Privacy Policy
Last updated: 10 September 2026 · Effective date: 24 September 2026
This is the same document bundled in the Nexus Dex app. If you have the app, you can read it offline under Settings → Legal.
This Privacy Policy explains what personal information GrowthEngine (ABN 18 266 807 610) ("Nexus Dex", "we", "us"), collects when you use the Nexus Dex mobile and web applications (the "Service"), why we collect it, how we use it, and the choices you have.
This policy is part of, and incorporated into, our Terms of Service.
We are an Australian sole trader based in New South Wales. This policy is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and to give equivalent protection to users in the EU/UK (GDPR / UK GDPR), California (CCPA / CPRA), and other jurisdictions, regardless of where you live.
1. Plain-English summary
- We collect the minimum data needed to run the Service for you.
- The live scan runs on your device and reads only your own screen. Those frames never leave your phone. Screenshots you choose to upload (a trainer profile, a team, a Pokémon) are stored so we can run the features you asked for. We never connect to the Pokémon GO servers and never read your login.
- We never sell your personal information.
- We never ask for your Pokémon GO login credentials, and we never connect to the game.
- Raw GPS coordinates never leave your device. We bucket geo data to a ~80 metre cell before anything is uploaded.
- You can delete your account and all your data at any time.
2. Information we collect
2.1 Information you give us directly
- Account info: email address, hashed password, optional display name, optional trainer code (used for friends and the Raid Hub), optional home region (free-text, e.g. "AU-NSW").
- Roster data: your Pokémon records (including CP, IVs, moves, and tags read from screens you share), custom dexes, friend list, trade strings, and screenshots you choose to upload (trainer profile, teams, individual Pokémon). From a trainer-profile screenshot we read your trainer name, team, level, and the statistics shown on it.
- Raid Hub activity: lobbies you host or join, seats taken, the ratings you give and receive, and reports you make or that are made about you.
- Referrals: the invite codes you share and redeem, so we can grant the rewards.
- Preferences: your priorities map (the answers from the in-app questionnaire), notification settings, theme.
- Subscription / payment status: which tier you are on (Basic, Pro, or Nexus Raid Passport). Actual payment processing is handled by the App Store or Google Play, we never see your card or bank details.
- Support correspondence: if you email us, we keep the message to respond and improve.
2.2 Information we collect automatically
- Device and app info: app version, OS version, device model, language, time zone, crash reports with a pseudonymous crash-reporting identifier.
- Usage events: which screens you open, which features you use, which custom dexes you build. Used to fix bugs and improve the product.
- Network info: IP address, approximate region (country / state level only) derived from IP, connection type.
2.3 Geo data, the privacy-critical case
When you upload a Trainer CSV (from any tracker you use, or your own offline spreadsheet) or capture a record in-app, the row may contain a latitude and longitude. We bucket the coordinate to an S2-cell-level-17 token (~80 metres across) on your device before anything is sent to our servers. Raw lat/long is discarded in memory and never written to disk on our servers. We refer to the bucketed token as the "geo bucket".
2.4 Optional server-side text check
When the on-device reader is unsure of a species name or a number, the app can send a small crop of just that text (never a full frame, at most a few hundred kilobytes) for a second opinion from an AI model on our hosting provider's platform. Crops are deleted after 30 days and are not used to train any model.
2.5 Information we do NOT collect
- Pokémon GO login credentials (we never ask).
- Your live screen. Live-scan frames are processed on your device and are never uploaded.
- Your real name (unless you put it in your display name field, which we recommend you don't).
- Your home address, work address, school, or any place identifier finer than ~80 metres.
- Any data from other people on your phone (contacts, SMS, photos outside ones you actively pick).
- Health, biometric, financial, religious, sexual orientation, or any other special category data under GDPR/Privacy Act.
3. Why we use it (purposes)
| Purpose | What it covers | Legal basis (GDPR/UK GDPR) | APP |
|---|---|---|---|
| Run the Service for you | account login, sync your roster across devices, compute matchmaking and storage rules | Contract | APP 6 |
| Bill subscriptions | tier status | Contract | APP 6 |
| Run the Raid Hub | show your trainer name to lobby members, release a host's friend code to seated members, ratings and reports | Contract | APP 6 |
| Keep the Service safe and reliable | crash reports, anti-abuse, rate-limit enforcement | Legitimate interests | APP 6 |
| Communicate with you | service announcements, security alerts, support replies | Contract / legitimate interests | APP 6 |
| Improve the Service via aggregate analytics | feature usage trends, performance metrics | Legitimate interests | APP 6 |
| Comply with law | respond to lawful requests, defend legal claims, prevent fraud | Legal obligation / legitimate interest | APP 6 |
We do not run targeted advertising. We do not profile you for advertising. We do not sell your personal information.
4. Sharing, who sees your data
We share personal information only in these limited cases:
- Cloud hosting: our hosting provider (Cloudflare) stores the database and files we run and provides the AI platform used for the optional text check in section 2.4. They are bound by a written data processing agreement and may not use your data for their own purposes.
- Subprocessors: a small number of vendors we use for crash reporting, transactional email, and payments. The current list is published at https://nexusdex.ai/legal/subprocessors and we update it before adding a new vendor.
- App Store / Google Play: they handle payment and may share aggregate purchase metrics with us. Their privacy policies apply to those parts.
- Other trainers: friends you connect with see your Pokédex completion, wish list, and trade matches. In the Raid Hub, members of a lobby see your trainer name, and a host's friend code is released only to trainers holding a seat. If you share a trade string or trainer code, the person you send it to sees it. We never show your data to other trainers without an action by you.
