Privacy Policy
Last updated: 15 July 2026 · Effective date: 29 July 2026
This is the same document bundled in the Nexus Dex app. If you have the app, you can read it offline under Settings → Legal.
This Privacy Policy explains what personal information Sam Ford, trading as GrowthEngine (ABN 18 266 807 610) ("Nexus Dex", "we", "us"), collects when you use the Nexus Dex mobile and web applications (the "Service"), why we collect it, how we use it, and the choices you have.
This policy is part of, and incorporated into, our Terms of Service. The separate Research Data Addendum governs any additional, opt-in use of your data for product research.
We are an Australian sole trader based in New South Wales. This policy is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and to give equivalent protection to users in the EU/UK (GDPR / UK GDPR), California (CCPA / CPRA), and other jurisdictions, regardless of where you live.
1. Plain-English summary
- We collect the minimum data needed to run the Service for you.
- Nexus Dex works with the screen reader and/or screenshots you share. It never connects to the Pokémon GO servers, never reads your login, and never observes anything outside the moments you choose to share with us.
- We never sell your personal information.
- We never ask for your Pokémon GO login credentials, and we never connect to the game.
- Raw GPS coordinates never leave your device. We bucket geo data to a ~80 metre cell before anything is uploaded.
- You can delete your account and all your data, including from the research lake, at any time.
2. Information we collect
2.1 Information you give us directly
- Account info: email address, hashed password, optional display name, optional trainer code, optional home region (free-text, e.g. "AU-NSW").
- Roster data: your Pokémon records, custom dexes, friend list, trade strings, screenshots you choose to upload.
- Preferences: your priorities map (the answers from the Nex companion questionnaire), notification settings, theme.
- Subscription / payment status: which tier you are on (Basic or Pro). Actual payment processing is handled by the App Store or Google Play, we never see your card or bank details.
- Support correspondence: if you email us, we keep the message to respond and improve.
2.2 Information we collect automatically
- Device and app info: app version, OS version, device model, language, time zone, crash reports.
- Usage events: which screens you open, which features you use, which custom dexes you build. Used to fix bugs and improve the product.
- Network info: IP address, approximate region (country / state level only) derived from IP, connection type.
2.3 Geo data, the privacy-critical case
When you upload a Trainer CSV (from any tracker you use, or your own offline spreadsheet) or capture a record in-app, the row may contain a latitude and longitude. We bucket the coordinate to an S2-cell-level-17 token (~80 metres across) on your device before anything is sent to our servers. Raw lat/long is discarded in memory and never written to disk on our servers. We refer to the bucketed token as the "geo bucket".
If you turn research mode off, even the bucketed token is dropped before upload. See the Research Data Addendum.
2.4 Information we do NOT collect
- Pokémon GO login credentials (we never ask).
- Your real name (unless you put it in your display name field, which we recommend you don't).
- Your home address, work address, school, or any place identifier finer than ~80 metres.
- Any data from other people on your phone (contacts, SMS, photos outside ones you actively pick).
- Health, biometric, financial, religious, sexual orientation, or any other special category data under GDPR/Privacy Act.
3. Why we use it (purposes)
| Purpose | What it covers | Legal basis (GDPR/UK GDPR) | APP |
|---|---|---|---|
| Run the Service for you | account login, sync your roster across devices, compute matchmaking and storage rules | Contract | APP 6 |
| Bill subscriptions | tier status | Contract | APP 6 |
| Keep the Service safe and reliable | crash reports, anti-abuse, rate-limit enforcement | Legitimate interests | APP 6 |
| Communicate with you | service announcements, security alerts, support replies | Contract / legitimate interests | APP 6 |
| Improve the Service via aggregate analytics | feature usage trends, performance metrics | Legitimate interests | APP 6 |
| Comply with law | respond to lawful requests, defend legal claims, prevent fraud | Legal obligation / legitimate interest | APP 6 |
| Optional research lake (separate, opt-in) | hypothesis testing on shiny rates, trade reroll bias, geographic patterns, see Research Addendum | Consent | APP 6, with consent |
We do not run targeted advertising. We do not profile you for advertising. We do not sell your personal information.
4. Sharing, who sees your data
We share personal information only in these limited cases:
- Cloud hosting: our hosting provider stores the database we run. They are bound by a written data processing agreement, may not use your data for their own purposes, and host within Australia or a country with adequate protection.
- Subprocessors: a small number of vendors we use for crash reporting, transactional email, and payments. The current list is published at https://nexusdex.ai/legal/subprocessors and we update it before adding a new vendor.
- App Store / Google Play: they handle payment and may share aggregate purchase metrics with us. Their privacy policies apply to those parts.
- Other users you choose to share with: if you share a trade string or your trainer code with a friend, that data is visible to them. We do not surface your data to other users without an action by you.
- Legal compliance: if compelled by a valid legal request from a court or regulator with jurisdiction over us. We push back on overbroad requests.
- Business transfer: if Nexus Dex is acquired or merged, your data may transfer to the successor under the same protections as this policy. We will notify you before that happens.
