Legal · Nexus & Nexus MEC

Terms of Service & Privacy Policy

Covers both app flavors - the general-audience nexus app and the campus-gated nexus_mec app - one backend, one privacy/security architecture. Content is derived directly from the live application code and database schema.

Effective date: 14th July 2026 Terms version: 1 Prepared under: India's DPDP Act 2023, with GDPR coverage where it asks for more
Part One

Terms of Service

Applies to the nexus app and the nexus_mec campus flavor together, unless a section says otherwise.

1Acceptance of Terms

By creating an account, browsing, or otherwise using Nexus - the mobile app, its backend APIs, the trusted-contact web portal, and related services - you agree to be bound by these Terms of Service and by our Privacy Policy, incorporated by reference. If you don't agree, don't use the Service.

2Eligibility

You must be at least 18 years old to use Nexus, in either flavor. There's no upper age limit on the main nexus app; nexus_mec is additionally capped at 27, matching its campus scope. Age is self-attested at signup - a slider, not an ID check - and enforced server-side against your variant's range at every layer (API validation plus a database trigger as a backstop), but we do not verify identity or run age-estimation on photos. If you're aware of an account misrepresenting its age, report it in-app (Report → "Underage"); we act on that the same way we act on any other Trust & Safety report.

nexus_mec additionally requires a verified email address on that flavor's configured campus domain - the main nexus app has no email-domain restriction.

3Two Flavors, One Service

nexus and nexus_mec share one backend and one privacy/security architecture. A nexus_mec account can generate a one-time export code to migrate into the main nexus app; the reverse isn't supported. Your flavor determines which age range, email-domain rule, and Spotify OAuth redirect apply - it never changes how your data is stored, encrypted, or protected.

4No Passwords - How You Sign In

Nexus has no password-based login. You sign in with Google Sign-In or a passwordless one-time email code. We never ask for, store, or have access to a password for your account.

A phone number is required to complete signup - the app verifies it by SMS one-time code before it will finish creating your profile. This exists specifically to make it harder to spin up large numbers of duplicate accounts off disposable email addresses alone; it is not a login credential by itself, and sign-in itself remains Google/email-OTP only.

5Open-Source License

AGPLv3 - not the more common GPL or MIT

Nexus's source is free software under the GNU Affero General Public License v3, published at github.com/devakesu/Nexus.

  • Your freedoms: run, study, redistribute, and modify the software.
  • Copyleft, including network use: AGPLv3 closes the "hosted SaaS" loophole plain GPL leaves open - modify this software and let others use your modified version over a network, and you must make that modified source available to them too (AGPLv3 §13). You can't fold this code into a closed-source product, hosted or not.
  • "AS IS," no warranty: because the program is licensed free of charge, there is no warranty for the program to the extent permitted by law. It's provided without warranty of any kind, express or implied, including merchantability and fitness for a particular purpose. The entire risk as to quality and performance is with you.

6Hosted Service - Acceptable Use

The source is free; using our hosted instance is a privilege - one that comes with real people's intimate profile data and emergency-safety information riding on it. You agree not to:

  • Abuse the API - script, scrape, or bot past normal usage patterns, or send more requests than a human could reasonably generate.
  • Attack device/security integrity - bypass, spoof, or reverse-engineer App Check, Play Integrity, App Attest, or any anti-abuse control.
  • Attack encryption - attempt to decrypt other users' encrypted profile fields, Signal-Protocol-encrypted chat messages (we can't read them either), or Meetup Safety evidence.
  • Weaponize Meetup Safety - file a false SOS/inform alert or harass a trusted contact through the escalation/portal flow. This notifies real people who believe someone may be in danger.
  • Evade moderation - create a new account to route around a suspension, ban, or block.
  • Harass, impersonate, or endanger other users, via profile, chat, or the discovery system.
  • Upload malware or attempt to compromise our infrastructure.
  • Misrepresent your identity, age, or campus affiliation (nexus_mec).

We may suspend, restrict, or terminate access for any violation, with or without notice, per §9.

