📧 Questions? Contact us at [email protected]
Welcome to BMB Nexus ("we," "our," or "us"). We are committed to protecting your privacy and handling your data in an open and transparent manner.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our AI-powered marketing automation platform.
Who We Are:
When you create an account, we collect:
Payment processing is handled by Stripe. We do NOT store your credit card numbers or payment details directly. We only retain:
When you use our platform to create content, we store:
When you connect social media accounts via OAuth:
To improve our service, we automatically collect:
If you connect the Telegram bot integration:
When you upload documents to Nexus (your AI brain):
We use your data for the following purposes:
Your content is NEVER used to train public AI models. However, third-party AI providers (OpenAI, Anthropic, etc.) may process your prompts according to their own privacy policies. We use enterprise API plans that do NOT train on customer data.
| Data Type | Storage Location | Encryption |
|---|---|---|
| Account & User Data | PostgreSQL Database | ✅ Encrypted at rest |
| Content & Campaigns | PostgreSQL Database | ✅ Encrypted at rest |
| Media Files (Images/Videos) | Google Drive | ✅ Google encryption |
| OAuth Tokens | PostgreSQL (encrypted) | ✅ AES-256 encryption |
| RAG Memory / Knowledge Base | Qdrant Vector DB | ✅ Encrypted at rest |
| Session Cache | Redis (temporary) | ✅ Encrypted in transit |
Social media access tokens (LinkedIn, Instagram, etc.) are encrypted using industry-standard AES-256 encryption before storage. We never see your platform passwords - OAuth flow is handled directly between you and the social platform.
| Service | Purpose | Privacy Policy |
|---|---|---|
| OpenAI (GPT-4) | Text generation, AI prompts | View Policy |
| Anthropic (Claude) | AI agents, strategic planning | View Policy |
| Runway ML | Video generation | View Policy |
| Fal.ai | AI image/video generation | Enterprise API (no training) |
| Kie.ai (Sora) | Advanced video generation | Enterprise API (no training) |
We integrate with (via OAuth - you control access):
We ONLY access what you explicitly authorize. You can revoke access anytime.
When you use AI features, your prompts are sent to third-party AI providers (OpenAI, Anthropic, etc.). We use enterprise API agreements that prohibit training on customer data. However, you should review their privacy policies linked above.
Under the General Data Protection Regulation (GDPR), you have the following rights:
You can request a copy of all personal data we hold about you.
How: Account Settings → Privacy → "Download My Data"
You can correct inaccurate or incomplete data.
How: Edit directly in Account Settings or contact support
You can request deletion of your account and all associated data.
How: Account Settings → Privacy → "Delete My Account"
Timeline: Complete deletion within 30 days
You can export your data in a machine-readable format (JSON).
Includes: Content, campaigns, analytics, settings
How: Account Settings → Privacy → "Export Data"
You can limit how we process your data.
How: Contact [email protected] with your request
You can object to processing for specific purposes (e.g., analytics).
How: Account Settings → Privacy → "Opt-out of Analytics"
You can revoke social media platform connections anytime.
How: Account Settings → Platform Connections → "Disconnect"
We use browser local storage for:
You can clear: Browser Settings → Clear Site Data
BMB Nexus is based in the European Union and prioritizes EU data protection standards.
Some AI services (OpenAI, Anthropic) may process data in the US. These providers:
BMB Nexus is not intended for users under 16 years old.
Age Verification: By creating an account, you confirm you are 16+ years old.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Until account deletion | Service provision |
| Content & Campaigns | 12 months (configurable) | User access, analytics |
| Analytics Data | 24 months | Platform improvement |
| Billing History | 7 years | Legal/tax compliance |
| Deleted Data | 30 days (soft delete) | Recovery window |
Data may be retained longer if:
We may update this Privacy Policy from time to time to reflect:
If you disagree with updated terms:
Previous versions available on request: [email protected]
📧 Email: [email protected]
⏱️ Response Time: Within 30 days (GDPR requirement)
🆘 Urgent Issues: [email protected] (24-48 hour response)
For GDPR-related inquiries, contact our Data Protection Officer:
Email: [email protected]
You have the right to lodge a complaint with your local data protection authority if you believe we've violated GDPR.
EU Users: Find your authority at https://edpb.europa.eu
BMB Nexus
[Your Registered Business Address]
[City, Postal Code, Country]
[VAT/Tax ID if applicable]