Legal

Privacy Policy

Last updated: June 1, 2026

1. Overview

EXIUSS Intelligence ("EXIUSS", "we", "us") operates the platform at app.exiuss.com. This Privacy Policy describes how we collect, use, and protect your information when you use our platform.

2. Information We Collect

  • Account information (email address, name) via Clerk authentication
  • Content you create within the platform (briefs, posts, routines)
  • OAuth access tokens for connected third-party platforms
  • Usage data (feature interactions, session activity)
  • Payment information processed by Stripe (we do not store card details)

3. Google API Usage

EXIUSS integrates with Google APIs to enable publishing to Google Business Profile and YouTube Community. When you connect a Google account, we request the following scopes:

  • https://www.googleapis.com/auth/business.manage — to create and manage Google Business Profile posts
  • https://www.googleapis.com/auth/youtube — to publish YouTube Community posts
  • https://www.googleapis.com/auth/userinfo.profile — to display your connected account name
  • https://www.googleapis.com/auth/userinfo.email — to identify your account

EXIUSS use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Google Business Profile Integration

When you connect Google Business Profile, EXIUSS stores your OAuth access token and refresh token in our secure database (Supabase) to enable publishing on your behalf. Tokens are encrypted at rest. We use these tokens only to publish content you explicitly initiate — we do not read, modify, or delete your business data for any other purpose.

5. YouTube Community Integration

When you connect YouTube, EXIUSS stores your OAuth access and refresh tokens to publish Community posts on your behalf. We access only the YouTube channel associated with your authorised Google account. We do not access video content, subscriber data, analytics, or private channel information.

6. OAuth Token Storage

All OAuth access tokens and refresh tokens — including those for Google, LinkedIn, Facebook, and other connected platforms — are stored in our Supabase database with row-level security. Tokens are scoped to your user account and are never shared with other users. You can revoke access at any time by disconnecting a platform from your settings, or by revoking access directly in the respective platform's security settings.

7. How We Use Your Data

  • To deliver platform features (content generation, publishing, scheduling)
  • To authenticate your connected social and business accounts
  • To publish content to platforms on your explicit instruction
  • To maintain your account and subscription
  • We do not sell your data to third parties
  • We do not use your content to train AI models

8. Data Retention

We retain your data for as long as your account is active. Content you create (briefs, posts, routines) is stored until you delete it or close your account. OAuth tokens are deleted when you disconnect a platform or close your account.

9. Data Deletion Requests

You may request deletion of your account and all associated data at any time. To submit a deletion request:

  • Email support@nexuss.pro with subject line "Data Deletion Request"
  • Include the email address associated with your account
  • We will process your request within 30 days

You can also revoke third-party platform access independently by visiting the security or permissions settings of each connected platform (Google, LinkedIn, Meta).

10. Third-Party Services

EXIUSS uses the following third-party services:

  • Clerk — authentication and user management
  • Supabase — database and storage
  • Anthropic — AI content generation
  • Stripe — payment processing
  • Google APIs — Google Business Profile and YouTube publishing
  • LinkedIn API — LinkedIn publishing
  • Meta Graph API — Facebook Page publishing

11. Security

We implement industry-standard security measures including encrypted data transmission (TLS), encrypted storage, and row-level security on all user data. OAuth tokens are stored server-side and never exposed to the client.

12. Contact

For privacy-related questions or data deletion requests, contact us at: support@nexuss.pro