7Meetup Safety - Read This Before You Rely On It

Not a substitute for emergency services

Trusted contacts, scheduled check-ins, Silent/Loud SOS, Digital Witness recording, and the dead-man's-switch escalation are designed to make in-person meetups safer - they cannot guarantee it. You understand and agree:

  • We are not a security or emergency-response company. In immediate danger, call your local emergency number first. Nexus notifying a trusted contact is not the same as dispatching help, and there's no guaranteed response time.
  • Delivery isn't guaranteed. Alerts go out via SMS and depend on the contact's phone being reachable, Twilio's delivery, and network conditions outside our control.
  • Trusted contacts are not our agents. They're third parties you chose, not Nexus staff, and under no obligation to respond. You're responsible for choosing people who'll actually see and act on an alert.
  • Trusted contacts have their own rights. Each is notified once, with a link to a self-service, identity-verified portal to see who listed them and remove themselves permanently, any time. If they do, you're notified - check Safety Center for coverage gaps.
  • Digital Witness isn't forensic-grade evidence. Recordings are encrypted and time-stamped, but this is a personal-safety feature, not a chain-of-custody system - we make no representation about evidentiary admissibility.
  • Location accuracy depends on your device's GPS/network positioning at the time.

8Your Content

You retain ownership of what you post. By posting it, you grant Nexus a license to store, display, and process it as needed to run the Service - e.g. showing your photo to a match, running it through discovery/matching. You're responsible for having the rights to anything you upload and for it not violating §6 or applicable law.

9Suspension, Termination & Account Deletion

We may suspend or terminate access for a Terms violation, at our discretion, with or without notice. You may delete your own account any time from Settings → Delete Account - see Privacy Policy §11 for exactly what happens to your data, including the recoverable grace window and what's retained under a time-boxed legal hold for safety-incident records.

10Third-Party Services

Nexus integrates Google Sign-In, optional Spotify music-taste sync, and the other services in Privacy Policy §9. Your use of those is also subject to that provider's own terms - we're not responsible for their availability, changes, or any enforcement action against your account with them.

11Disclaimer of Warranties

Beyond the AGPLv3 disclaimer in §5, the hosted Service is provided "as is" and "as available." We don't guarantee discovery/matching will produce compatible matches, that the Service will be uninterrupted or error-free, or that any safety feature will prevent harm. Your use of the Service - including any decision to meet another user in person - is at your own risk and judgment.

12Limitation of Liability

To the maximum extent permitted by law, Nexus and its creators, maintainers, and contributors are not liable for indirect, incidental, special, consequential, or punitive damages arising from your use of the Service - including harm arising from an in-person meetup, a failed or delayed safety alert, or reliance on another user's profile information.

13Indemnification

You agree to defend, indemnify, and hold harmless Nexus's creators, maintainers, and contributors from claims, damages, and reasonable legal fees arising from (i) your use of the Service, (ii) your breach of these Terms, or (iii) your violation of any law or a third party's rights (including a campus's own policies, for nexus_mec users).

14Changes to These Terms

We version these Terms (current version: 1). When we ship a materially updated version, you'll see a full-page re-consent screen the next time you open the app - accept the update or delete your account; there's no silent-continue path. Every acceptance and decline is logged with a timestamp, visible in your own data export.

15Governing Law

These Terms are governed by the laws of India, without regard to conflict-of-law principles. Disputes are subject to the exclusive jurisdiction of the courts at Kochi, KL, India.

16Contact & Grievance Officer

For legal inquiries, Terms violations, or data requests: [email protected]. Per DPDP §13, our Grievance Officer is named in Privacy Policy §16.


Part Two

Privacy Policy

Prepared with reference to India's DPDP Act 2023 and, where it asks for more, GDPR. Every table/column name below is the literal name in our live database schema - this document can be checked against the code, not just trusted.

1Who We Are

Nexus is a social-discovery app - browse, like, match, and chat, with real in-person meetups as the point, which is why intimate profile data and physical-safety data are both first-class here, not footnotes. Under DPDP, Nexus is the "Data Fiduciary" for the data described below; you - and, in one specific case (§4), the people you list as trusted contacts - are the "Data Principal(s)."

