Back to homepage

Legal information

Privacy Policy

This policy describes how NEXO REPORT processes personal data when you use the NEXO web or mobile application.

Protected personal information

1. Controller and contact

NEXO REPORT is responsible for data processing in connection with this application.

Contact address:
NEXO REPORT
Kasernenstrasse 1
CH-8180 Bülach, Switzerland

For privacy and support inquiries you can reach us at support@nexo.report or via the Support page.

2. Processed data

Depending on usage we process account data, profile and contact data as well as the financial, calendar, contact, invoice and document data you enter. In addition, technical data necessary for secure provision and troubleshooting are processed.

Payment data for paid subscriptions are processed by Stripe. NEXO REPORT does not store full card or bank details in the application.

3. Purpose and legal basis of processing

We process data to manage your account, provide features, bill subscriptions, provide support and to prevent abuse, security incidents and errors.

Processing is carried out in particular for performance of the contract, due to legal obligations, to protect legitimate interests, or—where necessary—with your consent. For persons within the scope of the GDPR, the applicable legal bases under Art. 6 GDPR apply.

4. Service providers and transfers

To operate NEXO we mainly use Google Firebase and Google Cloud for sign-in, database, file storage and server functions, Stripe for payments and subscription management, and Cloudflare for delivering emails to your NEXO address and for the protected connection to NEXO’s own AI server. The NEXO assistant uses AI models in this order: its own model on a server operated by NEXO in Switzerland, then Mistral AI (France, EU endpoint) and, only as a fallback, its own model in Google Cloud in the EU (Belgium). Optional add-on services such as image text recognition (Google Cloud Vision) or converting voice messages to text (Google Cloud Speech-to-Text) only receive the file required for that purpose. Photos of till receipts are first read by the same own model in Switzerland; only if it is unavailable or the amounts do not add up does Google Cloud Vision recognise the text.

If data are processed outside Switzerland or the European Economic Area, transfers will only occur on a recognised legal basis and with appropriate safeguards, where required.

5. Retention and security

We retain data only as long as necessary for the described purposes, contract fulfilment or statutory retention requirements.

We apply technical and organisational measures to protect data against unauthorised access, loss and alteration. These include access controls, encrypted transmissions and server‑side permission checks.

6. Your rights

You may request access, rectification, deletion, restriction of processing or the export of your data and object to processing to the extent permitted by applicable law. Consents given may be withdrawn with future effect.

Please contact support@nexo.report for this. You may also file a complaint with the competent data protection authority, in particular the Federal Data Protection and Information Commissioner (EDÖB), where Swiss data protection law applies.

7. Changes to this policy

We will update this policy if features, legal requirements or processing change materially. The current version will be published on this page.

Version as of 26 September 2026.

8. Recipients, international transfers and optional features

NEXO uses Google Firebase for sign-in, database, Cloud Storage and server functions. The database and the NEXO server functions run in the EU (Google Cloud region europe-west1, Belgium). Firebase Authentication also processes sign-in data such as the email address in the USA. Individual Google services such as Cloud Vision or Speech-to-Text may process data outside Switzerland and the EU.

Stripe processes payment data, billing address data where collected in Checkout, subscription data and invoice data for payment processing. For this purpose NEXO transmits the account email address, a technical NEXO reference, plan and currency. NEXO does not store complete card or bank details.

The optional NEXO assistant answers questions using your NEXO data. Many questions, for example about amounts, numbers from documents or the payment plan, are answered by NEXO directly in the server functions without an AI model. For other questions an AI model receives your question, the conversation so far and a shortened account extract from which passwords, card and IBAN numbers have been removed, but no account ID – in the order stated above (NEXO server in Switzerland, Mistral AI in the EU, as a fallback NEXO model in Belgium). Mistral AI does not store these requests (zero data retention) and does not use them to train its models. If you enable the optional image text recognition, the image file is sent to Google Cloud Vision; voice messages in the chat are sent to Google Cloud Speech-to-Text to be converted into text. Support requests are handled via the NEXO support mailbox.

