.
  • Gallery content — posts, images, comments, likes and follows. Public gallery content is visible to everyone.
  • Billing data — subscription status, plan, renewal date, a payment-provider customer ID, and your checkout confirmations (policy versions accepted and the cardholder confirmation). We never see or store your full card number.
  • Technical data — sign-in timestamps and error reports needed to keep the service running and secure.

3. Age policy and younger users

  • NEXUS is designed for high-school students. Anyone under 11 cannot create or use an account, and we do not knowingly collect data from anyone under 11. If we learn we have, we close the account and delete its data.
  • Every account has an age band on file. Accounts created before this policy are asked for one the next time they sign in.
  • We ask builders under 18 not to put their full name, school, address, phone number or photos of other people into projects, reflections or public gallery posts.
  • A parent, guardian or school can email [SUPPORT EMAIL — REQUIRED BEFORE LAUNCH] to review or delete a younger builder's account, or to raise a purchase they did not authorise.

4. Inferred information

NEXUS derives patterns about how you build (for example consistency or completion habits) from your activity. These are inferences, not facts, they are shown to you, and you can tell Wren when one is wrong — the correction is stored and the inference stops being used.

5. Service providers

  • Database, authentication, storage and server functions — provided through Lovable Cloud. Stores nearly all of the data listed above.
  • Lovable — hosting for the app and the AI gateway that routes prompts to the underlying AI models. Your prompts and the surrounding context pass through it.
  • Stripe — payments and subscription billing. Stripe collects and handles your card details directly under its own privacy policy; we receive only the status and identifiers we need.

These providers process data on our instructions and may store it outside the United Arab Emirates. We do not sell your data or use it for advertising.

6. Cookies and analytics

NEXUS stores your sign-in session in your browser so you stay logged in — this is strictly necessary for the app to work. Stripe sets its own cookies inside the checkout and billing portal, including fraud prevention. We do not run advertising cookies or third-party marketing trackers. The hosting platform may keep basic aggregate request and error logs. If we ever add a product analytics tool, this section will be updated first and the version number will change.

7. Keeping and deleting data

  • Account, project and memory data is kept while your account exists.
  • Deleting your account removes your profile, projects, memory events, reflections and gallery posts. Ask at [SUPPORT EMAIL — REQUIRED BEFORE LAUNCH] if you want confirmation in writing.
  • Backups and provider logs may retain copies for a short period after deletion before they roll off.
  • Billing, payment and consent records are kept for as long as tax, accounting and dispute rules require, even after account deletion.

8. Your choices

You can edit your profile, delete projects and posts, request a copy of your data (including your consent record), or request full deletion by emailing [SUPPORT EMAIL — REQUIRED BEFORE LAUNCH]. Depending on where you live you may have further rights; we will honour requests we are legally required to honour.

9. Security

Data is protected by per-user access rules in the database, and private data is only reachable with your own signed-in session. No system is perfectly secure; tell us at [SUPPORT EMAIL — REQUIRED BEFORE LAUNCH] if you spot a problem.

10. Changes

When this policy changes we publish a new version number and ask you to accept it the next time you use NEXUS. We keep a record of which version you accepted and when.

Operated by [LEGAL BUSINESS OR LICENCE HOLDER NAME — REQUIRED BEFORE LAUNCH] · Dubai, United Arab Emirates

Effective date: Draft — not yet in effect · Version 2026-09-11-draft-1