1. Scope
This Policy applies to information handled by NexA LLC (“we,” “us” or “NexA”) through Tesuji and its related web pages, APIs and MCP integrations (collectively, the “Service”). Processing performed on an external service is also subject to that provider’s terms and policies.
2. Information we collect
- Account information: name or display name, email address, profile image, external authentication identifiers, linked provider, authentication status and link date. Tokens needed for authentication are protected using measures such as encryption.
- Information you provide: profiles, public IDs, organization and role, biographies, nodes, links, articles, comments, work requests and responses, reports, inquiries and other content you submit.
- Usage and device information: session identifiers, cookies, IP address, user agent, access time, referrer, interaction history, and logs needed to investigate errors or misuse.
- MCP and API information: token name, scopes, token hash and identifying prefix, usage time, affected resource, request identifier and revision history. We do not retain the plaintext bearer token after issuance.
- Support information: contact details, inquiry content, attachments and response history submitted through CaseFlow or another support channel.
3. How we use information
- Provide the Service, authenticate users, and manage accounts, visibility and permissions.
- Operate publishing, connections, collaborative editing, comments, work matching and support features.
- Prevent abuse, maintain security, investigate incidents, audit changes and resolve disputes.
- Understand usage, improve quality, plan features and deliver important notices.
- Comply with law and our obligations, and establish or exercise legal rights.
4. Public information and visibility
Profiles, nodes, links, articles, comments and public portions of work requests that you choose to publish may be viewed by anyone, including people who are not signed in, and may be indexed or stored by search engines, AI services or archives. Do not publish confidential information, credentials or another person’s personal data without authority.
Private drafts and profiles, private work-request details and reports are limited to users who need them for the feature and authorized operators, except where access is required by law or to protect the Service.
5. Cookies, local storage and interaction recording
The Service uses cookies or browser local storage to maintain sign-in, protect OAuth flows, and remember language or consent choices. Disabling them may prevent sign-in or other features from working.
If FlowTrace is enabled, interaction recording starts only after the user expressly consents and only on the home/network pages. Visible text is masked, and login, profile editing, token, draft and article screens are excluded. Consent can be changed from My Page.
6. Service providers and external services
We engage providers only as needed for the purposes described above and take reasonable steps to select and oversee them. Providers may process information outside your country. Their own processing is also governed by their terms and policies.
- Google, X, LINE and Discord: authentication and account linking selected by the user.
- CaseFlow: display of the contact widget, receipt of inquiries and support handling. The browser may send connection metadata when loading the widget.
- FlowTrace: masked interaction recording when enabled and consented to by the user.
- Hosting, database, storage and other cloud providers: delivery, storage, backups, monitoring and security of the Service.
7. Disclosure to third parties
We do not disclose personal data to third parties except with consent, through a service provider or business succession arrangement, to protect life, safety or property, or as required by law. Information a user makes public remains available according to its visibility setting and is separate from such disclosure.
8. Security
We take reasonable safeguards appropriate to the information and risk, including access control, credential protection, encryption in transit, limited permissions, and log and revision management. No internet service can guarantee absolute security.
9. Retention and deletion
We retain information for as long as needed for the purposes above, service integrity, auditing and abuse prevention, legal obligations and the exercise of rights, and then delete or anonymize it. Backups, public caches, and collaborative-editing or audit histories may remain for a reasonable period after a request.
To preserve discussion and audit integrity, we may hide the body of a comment or similar record while retaining minimal records such as author and timestamp.
10. Your requests
Subject to applicable law, you may request notice of purpose, access, correction, addition, deletion, suspension of use or suspension of third-party disclosure for personal data we hold. Use the CaseFlow “Contact” widget at the bottom right or email contact@nex-a.net, and identify the account or URL and the request. We may verify identity to prevent impersonation.
11. Changes to this Policy
We may update this Policy as the Service or law changes. We will provide clear notice in the Service for material changes. Unless otherwise stated, an updated Policy takes effect when posted.
12. Operator and contact
NexA LLC. For privacy questions or requests, use the CaseFlow “Contact” widget at the bottom right of the screen or email contact@nex-a.net.
Tesuji