Privacy Policy
This page describes what we actually do with your data — not what a lawyer wishes we did. It's short because our data practices are short. Effective date: August 30, 2026.
Who we are
Nexus AgentWorks operates managed business AI agents — voice support, email operations, scheduling, lead qualification, invoice follow-up, and document collection — on behalf of small businesses. Questions about anything on this page go to hello@nexusagentworks.com and a human answers.
What we collect
We collect as little as the service needs to function:
- Sign-in profile. When you log in with Google or GitHub, we receive your email, username, display name, and your provider account ID. We use these to identify your account. We never post anywhere or touch your Google/GitHub data beyond the login profile.
- Your knowledge-base documents. Files you upload so your agents can answer questions from them. These are stored per-tenant in isolated Cloudflare Durable Objects and KV storage. Current stage capacity is 100 MB per tenant.
- Agent operation logs. What each agent did, decided, and why — the same audit trail you can see, which we use to operate and debug your service.
- Usage and billing records. Metered rows (cost, AI-answer counts) in a hash-chained ledger, so your invoices can be traced to actual usage.
- Support email. If you email us, we keep the thread.
Why we use it
Three reasons, and that's the whole list:
- To run your agents. Answer your customers' questions from your knowledge base, within your tenant. (Contractual necessity — it's the service you're paying for.)
- To bill accurately. Meter usage against the pricing in your agreement. (Contractual necessity.)
- To keep the service safe. Abuse prevention and security. (Our legitimate interest — and yours.)
We do not use your data to train AI models — ours or anyone else's. Nothing from one customer's workspace is used to serve another customer.
What we don't do
- We don't sell personal data. Not to anyone, ever. There is no "partners network," no data broker arrangement, no exception.
- We don't run ad trackers. No advertising trackers, no data brokers, no cross-site profiling, and no analytics inside the product. The one third-party script on this marketing site is Cloudflare Web Analytics (static.cloudflareinsights.com), which Cloudflare Pages injects into every page: it is cookieless, sets no identifier, does not follow you across sites, and reports aggregate page views only.
- We don't contact your prospects. Our agents are structurally incapable of deciding on their own to contact a person. No outbound contact happens until a real lead exists in your pipeline — that's a hard rule in our code, not a suggestion.
- We don't mix customer data. Tenant isolation is architectural, not a policy promise: each customer's workspace is its own isolated unit. Your knowledge base, logs, and memory are not shared with, or reachable from, any other customer's agents.
AI processing and third parties
To generate answers, your customers' questions may be sent to third-party language-model providers — OpenRouter or OpenAI, or your own provider key if you bring your own model (BYOM). Your knowledge-base documents are used for retrieval-grounded answers within your tenant only. We don't send your data anywhere else, and we don't select providers that train on customer payloads.
Human oversight
Our agents escalate to your team's humans whenever they're uncertain. They don't make fully-unattended money or legal commitments. Where an agent's output reaches someone outside your team, a human sign-off sits in between.
How long we keep things
Account data, knowledge-base documents, and agent logs are kept while your account is active. Usage and billing ledger rows are kept as long as we need them for accounting and tax purposes. When you ask us to delete your data, we delete it — the only survivor is what we're legally required to keep for billing records.
Export and deletion
Self-serve, from your workspace (Billing → Your data): Download my account data gives you your sign-in profile, your tickets and notifications, and your documents as one JSON file; Download workspace data (workspace owners) gives you the knowledge base with its text, bookings, agent configurations, evolution history, usage and the member roster — the same bundle our nightly backup keeps, so what you can download is exactly what we hold. Connected-service credentials are never in an export. Delete my account on the same panel removes your profile, tickets and notifications immediately and signs you out; it asks you to type DELETE first and nothing is deleted until you do. Deletion is real deletion, not a flag.
If you'd rather not use the buttons, email hello@nexusagentworks.com from your account address and we will do it by hand.
Your rights
Wherever you live, you can ask us for access to your data, a copy of it, a correction, or deletion — the export and deletion section above is how. If you're in the EU/EEA or UK, the legal bases we rely on are listed in "Why we use it" above, and you can object or complain to your local regulator. If you're a California resident: we do not sell or share personal information as those terms are defined by the CCPA, so there's nothing to opt out of. We don't discriminate against anyone for exercising their rights.
Security
Per-tenant isolation in isolated storage, no cross-tenant data paths, and an append-only hash-chained ledger so usage records can't be quietly rewritten. If something ever goes wrong with your data, we tell you promptly and straight.
Changes to this policy
If we change what we do with your data, we'll update this page and change the effective date above. We won't sneak a new data practice in under an old policy.
Contact
Privacy questions, export requests, deletion requests: hello@nexusagentworks.com. A human answers.
Related: Trust & Operating Principles · Terms of Service