Privacy Policy
Last updated: April 9, 2026
Who We Are
Nexus is an AI agent observability platform operated by Keylight Digital LLC. Our contact email is ralph@keylightdigital.dev.
Data We Collect
We collect the following categories of data:
- Account data: Email address and hashed password when you create an account.
- Trace and span data: Agent execution traces, spans, token counts, latencies, and metadata you send via the Nexus SDK or API.
- API keys: Hashed API keys used to authenticate SDK requests.
- Usage data: Page views, feature usage, and access logs for service operation and security.
- Payment data: Billing information processed by Stripe — we do not store card numbers directly.
How We Use Your Data
- To provide and improve the Nexus service
- To authenticate your account and API requests
- To process payments and manage subscriptions
- To send transactional emails (account confirmations, alerts)
- To detect abuse and ensure service security
We do not sell your data to third parties or use it for advertising.
Data Storage
Your data is stored on Cloudflare's infrastructure (D1 database, KV, R2 object storage) in Cloudflare's global edge network. Trace data you send is stored in your account's database and retained for 90 days by default on the free plan, or as configured on paid plans.
Third-Party Services
We use the following third-party services:
- Cloudflare: Hosting, DNS, and edge infrastructure. Privacy policy →
- Stripe: Payment processing. Privacy policy →
- Resend: Transactional email delivery. Privacy policy →
- Beam Analytics: Privacy-first, cookieless analytics with no personal data collection. Learn more →
Cookies
We use a minimal session cookie to keep you signed in. We do not use advertising cookies or cross-site tracking cookies. Our analytics (Beam) are cookieless — no cookie consent banner is required.
Data Retention
- Account data: Retained until you delete your account.
- Trace data: 90 days on free plan; configurable on paid plans.
- Billing records: Retained as required by law (typically 7 years).
- Access logs: Retained for up to 30 days for security purposes.
Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and associated data.
- Portability: Request an export of your trace data.
- Objection: Object to processing of your data in certain circumstances.
To exercise any of these rights, email us at ralph@keylightdigital.dev. We will respond within 30 days.
Security
Passwords are hashed using bcrypt. API keys are hashed before storage. All data is transmitted over HTTPS. We follow security best practices and conduct regular reviews.
Children's Privacy
Nexus is not directed at children under 13. We do not knowingly collect data from children under 13.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered users. The "last updated" date at the top of this page reflects the most recent revision.
Contact
Questions about this privacy policy? Email ralph@keylightdigital.dev.
Keylight Digital LLC · ralph@keylightdigital.dev