Privacy policy

Last updated 4 August 2026.

We collect only the data we need to run your account and ship your orders. We never sell your data, and we never share it with third parties outside of the processors listed below.

What we collect

  • Account data — your name, email, and avatar (if you provide one). Used to sign you in and identify you in the admin panel.
  • Order data — what you ordered, when, and the payment proof you uploaded. We keep this so we can resolve disputes and reissue invoices.
  • Message data — anything you send via Inbox, group chat, or Nelsen AI. We keep it so you have a history across devices.
  • Operational logs — basic request metadata (IP, user agent) for abuse prevention. Rotated on a 30-day cycle.

Processors we use

  • Supabase — our database and file storage provider. Data is hosted in the region you configure on sign-up (default: ap-southeast-1).
  • Google — for OAuth sign-in and the Gemini model behind Nelsen AI. Conversation data is sent to the model only when you actively send a message.

Your rights

You can request a copy of your data, ask us to delete your account, or correct anything we have wrong. The fastest route is to open the in-app account settings (Profile → Security) and either delete the account directly or send us a message via Inbox. We respond within 7 days.

Cookies

We use only the authentication cookies required by Supabase Auth. They are first-party, scoped to .nelsen.web.id, and never used for tracking.

Changes

If we change anything material, we'll surface a banner inside the app for at least 14 days before it takes effect. For minor edits (typos, clarifications) we update the “last updated” date at the top of this page.