Skip to main content
Beta Early access — Lock in $55/month for 24 months. Export your data with one command, any time.
Privacy policy

Privacy policy | Nulx

This policy explains what Nulx collects, why, and how you can control it. It reflects how the service actually operates today, not a generic template.

1. Information we collect

We collect the minimum information needed to provide the service, operate your account, and respond to inquiries.

  • Account credentials: your email address and a password, which we never store in plain text (it is hashed with bcrypt before being saved)
  • Your organization/tenant name and a separate billing email address for invoices and payment notices
  • Video content you or your team upload, plus related metadata (filename, duration, playback status)
  • Usage metering data (storage consumed, egress/bandwidth, transcoding minutes) used to calculate your bill
  • Audit logs of security- and billing-relevant actions, such as logins, API key creation, plan changes, and cancellation requests
  • Webhook endpoint URLs you configure, if you use the webhooks feature to receive event notifications
  • PayPal transaction references for completed payments and refunds; we do not receive or store your card number - PayPal handles the payment itself
  • IP addresses, captured for rate limiting (abuse prevention) and recorded in audit/session logs for security purposes

2. Cookies

We use a small number of strictly necessary cookies to run the service. We do not use analytics, advertising, or third-party tracking cookies today, so no cookie-consent banner is shown.

  • Session cookie: keeps you signed in. It is httponly (not readable by page scripts) and expires after 14 days of inactivity or 90 days total, whichever comes first
  • Locale preference cookie (sstream_locale): remembers your selected language for one year
  • Operator session cookie: used only by Nulx staff on internal operations tooling, not set for customer accounts
  • If we ever add analytics or advertising cookies in the future, we will update this section and add a consent banner before doing so.

3. Why we use it

Collected data is used for service delivery, account security, billing, customer support, and product improvement.

  • Service operations, including authentication and session management
  • Billing and payment processing
  • Support and follow-up
  • Security monitoring and abuse prevention
  • Product improvement

4. Processors and subprocessors

We share the minimum data needed with the following processors to operate the service.

  • PayPal: payment processing for subscriptions and usage charges
  • Creem: secondary payment processing for customer checkout, where applicable
  • Cloudflare R2: storage and delivery of uploaded video content
  • Email provider (SMTP): transactional email, such as billing and account notifications
  • Sentry: error tracking, only when configured for the environment

5. Where data is hosted

Application data (database) and uploaded video content are hosted on commercial cloud infrastructure (a VPS provider and Cloudflare R2 object storage). [LEGAL REVIEW: confirm and state the specific hosting region(s) once fixed - today this may span US and EU infrastructure depending on provider defaults] as we do not yet commit to a single fixed data region.

6. Retention

Data is retained only as long as needed for service and legal obligations. Audit events are retained per our configured retention window for security and accounting review. Database backups are retained per our backup retention window and may contain data for that additional period after deletion from the live database.

7. Your rights

You can request access to, correction of, or deletion of your personal data by contacting us via /contact. We aim to respond to and complete verified requests within 30 days. This includes the rights commonly recognized under data protection laws such as the GDPR (access, rectification, erasure, and objection), regardless of where you are located.

8. Deletion procedure

When we receive and verify a deletion request - including a self-serve cancellation from your account settings - deletion is carried out by an operator following a documented internal procedure, not by an automated self-service action, and is completed within 30 days of verification. This includes removing account records and stored video content, while retaining what we are legally required to keep (for example, finalized billing records for accounting and tax purposes) in anonymized form where possible. Deleted data may still exist in database backups until those backups are rotated out per our backup retention window. Existing public video embeds may continue to play until the deletion process completes.

9. Legal basis, entity, and governing law

[LEGAL REVIEW: this section requires counsel input before launch] Processing is based on contract necessity (providing the service you signed up for), legitimate interest (security and abuse prevention), and consent where required (e.g. marketing, if introduced later). [LEGAL REVIEW: insert the operating legal entity name and registered address here.] [LEGAL REVIEW: insert governing law and jurisdiction for disputes.] A data processing agreement (DPA) is available on request for customers who require one; [LEGAL REVIEW: finalize DPA template and standard contractual clause references before offering it].

10. Contact

For privacy questions or data-subject requests, contact us via /contact or email contact@nulx.dev.