These providers may process data outside Switzerland and the European Economic Area, including in the United States. NEXO uses such services only for the purposes described and implements the contractual and organisational safeguards required by applicable law. Information about the specific contractual and transfer documentation can be requested from support.

9. Document analysis, AI features and your choice

Text from PDF, Office, spreadsheet and text files is processed by NEXO to provide a preview and reviewable suggestions for filing, appointments or tax documents. For image files, external text recognition is used only when you explicitly enable it before upload. Without activation, the image file is stored but is not read by Google Cloud Vision.

The NEXO assistant is optional. It only uses the information from your account needed for the answer, for example details from uploaded documents, open bills, amounts or due dates. AHV/social security numbers are masked in text excerpts unless you explicitly ask for them. Do not use the assistant for passwords, access codes or full payment details.

Documents, recognised raw text and analysis results are stored in your NEXO account so that you can review, assign or delete them. Appointments or tax values are transferred only after your review and confirmation.

10. Retention, deletion and access protection

Account data and content you create are generally retained until you delete them or request deletion of your account. Subscription and transaction references and records may be retained longer where needed for contract fulfilment, fraud prevention, troubleshooting or a legal retention obligation.

Documents are opened through a time-limited access link after an authorised request. NEXO does not store permanently valid access links for new documents. When a document is deleted, deletion of the stored file is requested in addition to deletion of the record.

Chat histories, support requests and technical logs are retained only as long as needed for the relevant conversation, handling, security or legal obligation. NEXO continually reviews retention periods and adjusts them when a binding retention concept or legal requirements require this.

11. Requests about your data

For access, correction, deletion, restriction, data export or objection, contact support@nexo.report. Please use the email address of your NEXO account or provide another secure way to verify your identity. NEXO responds to valid requests within the period required by applicable law.

12. Email inbox (forwarding and mailbox connection)

You can forward emails to your personal NEXO address (…@in.nexo.report). Delivery takes place via Cloudflare Email Routing (Cloudflare, Inc., USA); the email is only processed there to pass it on to NEXO. NEXO takes over attachments and relevant email texts into your documents. You can switch forwarding off at any time or create a new address; the old address then stops working.

Alternatively, you can connect your mailbox via IMAP with an app password. The app password is stored encrypted (AES-256) and only used for reading. NEXO fetches new emails about every 15 minutes, checks them automatically in the NEXO server functions and only takes over emails that look like bills, reminders, appointments, contracts or official letters. Other emails are discarded immediately and not stored; to avoid duplicate imports only an irreversible hash of the message ID is stored. NEXO does not mark anything as read, move or delete anything.

For recognised emails NEXO stores the sender, subject, time, result and the text of the email in the log so that you can view it in NEXO. “Disconnect” deletes the access data immediately. Documents that were taken over remain in your account until you delete them.

13. Payment plan and payment letters

The payment plan evaluates the bills, reminders and payment reminders recorded in NEXO (for example amount, due date, creditor and reminder level) and suggests an order. The evaluation is rule-based in the NEXO server functions, without external AI. Your decisions, such as “postpone” or “paid”, are stored in your account.

Templates for payment deferral or instalment requests are only created when you trigger them. NEXO does not send these letters itself; you decide whether and to whom to send them. The payment plan is a tool and not legal, debt or financial advice.

14. Support access only with your consent

In the settings under “Security” you can give NEXO support read access for troubleshooting for 24 hours or 7 days and withdraw it at any time. Without an active consent the NEXO application shows support no account view.

The view is read-only and shows account status and plan, detected problems, people (name), open reminders with amount and due date, the latest bookings and the file names and titles of the latest documents, but no document files. With your consent, NEXO can use a short technical account diagnosis (plan, number of entries, detected problems) for the reply draft to your support requests. Every access is logged with time and role; you can see the log in the settings.

15. Access without subscription and overload protection

NEXO can unlock a plan for individual accounts without a subscription and without payment details, optionally for a limited time. For this, the plan, duration and an internal note are stored in the account together with an entry in the audit log. When it expires, the free plan applies again automatically.

To protect against misuse and overload, NEXO counts the assistant requests and imported emails per account and period (only counter and time, no content). When a limit is reached, further requests are paused briefly.