Privacy
Last updated: 28 July 2026
Nexo ID is the identity service of the Nexo ecosystem: one account for every Nexo tool. It is open source and self-hostable, and this policy describes what this instance does. We store the minimum needed to identify you and nothing else: no tracking cookies, no third-party analytics, no advertising.
What we store about your account
Your display name, your email address and your password turned into an irreversible hash: nobody can read it, not even whoever runs this instance. We also store the date you verified your email and the language you chose. The email is stored normalized (trimmed and lowercased) so the same address cannot register twice.
Email verification
When you register we send you a signed link that expires. Until you confirm it you cannot reach your profile or authorize any tool to use your account: verification is what makes your identity count in the rest of the ecosystem.
Your sessions
For every sign-in we store a session identifier, the IP address and the browser you signed in from, and the time of the last activity. You can see them all under "Your account" and close any of them, or every other one at once. They exist so you can spot an access that is not yours, and they are deleted when you sign out or when they expire.
What a tool receives when you authorize it
When you sign in to a Nexo tool with your account, that tool receives only the data covered by the scope it was granted: always an identifier for your account (the "sub" claim) and — if it asks for the profile or email scope — your display name ("name"), your email address ("email") and whether it is verified ("email_verified"). It never receives your password, your sessions, your IP address or the list of the other tools you use.
Your identifier is the same in every tool
The identifier tools receive is your account id and it never changes: it is what makes you still be you when you come back, and what makes "one account for everything" possible. The honest trade-off is that two tools comparing that value can tell you are the same person. If you would rather avoid that, use separate accounts or each tool's standalone mode, which works without Nexo ID.
What we store about authorizations
We store which application you authorized, with which scopes and until when, as codes and tokens tied to your account; they expire on their own and can be revoked. The Nexo tools themselves are first-party clients and show no consent screen, because whoever runs this instance registered them; a third-party application does ask for your consent. There is no screen in your profile yet to review and revoke those grants: if you want one cut off, write to this instance's contact.
Cookies
Only the ones the service needs: the session cookie (encrypted), the CSRF protection cookie, and two preferences shared with the rest of the ecosystem — "nexo-lang" for the language and "nexo-theme" for the light/dark theme — which are deliberately unencrypted so every tool can read them and hold no data about you. If you tick "Remember me" a cookie with a random token is added so you are not asked for your password on every visit. None of them is used for advertising or tracking.
Emails we send you
Account emails only: email verification, password reset and the notice you get when your password changes. They go out through the email provider this instance has configured, which necessarily processes the destination address and the message content in order to deliver it. We send no newsletters and no promotions.
Security and rate limits
We count failed sign-in attempts per email and IP address combination to temporarily block brute-force attacks, and we apply per-IP limits to sensitive requests. Those counters are temporary, live in the cache and expire on their own.
Metrics
This instance may enable the ecosystem pageview counter, which sends an anonymous signal — tool and path, nothing else — with no cookies and honouring "Do Not Track". It ships disabled and identifies nobody.
Every tool has its own policy
Nexo ID only deals with your identity. What each tool does with whatever you create inside it — your links, your bookings, your events — is explained by that tool's privacy policy, not by this one.
How long we keep the data
Your account and its data are kept for as long as the account exists. Sessions and tokens expire on their own; verification and password reset links expire within minutes and are single-use.
Your rights
You change your display name and your password yourself under "Your account". To request access to your data, its correction or the deletion of your account, write to whoever runs this instance (the contact is below and on the help page).
Other instances
Nexo ID can be installed on any server. Each installation is independent and answers for its own data: this policy covers this instance only.
Who runs this instance
This instance is operated by Alvaro Carrizales. You can write to contact@alvarocdev.com.
Privacy · Terms · Help center