Controller and contact
XRT Technologies Szoftverfejlesztő Zártkörűen Működő Részvénytársaság is the controller for Nexpot. Registered office: 1031 Budapest, Záhony utca 7. Hz. ép., Hungary. Registering court: Fővárosi Törvényszék Cégbírósága. Company registration number: 01-10-141835. Tax number: 27826209-2-41.
Privacy contact: hello@nexpot.ai; telephone: +36 30 740 2266. You can also use our privacy request form.
What we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account email, name, profile image, authentication method, password hash, session-token hash and short-lived hashed Google sign-in nonce where used | Create and secure your account, sign you in, prevent sign-in replay and recover access. | Contract; legitimate interest in authentication and security. |
| Prompts, recent conversation context, visible-screen screenshots, active application or tab context and Autopilot action results that you invoke | Answer your request, point at the relevant control, or perform the visible action you requested. | Contract and requested pre-contract steps for ordinary data. Nexpot is not designed to process special-category data; do not invoke screen-aware features while such data is visible. |
| Microphone audio, transcripts and text sent for speech synthesis | Provide push-to-talk transcription and spoken replies when you turn those features on. | Contract; explicit user action. Do not activate voice around people who have not agreed to be recorded. |
| Credit balance, feature source, credits used, timestamps and limited diagnostics | Meter the service, show account history, prevent abuse and diagnose failures. | Contract; legitimate interests in service integrity and security. |
| Stripe customer, checkout, invoice, payment-intent and subscription identifiers, product, amount and currency | Take payment, administer subscriptions, issue receipts, handle disputes and meet accounting duties. We do not receive full card numbers. | Contract and legal obligations. |
| Support, team and legal-request details you submit | Answer the request, verify identity where needed and keep an evidence trail. | Contract, legal obligation or legitimate interest depending on the request. |
| IP address, request time, requested route, response status, browser/device and limited network, security, diagnostic and runtime-log data processed by Vercel | Deliver the website, route requests, protect availability, investigate abuse and failures, and maintain operational security. This necessary hosting processing occurs whether or not optional analytics is allowed. | Contract where needed to serve your request; legitimate interests in secure, reliable delivery. Vercel may separately process limited data as an independent controller for its own security and legal duties as described in its notice. |
| Consent choice, aggregated page analytics, public call-to-action selections and a pseudonymous capped download identifier | Remember your choice and, only with analytics consent, understand page use, which public Download, Platform, Chrome or plan links are selected, and limited download totals. We do not send form values, account actions or payment details as analytics events. | Consent for optional analytics; strictly necessary storage for the choice itself. |
| Legacy Windows product telemetry in versions before 1.10.7 | Those builds used PostHog for product and diagnostic events and may have included account email, prompt/response text, element labels or raw error text. That transmission was broader than the current minimisation standard and is disabled in 1.10.7. Current desktop builds contain no active PostHog project key and send no desktop analytics. | The intended purpose was service diagnostics based on legitimate interest. Nexpot has stopped the processing in current builds; affected users may request access or deletion through the rights form. |
Nexpot does not sell personal data, build advertising profiles, broker browsing data, or continuously collect browsing history. Screen and tab context is processed when you invoke a feature that needs it.
AI and automation
Nexpot is an AI system. Selected prompts, screenshots, audio, transcripts and request context are sent to the AI or speech provider needed for the feature. Outputs may be wrong. Autopilot can propose or carry out interface actions, but you remain the operator and can pause, stop or cancel it.
We do not use Nexpot output to make legal, employment, credit, insurance, medical or other decisions producing legal or similarly significant effects about you. Read the AI Transparency Notice.
Sources and organisational use
Data comes from you and your device, from an organisation that invites you to a workspace, and from providers you choose or use, such as Google for sign-in and Stripe for transaction status. We do not purchase data-broker profiles.
For personal Nexpot accounts, we generally act as controller. Where a business customer determines why its members use Nexpot and what work context they submit, that organisation may be the controller and Nexpot may act as its processor under the applicable business agreement. Business customers can request a data processing agreement from the privacy contact.
Recipients and processors
- Anthropic and OpenAI: hosted language, vision and Codex-related processing, depending on the selected feature and model.
- AssemblyAI and ElevenLabs: streaming transcription and speech generation when those features are enabled.
- Google: Google sign-in when you choose it.
- Stripe: checkout, payments, subscriptions, invoices, tax and fraud prevention.
- Neon: hosted application database.
- Vercel: necessary website delivery and operational logs, plus web analytics only after the separate analytics choice.
- Resend: transactional, support and account email delivery.
- PostHog: historical Windows telemetry from versions before 1.10.7. Collection is disabled in the current release; the controller is reviewing and purging the historical dataset.
We may also disclose data when lawfully required, to protect users and service security, or during a corporate transaction subject to equivalent safeguards. Service providers receive only the data needed for their task and act under contractual confidentiality and data-protection terms.
International transfers
Some providers process data outside the European Economic Area, including in the United States. Where required, a provider may be used only with an applicable adequacy decision or a valid transfer mechanism such as the EU Standard Contractual Clauses and appropriate supplementary safeguards. Provider public DPAs are linked above; the controller maintains a separate evidence register for the applicable subscription and transfer terms. You may request information or a copy of the relevant safeguards through the privacy contact, subject to protected commercial terms.
Sensitive screens and human access
Nexpot does not require health, biometric-identification, political, religious, sexual-life or other special-category data. The desktop app does not maintain a separate screen-consent profile or send screen-consent events. Screen context is processed only when you deliberately invoke a voice, typed or UI Autopilot request.
