Privacy policy
Last updated: Aug 3, 2026
01Who we are
The nerix.ai service is operated by nerix.ai [legal entity to be confirmed], [registered address to be confirmed]. For anything in this policy, write to info@nerix.ai — a person reads every message.
02What this policy covers
Two surfaces: this marketing site at nerix.ai, and the product at app.nerix.ai. They handle very different data, so this policy treats them separately.
03What the marketing site collects
Almost nothing. A cookie holding the language you chose, and a cookie recording your cookie-consent decision. No analytics, no tracking pixels, no third-party scripts of any kind — the site's security policy blocks them by construction.
If you use the contact form, we receive what you type in it: your name, email address, optional company and team size, and your message. It is used to reply to you, and for nothing else.
04What the product collects
Your account and organisation details; the documents, conversations and Sheets your workspace uploads and creates; and usage and audit records — who did what, when, and what it cost in credits. The audit log exists for your organisation's benefit and cannot be edited or deleted, including by us acting on an owner's request.
05Purposes and lawful bases
We process account and content data to provide the service (contract); usage and audit records to keep it secure, billable and accountable (legitimate interests and contract); and consent-based processing only where you have actually consented — such as optional cookies, of which none currently exist.
06Where your data lives
In the data region your organisation selects: European Union (Frankfurt), United Kingdom (London) or United States (Virginia). Documents, embeddings and logs are stored and processed there. Changing region moves the data and records the move in the audit log.
07AI providers as processors
When your organisation routes a conversation to an AI provider — Mistral (EU-hosted, the default), OpenAI or DeepSeek — that provider processes the passages needed to answer, as a processor, only for that conversation. Your organisation chooses which providers are allowed and can restrict the choice to providers hosted in its data region. Each provider's cautions are printed in the product, on the picker.
08Your content never trains models
Your documents are never used to train any model, by us or by a provider. In the product this reads "Never" and cannot be changed — it is a property of the system, not a preference.
09Retention and erasure
Retention is configurable by your organisation, for documents and conversations separately, from 90 days to indefinite. An export gives you a machine-readable copy of every document, conversation and Sheet in the workspace. Erasure is permanent and takes effect within 30 days, including in backups.
10Your rights
Access, rectification, erasure, portability, restriction and objection, under the UK GDPR and the EU GDPR. Export and erasure are self-serve in the product; for the rest, write to info@nerix.ai. You can also complain to the ICO in the UK or to your local supervisory authority in the EU.
11International transfers
Data leaves your selected region only where your organisation chooses a provider or region outside it. Where a transfer requires safeguards, we rely on the applicable standard contractual clauses or equivalent mechanisms; details are available from info@nerix.ai.
12Security
PII redaction before text reaches a provider (optional, on by default), an append-only audit log, a strict per-request Content-Security-Policy, API secrets stored as prefix and hash, and conversation sharing that redacts by default. The security page describes each in plain language.
13Changes to this policy
When this policy changes materially, the date above changes with it, and signed-in organisation owners are notified in the product. The current version always lives at this address.