Legal
Privacy Policy
Last updated 16 September 2026
This policy explains what Nexet collects when you use the platform, how we use it, and the choices you have — including how we handle data from the Google and YouTube integrations you may choose to connect.
1. Who we are
Nexet ("Nexet", "we", "us") operates the collaboration platform available at https://nexet.co and its dens. This policy explains what we collect, why, and what control you have over it.
2. Information we collect
Account information. When you create an account we receive your email address, display name, and profile image through our authentication provider, Clerk. If you sign in with Google, Clerk receives your basic Google profile (name, email address, profile image).
Your work. The projects, manuscripts, scenes, timelines, comments, submissions, review notes, chat messages, and uploaded media you create through the product. This lives in our database and object storage under your account.
Payment information. Paid access is sold through Whop, our payment processor. We never receive or store your card details. We store only the entitlement that results from a payment — which plan you hold, and until when — so we can unlock the room you paid for.
Usage and device data. Product analytics events (pages viewed, features used, sign-in and sign-out events), plus the technical data any web application receives: IP address, browser type, and timestamps. We resolve page views to a stable page identity rather than storing the raw URL, so an individual project path is not retained in analytics.
3. Google and YouTube data (YouTube API Services)
Nexet uses YouTube API Services. When you connect a YouTube channel in the Creators Den, you authorise us through Google Sign-In to read limited information about that channel and its performance. You can only connect a channel you control, and the connection is always started by you.
We request exactly two Google scopes for this feature, plus basic sign-in:
-
openidandemail— to identify your account. -
https://www.googleapis.com/auth/youtube.readonly— to read your channel's public identity and branding (channel title, handle, avatar, banner) so the channel appears correctly inside your workspace, and to read your video list. -
https://www.googleapis.com/auth/yt-analytics.readonly— to read your own channel's performance metrics so we can display them in your analytics view.
The Google user data we access. Through the scopes above, Nexet accesses: your channel's identifier, title, handle and description; your channel's branding images (avatar and banner); the list of videos published on your channel; and aggregate performance metrics for your own channel, such as views and watch time. We do not request access to your subscribers' or viewers' personal data, we do not access your Google Account profile beyond the name, email address and profile image used for sign-in, and we do not access any other Google service.
How we use it. We will use your Google user data to provide you with the services you requested — showing your connected channel and its analytics back to you in the Creators Den, and keeping that display current. That is the only purpose. We do not use Google user data for targeted, personalized, retargeted, interest-based or any other advertising; we do not sell it, provide it to data brokers or information resellers, or use it to determine credit-worthiness or for lending; and we do not use it to create databases.
No AI or machine-learning training. We do not use Google user data to develop, improve or train generalized, personalized or non-personalized artificial intelligence or machine-learning models. The advisory writing and production assistants described in section 5 receive no Google user data and are not trained on it.
With whom we share it. We do not transfer or disclose your information to third parties for purposes other than the ones described above. Google user data is shared only with the infrastructure providers named in section 4, which process it on our instructions to host the product on our behalf, and only as strictly necessary to run the feature you asked for.
How we protect and store it. OAuth access and refresh tokens are encrypted at rest before being written to our database and are transmitted over TLS. Security procedures are in place to protect the confidentiality of Google user data, and tokens are used only to make the API calls described above. Channel metadata and cached analytics figures are stored alongside your account.
Revoking access. You can disconnect a channel at any time from its card in the Creators Den, which deletes the stored tokens and stops all further API calls. You can also revoke Nexet's access independently of our product, at any time, at https://myaccount.google.com/permissions. Revoking access there stops new API calls but does not by itself delete data we already hold — ask us and we will delete it.
Nexet's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your use of YouTube is also governed by the YouTube Terms of Service and the Google Privacy Policy.
4. Service providers we share data with
We do not sell your personal information. We share it only with the providers that run the product on our behalf, each bound to use it solely for that purpose:
- Clerk — authentication and identity.
- A managed PostgreSQL host — the application database.
- Cloudflare R2 — storage of uploaded and processed media.
- Whop — payment processing and subscription management.
- Render — application hosting.
- Mixpanel — product analytics.
- Google / YouTube — the channel integration described in section 3.
We may also disclose information where the law requires it, or where it is necessary to protect the rights and safety of our users.
5. AI features
The Story Oracle and Role Oracle are advisory assistants. When you use them, the text you submit for that request is sent to whichever model provider your workspace is configured with, which may be a hosted provider (such as Groq or OpenRouter) or a model running on your own machine (such as Ollama or LM Studio). The product reports which provider answered for each request.
AI output is a suggestion only. No synthetic content is ever merged into another person's work on your behalf, and no AI system stands in for a human contributor.
6. Cookies and local storage
We use strictly necessary cookies and local storage to keep you signed in, to deliver realtime updates, and to remember interface state. These are required for the product to function. We do not use advertising cookies and we do not sell data to advertisers.
7. How long we keep data
Account data and your work are kept for as long as your account exists — for the length of time needed to fulfil the purposes outlined in this policy, unless a longer retention period is required or permitted by law. Uploaded video originals are subject to a retention window and are removed from primary storage after it elapses; the associated proxies, versions, and project records remain so the work stays usable. When the data retention period expires for a given type of data, we delete or destroy it.
Google and YouTube data. Channel metadata and cached analytics figures are retained only while your channel stays connected, and are removed when you disconnect it. Disconnecting a channel deletes the stored OAuth tokens immediately and stops all further API calls. You may request that we delete any Google user data we still hold at any time by emailing support@nexet.co, and we will action the request. Closing your account likewise deletes or irreversibly anonymises your personal data, except where we must retain records for legal, tax, or fraud-prevention purposes.
8. Security
Access to data is enforced server-side: ownership and state transitions are checked by the API, never only by the interface. We use encryption to protect your information — Google user data is encrypted in transit using TLS, and OAuth access and refresh tokens are encrypted at rest. Security procedures are in place to protect the confidentiality of the data we hold. No system is perfectly secure, so we cannot guarantee absolute security — please use a strong, unique password for your account.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. You can exercise these rights from your profile page where the product supports it, or by writing to us. You can disconnect any Google or YouTube integration yourself at any time, as described in section 3.
10. Children
Nexet is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
11. International transfers
We and our service providers may process your information in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards such as standard contractual clauses.
12. Changes to this policy
We may update this policy as the product changes. When we do, we will revise the "last updated" date above, and we will notify you in the product if the changes are material.
Questions about this page? Write to support@nexet.co.