Personal data we collect
From you directly
- Account details. When you sign in, our authentication provider holds your email address, display name, and an identifier for your account.
- Workspace and team information. Your role in a workspace, and the email address of anyone you invite to join one. If our support or platform-admin staff take an action on your workspace, we keep a record of what was done and by whom, so we can explain any change if you ask.
- Content you write into your workspace. Messages you send to the architecture chat assistant, and any feedback you submit — optionally your name and email, the page you were on, your description, and a screenshot if you choose to attach one. Please check what a screenshot shows before sending it, since it captures whatever is on your screen at that moment.
- Billing details. If you subscribe to a paid plan, you enter your card details directly with our payment processor, Stripe. We never see or store your full card number — we keep a reference connecting your workspace to your Stripe customer and payment method so we can manage your subscription.
- Beta waitlist requests. If you request access, we keep the name, email, company, role, and any notes you give us, to review and respond to your request.
Automatically
- API credentials. When you create a credential to let an AI coding agent connect to your workspace, we store the credential only as a one-way cryptographic hash we cannot reverse. We separately record when it was last used, from which network address, and what client software made the request — this is security telemetry to help you and us spot unexpected use, not the credential itself.
- Site usage. Pages you visit on our site are measured with Google Analytics, which sets cookies and can see your device, browser, and IP address. See Cookies and analytics below.
From AI agents connected to your workspace
You can connect your own AI coding agent (for example, Claude Code) to your workspace using an API credential you create. That agent is your tool, running under your account with its own AI provider — we do not choose it, operate it, or see the conversations you have with it. What we do receive is whatever that agent sends to our tools on your behalf: the architecture information it writes to your workspace, and, if it or our system automatically reports a problem, identifying details about the agent itself (such as the model, provider, and client name it reports) alongside the error.
How we use personal data
- To operate your account and workspace, and let you sign in securely.
- To provide features that use AI — the architecture chat assistant and automatic data extraction — which involves sending the relevant content to an AI infrastructure provider to generate a response (see Who we share data with).
- To process payment and manage your subscription.
- To respond to support requests, feedback, and beta access requests.
- To detect and investigate misuse, security incidents, and unusual API activity.
- To understand how our site and product are used, so we can improve them.
- To meet our legal and accounting obligations.
Our legal bases for processing (UK/EU GDPR)
If you are in the UK or EEA, we rely on one of the following for each use above:
- Contract — to provide the workspace and features you sign up for.
- Legitimate interests — for security, fraud prevention, and improving the product, balanced against your rights.
- Consent — for non-essential cookies and any marketing communication, which you can withdraw at any time.
- Legal obligation — for records we must keep, such as billing and tax records.
Who we share data with
We do not sell personal data. We share it with the service providers who help us run Nexarch, each acting under contract on our instructions:
- Neon — hosts our database and provides sign-in (authentication) for your account.
- Vercel — hosts the application, and its AI Gateway routes our AI-assisted features (chat and data extraction) to an underlying model provider, currently an OpenAI model. That provider processes the content of that request under its standard API terms, which do not permit using it to train the underlying models. This is separate from any AI agent you connect to your own workspace yourself.
- Resend — delivers transactional emails, such as sign-in links and invitations.
- Stripe — processes payments for paid plans.
- Google — provides analytics for our public site (Google Analytics).
We may also disclose personal data if required by law, or to protect the rights, property, or safety of Nexarch, our users, or others.
International data transfers
Our service providers may process data outside your country, including in the United States.
To confirm before this goes live
Hosting regions for Neon and Vercel, and the transfer mechanism relied on — for example Standard Contractual Clauses — for any transfer out of the UK or EEA.
Cookies and analytics
We use a small number of cookies:
- Essential cookies — keep you signed in, remember which workspace you have open, and support our staff's access to your workspace when you ask for help. The product does not work without these.
- Analytics cookies — set by Google Analytics on our public site, to measure which pages are visited. These are not essential.
To confirm before this goes live
A cookie consent mechanism for the analytics cookies above is not yet in place. It needs to be added, or the analytics configuration changed, before this section can accurately describe a compliant setup.
How long we keep data
We keep account and workspace data for as long as your workspace is active, and for a limited period after closure to allow recovery and to meet legal obligations (for example, billing records). Feedback and support records are kept long enough to act on them and to spot recurring problems.
To confirm before this goes live
Specific retention periods per data category.
Security
We use industry-standard measures to protect personal data, including encryption in transit, hashed storage of API credentials, and access controls limiting who can view your workspace. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your privacy rights
Subject to applicable law, you can ask us to:
- Confirm what personal data we hold about you, and give you a copy of it.
- Correct inaccurate or incomplete data.
- Delete your personal data, or restrict how we use it.
- Provide your data in a portable format.
- Object to processing based on our legitimate interests.
- Withdraw consent at any time, where we rely on consent.
To exercise any of these, contact us at [privacy@nexarch.ai]. If you are in the UK or EEA and are not satisfied with our response, you can complain to your local data protection authority (in the UK, the Information Commissioner's Office).
Children
Nexarch is a business tool intended for professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We will update this page when what we collect or how we use it changes, and update the date at the top. We will tell current customers directly about material changes.
Contact us
Questions about this policy or your data can be sent to [privacy@nexarch.ai] or hello@nexarch.ai.