Privacy Policy
Genexti Privacy Policy
This Privacy Policy explains how Genexti ("Genexti", "we", "us", "our"), operating the Genexti platform ("Genexti", "Service"), collects, uses, stores, shares, and deletes information, including data accessed through Google APIs. It applies to visitors, registered users, and workspace administrators of Genexti's website builder, industry management systems, AI Code Fixer, and workflow automation products.
If you do not agree with this Policy, please do not use the Service. By creating an account or connecting a third-party account (including Google), you agree to the practices described here.
1. Information We Collect
1.1 Information you provide directly
- Account data: name, email address, password (stored as a salted hash), company/workspace name.
- Billing data: plan tier, billing address, and transaction records. Full card numbers are handled by our payment processor and are never stored on our servers.
- Content you create: websites, pages, templates, management-system records (e.g., School ERP data), workflow configurations, and code submitted to the Code Fixer.
- Support communications you send to us.
1.2 Information collected automatically
- Usage and log data: IP address, browser/device type, pages viewed, timestamps, and error logs, used for security, debugging, and service improvement.
- Cookies and similar technologies, used for authentication (session cookies), preference storage, and basic analytics.
1.3 Google user data (via Google OAuth)
When you connect a Google Account to power a Genexti workflow, we request only the specific Google API scopes required for the feature you turn on, and never more than that:
- Gmail (gmail.send) — used solely to send email messages that you explicitly configure inside a Genexti workflow (e.g., an automated notification). We cannot read your inbox and do not request read access.
- Google Calendar (calendar.events) — used solely to create, update, or remove calendar events that your workflow is configured to manage on your behalf.
- Google Sheets (spreadsheets) — used solely to read or write the specific spreadsheet(s) you connect, in order to move data into or out of a workflow you build.
Each scope is invoked only at the moment your workflow runs the corresponding step; Genexti does not poll, mine, or background-scan connected Google accounts.
2. Google API Services User Data Policy — Limited Use Disclosure
Genexti's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practical terms, this means:
- Google user data obtained through the scopes above is used only to provide or improve user-facing features of Genexti that you have directly requested — never for advertising.
- Google user data is never sold, and is never shared with third parties except the sub-processors listed in Section 5, under confidentiality obligations equivalent to this Policy.
- Human access to Google user data is limited to what is necessary for security, legal compliance, or with your consent (e.g., a support request), and is logged.
3. How We Use Information
- Provide, operate, and maintain the Service (including multi-tenant hosting, subdomain routing, and custom domains).
- Execute the specific workflow actions you configure that touch Google data (sending an email, creating an event, updating a sheet).
- Process payments and manage subscriptions.
- Monitor for fraud, abuse, and security incidents.
- Provide customer support and respond to inquiries.
- Comply with legal obligations.
4. AI and Machine Learning Use of Data
Genexti's Code Fixer and related AI-assisted features are powered by large-language-model APIs, including Google's Gemini API and/or other third-party AI providers disclosed to Google upon request. The following restrictions apply to all such integrations:
- Google user data (raw, aggregated, or derived) is never used, transferred, or sold to train, retrain, fine-tune, or otherwise improve any foundational or general-purpose machine learning model — whether operated by Genexti or by a third-party AI provider.
- When Google user data is passed to a third-party AI API to generate a response (for example, using Sheets data to draft a workflow), that data is transmitted solely to produce the immediate output for your request, under that provider's standard commercial API terms, and is not retained by the provider for model-training purposes.
- Genexti does not run self-hosted or offline copies of any third-party model; all AI processing occurs through the providers' hosted, no-training-on-API-data commercial tiers.
- Genexti maintains an internal, up-to-date list of every third-party AI integration and the data each one receives, and will provide this list to Google or to you upon request.
Limited Use Compliance Statement: Genexti's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, across all AI-assisted features described above.
5. How We Share Information
We do not sell personal data or Google user data. We share information only with:
- Infrastructure and sub-processors: our hosting provider (Contabo VPS), payment processor, and email/SMS delivery providers, each bound by contract to protect the data and to use it only to provide services to us.
- AI providers, strictly as described in Section 4, and strictly limited to the data needed for the feature you triggered.
- Legal and safety: where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Genexti, our users, or the public.
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to this Policy continuing to apply to previously collected data.
6. Data Protection Mechanisms for Sensitive Data
Genexti applies the following technical and organizational measures to protect account credentials, OAuth tokens, and other sensitive data:
- Encryption in transit: all traffic between your browser, Genexti servers, and Google's APIs is encrypted using TLS/HTTPS.
- Encryption at rest: passwords are stored as salted, one-way hashes; OAuth access and refresh tokens are stored encrypted and are never exposed to client-side code or logs.
- Access controls: production database and server access is restricted to authorized personnel on a least-privilege basis, gated behind authenticated access to our infrastructure.
- Scope minimization: we request only the Google API scopes strictly required for the feature you enable, and re-request consent if a feature ever needs an additional scope.
- Network hardening: our backend runs behind a reverse proxy (Nginx) with a managed process supervisor (PM2), kept current with security patches for the OS, Node.js runtime, and dependencies.
- Monitoring and incident response: server logs are monitored for anomalous access, and we maintain a process to investigate and, where required by law, notify affected users of any confirmed data breach without undue delay.
7. Data Retention and Deletion
7.1 General retention
We retain account and content data for as long as your account is active, and for a limited period afterward as needed for legal, billing, or security purposes, after which it is deleted or anonymized.
7.2 Google user data specifically
- OAuth tokens and any Google data cached to run a workflow are retained only for as long as the corresponding integration remains connected and active in your account.
- If you disconnect a Google integration in your Genexti settings, or revoke Genexti's access from your Google Account permissions page, we delete the associated OAuth tokens and any locally cached Google user data from our active systems within 30 days, and from encrypted backups within 90 days.
- If you delete your Genexti account, all associated Google user data is deleted from active systems within 30 days and purged from backups within 90 days, except where retention is required by law.
- You may request immediate deletion of your Google-connected data at any time by emailing privacy@genexti.com; we will confirm deletion in writing.
8. International Data Storage
Genexti's infrastructure is hosted on servers operated by our hosting provider and may process data in locations outside your country of residence. We take contractual and technical steps to ensure data receives a comparable level of protection wherever it is processed.
9. Your Rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@genexti.com. You can revoke Genexti's access to your Google Account at any time at myaccount.google.com/permissions.
10. Children's Privacy
Genexti is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified via email or an in-app notice, and the "Effective date" above will be updated. Continued use of the Service after changes take effect constitutes acceptance.
12. Contact Us
Questions about this Policy or Genexti's handling of Google user data can be sent to privacy@genexti.com.