- Legal compliance: if compelled by a valid legal request from a court or regulator with jurisdiction over us. We push back on overbroad requests.
- Business transfer: if Nexus Dex is acquired or merged, your data may transfer to the successor under the same protections as this policy. We will notify you before that happens.
We never sell, rent, license, or otherwise commercialise your personal information.
5. International transfers
We are based in Australia. Our hosting provider runs a global network with data centres in Australia and elsewhere, so your data may be stored or processed outside Australia, including in the United States. Where that happens we rely on one of the following safeguards:
- the destination country has a level of privacy protection equivalent to Australia (or, for EU/UK users, an adequacy decision),
- Standard Contractual Clauses (SCCs) with the subprocessor, or
- another mechanism approved by the relevant regulator.
You can request a copy of the safeguards in place by emailing privacy@nexusdex.ai.
6. How long we keep it
| Data | Retention |
|---|---|
| Account info | for as long as your account is active, plus 30 days after deletion (recovery) |
Pokémon records (pokemon_records) | until you hide, delete, or remove them, or until the account is deleted |
| Uploaded screenshots | until you delete the record they belong to, or until the account is deleted |
| Text-check crops (section 2.4) | 30 days |
| Raid Hub records (lobbies, ratings, reports) | while your account exists; a lobby itself closes after 10 minutes |
| Crash reports | 90 days |
| Server access logs | 30 days |
| Subscription / billing records | as required by Australian tax law, typically 7 years |
| Support correspondence | 2 years from last message |
When you delete your account, we delete or de-identify your personal information within 30 days, except where we must keep it for legal reasons (e.g. tax records, fraud-prevention logs).
7. Your rights and how to exercise them
Wherever you live, you have rights over your data with us. Depending on your jurisdiction these include:
- Access: ask what we hold about you and get a copy.
- Correction: ask us to fix inaccurate or incomplete data.
- Deletion / erasure: ask us to delete your data (subject to limited legal exceptions).
- Objection / restriction: ask us to stop or limit certain processing, e.g. legitimate-interest analytics.
- Portability (where applicable): export your data in a machine-readable format.
- Lodge a complaint: with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or your local data-protection authority.
We never charge for these requests and we respond within 30 days (or sooner if your local law requires).
To exercise a right, email privacy@nexusdex.ai from the address linked to your account, or use the in-app controls in Profile.
8. Security
We protect your data with:
- transport-layer encryption (TLS 1.2+) on every connection,
- encryption at rest for the production database,
- scrypt password hashing with a unique salt per account,
- session-token rotation on sensitive actions,
- principle-of-least-privilege access for our team, audited,
- automated and manual security testing, including the anti-tampering controls described in our Terms.
If we ever experience a data breach that affects your personal information and is likely to result in serious harm, we will notify you and the OAIC under the Notifiable Data Breaches scheme, and equivalent EU/UK/CCPA notification laws where they apply.
9. Children's privacy
We take children's privacy seriously and apply a stricter standard than the law requires.
- Under-13 accounts can only be created by a parent or guardian via a verifiable parental consent flow.
- 13-17 year olds can create accounts only with parental knowledge. We do not market to them.
- We collect the minimum data needed, never special-category data, and do not run targeted advertising to any user, child or adult.
- A parent or guardian may review, export, or delete a child's account by emailing privacy@nexusdex.ai with a copy of suitable ID and proof of guardianship. We respond within 30 days.
This aligns with the Children's Online Privacy Protection Act (COPPA) in the US, the UK Children's Code (ICO), and the OAIC's guidance on children's privacy in Australia.
10. Cookies and similar technologies
The web portal uses a small number of strictly-necessary cookies to keep you signed in and to remember theme preferences. We do not use advertising cookies, third-party trackers, or session-replay tools. The mobile app stores session tokens in OS-secure storage only.
11. Region-specific notes
11.1 Australia (Privacy Act 1988)
You have rights under the Australian Privacy Principles. Complaints can be made to us first, or to the OAIC at oaic.gov.au.
11.2 European Economic Area / United Kingdom (GDPR / UK GDPR)
You have GDPR/UK GDPR rights as listed in section 7. Our legal bases are listed in section 3. We have not appointed an EU representative because we do not target the EU market at scale, but if your local DPA considers we should, we will appoint one. Lodge complaints with your local DPA.
11.3 California, Colorado, Virginia, etc. (CCPA/CPRA and equivalents)
You have rights to know, access, delete, correct, and opt out of the "sale" or "sharing" of your personal information. We do not sell or share your personal information. To exercise rights, email privacy@nexusdex.ai. We do not discriminate against users who exercise their rights.
11.4 Other jurisdictions
If your local privacy law gives you rights stronger than those in section 7, those stronger rights apply.
12. Contact
We are a sole trader based in New South Wales, Australia. Email is the fastest way to reach us and we answer every message.
- Privacy questions and requests: privacy@nexusdex.ai
- General support: support@nexusdex.ai
- Legal notices: legal@nexusdex.ai
If you need a postal address for a formal notice or a regulator's request, email legal@nexusdex.ai and we will provide one.
13. Changes to this policy
We update this policy when our practices change. Material changes will be notified in-app or by email at least 14 days before they take effect. The "Last updated" date at the top of this policy is the source of truth.
By trainers, for trainers. We pay the bills with Pro. We don't sell your data. Ever.
Nexus Dex is an independent companion app. Not affiliated with, endorsed by, or sponsored by Scopely Explore, Niantic, Nintendo, Game Freak, Creatures Inc., The Pokémon Company, or The Pokémon Company International. Pokémon and Pokémon character names are trademarks of Nintendo.