NexGate
Legal

Privacy Policy

How NexGate collects, uses, and protects your data.

Quick summary

NexGate does not store the content of your API requests or responses. We collect only what is necessary to operate the service — usage metadata, billing information, and account data.

Effective date: May 21, 2026 · Last updated: May 21, 2026

NexGate ("we", "us", or "our") is operated by NexGate. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use nexgate.app and the NexGate API (collectively, the "Service"). By using the Service, you agree to the terms of this policy.


1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Email address (via Clerk authentication)
  • Name (if provided)
  • OAuth provider identifiers (e.g. Google ID), if you sign in with a third-party provider

We use Clerk for authentication. Clerk's own privacy policy governs how Clerk stores your credentials. We receive only the user profile data Clerk shares with us.

1.2 API Usage Metadata

For each API request you make, we log:

FieldPurpose
TimestampUsage history and billing
Model IDRouting and cost calculation
Token counts (prompt + completion)Credit deduction
Latency (ms)Performance monitoring
HTTP status codeError tracking
API key ID (not the key itself)Attribution

We do not store prompts or completions

The content of your messages — prompts, completions, tool calls, images — is never written to our database. It flows through our servers only for the duration of the request.

1.3 Billing Information

When you purchase credits, payments are processed by DodoPayments. We do not receive or store your card number or payment credentials. We receive:

  • Payment confirmation and amount
  • Transaction ID (for idempotency)
  • Country of payment (for tax compliance)

1.4 Technical Data

We automatically collect:

  • IP address (used for rate-limit enforcement; not stored long-term)
  • User-agent string
  • Referrer URL

1.5 Cookies

We use strictly-necessary session cookies set by Clerk for authentication. We do not use tracking or advertising cookies.


2. How We Use Your Information

We use the information we collect to:

  • Provide the Service — route API requests, deduct credits, and return responses
  • Billing — process payments, apply credits, and generate transaction records
  • Security — detect abuse, enforce spend limits, and prevent unauthorized access
  • Communications — send transactional emails (e.g. low-balance alerts) if you opt in
  • Improvements — analyze aggregate, anonymized usage trends to improve the platform

We do not use your data to:

  • Train AI models
  • Sell or rent data to third parties
  • Serve advertising

3. Data Sharing

We share data only in these limited circumstances:


4. Data Retention

Data typeRetention period
Account informationUntil account deletion
API usage logs12 months rolling
Transaction records7 years (tax/accounting)
IP addresses30 days

You may request deletion of your account and associated data at any time (see Section 6).


5. Security

We implement industry-standard safeguards:

  • All data in transit is encrypted with TLS 1.2+
  • API keys are stored as bcrypt hashes — we cannot recover your key if lost
  • Database access is restricted to the application layer; no direct public access
  • Clerk handles password storage; we never see plaintext passwords

No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we take reasonable measures to protect your data.


6. Your Rights

Depending on your location, you may have rights to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your account and personal data
  • Portability — receive your data in a machine-readable format
  • Object — object to certain processing activities

To exercise any of these rights, email privacy@nexgate.app. We will respond within 30 days.


7. Children's Privacy

The Service is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.


8. International Transfers

NexGate's infrastructure is hosted primarily in the United States via Vercel. If you access the Service from outside the US, your data may be transferred to and processed in the US, which may have different data protection laws than your jurisdiction.


9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify registered users by email at least 14 days in advance.


10. Contact

For privacy-related questions or requests:

On this page