Security and privacy
Your tests and evidence stay on your machines. This page lists what does leave them, what your account keeps and for how long, and how to get a copy of it. The Privacy Policy is the legal text; this page is the practical version.
What leaves your machine
Nexus Studio makes one connection on its own: the license check. On the Studio's License screen, What leaves this machine shows the next request exactly, with the key or the token masked.
- Activation, once per machine: your license key, the machine hash and a nonce.
- Renewal, when the Studio starts and once a day while it runs, or every hour while a check is overdue: the activation token, the machine hash and a new nonce. A server that runs the engine without the Studio renews before a command, once its check is due.
- Never: test names, test code, results, screenshots, videos, reports, history, or the addresses of the applications you test.
What each part is:
- Machine hash. A SHA-256 of your machine's own ID: the MachineGuid on Windows,
/etc/machine-idon Linux. The ID itself is never sent. Every Windows user and every reinstall of the Studio on one machine give the same hash, which is why they share one seat. - Nonce. 32 random bytes, new on every request. The answer has to carry it back, signed, so an old answer cannot be replayed.
- Activation token. A random secret the license server gives this machine when it activates. It stands for this machine's seat, and the server keeps only a hash of it.
The answer is a signed confirmation: your license ID, plan, machine hash and dates. The Studio keeps it only after it checks the signature, the nonce and the machine hash, and never trusts one for more than 16 days, whatever it says. Your license ID comes back in that answer; the request does not carry it.
The license server runs on Cloudflare, which sees the IP address a check comes from. Anything else you connect, such as Jira, Slack, Telegram or a cloud AI provider, is reached straight from your machine, never through us.
Keys and tokens
- Your license key is shown once, in your account. We keep only its prefix, which tells keys apart, and a SHA-256 hash of the key, so nobody can read it back from us, you included.
- The Studio sends the key once, to activate, and does not store it. It stores the activation token and the latest confirmation in
license.json, in the.sentinel-studiofolder of your user profile, sealed with an HMAC keyed to this machine: a copied or edited file counts as missing. - A lost or stolen laptop: in your account, under License & machines, deactivate it. Its token stops working at once, and it turns read-only when its last confirmation runs out, 11 days at most. Regenerating the key does the same for every machine.
- Your account signs in with a link that works once, for 15 minutes, or with Google. A session lasts 30 days, and Settings can sign out every other session.
What we keep, and for how long
The account portal and the license server keep their records in one database. Each row below is one of its tables, with how long it is kept, including after you delete your account. A scheduled job does the purging. The Privacy Policy says why we keep each one, and who processes it.
| Record | What it holds | How long |
|---|---|---|
| Account | Your email and whether it is verified, your Google account ID if you use Google, your Stripe customer ID once you pay, which Terms you accepted and when, a checkout you have open, when the account was created. | While the account is open. On deletion the email becomes a placeholder and the Google ID is erased; the account ID, its dates, the Stripe customer ID and the Terms acceptance are purged 24 months later. |
| Sessions | A SHA-256 hash of each session token, and when it started, ends or was signed out. | A session lasts 30 days; its record is purged 30 days after it ends. Erased on deletion. |
| Sign-in links | The address a link went to, a hash of the link, and when it expires or was used. | A link works for 15 minutes; its record is purged 1 day after it expires. Erased on deletion. |
| License | Plan, billing interval, machines allowed, status and why it was revoked, Stripe subscription ID, the paid-until and grace dates, a scheduled end, the first activation, when we sent the trial and renewal reminders. | While the account is open. On deletion it is marked canceled, or stays revoked, with nothing in it that names you, and is purged 24 months later. |
| License key | The key's prefix and a SHA-256 hash of it; when it was created and replaced. | While the account is open. Erased on deletion: the key stops working. |
| Machines | Each activated machine's hash, a hash of its activation token, and when it was activated, last checked in and deactivated. | While the account is open. Erased on deletion: each machine stops renewing. |
| Trial machines | The hash of each machine that started a trial, and which trial. | While the account is open, then 24 months after deletion, so a machine still gets one trial. |
| Emails | Which email went out and when: sign-in links, trial and renewal reminders, notices about your plan, license and account. Never your address: a sign-in row holds a hash of it, a reminder row your account ID. | While the account is open. Erased on deletion, except the notice that the account was deleted, purged 24 months later. |
| Audit log | Account events: the Terms accepted, a key regenerated, a payment not applied or refunded automatically, a license revoked or restored and why, the deletion itself. | While the account is open, then 24 months after deletion. Nobody can edit it. |
| Payment events | The ID and type of each notification Stripe sends, and when it arrived. | Kept: there is no personal data in it. |
| Website visits | A page view or a download: the page path, the site that linked to it, the time. No IP address, cookie or identifier. | 13 months. Never linked to an account. |
What stays after a deletion is what a billing dispute or a second trial on the same machine would need, and it is purged after 24 months. Deleting the account also deletes your customer record at Stripe, with its saved cards; the invoices and payments stay at Stripe, for accounting.
Cookies
This website sets no cookies and stores nothing in your browser. The account portal sets two, both needed to sign you in, and none for analytics or advertising, so there is no cookie banner to accept.
__Host-sessionkeeps you signed in to the portal for 30 days, or until you sign out. It holds a random token that page scripts cannot read (HttpOnly), that travels only over HTTPS (Secure) and only to our own domain, with SameSite=Lax. We keep only a hash of the token.__Host-g_oidcexists only while you sign in with Google. It protects that sign-in, and it is deleted when the sign-in ends, or after 5 minutes.
Download your data
- In your account, open Privacy and choose Download my data.
- You get a JSON file named
nexus-account-and the date. It holds your account, license, keys (prefix and dates only), machines and trial machines, sessions, sign-in links, the emails we sent you and your audit log.
It never includes the stored hashes of your keys, tokens or sessions. Your invoices, card and billing address are held by Stripe: open Plan & billing, then Manage billing. To erase the account, see Deleting your account.