Privacy Policy
Last updated: September 5, 2026
1. Who we are and what this covers
Nexus AI is operated by BreakPoint Systems (“we”, “us”). This policy explains what we collect, why, and who we share it with, for the service at nexusai.breakpointsystems.com.
It covers two different groups of people, and the distinction matters:
- Users — people with a login: the account owner and invited team members.
- Contacts — people whose details a user enters or imports into the CRM: leads, customers, prospects. Contacts do not have accounts and generally have no direct relationship with us.
We hold contact data on behalf of the user’s organisation. Under data protection law they are generally the controller of it and we are the processor. If you are a contact and want your data corrected or removed, the fastest route is the business that holds your record; you can also reach us at the address in Section 10 and we will pass it on.
2. What we collect
From users:
- Account details: name, email address, password (stored hashed by our authentication provider — we never see it in plain text), profile photo if set.
- Workspace settings and preferences.
- Usage and diagnostic records: sign-in times, actions taken in the app, error logs.
About contacts — whatever a user enters or imports:
- Name, email address, phone number, business name.
- Postal address, date of birth, and any custom fields the workspace defines.
- Notes, tasks, deals, appointments, quotes, and activity history.
- Message history for channels in use: emails sent and received, chat transcripts, call summaries and transcripts.
- Marketing attribution captured on public form submissions: UTM parameters, referring page, landing page, and click identifiers such as
fbclidorgclid. - Approximate location derived at form submission from IP address or phone country code, used to place a pin on the leads map.
Automatically: IP address, browser and device information, and timestamps, in server logs.
What we do not do: we do not run advertising or analytics tracking scripts on this deployment. No Meta Pixel, no Google Tag Manager, no third-party analytics are configured. We do not sell personal information, and we do not use customer data to train AI models.
3. How we use information
- To provide the Service: storing records, sending the messages you ask us to send, running scheduled work, powering search and reporting.
- To authenticate users and keep accounts secure.
- To generate AI output you request — replies, summaries, drafts, images.
- To diagnose faults and improve reliability.
- To contact users about the Service: billing, security, and material changes.
- To meet legal obligations and enforce our Terms.
4. Who we share it with
We share data with service providers who process it on our behalf. As of this policy’s date these are the providers actually in use:
| Provider | What it processes | Why |
|---|---|---|
| Google Cloud / Firebase | All stored records, credentials, files | Database, authentication, storage |
| Vercel | Requests and server logs | Application hosting |
| Resend | Email content, sender and recipient addresses | Sending and receiving email |
| OpenRouter | Message content sent for AI processing | AI assistant and agent replies |
| Google Gemini | Image prompts | AI image generation |
| Cloudinary | Uploaded and generated images | Image hosting and transformation |
| Retell | Phone numbers, call audio, transcripts | AI voice calling |
| Cal.com | Booking details, attendee name and email | Calendar scheduling |
| Blotato | Post content and images | Social media publishing |
| Mapbox | Location coordinates and search text | Maps and geocoding |
| Upstash | Job payloads referencing record IDs | Scheduled and queued background work |
Each provider receives only what its function requires, and is bound by its own terms. Features not enabled on a workspace send nothing.
We may also disclose information where required by law, or to protect our rights, safety, or property — and we will tell the affected user unless legally prevented from doing so.
5. Where data is stored
Data is stored in our Google Cloud / Firebase project and processed in the United States. Some providers listed above may process data in other countries in the course of delivering their service.
6. Retention
- Active records are kept for as long as the workspace is active.
- After account termination, data is retained for 30 days so it can be recovered if the closure was a mistake, then deleted from active systems. Backups cycle out on their own schedule.
- Message and activity history is kept for as long as the associated contact record exists.
- Server logs are kept for a limited period for security and debugging.
- Deleting a contact in the app removes their record and its associated notes, activities, and messages.
Earlier deletion is available on request — see Section 10.
7. Security
- Data is encrypted in transit (HTTPS) and at rest by our infrastructure providers.
- Access is controlled by workspace membership and role. Users only see the workspaces they are a member of.
- Credentials for integrations are stored server-side in locations that are not readable by any browser client.
- Passwords are handled by our authentication provider and are not visible to us.
No system is perfectly secure. If a breach affects your data, we will notify you without undue delay.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent.
- Users: most of this is self-service in the app; anything else, contact us.
- Contacts: contact the business holding your record, or reach us and we will forward your request to them.
We do not sell personal information or share it for cross-context behavioural advertising.
9. Changes to this policy
We may update this policy. Material changes will be notified by email or in the app before taking effect. The current version is always the one on this page, dated above.
10. Contact
BreakPoint Systems
hello@breakpointsystems.com
nexusai.breakpointsystems.com
See also our Terms of Service.