Prelaunch preview. Explore AROS products and skills. Checkout is in sandbox; no real payment.
Legal

Privacy Policy

Last updated 5 October 2026. See also our Terms of Service.

1. Scope

This policy explains what AROS Cloud Federation ("the Service"), operated by 合同会社 Nexitia(ネクシア) (Nexitia LLC) and served from nexitia.ai, does with personal data. It covers the website, the authenticated dashboard, the LLM gateway, and brain federation sync.

The data controller is 合同会社 Nexitia(ネクシア) / Nexitia LLC (2-8-573 Hashinouchi, Ibaraki-shi, Osaka 567-0805, Japan); privacy requests are handled at the address in section 15.

It is written to describe what the software actually does, and each claim below corresponds to a specific part of the system rather than to an intention.

2. What we collect

Account identity. When you sign in with Google we receive and store your email address, display name, profile picture URL, and Google account identifier. We never receive your Google password.

Organization records. Organization name and contact email, subscription tier and status, credit balance, storage quota and usage, whether federation is enabled, and a Stripe customer identifier where billing applies.

API keys. Keys issued to your organization, and the time each was last used.

Usage logs. For every call through the LLM gateway we record the model name, the region that served it, prompt and completion token counts, latency, and whether the call succeeded, was rate limited, or errored — together with the organization and key responsible.

Brain snapshot metadata. For each federation sync: a storage path, a SHA-256 checksum, counts of the components in the envelope, merge status and timing, and any error log.

Administrative audit records. Sign-ins to the admin panel and the actions taken there, so privileged access is attributable.

Technical data. Standard server logs from Google Cloud Run, including IP address, user agent, and request metadata.

3. What we do not collect

The following describes the service scope and gateway logging. Model requests, application inputs and federation snapshots are separate data paths:

  • We do not log the content of your prompts or the model's responses. The usage log records counts and timings only. There is no field in it that can hold a prompt, and the gateway does not persist request bodies.
  • Do not upload regulated or identifiable research data. Local storage alone does not prevent content from being transmitted through a model request, app input or synchronization envelope. Review each enabled feature and its permitted inputs.
  • Execution depends on the feature. Local agents run on your hardware; enabled hosted applications may dispatch work to cloud infrastructure. The cloud also provides a gateway, synchronization and a catalog.
  • We do not sell personal data, and we do not use it for advertising.

4. Brain federation snapshots

If your organization enables federation, your local AROS instance uploads selected snapshots. Organization sharing and optional Commons contributions have different scopes; neither is permission to publish or sell private research. Current exporter source includes artifact filters, size limits and separate Commons screening, but these controls do not guarantee that all sensitive content is excluded. Confirm your deployed version and review the actual envelope.

Check whether federation is enabled in your local instance and workspace configuration. What ends up in a snapshot is determined by your local instance, so treat the contents as your responsibility: do not place regulated or identifiable data into the structures that get synced.

Snapshot envelopes are stored in Google Cloud Storage; their metadata is stored in the database.

5. Public federation statistics

The Service publishes aggregate federation statistics. Your organization is included only if it has given publicity consent, which is recorded together with the time and source of that consent. Published figures are aggregated and subject to the publication threshold. Aggregation reduces disclosure risk; it is not a guarantee against identification in every context. You can withdraw consent by contacting us.

6. How we use what we collect

  • To authenticate you and enforce per-organization access.
  • To route, meter, and bill gateway usage, and to enforce quotas and credits.
  • To merge federated knowledge and report on merges.
  • To operate, secure, debug, and improve the Service.
  • To contact you about the Service, including changes that affect you.

7. Who we share it with

We use a small number of processors, each acting on our instructions:

  • Google Cloud Platform — hosting (Cloud Run), the database (Cloud SQL), object storage (Cloud Storage), and secret management. Infrastructure is currently in the us-central1 region.
  • Google Sign-In — authentication. We receive your profile; Google receives the fact that you signed in.
  • Google Vertex AI and Google AI — the upstream model providers the gateway proxies to. Your prompt content is transmitted to them to be answered, subject to their terms. We do not retain it.
  • Stripe — payment processing where billing applies. Card details go to Stripe directly; we store only a customer identifier and never see card numbers.

We also disclose data where we are legally required to, or to protect the rights, safety, or property of users or the Service.

8. Where your data is held

Infrastructure is hosted on Google Cloud Platform in the us-central1 region in the United States. If you are outside the United States, using the Service involves transferring your data there.

9. Retention and deletion

  • Account and organization records are kept for as long as the organization is active. Deletion is recorded with a timestamp so that billing and audit history stays intact.
  • Usage logs and billing ledger entries are retained as financial records; they are deliberately protected against cascading deletion so that a catalogue change cannot erase billing history.
  • Snapshot envelopes are retained until deleted by you or by us at your request.

To request export or deletion of your organization's data, contact support@nexitia.ai. We will confirm your authority to make the request before acting on it.

10. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal data, to object to certain processing, and to complain to a data protection authority. Exercise any of these by contacting support@nexitia.ai.

11. Cookies and local storage

We do not use advertising or third-party tracking cookies.

  • Session cookie. Signing in sets a NextAuth session cookie. It is required for the Service to work; clearing it signs you out.
  • Local storage. Your light/dark theme preference is stored in your browser and never sent to us.

12. Security

Secrets are held in Google Secret Manager rather than in configuration or source. All traffic is served over HTTPS with Google-managed certificates. Database credentials are rotatable and access to production is restricted. API keys are scoped per organization and can be rotated by you at any time.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to support@nexitia.ai rather than disclosing it publicly, and we will work with you on it.

13. Children

The Service is for research and professional use and is not directed at children under 16. We do not knowingly collect their personal data.

14. Changes to this policy

We may update this policy. The revision date at the top of this page always reflects the current version, and material changes will be notified through the Service.

15. Contact

Questions, requests, or complaints about privacy: support@nexitia.ai