Privacy Policy

Last updated: March 25, 2026

1. Introduction

This Privacy Policy describes how Nexus Content Engine ("Nexus", "we", "our", "the Application"), operated at app.ecuacionesdiferencialesaplicaciones.com, collects, uses, shares, and protects your information when you use our AI-powered content automation platform.

By using Nexus, you consent to the data practices described in this policy. If you do not agree, please discontinue use of the Application.

2. Information We Collect

2.1 Account Information

  • Email address (via Supabase authentication)
  • Display name / username
  • Account creation date

2.2 Content You Generate

  • AI-generated videos and images
  • AI-generated copy and social media text
  • Generation metadata (prompts, configurations, selected options)

2.3 Social Media Integration Data

When you connect social media accounts (TikTok, X/Twitter, BlueSky, Meta/Threads, YouTube), we collect:

  • OAuth 2.0 access tokens and refresh tokens
  • Platform user IDs
  • Basic profile information (name, handle) for verification purposes only

Important: We do NOT store your social media passwords. All authentication uses industry-standard OAuth 2.0 protocols.

2.4 Usage Data

  • Features used and frequency of use
  • Content generation statistics
  • Error logs for debugging purposes

3. How We Use Your Information

3.1 Content Generation

  • Creating videos and images via AI providers (Fal.ai / Flux Pro)
  • Generating social media copy via AI language models (OpenRouter)

3.2 Social Media Publishing

  • Publishing content to platforms you have authorized
  • Scheduling future publications on your behalf

3.3 Service Improvement

  • Analyzing usage patterns to improve the platform
  • Optimizing AI content quality
  • Providing usage and cost statistics in your dashboard

3.4 Communication

  • Sending transactional emails (account verification, password resets)
  • Notifying you of material changes to these policies or our Terms of Service

4. How We Share Your Information

4.1 Third-Party Service Providers

We share data with the following providers solely to deliver our services:

ProviderPurposeData Shared
Fal.ai / Flux ProVideo and image generationPrompts, generation configurations
OpenRouterText / copy generationPrompts, brand context
TikTok APIVideo publishingVideos, captions, OAuth tokens
X / Twitter APITweet publishingMedia, text, OAuth tokens
Meta Graph APIThreads / Instagram publishingMedia, text, OAuth tokens
BlueSky APIPost publishingMedia, text, credentials
YouTube APIVideo / Shorts publishingVideos, metadata, OAuth tokens
SupabaseDatabase and authenticationAll application data (encrypted)

4.2 We Do NOT Sell Your Data

We never sell, rent, or share your personal information with third parties for marketing or advertising purposes.

4.3 Legal Requirements

We may disclose information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Data Security

5.1 Protection Measures

  • Encryption in transit: All data is transmitted over HTTPS / TLS 1.3
  • Encryption at rest: Database encrypted via Supabase PostgreSQL
  • Secure tokens: OAuth 2.0 with automatic refresh token rotation
  • Row Level Security (RLS): Database access restricted per user
  • Environment isolation: API keys and secrets stored in encrypted environment variables

5.2 Token Retention

  • OAuth tokens: Stored encrypted in Supabase
  • Duration: Until you revoke access or delete your account
  • Renewal: Automatic via refresh tokens when supported by the platform

6. Your Rights

6.1 Access and Export

You may request a copy of all personal data we hold about you by contacting us at the email below.

6.2 Deletion

You may delete your account and all associated data from your Dashboard settings. Upon account deletion, all your data will be permanently removed within 30 days.

6.3 Revoking Social Media Access

You can revoke Nexus's access to your social media accounts at any time through:

  • TikTok: Settings → Privacy → Authorized Apps
  • X / Twitter: Settings → Security → Apps and Sessions
  • Meta (Threads/Instagram): Settings → Security → Apps and Websites
  • BlueSky: Settings → App Passwords
  • YouTube / Google: Google Account → Security → Third-party apps

6.4 Opt-Out

You may opt out of non-essential communications at any time by contacting us or using the unsubscribe link in our emails.

7. Social Media API Usage Details

7.1 TikTok API

  • Scopes: video.upload, video.publish, user.info.basic
  • Data accessed: Basic profile (read-only), video upload capability
  • Frequency: Only when you manually initiate a publication
  • Retention: Tokens stored until you revoke access
  • Data deletion: Tokens are deleted when you disconnect TikTok or delete your account

7.2 X / Twitter API

  • Scopes: tweet.write, users.read, media.upload
  • Data accessed: Basic profile, tweet publishing capability
  • Frequency: Only when you manually initiate a publication

7.3 Meta Graph API (Threads / Instagram)

  • Scopes: pages_manage_posts, pages_read_engagement
  • Data accessed: Authorized pages, publishing capability
  • Frequency: Only when you manually initiate a publication

7.4 YouTube API

  • Scopes: youtube.upload
  • Data accessed: Channel info, video upload capability
  • Frequency: Only when you manually initiate a publication

8. Cookies and Tracking

8.1 Essential Cookies

  • Supabase Auth: Session cookie (sb-access-token) for authentication
  • Duration: Current session or up to 7 days with "Remember Me"

8.2 What We Do NOT Use

  • No advertising cookies
  • No third-party tracking cookies
  • No Google Analytics or similar analytics trackers
  • No fingerprinting or cross-site tracking

9. Data Retention

We retain your data as follows:

  • Account data: Until you delete your account
  • Generated content: Until you delete it or your account
  • OAuth tokens: Until you revoke access or delete your account
  • Usage logs: Up to 90 days, then automatically purged
  • After account deletion: All data permanently deleted within 30 days

10. Children's Privacy

Nexus is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If we learn that we have collected data from a minor, we will promptly delete that information.

11. International Data Transfers

Your data may be processed in countries other than your own. Our service providers (Supabase, Fal.ai, OpenRouter, Vercel) may store and process data in the United States and other jurisdictions. By using Nexus, you consent to such transfers.

12. Legal Compliance

This Application is designed to comply with:

  • GDPR (European Union General Data Protection Regulation)
  • CCPA (California Consumer Privacy Act)
  • TikTok API Terms of Service and Developer Policies
  • X / Twitter API Terms of Service
  • Meta Platform Terms and Developer Policies
  • YouTube API Services Terms of Service
  • Google Privacy Policy

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email at least seven (7) days before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.

14. Contact Us

For privacy-related questions, data requests, or concerns:

Version 2.0.0 — Nexus Content Engine — Antigravity