How NULX handles your data
This policy explains what NULX collects, why, and how you can control it. It reflects how the service actually operates today, not a generic template.
Effective
1. Information we collect
We collect the minimum information needed to provide the service, operate your account, and respond to inquiries.
- Account credentials: your email address, and how you sign in - either a one-time code we email you (we only ever store a hashed, expiring digest of it, never the code itself) or your verified Google account identifier if you use Google sign-in
- Your organization/tenant name and a separate billing email address for invoices and payment notices
- Video processed by you or your team plus related metadata. Permanent sources and outputs live in customer R2, while managed transcoding temporarily processes media on a NULX worker
- Usage metering data for encoding, automatic captions, and internal storage or delivery measurements
- Audit logs of security- and billing-relevant actions, such as logins, API key creation, plan changes, and cancellation requests
- Operational request analytics: the account or authenticated user, requested feature, timestamp, HTTP result, server processing time, reported device/OS category, and referring domain. These records do not contain passwords, API tokens, request bodies, full referring URLs, or screen recordings; they use a separately configured retention period of 30 days by default
- Webhook endpoint URLs you configure, if you use the webhooks feature to receive event notifications
- IP addresses, captured for rate limiting (abuse prevention) and recorded in audit/session logs for security purposes
2. Cookies
We use first-party cookies for login, form security, and language preferences. Operational request analytics uses server-side request records and does not create a separate visitor-tracking cookie. We do not use advertising or third-party tracking cookies.
- Form-security session cookie (_control_plane_session): may be set before login to prevent forged requests and carry page notices; this cookie alone does not mean you are signed in
- Login cookie (session_id): keeps you signed in. It is httponly (not readable by page scripts) and expires after 14 days of inactivity or 90 days total, whichever comes first
- Locale preference cookie (nulx_locale): remembers your selected language for one year
- Operator session cookie: used only by NULX staff on internal operations tooling, not set for customer accounts
- If we ever add analytics or advertising cookies in the future, we will update this section and add a consent banner before doing so.
3. Why we use it
Collected data is used for service delivery, account security, billing, customer support, and product improvement.
- Service operations, including authentication and session management
- Billing and payment processing
- Support and follow-up
- Security monitoring and abuse prevention
- Product improvement
4. Processors and subprocessors
We share the minimum data needed with the following processors to operate the service.
- Cloudflare R2: permanent storage of sources and outputs in the customer-connected bucket and Cloudflare-based playback paths
- Groq: transcription of a low-bitrate audio extract when the customer enables automatic captions (United States)
- Email provider (SMTP): transactional email, such as billing and account notifications
- Sentry: error tracking, only when configured for the environment
5. Where data is hosted
Application data is hosted on commercial VPS and database infrastructure used by NULX. Permanent sources and streaming outputs live in customer-connected Cloudflare R2, while managed workers temporarily process media. R2 Location Hint is not a residency guarantee, and automatic captions send an audio extract to Groq in the United States.
6. Retention
Data is retained only as long as needed for service and legal obligations. Audit events are retained per our configured retention window for security and accounting review. Database backups are retained per our backup retention window and may contain data for that additional period after deletion from the live database.
7. Your rights
You can request access to, correction of, or deletion of your personal data through /contact. After verifying the request, we explain its scope and expected completion date. Rights available under applicable data-protection law are not limited by this policy.
8. Deletion procedure
Canceling an account stops new uploads and write actions but does not automatically delete data. After a separate deletion request is verified, we follow the documented procedure for account data and customer-storage objects NULX can access and provide an expected completion date. Customers can revoke the R2 token or delete objects directly. Finalized billing records and backups may remain where retention is required.
9. Legal basis, entity, and governing law
Free signup is available, and paid plans are billed by invoice. Account and billing data are processed to provide the requested service. Pricing and payment conditions are shown on the pricing and billing screens; enterprise data-processing terms are agreed separately.
10. Contact
For privacy questions or data-subject requests, contact us via /contact or email contact@nulx.dev.