Privacy Policy
This policy explains what information Nexa Office collects, why, and how it's used — including information accessed through Gmail and other mail providers you choose to connect. It's written to be read in full, but the summary in each section heading should get you to the part you need quickly.
01 Overview
Nexa Office ("Nexa Office", "we", "us") is a workspace that lets an account owner connect multiple email accounts they are authorized to access, view them in one organized interface, and optionally grant limited, controlled access to team members. This policy covers the web app and the Android app.
We built Nexa Office around a simple principle: connecting an inbox to Nexa Office should never mean handing over your email password to anyone, including us. Access is granted through each provider's own sign-in and permission screen (for example, Google's OAuth consent screen), and can be revoked at any time — by you, from inside Nexa Office, or directly from your provider's account settings.
02 Data we collect
Account information
Name, email address, password hash (for accounts not using a third-party sign-in), and basic workspace settings.
Connected mail account data
When you connect a mail account, we request permission to access only what Nexa Office's features require — typically message headers, message content, labels, and folder/read state — so it can be displayed and organized inside your workspace. We do not request access beyond what a given feature needs.
Authorization tokens
OAuth access and refresh tokens issued by your mail provider, stored encrypted, used to keep a connected account synced without ever seeing or storing your provider password.
Team & permission data
If you invite team members, we store their account details, the specific inboxes and actions you've granted them, and a log of actions taken inside shared inboxes.
Usage & device data
Basic technical data such as browser or device type, IP address, and in-app usage events, used for security, reliability, and improving the product.
03 Google user data & Limited Use
Nexa Office's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Gmail data is used only to provide and improve the user-facing features you interact with directly inside Nexa Office — displaying, organizing, searching, and (where you grant the permission) sending or modifying messages on your behalf.
- Gmail data is never used to serve advertising, and is never sold, rented, or shared with data brokers.
- Gmail data is not used to train generalized AI or machine-learning models that are not directly related to providing or improving Nexa Office's own features.
- Human access to Gmail data is limited to circumstances required by law, to maintain the security of the system, to investigate abuse, or with your explicit consent (for example, when you contact support about a specific message).
04 How we use data
- To operate core functionality: syncing, displaying, organizing, and letting you act on connected inboxes.
- To power organization features (categorization, priority signals, and — where enabled — AI-assisted summaries).
- To enforce the access rules an account owner sets for team members.
- To secure accounts, detect abuse, and maintain reliability.
- To communicate service updates, security notices, and, only with your consent, product news.
05 Team & VA access
Team members never see the account owner's mail provider credentials and never complete a separate OAuth authorization for inboxes they don't own. Instead, the account owner authorizes each connected inbox once, and grants specific team members read and/or action permissions inside Nexa Office. Nexa Office enforces those permissions on the backend, and the account owner can view an activity log of actions taken by team members and revoke access at any time.
07 Storage & security
Authorization tokens are encrypted at rest and never stored in plain text. Access to production data is limited to personnel who need it to operate or support the service, and is logged. We use industry-standard transport encryption (TLS) for data in transit. No system is perfectly secure, and we can't guarantee absolute security, but we treat connected-account data with the same level of care we'd want applied to our own inboxes.
08 Retention & deletion
We retain synced message data and tokens for as long as an account remains connected, so the workspace stays usable. Disconnecting a mail account revokes its token and queues the associated synced data for deletion. Deleting your Nexa Office account removes your profile, team assignments, and synced data within a reasonable operational window, except where we're required to retain limited records for legal, security, or accounting purposes.
09 Your rights & choices
- Disconnect any mail account at any time, from Nexa Office or your provider's own account settings — this immediately revokes Nexa Office's token for that account.
- Request a copy of the personal data we hold about you.
- Request correction or deletion of your data.
- As a team member, ask the workspace owner to review or revoke the access they've granted you.
To exercise any of these, reach out using the contact details below.
10 Children's privacy
Nexa Office is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect data from children.
11 International transfers
Data may be processed and stored in countries other than your own. Where required, we rely on appropriate safeguards for cross-border transfers, such as standard contractual clauses or an equivalent legal mechanism.
12 Changes to this policy
If we make material changes to this policy, we'll update the date above and provide reasonable notice — for example, an in-app notice or email — before the changes take effect.
13 Contact
Questions about this policy or your data can be sent to: