Privacy Policy

1. Information We Collect

We collect information you provide directly to us, such as when you create an account, use our services, or communicate with us. This may include your name, email address, phone number, and other information you choose to provide.

2. How We Use Your Information

We use the information we collect to provide, maintain, and improve our services, to process transactions and send you related information, to communicate with you about our services, and to comply with legal obligations.

3. Information Sharing

We do not sell, trade, or otherwise transfer your personal information to third parties without your consent, except as described in this policy or as required by law. We may share information with service providers who perform services on our behalf.

4. Google Services Integration

Nexora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the file-management features you explicitly request, it is never used for advertising, to train AI or ML models, or shared with third parties for purposes unrelated to operating the service.

Data Accessed

When you choose to connect Google Drive as your storage provider, Nexora requests the following OAuth 2.0 scopes and accesses the corresponding data:

  • https://www.googleapis.com/auth/drive : Read, create, update, and delete files and folders in your Google Drive that were created by Nexora
  • https://www.googleapis.com/auth/drive.metadata.readonly : File names, sizes, MIME types, timestamps, and storage quota information
  • https://www.googleapis.com/auth/userinfo.email : Your Google account email address, used solely to identify which Google account is linked to your Nexora organization

Nexora only accesses data within the scopes listed above and does not request access to Gmail, Google Calendar, Google Contacts, or any other Google service.

Data Usage

Google user data is used exclusively to:

  • Upload, download, rename, move, and delete files on your behalf in Google Drive
  • Display file listings and storage quota within the Nexora interface
  • Identify the connected Google account to associate it with your Nexora organization
  • Maintain your authenticated session so you do not need to re-authorize on every action

Google user data is never used for profiling, advertising, analytics sold to third parties, or any purpose beyond directly providing the file-management features described above.

Data Sharing

Nexora does not sell, rent, or share Google user data with any third party. The only data flows involving Google user data are:

  • Google APIs: All file operations are performed directly through the official Google Drive API on your behalf
  • Your organization's own Google Cloud project: each organization supplies its own OAuth credentials (Client ID and Client Secret) from its own Google Cloud Platform project; credentials and tokens are never shared between organizations

No analytics providers, advertising networks, or other third-party services receive your Google user data.

Data Storage & Protection

Nexora applies the following technical controls to protect Google user data:

  • OAuth refresh tokens are encrypted at rest using AES-256-GCM with PBKDF2 key derivation (100,000 iterations, SHA-256) before being stored in our database
  • OAuth access tokens are held in server-side memory only for the duration of the request and are never written to disk or logged
  • All API calls to Google services and all communication between your browser and our servers are made exclusively over TLS (HTTPS)
  • Files are stored within a dedicated "Nexora" folder in your own Google Drive, Nexora does not store file content on its own servers
  • Access to stored tokens is restricted to the application service account and is not accessible to Nexora employees in plaintext

Data Retention & Deletion

Google user data is retained only as long as necessary to provide the service:

  • Disconnect integration: You can disconnect Google Drive at any time via Organization Settings → Storage → Google Drive → Disconnect. This immediately and permanently deletes all stored OAuth refresh tokens for your organization from our database
  • Delete Nexora account: When your organization account is deleted, all associated Google OAuth tokens are purged within 30 days
  • Revoke via Google: You can revoke Nexora's access at any time through Google Account Permissions. Revoking access there will cause our stored refresh token to become invalid; Nexora will detect this on the next API call and prompt you to re-authorize or remove the integration
  • File data: Files you delete through the Nexora interface are deleted from your Google Drive. Files are never copied to Nexora's own servers, so no additional deletion step is required on our end

To request manual deletion of any Google user data we hold, email us at support@nexora.appfy.co.za and we will process your request within 30 days.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet is completely secure.

6. Your Rights

You have the right to access, correct, or delete your personal information. You may also opt out of certain communications from us. To exercise these rights, please contact us through the support channels provided in our application.

7. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date.

8. Contact Us

If you have any questions about this privacy policy, please contact us through our support system or by email at support@nexora.appfy.co.za.

Last Updated: May 29, 2026