Privacy Policy

Last updated: April 9, 2026

Who We Are

Nexus is an AI agent observability platform operated by Keylight Digital LLC. Our contact email is ralph@keylightdigital.dev.

Data We Collect

We collect the following categories of data:

  • Account data: Email address and hashed password when you create an account.
  • Trace and span data: Agent execution traces, spans, token counts, latencies, and metadata you send via the Nexus SDK or API.
  • API keys: Hashed API keys used to authenticate SDK requests.
  • Usage data: Page views, feature usage, and access logs for service operation and security.
  • Payment data: Billing information processed by Stripe — we do not store card numbers directly.

How We Use Your Data

  • To provide and improve the Nexus service
  • To authenticate your account and API requests
  • To process payments and manage subscriptions
  • To send transactional emails (account confirmations, alerts)
  • To detect abuse and ensure service security

We do not sell your data to third parties or use it for advertising.

Data Storage

Your data is stored on Cloudflare's infrastructure (D1 database, KV, R2 object storage) in Cloudflare's global edge network. Trace data you send is stored in your account's database and retained for 90 days by default on the free plan, or as configured on paid plans.

Third-Party Services

We use the following third-party services:

Cookies

We use a minimal session cookie to keep you signed in. We do not use advertising cookies or cross-site tracking cookies. Our analytics (Beam) are cookieless — no cookie consent banner is required.

Data Retention

  • Account data: Retained until you delete your account.
  • Trace data: 90 days on free plan; configurable on paid plans.
  • Billing records: Retained as required by law (typically 7 years).
  • Access logs: Retained for up to 30 days for security purposes.

Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your account and associated data.
  • Portability: Request an export of your trace data.
  • Objection: Object to processing of your data in certain circumstances.

To exercise any of these rights, email us at ralph@keylightdigital.dev. We will respond within 30 days.

Security

Passwords are hashed using bcrypt. API keys are hashed before storage. All data is transmitted over HTTPS. We follow security best practices and conduct regular reviews.

Children's Privacy

Nexus is not directed at children under 13. We do not knowingly collect data from children under 13.

Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to registered users. The "last updated" date at the top of this page reflects the most recent revision.

Contact

Questions about this privacy policy? Email ralph@keylightdigital.dev.

Keylight Digital LLC · ralph@keylightdigital.dev