Hide unrelated windows, notifications, credentials and sensitive content before invoking screen guidance. Nexpot does not perform unrelated background capture. Do not intentionally submit special-category data. Submit third-party information only where you have a valid legal basis and authority.
We apply data minimisation by using only the visible screens needed for the invoked request, not intentionally storing raw screenshots in the application database, excluding the Nexpot overlay from capture where supported, and requiring product and provider reviews before expanding screen uses. A draft internal DPIA records the remaining risks; management, privacy-counsel and provider-control approval remains a release requirement and is not described as an implemented in-app consent gate.
Authorised personnel access account or request data only when needed for user-requested support, security and abuse investigation, legal obligations, or service administration under confidentiality and access controls. Raw screen and audio content is not routinely reviewed by humans.
Use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including Limited Use requirements.
Retention
| Record | Normal retention |
|---|---|
| Raw screenshots and microphone audio | Not intentionally stored in the Nexpot application database after the request. Providers may temporarily retain request data under their service terms, commonly up to 30 days unless a different approved configuration applies. |
| Account and profile | While the account exists, then deleted or anonymised unless law requires limited retention. |
| Signed-in session, sign-out retry, reset/verification token and Google nonce replay record | Session up to 30 days; a one-way session-token hash queued after sign-out is removed when revocation is processed and in any event is limited to 35 days; password reset token up to 2 hours; email-verification token up to 24 hours. One-way Google nonce hashes expire with the signed ID token. Used or expired records are removed by the authenticated retention job, and account-linked records are removed with account deletion where applicable. |
| Usage and security metadata | While the account exists and as needed for metering, security, disputes and legal claims. It is removed with account deletion unless a legal exception applies. |
| Team request-cluster insights | Raw question text is not stored for this feature. If the workspace insight secret is configured, Nexpot stores only a keyed fingerprint and an opaque cluster label for up to 180 days while the relevant workspace exists, then removes it through the daily retention job. Without that secret, collection stays off. |
| Direct support correspondence outside the online legal-request form | Normally up to 24 months after closure, longer if needed for a dispute or legal duty. |
| Online privacy, withdrawal, billing, complaint and other legal-request records, submissions, delivery status and responses | Three years, unless a longer legal hold is necessary. Confirmation and internal-notification delivery states and bounded retry counts are retained with the request; delivery is attempted at most 12 times using stable message identifiers. Expired records are automatically deleted when no hold applies. |
| Vercel hosting and runtime logs available to Nexpot | The plan-configured operational period, no more than 30 days and commonly much shorter. Vercel may retain separate provider-security, fraud, billing or legal records for the periods stated in its own Privacy Notice. |
| Legacy PostHog desktop telemetry | No new collection from 1.10.7. Historical records are subject to an immediate controller deletion review and any user-specific access/deletion request, except where a narrow legal hold applies. |
| Billing and accounting records | For the statutory period, generally up to 8 years under Hungarian accounting requirements. On account deletion, completed checkout evidence moves to a purpose-limited archive. New archive rows use a versioned, keyed HMAC pseudonymous subject reference. Legacy version 1 rows used a one-way email hash; they cannot be transformed without the original address and are identified honestly by their stored version. |
| Deleted-account billing safety record | While external billing cleanup is incomplete, Nexpot keeps the random internal account ID and relevant Stripe event or object IDs, without the email or profile, so cleanup can safely retry and late fulfillment is blocked. Once deletion completes, a 90-day retention period starts so delayed signed billing events can still be canceled or refunded; the daily retention job then removes the record and linked event statuses. |
| Withdrawn download-counter identifier | After analytics withdrawal, the random identifier is kept only on a server-side suppression list for up to 7 days so an already-running download write cannot recreate deleted analytics. |
| Page and public call-to-action analytics; download counter | Only after consent. Query strings are removed and reset pages are excluded. Vercel's session hash is discarded within 24 hours; aggregated reporting follows the configured Vercel account retention. The local identifier cookie and identifiable download events last no more than 180 days. Withdrawing consent stops future analytics immediately; if linked-record deletion cannot finish at once, a non-identifying necessary retry flag preserves the deletion request while analytics stays off. |
Your choices and rights
Depending on the circumstances, you can request access, a portable copy, correction, deletion, restriction, or object to processing. Where processing relies on consent, you can withdraw it at any time without affecting earlier lawful processing. You can export or delete a signed-in account directly on the account page.
We normally respond within one month. We may need to verify identity and may retain data that the law requires us to keep. You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), naih.hu, or to your local EEA supervisory authority, and you may seek a judicial remedy.
Security, children and changes
We use transport encryption, password hashing, hashed server-side session tokens, access controls and provider restrictions. No internet service can promise absolute security. Tell us promptly if you suspect account misuse.
Nexpot is not directed to children under 16 and we do not knowingly create accounts for them without a valid parent or guardian basis. If you believe a child supplied data, contact us for removal.
We will post material changes here and, where appropriate, provide an in-product or email notice before they take effect. A new purpose that requires consent will not be applied without asking first.
Additional US state rights
Where a US state privacy law applies, residents may also have rights to know, access, correct, delete or obtain a portable copy, and to appeal a denied request. Nexpot does not sell personal data or share it for cross-context behavioural advertising, so no sale or targeted-advertising opt-out is needed. We do not discriminate for exercising a privacy right. An authorised agent may submit a request, subject to verification of authority and identity.