2Information We Collect

Account & identity - sign-in via Google or passwordless email OTP (never a password); a phone number, verified by SMS one-time code as part of completing signup - an anti-abuse measure so duplicate accounts can't be created off disposable emails alone, encrypted at rest and never a login credential itself; name and self-attested age (range-checked per flavor); campus year/branch/institute name on nexus_mec (encrypted); which flavor your account is on.

Music taste (Spotify, optional) - read-only access (user-top-read, playlist-read-private, playlist-read-collaborative). We store top artists and, from playlists, track/artist names only - never album art, previews, popularity, or audio-feature analysis, per Spotify's Developer Policy. Feeds a matching-only "artist affinity" score, never shown to other users. Your refresh token is encrypted; we never see your Spotify password.

Discovery, likes, matches, reports - every pass/like/superlike/hide/block is recorded (passes auto-expire in 14 days); mutual likes become a match; reports carry a structured reason, and if you file one, your identity is stripped from what the reported user's own data export could ever surface.

Chat - end-to-end encrypted via the Signal Protocol; see the dedicated breakdown below.

Meetup Safety & emergency data - trusted contacts (name/phone, encrypted, likely non-users - see §4), SOS/check-in alerts with encrypted location, Digital Witness audio/video evidence with an encrypted decryption key, and check-in session state (battery/connection readings, escalation history).

Device & technical data - push token and platform, Play Integrity/App Attest device-attestation tokens (via Firebase App Check), and standard request metadata (IP, app version).

Support communications - your message, category, optional screenshots, and (bug reports) app version/device info.

Consent records - every accept/decline of general, special-category, or safety-data consent, with version and timestamp - included in your own data export.

What we see in chatServer-readable?
Message contentNever - Signal Protocol ciphertext only
Chat media attachmentsNever - stored as ciphertext in a private bucket
Who's talking to whom, whenYes - conversation participants & timestamps
Read receipts / online statusYes, if you leave those toggles on (default: on)
Proposed-meetup date/time/locationEncrypted at rest, operationally decryptable - needed for reminders & safety auto-configuration
Proposed-meetup title/notesNever - stays inside the linked message's ciphertext

3What We Never Collect

No server-side AI/ML content moderation, image scanning, or biometric/facial-recognition analysis on your photos - the only AI processing your photos ever undergo is the on-device aesthetic vibe-tagging in §2, which runs locally on your phone, never on our servers. No advertising trackers or third-party analytics SDKs. We do not sell your data, to anyone, for any reason.

4Non-Users: Your Trusted Contacts' Data

They never signed up - here's what we still owe them

Your trusted contacts almost certainly never saw this policy or consented to anything with us directly - their name and phone number reach us because you entered them. So:

  • One-time notice - the first time a phone number is added, we SMS it a one-time explanation and a link to manage that.
  • Self-service portal, real identity check - that link leads to an OTP-verified page showing who listed them (your name, photo, hometown, current place - enough to confirm it's really you, nothing more) with an option to remove themselves.
  • Removal is permanent and enforced - a removed phone number is durably blocked from silent re-addition on a future sync, even though your device is otherwise the source of truth for your contact list.
  • You're told if it happens - push, SMS, and email, so you're never left thinking you have coverage you don't.
  • What they receive if an alert fires - an SOS/check-in text naming you and, only then, your last-known location. Nothing otherwise.
  • Retention - deleted with your account; never kept for anything beyond delivering alerts on your behalf.

5How We Use Your Information

  • Discovery & matching - the core service; see §8 for exactly what drives it.
  • Delivering Meetup Safety - composing/sending alerts, running escalation, decrypting evidence for an authenticated trusted contact.
  • Trust & Safety - reviewing reports, enforcing Acceptable Use, maintaining the re-signup blocklist for accounts removed for cause.
  • Notifications - push and, per your preferences, email.
  • Legal compliance - lawful requests, Terms enforcement, retention/legal-hold handling (§11).
  • Operating the service - error monitoring (PII scrubbed before it reaches our tooling), abuse rate-limiting.

