Privacy Policy
How NexGate collects, uses, and protects your data.
Quick summary
NexGate does not store the content of your API requests or responses. We collect only what is necessary to operate the service — usage metadata, billing information, and account data.
Effective date: May 21, 2026 · Last updated: May 21, 2026
NexGate ("we", "us", or "our") is operated by NexGate. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use nexgate.app and the NexGate API (collectively, the "Service"). By using the Service, you agree to the terms of this policy.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address (via Clerk authentication)
- Name (if provided)
- OAuth provider identifiers (e.g. Google ID), if you sign in with a third-party provider
We use Clerk for authentication. Clerk's own privacy policy governs how Clerk stores your credentials. We receive only the user profile data Clerk shares with us.
1.2 API Usage Metadata
For each API request you make, we log:
| Field | Purpose |
|---|---|
| Timestamp | Usage history and billing |
| Model ID | Routing and cost calculation |
| Token counts (prompt + completion) | Credit deduction |
| Latency (ms) | Performance monitoring |
| HTTP status code | Error tracking |
| API key ID (not the key itself) | Attribution |
We do not store prompts or completions
The content of your messages — prompts, completions, tool calls, images — is never written to our database. It flows through our servers only for the duration of the request.
1.3 Billing Information
When you purchase credits, payments are processed by DodoPayments. We do not receive or store your card number or payment credentials. We receive:
- Payment confirmation and amount
- Transaction ID (for idempotency)
- Country of payment (for tax compliance)
1.4 Technical Data
We automatically collect:
- IP address (used for rate-limit enforcement; not stored long-term)
- User-agent string
- Referrer URL
1.5 Cookies
We use strictly-necessary session cookies set by Clerk for authentication. We do not use tracking or advertising cookies.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service — route API requests, deduct credits, and return responses
- Billing — process payments, apply credits, and generate transaction records
- Security — detect abuse, enforce spend limits, and prevent unauthorized access
- Communications — send transactional emails (e.g. low-balance alerts) if you opt in
- Improvements — analyze aggregate, anonymized usage trends to improve the platform
We do not use your data to:
- Train AI models
- Sell or rent data to third parties
- Serve advertising
3. Data Sharing
We share data only in these limited circumstances:
4. Data Retention
| Data type | Retention period |
|---|---|
| Account information | Until account deletion |
| API usage logs | 12 months rolling |
| Transaction records | 7 years (tax/accounting) |
| IP addresses | 30 days |
You may request deletion of your account and associated data at any time (see Section 6).
5. Security
We implement industry-standard safeguards:
- All data in transit is encrypted with TLS 1.2+
- API keys are stored as bcrypt hashes — we cannot recover your key if lost
- Database access is restricted to the application layer; no direct public access
- Clerk handles password storage; we never see plaintext passwords
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we take reasonable measures to protect your data.
6. Your Rights
Depending on your location, you may have rights to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your account and personal data
- Portability — receive your data in a machine-readable format
- Object — object to certain processing activities
To exercise any of these rights, email privacy@nexgate.app. We will respond within 30 days.
7. Children's Privacy
The Service is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
8. International Transfers
NexGate's infrastructure is hosted primarily in the United States via Vercel. If you access the Service from outside the US, your data may be transferred to and processed in the US, which may have different data protection laws than your jurisdiction.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify registered users by email at least 14 days in advance.
10. Contact
For privacy-related questions or requests:
- Email: privacy@nexgate.app
- General support: support@nexgate.app
- Website: nexgate.app