XPerimeter · NEXUS

Privacy Policy

Last updated: 3 July 2026

This Privacy Policy explains how XPerimeter, a company incorporated in Columbus, Ohio, United States (“XPerimeter”, “we”, “us”), handles information in connection with NEXUS — the identity, billing, and authentication hub for the XPerimeter product family — hosted at nexus.xperimeter.com, and the XPerimeter products that rely on it (including Mesh1, XVIS, XINT, XACT, XDEV, and other applications).

Privacy at XPerimeter is enforced by architecture, not policy: no biometrics, no persistent identity of monitored individuals, and automatic deletion of operational data at event end. This is a load-bearing design principle of the platform, not a configurable feature.

1.Who this policy covers

NEXUS is the single identity provider for the entire XPerimeter group. This policy covers two very different categories of information, and it is important not to confuse them:

  • Account data — information about the people and organizations who hold XPerimeter accounts (our customers, their team members, and developers). NEXUS is the controller of this data.
  • Operational data — signals processed by operational products (for example video or sensor feeds handled during a live event). XPerimeter processes this on behalf of the customer, under the customer’s instructions, and it is governed by the privacy-by-architecture guarantees in Section 6.

2.Account information we collect

To operate accounts, we collect and store:

  • Identity & login — name, email address, and email-verification status; authentication credentials (passwords are stored only as salted hashes, never in plain text); multi-factor authentication (MFA) settings and backup codes; and passkey (WebAuthn) registrations.
  • Organization & membership — the organization a user belongs to, their role and product permissions, invitations, and service-account and API-key metadata. Accounts are organization-scoped: billing, credit, and quota are tracked at the organization level.
  • Verification (KYC) — for higher-tier access we run identity verification through Stripe Identity. We record only the verification status and a Stripe reference identifier. We do not receive or store the underlying government-ID images or biometric checks — those are held by Stripe as processor.
  • Billing & tax — plan and subscription details, the prepaid credit ledger, usage events, invoices, refunds, auto-reload configuration, and tax registration inputs. Card and bank details are handled by Stripe; we store Stripe reference identifiers, not raw payment instruments.
  • Technical & security — session records, IP addresses, request metadata, API-key usage, IP-allowlist and request-signing configuration, webhook endpoints and delivery logs, and an append-only audit log of security- and billing-relevant actions.

3.How we use account information

We use account information to:

  • authenticate users and issue short-lived, scoped access tokens (JWTs) that let XPerimeter products verify identity, organization, role, and entitlements;
  • operate billing — metering usage, maintaining the credit ledger, processing top-ups and auto-reload, generating invoices, and calculating tax;
  • enforce entitlements and limits (product access, seats, quotas) before requests reach downstream products;
  • secure the platform — MFA, rate limiting, request signing, IP allowlisting, fraud and abuse prevention, and audit logging;
  • send operational and account notifications, including low-balance and usage-threshold alerts;
  • meet legal, accounting, and audit obligations.

4.Legal bases for processing

Where the GDPR or comparable laws apply, we rely on: performance of our contract with you (operating your account and the services); legitimate interests (securing the platform, preventing abuse, and maintaining audit integrity); legal obligation (tax, accounting, and KYC/AML requirements); and consent where specifically requested (for example certain optional communications). You may withdraw consent at any time without affecting processing already carried out.

5.How identity flows between products

XPerimeter products do not maintain their own user databases. When you sign in, NEXUS authenticates you and issues a cryptographically signed JWT that carries your user and organization identifiers, roles, and entitlements. Products verify that token against NEXUS’s published public keys — they read your permissions from the token rather than storing your identity. Because there is one identity store, suspending or removing an account revokes access everywhere at once, and there is no orphaned copy of your identity to leak from an individual product.

6.Operational data — privacy by architecture

XPerimeter’s operational products provide real-time situational awareness in safety-critical physical environments. The platform is built so that privacy does not depend on operator discipline or configuration:

  • No biometrics. We do not perform facial recognition or build biometric identifiers of monitored individuals.
  • No persistent identity. Individuals observed during an operation are not enrolled into a persistent profile or tracked across events.
  • Automatic deletion at event end. Operational data is deleted automatically when the associated event or session ends. Retention is not an opt-in setting.
  • Human-confirmed AI. AI agents advise operators but never act autonomously; every recommended action requires human confirmation.

For operational data, the customer deploying the product is the controller and XPerimeter acts as processor under the customer’s data-processing terms.

7.Sharing and disclosure

We do not sell personal information. We share account information only with:

  • Service providers acting as processors under contract — including Stripe (payments, tax, and identity verification), our database and hosting providers (Neon and Vercel), and email delivery providers;
  • Your organization — organization administrators can see membership, roles, billing, usage, and audit information for their org;
  • Authorities where required by law, and to protect the rights, safety, and security of users and the platform;
  • A successor entity in connection with a merger, acquisition, or reorganization, subject to this policy.

8.International transfers

Our providers may process data in jurisdictions other than your own. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or equivalent mechanisms. The platform is designed to be portable to private-cloud, air-gapped, on-premises, and government environments where data-residency requirements demand it.

9.Data retention

Operational data is deleted automatically at event end as described in Section 6. Account, billing, and audit data is retained for as long as your account is active and thereafter only as required to meet legal, tax, accounting, and SOC 2 audit obligations. Financial and audit records are append-only by design and are retained for the statutory period. When retention is no longer required, data is deleted or irreversibly anonymized.

10.Security

We protect information with encryption in transit, hashing of credentials and secrets, MFA and passkey support, scoped short-lived tokens, rate limiting, request signing, IP allowlisting, least- privilege service accounts, and an append-only audit log. The platform is built and operated to be capable of an independent SOC 2 audit. No system is perfectly secure, but security is a primary design constraint rather than an afterthought.

11.Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise these rights, contact us using the details in Section 14. If your data is processed by XPerimeter on behalf of your organization or an event operator, we will direct your request to the relevant controller.

12.Cookies and sessions

NEXUS uses strictly necessary cookies to keep you signed in, maintain session security, and protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies. Disabling strictly necessary cookies will prevent you from signing in.

13.Children

XPerimeter is a business platform intended for professional use by organizations. It is not directed to children, and we do not knowingly collect personal information from anyone under 16.

14.Changes and contact

We may update this policy to reflect changes to the platform or the law. Material changes will be signalled by updating the “Last updated” date above and, where appropriate, by notifying account administrators. Continued use after an update constitutes acceptance of the revised policy.

Questions or privacy requests: privacy@xperimeter.com — or general support at support@xperimeter.com.