We do not use your data for third-party advertising, and we do not sell it.

6Consent - What's Mandatory, What's Optional

Not one bundled checkbox. The first time you use Nexus, and again whenever a consent version changes, you're shown three separate choices:

Consent categoryRequired?Declining does
General Terms of Service & Privacy PolicyMandatoryRoutes to account deletion
Special-category data (orientation, religion)Optional, asked separatelyLocks those two profile fields (no real value selectable) until turned on later - nothing else affected. "Prefer not to say" never needs it.
Meetup Safety dataOptionalGates only the Safety Center meetup-safety features & chat check-in toggle - nothing else. Grantable later, any time.

Every accept and decline is logged and exportable.

7How We Protect Your Information

  • Encryption at rest - sensitive fields (profile attributes, phone numbers, chat-event scheduling data, Spotify tokens, safety contacts/alerts/evidence keys) Fernet-encrypted with rotation support - an old key can be retired without a hard cutover.
  • Blind indexing - fields we need to query for exact matches (e.g. the deletion blocklist) use a deterministic HMAC-SHA256 index rather than ever running equality search against decrypted values.
  • End-to-end chat encryption - Signal Protocol (X3DH + Double Ratchet). Your device holds the only copy of your private key material.
  • Pseudonymized matching embeddings - semantic vectors for bio/career/identity similarity are stored keyed by a random pseudonym id, not your real profile id; the mapping lives in a separate, deny-all table. A raw leak of the embeddings table alone can't be trivially traced back to you.
  • Transport security - TLS for everything in transit.
  • Device attestation - Firebase App Check (Play Integrity / App Attest) distinguishes real app traffic from scripted abuse.
  • Access control - row-level security scoping every table to its owner; internal tables (embeddings, pseudonym map, audit logs) deny all client-side access.
  • Rate limiting - per-endpoint limits on auth, discovery, safety actions, OTP requests, and more.
  • Error monitoring - redacts emails and token/secret-shaped strings before anything is sent; never receives message content.
  • Authentication audit logging - our auth provider keeps a security audit log of sign-in events (timestamps, event type) for detecting account-takeover attempts and unusual sign-in patterns - a standard, retained security control, not a feature we turn off to save storage.

8Automated Matching - What Drives It

Discovery across Dating, Friends, and Professional is powered by a scoring engine we can describe, not a black box. It blends structured profile fields (values, interests, lifestyle, career/identity signal, location, age) with AI-derived semantic similarity on your bio/career/identity text (pseudonymized, §7), weighted differently per tab. Two hard exclusion rules exist on Dating (drinking/smoking mismatches), applied before scoring, not learned.

9Who Else Sees Your Data - Sub-processors

None of the providers below see your data for anything beyond the specific job listed.

Supabase

Purpose: database, auth, file storage
Data: essentially everything in §2, encrypted as described in §7
Location: Mumbai, India (AWS ap-south-1)
Privacy Policy →

Twilio

Purpose: SMS - OTP, Meetup Safety alerts, trusted-contact notices
Data: phone number & message body at send time
Location: Global
Privacy Policy →

Brevo

Purpose: transactional email (also marketing/promotional if allowed in settings)
Data: your email & the message being sent
Location: EU (France)
Privacy Policy →

Hetzner

Purpose: compute hosting for our application servers
Data: ephemeral request processing; Supabase is the durable data store, not the server itself
Location: Germany / Finland (EU)
Privacy Policy →

Cloudflare

Purpose: DNS, edge network, DDoS/WAF in front of our backend & the trusted-contact portal
Data: connection metadata (IP, headers) inherent to routing traffic - never profile/message content
Location: Global (edge)
Privacy Policy →

Google - Sign-In, App Check, FCM

Purpose: auth, device attestation, push delivery
Data: Google account id (if used), Play Integrity tokens, push token
Location: Global
Privacy Policy →

Apple - App Attest

Purpose: iOS device-integrity attestation
Data: attestation tokens, device integrity signals
Location: Global
Privacy Policy →

Spotify (optional)

Purpose: music-taste sync, only if connected
Data: top artists, playlist track/artist names - read-only
Location: Global (EU-HQ)
Privacy Policy →

