Your privacy is the product, not the price. This policy explains what NexGuard does and doesn’t collect, why, and the controls you have. We designed the system so that the most sensitive data — your passwords, logins and authenticator secrets — is unreadable to us, and we say plainly which vault items are not in that category.
This document is written in plain language for clarity and reflects how NexGuard actually works today. It is a good-faith template and not legal advice — have it reviewed by qualified counsel and localized for your jurisdiction before you rely on it in production.
Who we are
Nexonix Systems ("we", "us") provides the NexGuard application and this website. This policy covers both.
What we collect
- Account data: your email address and a securely hashed password. We never store your password in the clear.
- Security signals you scan: results of device security and privacy checks you run, and the fact that a scan occurred — used to show your score, history and enforce fair-use limits.
- Installed apps: the list of apps on your phone and the permissions each holds, read during a scan so the privacy report can show what reaches your location, camera, mic and contacts. We read which permissions apps hold, never your contacts, messages or files themselves.
- Approximate location: coarse location is used only for the Wi-Fi safety check and is turned into a keyed, non-reversible network fingerprint — we store that, never your address or precise position.
- App-usage totals (optional): only if you turn on dashboard sync, daily screen-time totals are uploaded so they show on the web. Which apps you used, and for how long, never leave the phone.
- Push notifications: alerts are delivered through Google’s Firebase Cloud Messaging, so Google handles the message in transit. A push carries the alert’s own text and nothing else — never a vault item, password, code or scan detail.
- Vault data: stored only as ciphertext, under one of two keys. Passwords, logins and authenticator secrets use a key that never leaves your phone, so we cannot read them. Photos, videos, documents and notes may optionally use a key we hold, which is what makes them openable on your web dashboard — those we are able to decrypt. See “Your vault, and which parts we can open”.
- Support & updates: if you contact us or subscribe to product updates, the details you submit (name, email, message). Support reaches us by email or the contact form on this site; there is no third-party chat widget on any page.
- Minimal technical data: basic logs needed to run and secure the service. We record the fact of sensitive actions for audit — never their secret contents.
What we do NOT collect
- We do not silently read your messages, calls, contacts, microphone, camera or screen. Scam and link checks run only on content you choose to paste in.
- We do not store your payment card. Paid plans are handled by Google Play.
- We do not sell your data or use it to train third-party AI models.
Your vault, and which parts we can open
Vault items are always encrypted on your device before they are sent, item names included. Which key is used depends on what the item is, and the difference decides what we are able to do with it.
Passwords, logins and authenticator secrets are encrypted with a non-exportable, hardware-backed key that stays on your phone. We never receive it, so we cannot read, recover, or disclose these items — not for you, not for anyone who asks us. Encrypted backups work the same way, sealed with a passphrase only you know.
Photos, videos, documents and notes can optionally be stored under a per-account key that we hold, kept encrypted at rest under a separate key of ours. This is what makes it possible to open the same items on your web dashboard. It also means we are technically able to decrypt them. We do not read them, each decryption for the web is recorded in your audit log, and the option is off unless you turn it on — but we will not tell you we cannot open something we can.
How we use data
- To provide the service: compute scores, run checks, store your (encrypted) vault, manage your account.
- To enforce plan limits and entitlements fairly, on our backend.
- To secure the service and prevent abuse.
- To respond to you when you contact us or to send product updates if you subscribed to them.
Legal bases & your rights
Where applicable law (such as the GDPR or similar regimes) grants you rights, you may request access to, correction of, or deletion of your personal data, and object to certain processing. Contact us to exercise these rights. Deletion of ciphertext is straightforward whichever key sealed it. We cannot alter or produce the items sealed with your device key, because we cannot read them; items under the hosted key we can decrypt, and a request about those is one we are able to act on. To delete your whole account and its data, see how to delete your account.
Sharing
We share data only with service providers strictly necessary to operate NexGuard — our hosting, and Google Play for purchase verification — each bound to protect it, or where legally required. We do not sell personal data.
Retention
We keep account and security-history data for as long as your account is active and as needed to provide the service, then delete or anonymize it within a reasonable period. You can delete your account — and everything in it — at any time from inside the app, or request deletion by email. See how to delete your account.
Children & age
NexGuard is intended for people aged 13 and over. Where applicable law requires a higher minimum age for this kind of service, the higher age applies. We do not knowingly collect data from anyone below the applicable minimum age; if you believe a minor has provided us data, contact us and we will remove it.
Changes
We’ll update this policy as the product evolves and revise the “last updated” date. Material changes will be communicated in-app or by email where appropriate.
Questions about this policy
Contact us at support@nexonixsystems.com or through our contact page.