Privacy Policy

Last updated: 27/07/2026

This document describes how EngineerEconomics Nexus AI handles personal data, written from the app's real behaviour: authentication, database, file storage, AI features, collaboration and Paddle billing.

1. Data controller

EngineerEconomics Nexus AI (“Nexus AI”, “the app”) is the controller of the data described in this document.

Privacy contact: privacidad@buildai.nexus. For anything else, soporte@buildai.nexus or the form at buildai.nexus/contacto.

TO BE COMPLETED MANUALLY: legal company or owner name, tax identification number and full registered address.

2. Data we actually collect

The app collects only what its features require:

  • Account data: email address and hashed password, or your Google/Apple account identifier if you sign in with those providers.
  • Profile: full name, username, preferred language, avatar, bio, optional phone, country, university, major, academic level, interests, goals and self-declared investment and programming experience, collected in the onboarding wizard and editable later.
  • Content you create: AI conversations and messages, chat folders, projects, tasks, project entries, calendar events, library items, notes and projects generated with Nexus Builder AI.
  • Files you upload: chat attachments and images (private “chat-attachments” bucket) and library documents (private “library” bucket), including images pasted or captured for math or visual analysis.
  • Audio: when you use voice input, the recording is sent for transcription and is not permanently stored by the app.
  • Social data: friend requests, friendships, group membership, direct messages, group messages, project messages and project invitations.
  • Learning data: course enrollments, lesson progress and exam attempts with their results.
  • User financial inputs: portfolio holdings and price alerts you enter manually (symbol, quantity, buy price, notes). The app does not connect to your broker or bank.
  • Subscription and payments: active plan, billing cycle, status, renewal date, credits, subscription history and payment history (amount, currency, status, description, transaction identifiers and Paddle invoice link).
  • Sales inquiries: if you submit the Enterprise form we store name, email, company, country, phone, seat count and your message.
  • AI usage: credit consumption events (action, credits spent and a short description).
  • Minimal technical data from HTTP requests needed to serve the app and keep it secure.

3. We never collect card data

The app never receives, processes or stores card numbers, CVV or bank details. Payment happens entirely inside Paddle's hosted checkout. Nexus AI only receives the transaction outcome and the identifiers it needs (customer, subscription and transaction IDs).

4. Purposes and legal bases

  • Performance of contract: creating and maintaining your account, providing AI, chat, project, class, market and library features, and managing your subscription.
  • Legitimate interest: platform security, abuse prevention and enforcement of usage and credit limits.
  • Legal obligation: retention of billing and tax records handled through Paddle.
  • Consent: optional content you choose to upload or publish (avatar, files, bio, non-mandatory profile fields).

5. How data is stored and protected

  • Data is stored in the managed Supabase (PostgreSQL) database used by the app, encrypted in transit via HTTPS/TLS and at rest by Supabase infrastructure.
  • Every user-data table has Row Level Security enabled, with policies restricting access to your own rows or to authorised members of a group or project.
  • Files live in private storage buckets and are accessed through short-lived signed URLs tied to your session.
  • Passwords are never stored in plain text; they are hashed by the authentication service.
  • Service keys and third-party credentials are stored as server-side secrets and never exposed to the browser.
  • Administrative access for the platform owner is governed by a separate roles table.

6. External providers actually used

  • Supabase — database, authentication and file storage (processor).
  • Lovable — application hosting and the Lovable AI Gateway used to route model requests.
  • Paddle.com Market Ltd — payment and subscription processing. Paddle acts as Merchant of Record and handles your payment and billing data under its own privacy policy.
  • Google (Gemini) — AI models used for chat, exams, image/math analysis, image generation, sports reports, project planning and code generation.
  • OpenAI (GPT models) — available as an alternative engine in the AI selector and in the multi-opinion panel.
  • Google Sign-In and Apple Sign-In — optional identity providers.
  • Yahoo Finance — public source for quotes and market history. Only ticker symbols are requested; no personal data is sent.

7. How data sent to AI models is handled

When you use an AI feature, your request is sent to the selected model through the AI gateway. It may include your message text, recent conversation history (or an automatic summary of older messages), any files or images you attach, and context from the project or course you are working in.

In group and project chats, AI assistance is opt-in and only runs when someone explicitly requests it; the recent context of that conversation is then sent.

Generated messages are stored in your account so you can review and export them. You can delete conversations, and their messages, from the app.

We do not use your conversations to train our own models. Each model provider's own policies govern its processing.

AI output can be wrong. It is not financial, investment, legal, medical or professional advice.

8. Subscriptions and payments

Subscriptions run on Paddle Billing. Starting a purchase opens Paddle's checkout and passes your internal user identifier so the subscription can be linked to your account.

Paddle notifies us of subscription events (created, updated, renewed, cancelled, payment completed or failed) through a signed webhook. We use that information to update your plan, credits, renewal date and payment/subscription history.

9. Cookies and local storage

The app uses no advertising or third-party analytics cookies.

Browser localStorage keeps you signed in and remembers your language, AI engine, answer-length preference and some interface settings. This storage is strictly necessary to run the service.

Paddle's checkout may set its own cookies required to process payment and prevent fraud.

10. Data retention

We keep your data while your account is active. Content you delete in the app (chats, projects, tasks, library items, events) is deleted or marked deleted accordingly.

Billing records are retained for the period required by applicable tax law.

TO BE COMPLETED MANUALLY: specific retention periods after account closure.

11. Account and data deletion

Today the app lets you delete individual content (conversations, chats, projects, library files and events) and edit or clear your profile fields in the Profile section.

The app does not yet include a self-service “delete my account” button. To request full deletion of your account and associated data, email the support address below; requests are handled manually.

TO BE COMPLETED MANUALLY: support email and committed response time for deletion requests.

12. Your rights

You may request access, rectification, erasure, restriction, objection and portability, and withdraw consent where it is the legal basis. You can also export your conversations from within the app in several formats.

TO BE COMPLETED MANUALLY: rights-request email and the competent supervisory authority for the company's jurisdiction.

13. Minors

The service targets university students and professionals. It is not designed for children under 16 and we do not knowingly collect their data.

TO BE COMPLETED MANUALLY: final minimum age for the chosen jurisdiction.

14. Changes to this policy

Material changes will be published on this page and the “Last updated” date will change.

15. Contact

TO BE COMPLETED MANUALLY: support email, privacy email and postal address.