Sentry

Purpose: backend error monitoring (no-op unless configured)
Data: scrubbed errors - emails/tokens redacted, message content never in scope
Location: Global
Privacy Policy →

Redis

Purpose: short-lived cache, rate-limit & OTP state only
Data: nothing outlives its TTL (typically minutes) - not a system of record

10International Data Transfers

Your data is stored in Mumbai, India. Twilio, Brevo, Google/Firebase, Apple, Spotify, and Sentry are each headquartered (and process data) outside India, so parts of the flow above cross borders in the ordinary course of sending an SMS, a push notification, or a monitored error. If you're in the EU: India has no European Commission adequacy decision, so a formal transfer mechanism (e.g. Standard Contractual Clauses) may be required for your data specifically - this is under review rather than something we assert is already fully in place.

If you're in the EU, two more things are under active review rather than settled: whether GDPR Art. 37 requires formally designating a Data Protection Officer (plausible, given the scale of special-category processing in §2 and §8), and naming an EU representative under Art. 27 if we have no EU establishment. Separately, where DPDP treats nearly everything here as consent-based, GDPR offers other legal bases - core matching plausibly sits on "necessary for performance of a contract" (Art. 6(1)(b)) rather than withdrawable consent, while special-category data and marketing (§14) stay consent-based either way. This mapping is being finalized, not asserted as complete today.

11Data Retention & Deletion

Deleting your account starts a 14-day recoverable grace window - sign back in and it's fully reversed, matches and chats intact. After that, your account is anonymized in place (every profile field wiped, email/phone unlinked) rather than row-deleted, so your former matches' own chat history stays intact on their end. A phone-number hash is added to a re-signup blocklist only if your account was actually flagged at deletion time - a good-standing account leaves no such trace. Three years after anonymization, the account is hard-deleted for good.

Meetup Safety data - shorter, separate timers
  • Digital Witness recordings hard-deleted after 365 days, for every account, active or deleted - a hard cap, not a default you can extend.
  • Alerts/evidence tied to a deleted account kept under a 180-day legal hold (in case of a live safety investigation), then purged for good.
  • Trusted contact records are deleted with the rest of your profile at anonymization - not held under the legal-hold window above.

12Your Rights

  • Access & export - Settings → Export My Data: a structured export of your profile, matches, chat metadata (never content), safety data (evidence via signed link, never the raw key), and consent history. OTP-verified, rate-limited.
  • Correction - edit your profile directly, any time.
  • Erasure - delete your account (§11).
  • Withdraw consent - decline an updated Terms version (routes to deletion, since general consent is structurally required to use Nexus at all); turn special-category consent or Meetup Safety data off any time - neither requires deleting anything, both just lock their respective fields/features until re-granted.
  • Object to marketing - toggle "Product Updates" / "Promotions & Offers" off independently; security/transactional email is never optional.
  • Grievance redressal - §16.
  • Nomination (DPDP §14) - naming someone to exercise your rights after death or incapacity isn't implemented yet; a genuinely new right with little settled practice, tracked rather than ignored.

13Children's Privacy

Nexus is not for anyone under 18, on either flavor. We do not knowingly collect data from minors. Age is self-attested, not ID-verified (Terms §2) - an accepted residual risk of the product category rather than something we pretend doesn't exist. "Underage" reports are handled the same as any other Trust & Safety report.

14Marketing Communications

Five independently toggleable email categories: new matches/likes, new messages, an activity digest, product updates, promotions/offers. All five currently default to on for a new account - turn any off any time, no justification required. Security and account-lifecycle email is never gated by these toggles.

15Changes to This Policy

Versioned alongside the Terms of Service. A materially updated version triggers the same full-page re-consent flow described in Terms §14 - you'll always know when something changed and get a real choice about it.

16Grievance Officer & Contact

Per DPDP §13, our designated Grievance Officer:

DEVANARAYANAN
Email: [email protected]
Phone: +91 88917 50777
Website: https://nexus.devakesu.com/grievances

General privacy questions: [email protected].