Template for review. This document reflects how the service is built and operated, but it is a starting draft — have it reviewed by qualified counsel before you rely on it. It is not legal advice.

Privacy Policy

Effective 2026-09-26 · Nexus AI Solutions LLC

1. Overview

This Policy explains what we collect, how we use it, and the choices you have. Our core design principle is that your content stays private: the Service runs on private, US-hosted GPUs, and your prompts and documents are not used to train shared models.

2. Information we collect

3. Customer content

Your prompts, uploaded documents, fine-tuning data, and generated outputs ("Customer Content") are processed to deliver the Service to you and are stored in your isolated tenant. We do not sell Customer Content, do not use it to train shared or foundation models, and restrict staff from reading it. Fine-tuning runs only on your instruction and produces an adapter that stays in your tenant.

4. How we use information

We do not use your information for third-party advertising.

5. Where your data lives

Compute and storage are located in the United States. We launch US-only; customers with in-region requirements outside the US should ask about a dedicated or on-prem deployment.

6. Service providers (sub-processors)

These providers process limited data only to perform their function. We will keep this list current as it changes.

7. Retention

Account and billing records are kept for as long as your account is active and as required for tax and accounting. Audit logs are retained per your plan and regulatory needs (for example, 7 years for SEC/FINRA contexts, 6 years for HIPAA), configurable for dedicated tenants. On termination, Customer Content may be exported within 30 days and is then deleted.

8. Security

Safeguards include per-tenant isolation, encryption of stored data, air-gapped compute nodes with no default public egress, encrypted ephemeral scratch that is wiped at the end of each job, and access controls that prevent cross-tenant access. Our SOC 2 program is in progress. No system is perfectly secure.

9. Regulated data (HIPAA / GLBA)

If you process protected health information, a Business Associate Agreement must be in place first; GLBA service-provider terms are available for financial firms. Do not submit regulated data without the corresponding agreement.

10. Your choices & rights

You may access, correct, export, or delete your account data by contacting us or using the portal. Depending on where you live, you may have additional rights under applicable law; we will honor rights that apply to you.

11. Cookies

Our marketing site uses minimal, essential storage. The tenant portal stores a session token in your browser so you stay signed in; it is not used for cross-site tracking or advertising.

12. Children

The Service is for organizations and adults; it is not directed to children and we do not knowingly collect data from anyone under 18.

13. Changes

We may update this Policy; material changes will be posted here with a new effective date and, where appropriate, notified by email.

14. Contact

Privacy questions or requests: contact us.