Privacy Policy
NexorFlow — nexorflow.ai
Last updated: June 2026
What we collect
When you use NexorFlow, we collect:
- Email address — used to authenticate you via magic link. Nothing else.
- GitHub repository data — file paths, markdown document content, and recent commit messages from repositories you explicitly connect. We read only. We never write to, commit to, or modify your repository in any way.
- Project data — your project name, build sequence steps, session breadcrumbs, and repository scan results. This is stored to power your session across visits.
- Build plan wizard input — when you use the onboarding wizard, the answers you type (project description, recent activity, next step) are used only to generate a BUILDPLAN.md file locally in your browser. This data is never sent to our servers and is never stored by NexorFlow.
- Browser storage — NexorFlow uses sessionStorage to carry wizard state between pages within a single visit, and localStorage to remember your UI preferences (such as dismissed hints). No personal data is stored in browser storage.
We do not collect: browsing history, device fingerprints, analytics or tracking data, or payment information.
How we store it
Your data is stored in Supabase (PostgreSQL), hosted in the EU. Supabase is SOC 2 Type II certified. We do not sell, share, or transfer your data to third parties. Scan results including markdown content from your repository are stored to enable session continuity. You can delete all stored data at any time from Settings → Disconnect GitHub.
GitHub access
NexorFlow connects to GitHub via OAuth. The OAuth scope we request technically includes repository write access, but NexorFlow never writes to, commits to, creates branches in, or modifies your repository in any way. We request this scope only because GitHub's permission model does not offer a strictly read-only OAuth scope for private repositories.
You can revoke NexorFlow's GitHub access at any time from GitHub Settings → Applications → Authorized OAuth Apps. Revoking access does not delete your NexorFlow account or stored session data — you can do that from Settings inside NexorFlow.
Your rights (GDPR)
You have the right to access, correct, export, or permanently delete your data at any time. To delete your data, disconnect GitHub from Settings — this permanently removes all scan history, build sequences, and session data. To delete your account entirely or request a data export, contact us at: bjorn@nexorflow.ai
Cookies
NexorFlow uses one strictly necessary session cookie. We do not use analytics cookies, advertising cookies, or third-party tracking.
Contact
NexorFlow is operated by Bjørn Erik Lilleskare, Norway.
Email: bjorn@nexorflow.ai