Privacy Policy
Last updated: December 8, 2025
Introduction
At Nexable ("we," "us," or "our"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered course creation platform.
By accessing or using Nexable, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
1. Information We Collect
1.1 Personal Information
When you create an account, we collect:
- Email address
- Full name (optional)
- Profile information you choose to provide
- Authentication data (password, OAuth tokens for Google sign-in)
1.2 Content Information
When you use our services, we collect:
- Course content you create (titles, prompts, lessons, chapters)
- PDF files you upload for course generation
- Course metadata (creation dates, difficulty levels, chapter counts)
- Progress tracking data for courses you're enrolled in
1.3 Usage Information
We automatically collect information about how you use Nexable:
- Credit usage and transaction history
- Features accessed and actions performed
- Device information (browser type, operating system)
- IP address and geographic location
- Referral sources and campaign data
1.4 Payment Information
If you purchase credits or subscriptions:
- Payment information is processed securely by Lemon Squeezy
- We do not store full credit card numbers
- We retain transaction IDs and payment history for accounting purposes
2. How We Use Your Data
We use the information we collect for the following purposes:
2.1 Service Delivery
- Generate AI-powered courses based on your inputs
- Process and store your created content
- Manage your credits and subscriptions
- Enable course sharing and collaboration features
2.2 Platform Improvement
- Analyze usage patterns to improve our AI models
- Monitor system performance and reliability
- Debug technical issues and enhance user experience
- Develop new features based on user needs
2.3 Communication
- Send account-related notifications and updates
- Respond to your support requests and feedback
- Share product updates and new features (with your consent)
- Send referral rewards and credit notifications
2.4 Legal Compliance
- Comply with legal obligations and regulations
- Enforce our Terms of Service
- Protect against fraudulent or illegal activity
- Resolve disputes and enforce our agreements
3. Data Storage & Security
3.1 Data Storage
Your data is stored securely using:
- Supabase: For user authentication, profiles, and course data (hosted on AWS with EU data residency options)
- Vercel: For application hosting and static assets
- Third-party AI providers: For course generation (prompts and content are processed but not permanently stored by AI providers)
3.2 Security Measures
We implement industry-standard security measures:
- End-to-end encryption for data in transit (HTTPS/TLS)
- Encryption at rest for stored data
- Row-level security (RLS) policies in our database
- Regular security audits and updates
- Secure password hashing (bcrypt)
- OAuth 2.0 for third-party authentication
3.3 Data Retention
We retain your data for as long as your account is active or as needed to provide services. When you delete your account, we permanently delete your personal information and course content within 30 days, except where we're required to retain data for legal or regulatory purposes.
5. Your Rights (GDPR & Privacy Laws)
Depending on your location, you have certain rights regarding your personal data:
5.1 Access & Portability
- Request a copy of your personal data
- Export your courses and content in PDF or JSON format
5.2 Correction & Deletion
- Update or correct your account information at any time
- Delete your account and associated data from Settings
5.3 Objection & Restriction
- Object to certain data processing activities
- Request restriction of processing in specific cases
5.4 Withdraw Consent
You can withdraw consent for marketing communications at any time by adjusting your account settings or clicking "unsubscribe" in emails.
7. Children's Privacy
Nexable is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@nexable.net.
8. International Data Transfers
Nexable is based in Estonia (EU). If you access our services from outside the EU, your data may be transferred to and processed in the EU and other countries. We ensure appropriate safeguards are in place for international data transfers in compliance with GDPR and other applicable laws.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a prominent notice on our platform. Your continued use of Nexable after changes become effective constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or want to exercise your rights, please contact us:
Nexable
Email: privacy@nexable.net
Address: Tallinn, Estonia
Response time: We aim to respond to all privacy requests within 30 days.