We never sell, rent, license, or otherwise commercialise your personal information.
5. International transfers
We are based in Australia. Your data is stored in Australia by default. If a subprocessor needs to process data outside Australia, we use one of the following safeguards:
- the destination country has a level of privacy protection equivalent to Australia (or, for EU/UK users, an adequacy decision),
- Standard Contractual Clauses (SCCs) with the subprocessor, or
- another mechanism approved by the relevant regulator.
You can request a copy of the safeguards in place by emailing privacy@nexusdex.ai.
6. How long we keep it
| Data | Retention |
|---|---|
| Account info | for as long as your account is active, plus 30 days after deletion (recovery) |
Pokémon records (pokemon_records) | until you hide, delete, or remove them, or until the account is deleted |
Research lake events (research_events) | until you opt out (then we stop adding more) or you delete the account (cascade) |
| Crash reports | 90 days |
| Server access logs | 30 days |
| Subscription / billing records | as required by Australian tax law, typically 7 years |
| Support correspondence | 2 years from last message |
When you delete your account, we delete or de-identify your personal information within 30 days, except where we must keep it for legal reasons (e.g. tax records, fraud-prevention logs).
7. Your rights and how to exercise them
Wherever you live, you have rights over your data with us. Depending on your jurisdiction these include:
- Access: ask what we hold about you and get a copy.
- Correction: ask us to fix inaccurate or incomplete data.
- Deletion / erasure: ask us to delete your data (subject to limited legal exceptions).
- Objection / restriction: ask us to stop or limit certain processing, e.g. legitimate-interest analytics.
- Portability (where applicable): export your data in a machine-readable format.
- Withdraw consent: turn off research mode at any time, no questions asked.
- Lodge a complaint: with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or your local data-protection authority.
We never charge for these requests and we respond within 30 days (or sooner if your local law requires).
To exercise a right, email privacy@nexusdex.ai from the address linked to your account, or use the in-app controls in Profile.
8. Security
We protect your data with:
- transport-layer encryption (TLS 1.2+) on every connection,
- encryption at rest for the production database,
- bcrypt password hashing with a cost factor of at least 12,
- session-token rotation on sensitive actions,
- principle-of-least-privilege access for our team, audited,
- automated and manual security testing, including the anti-tampering controls described in our Terms.
If we ever experience a data breach that affects your personal information and is likely to result in serious harm, we will notify you and the OAIC under the Notifiable Data Breaches scheme, and equivalent EU/UK/CCPA notification laws where they apply.
9. Children's privacy
We take children's privacy seriously and apply a stricter standard than the law requires.
- Under-13 accounts can only be created by a parent or guardian via a verifiable parental consent flow. Research mode is forced off and cannot be enabled, regardless of regional age of digital consent.
- 13-17 year olds can create accounts only with parental knowledge. We do not market to them.
- We collect the minimum data needed, never special-category data, and do not run targeted advertising to any user, child or adult.
- A parent or guardian may review, export, or delete a child's account by emailing privacy@nexusdex.ai with a copy of suitable ID and proof of guardianship. We respond within 30 days.
This aligns with the Children's Online Privacy Protection Act (COPPA) in the US, the UK Children's Code (ICO), and the OAIC's guidance on children's privacy in Australia.
10. Cookies and similar technologies
The web portal uses a small number of strictly-necessary cookies to keep you signed in and to remember theme preferences. We do not use advertising cookies, third-party trackers, or session-replay tools. The mobile app stores session tokens in OS-secure storage only.
11. Region-specific notes
11.1 Australia (Privacy Act 1988)
You have rights under the Australian Privacy Principles. Complaints can be made to us first, or to the OAIC at oaic.gov.au.
11.2 European Economic Area / United Kingdom (GDPR / UK GDPR)
You have GDPR/UK GDPR rights as listed in section 7. Our legal bases are listed in section 3. We have not appointed an EU representative because we do not target the EU market at scale, but if your local DPA considers we should, we will appoint one. Lodge complaints with your local DPA.
11.3 California, Colorado, Virginia, etc. (CCPA/CPRA and equivalents)
You have rights to know, access, delete, correct, and opt out of the "sale" or "sharing" of your personal information. We do not sell or share your personal information. To exercise rights, email privacy@nexusdex.ai. We do not discriminate against users who exercise their rights.
11.4 Other jurisdictions
If your local privacy law gives you rights stronger than those in section 7, those stronger rights apply.
12. Contact
We are a sole trader based in New South Wales, Australia. Email is the fastest way to reach us and we answer every message.
- Privacy questions and requests: privacy@nexusdex.ai
- General support: support@nexusdex.ai
- Legal notices: legal@nexusdex.ai
If you need a postal address for a formal notice or a regulator's request, email legal@nexusdex.ai and we will provide one.
13. Changes to this policy
We update this policy when our practices change. Material changes will be notified in-app or by email at least 14 days before they take effect. The "Last updated" date at the top of this policy is the source of truth.
By trainers, for trainers. We pay the bills with Pro. We don't sell your data. Ever.