NexoToken privacy policy
The privacy policy explains account information, usage data, and logs processed to provide the service, together with requests users may make.
- Effective date
- 2026-08-11
- Last updated
- 2026-08-11
1. Scope
This policy explains how NexoToken handles service-related information when you visit the website, register or manage an account, use model interfaces, or contact support. Third-party websites and other services you connect independently follow their own privacy rules.
2. Information we process
Depending on the functions you use, information may include account identifiers and security information, top-up and order records, interface call times and usage, IP addresses and necessary device or access logs, and support materials you choose to provide.
To complete model requests, the platform must transmit and process submitted request content and returned content. Avoid placing unrelated sensitive personal information in prompts, attachments, or support materials.
3. Purposes of processing
Information is used to create and protect accounts, complete interface requests, calculate usage and transactions, troubleshoot issues, answer support requests, prevent fraud and abuse, improve functions, and meet applicable legal obligations. The platform does not arbitrarily expand processing to purposes unrelated to the service.
4. Retention and deletion
Information is retained only as long as needed to provide services, maintain security, handle disputes, and meet applicable legal obligations. Periods vary by account status, transaction records, log purpose, and legal requirements. When a period ends, information is deleted, anonymized, or retained as legally required under applicable procedures.
5. Security measures
The platform uses transmission protection, access controls, credential protection, log review, and organizational measures appropriate to risk. No system can guarantee absolute security. You should use a unique strong password, limit key permissions, and rotate or disable credentials promptly after detecting unusual activity.
6. Your rights and choices
To the extent provided by applicable law, you may request access, correction, or deletion of relevant personal information, withdraw particular consent, close an account, or raise questions and complaints about processing. Some requests require identity verification, and legal retention, transactions, security investigations, or disputes may limit immediate deletion.
7. Third-party processing principles
Information may be processed by service processors performing model requests, payments, infrastructure operations, or necessary support. The platform transfers information only as needed for the function and uses access restrictions, contracts, or other safeguards as applicable.
The platform does not sell personal information to unrelated parties. Information may be disclosed or transferred where legally required, necessary to protect users and the platform, or part of a lawfully conducted business change.
8. Cookies and local storage
The site may use cookies or browser local storage to maintain sign-in state, remember language and theme preferences, and support necessary functions. You can clear or restrict this data in your browser, but sign-in and some personalized functions may then stop working correctly.
9. Minors
The service is primarily intended for developers and teams with the legal capacity to use it. Minors should use it only with guardian guidance and as permitted by applicable law. A guardian who believes a minor's information was handled improperly can contact us through the official support entry.
10. Policy changes
The platform may update this policy when functions, processing, or legal requirements change and will show the updated date on this page. Important changes that materially affect your rights will be highlighted through the page or account where reasonably practical.
11. Contact us
To exercise privacy rights, ask about this policy, or report a security issue, submit a request through the official NexoToken support entry. Identify the request type and related account, but do not send passwords, complete API keys, or other unnecessary sensitive information.