Privacy Policy

Last updated: May 2026

1. Absolute Data Encryption (Zero-Knowledge Architecture)

At NexID, your privacy is the core foundation in all our technical designs. We understand that contacts, phone numbers, emails, and partner/client information are highly sensitive personal and business assets. Therefore, our system is designed on a "Zero-Knowledge" architecture - where even the service provider (us) cannot know the content of your data.

Extremely important note: We DO NOT STORE any personal contact information (like email, phone number, address) in plain-text in the database. All data you enter, including contacts and sensitive fields, are encrypted using the AES-256 (Advanced Encryption Standard).

2. Operation Mechanism & Control Delegation

Unlike regular platforms that store your data to exploit ads or track behavior, we completely eliminate that possibility with the following transparent operational method:

  • End-to-End Client-Side Encryption:Right on your phone or computer's browser, data is transformed into a meaningless string (ciphertext) before being sent to the server. During transmission, no one (not even network providers) can intervene or eavesdrop on the information.
  • On-Demand Decryption:The server only acts as a secure "storage" for those encrypted strings. Data only returns to normal text (plain-text) right on the user's device screen when there is a valid security Token or authenticated login session.
  • Absolute Invisibility to Administrators (Admin Blindness):Even software engineers, database administrators, or customer support staff of NexID CANNOT decrypt the data without the authorization key from the user. This maximizes the prevention of internal risks.

3. Basic Data Collection & No Data Selling

To provide and maintain the digital business card service, we only require storing public configuration information (like username, avatar link, job title) and account information (securely hashed login email).

We guarantee absolutely no commercialization: Your data is exclusively owned by you. We strictly commit not to do business, rent, exchange, or share any part of your data to third parties, advertising organizations, or data brokers for any commercial purpose.

4. Permanent Data Deletion & Data Lifecycle

We hand over the full decision rights of the data lifecycle to you. Whenever you click the "Delete" button for a contact in the Mini CRM or delete the entire account, the corresponding encrypted records will be immediately and permanently deleted from our server system. We do not maintain background backups containing deleted data to prevent unintended extraction.