Privacy Policy

Last updated: May 2026

Nexio Watch ("we", "us") is operated by Fiksu Design from Finland. This policy explains what personal data we collect, why we use it, and what choices you have.

1. Who is responsible for your data

Fiksu Design is the data controller for personal data processed through Nexio Watch (https://nexiowatch.com). For privacy questions or to exercise your rights, email admin@fiksudesign.fi.

2. Information we collect

Account and profile: email address, display name and profile image (when you sign in with Google or Facebook), and optional phone number for SMS alerts and verification. Authentication: we support email one-time codes, Google, and Facebook (when enabled). Monitoring configuration: monitor names and URLs, check types and intervals, regions, alert channels, escalation rules, quiet hours, and credentials you provide for integrations (e.g. Slack, Discord, Telegram, or custom webhook URLs). Check and incident data: HTTP status, latency, error messages, SSL and domain expiry metadata, DNS results, and check history retained according to your plan. Screenshot monitoring: for screenshot-diff monitors we store page screenshots and diff images in Google Cloud Storage, plus optional AI-generated change summaries. Billing: subscription plan, Stripe customer identifier, and payment status (card details are handled only by Stripe). Team and API access: organization membership, team invite email addresses, and API token metadata (hashed tokens, scopes, last use). Communications: product and account emails, optional marketing opt-in at signup, feedback messages you send us, and marketing email send logs when applicable. Usage on our website: if you accept cookies, we use Google Analytics and Google Ads tags to understand product usage and measure advertising.

3. How we use your information

We use your data to provide uptime monitoring and alerting, operate team features and the external API, process subscriptions, send transactional messages, respond to support and feedback, improve reliability and security, and—only where permitted—send marketing email to users who opted in. Screenshot AI summaries are generated only for monitors with visual break detection enabled, to describe visible page changes in alerts. We do not sell your personal information.

4. Legal basis (EEA/UK users)

Where GDPR applies, we rely on: performance of a contract (providing the service you signed up for); legitimate interests (security, fraud prevention, service improvement, and non-marketing product communication); consent (optional marketing email and non-essential analytics cookies); and legal obligation where required (e.g. tax and accounting records for paid subscriptions).

5. Cookies and analytics

Essential cookies and similar technologies are used to keep you signed in and to operate the dashboard. With your consent, we load Google Analytics and Google Ads (gtag) in production to measure usage and conversions. You can accept or decline analytics cookies via the banner; declining means those tags are not loaded. The mobile app uses the same session mechanism as the web app when you sign in through the in-app browser.

6. Third-party services we use

We share data with service providers only as needed to run Nexio Watch: Google (Cloud Platform for hosting, checks, and screenshot storage; Google/Facebook sign-in), Stripe (payments and billing portal), Mailgun EU (transactional and marketing email), SMSAPI (SMS alerts and phone verification codes), and OpenAI (optional screenshot change summaries). When you configure alert integrations, incident data is sent to the endpoints you provide (Slack, Discord, Telegram, email recipients, SMS numbers, or your webhooks). Those services process data under their own policies. We choose providers with appropriate safeguards; some may process data outside the EU (including the United States). Where required, we rely on standard contractual clauses or equivalent mechanisms.

7. Screenshot monitoring and AI

If you enable visual break detection, we capture page images during checks, store them in our cloud storage, and may compare them to prior images to detect visual changes. When a meaningful change is detected, we may send the previous, current, and diff images to OpenAI to generate a short plain-text summary included in alerts. You control this feature per monitor. Do not point screenshot monitors at pages that display sensitive personal data unless you accept that such content may be stored and, when changed, processed for summarisation.

8. Public status sharing (status board)

On the Business plan you can enable a shareable status board. Anyone with the link can see monitor names and status for your organization within the time window you configure. You may protect access with an optional code. Treat share links like credentials—revoke or rotate them from account settings if they are exposed.

9. Where data is stored and how long we keep it

We operate from Finland. Primary application and operational data are hosted in the European Union (Google Cloud). Checks may run from regions you select, including locations in Europe, the United States, and Australia, so check traffic originates from those areas. Check history is retained for 7 days on the Free plan, 30 days on Pro, and 90 days on Business, after which it is deleted or aggregated as part of normal operation. Sign-in codes, phone verification codes, and similar short-lived records expire within minutes. Screenshots are kept for the same retention period as related check history unless deleted earlier when you remove a monitor.

10. Security

We use industry-standard technical and organisational measures to protect your data, including encryption in transit, access controls, and hashed storage for API tokens. Payment card data is collected and stored only by Stripe, not on our servers. No method of transmission or storage is completely secure; please use a strong, unique password for any linked OAuth provider and protect API tokens you create.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. You can update much of your account information (including phone number and marketing preferences where shown) in the dashboard. To request account deletion, a data export, or help exercising any right, email admin@fiksudesign.fi. We will respond within the time required by applicable law (typically one month under GDPR). You may lodge a complaint with your local supervisory authority; in Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutettu).

12. Children

Nexio Watch is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. We will post the revised version on this page and update the "Last updated" date. For material changes, we may also notify you by email or through the service.

14. Contact

Privacy enquiries and data subject requests: admin@fiksudesign.fi. General product feedback may also be sent from the in-app feedback form.