Privacy Policy

Last updated: June 16, 2026

This Privacy Policy explains how Nexioty Electronics Limited ("Nexioty", "we", "us") collects, uses, and protects personal data when you use TermIQ ("the Service"). TermIQ is a remote-access bridge for AI terminals: your computer runs the AI tools, and your phone keeps you in control. Terminal content is end-to-end encrypted and we cannot read it — see "How TermIQ handles terminal content" below.

1. Who is responsible for your data

The data controller for TermIQ is:

Nexioty Electronics Limited, a limited company incorporated in Hong Kong SAR.
Registered address: Flat/RM 1019B, 10/F, Liven House, 61-63 King Yip Street, Kwun Tong, Kowloon, Hong Kong.
Privacy contact: [email protected]

For general support contact [email protected]. To report abuse contact [email protected].

2. Our representatives in the EU/EEA and the UK

Nexioty is established in Hong Kong and offers the Service to users in the EU/EEA and the United Kingdom. Under Article 27 of the EU GDPR and the UK GDPR, a controller in this position designates a representative in those regions.

You can raise any data-protection matter with us directly at [email protected] — including if you are located in the EU/EEA or the United Kingdom — and we will respond. Where a designated Article 27 representative is appointed for the EU/EEA or the UK, their name and contact details are published in this section and in our Imprint.

3. What personal data we collect

We collect only what the Service needs to function. Categories below are derived from our actual data model.

CategoryData pointsSource
AccountEmail, name (optional), avatar URL, password hash (if not using Google), Google account ID (if using Google sign-in), email-verification state, interface languageYou / Google OAuth
Authentication & sessionsHashed session/refresh tokens, IP address, device/user-agent, approximate GeoIP location, last-login timeAutomatic on sign-in
BillingStripe customer & subscription identifiers, plan, account type, billing name, billing address, VAT number, phoneYou / Stripe
Push notificationsPush subscription endpoint and keys, push privacy-mode preferenceYour browser/device
Terminal connectionsAgent, workspace, terminal and task records — names/paths/commands stored only as end-to-end-encrypted blobs we cannot decrypt; plus non-content metadata (machine ID, OS label, online status, public key, timestamps)Your VS Code extension / CLI
SupportTickets and ticket messages, plan/app-version/device captured at ticket creationYou
API accessAPI-key name, key prefix, SHA-256 key hash, last-used timeYou
Promotions & referralsReferral code, who referred you, promo-code usage recordsYou / referrer
MarketingMarketing consent state, consent timestamp/source, unsubscribe state, per-recipient email send log, suppression list (keyed by email)You
AuditRecords of security-sensitive admin actions, which may reference your email/identifierAutomatic (admin actions)
WaitlistEmail, name, position, source, IP, user-agent (if you joined the waitlist)You
Acquisition & attributionMarketing-campaign parameters (utm_source, utm_medium, utm_campaign) and the landing-page referrer, captured first-party when you sign upYour browser at sign-up

We do not intentionally collect special-category data, and you should not place it in fields such as your name or support messages.

4. How TermIQ handles your terminal content

TermIQ is a content-blind relay. Your AI tools (such as Claude Code or Gemini CLI) run on your own machine using your own credentials. TermIQ transmits the terminal input/output between your computer and your phone after it has been end-to-end encrypted on your own devices (NaCl / XSalsa20-Poly1305). Our servers only ever hold opaque encrypted blobs and the keys never leave your devices, so we cannot read, search, or reconstruct your terminal content, commands, file paths, or AI prompts and responses.

To be accurate and transparent: this encrypted data is transmitted and stored by us in encrypted form so the Service can synchronize between your devices — it is not ephemeral and is not auto-deleted after a fixed number of hours. Encrypted terminal metadata persists until the corresponding resource (terminal, workspace, agent) or your account is deleted. The protection is not that "nothing is stored" — it is that the server is blind to the content.

We previously described terminal data as deleted after 24 hours and "not stored". That description was inaccurate and has been replaced by this section.

5. Why we use your data and our legal bases

Where the GDPR / UK GDPR applies, we rely on these legal bases:

PurposeLegal basis
Create and operate your account; relay terminal sessionsPerformance of a contract (Art. 6(1)(b))
Process payments and manage subscriptionsPerformance of a contract (Art. 6(1)(b))
Send transactional emails (verification, security, billing)Performance of a contract (Art. 6(1)(b))
Send push notifications about your terminalsPerformance of a contract (Art. 6(1)(b)) / consent
Secure the Service, prevent fraud and abuse, keep audit logsLegitimate interests (Art. 6(1)(f))
Record session IP / device / GeoIP for security and account safetyLegitimate interests (Art. 6(1)(f))
Understand which channels bring users (acquisition / attribution analytics)Legitimate interests (Art. 6(1)(f))
Send marketing emailsConsent (Art. 6(1)(a)) — opt-in, withdrawable anytime
Comply with tax, accounting, and legal obligationsLegal obligation (Art. 6(1)(c))

You can withdraw consent (e.g. for marketing) at any time without affecting prior processing.

6. Service providers (sub-processors) we use

We do not sell your personal data. We share it only with vetted service providers that process it on our behalf, under data-processing agreements:

ProviderPurposeRegionTransfer mechanism
Google LLC / Google Ireland LtdGoogle sign-in (OAuth) and Workspace SMTP relay for transactional & marketing emailUS / EUEU-US DPF + SCCs
Stripe, Inc.Payment processing and billing identifiersUSSCCs / DPF
Hetzner Online GmbHCloud hosting (application servers, PostgreSQL, Redis)Germany (EEA)Within the EEA
Cloudflare, Inc.CDN, DNS, WAF, and TLS terminationUS / globalSCCs / DPF
Functional Software, Inc. (Sentry)Error and performance monitoringUSSCCs / DPF

A current, versioned list is published at /subprocessors.

Important — AI providers are NOT our sub-processors. The AI tools you use (such as Anthropic's Claude Code or Google's Gemini CLI) run on your own machine under your own account and credentials. TermIQ never sends your prompts or terminal content to those providers — it only relays the end-to-end-encrypted stream between your own devices and cannot read it. Your use of those AI tools is governed by your own agreement with the respective AI provider.

We may also disclose data where required to comply with the law, enforce our terms, or protect the rights and safety of users and the public.

7. International data transfers

TermIQ involves transfers of personal data across borders:

  • Hong Kong — Nexioty, the controller, is established here.
  • United States — Google, Stripe, Cloudflare, and Sentry process certain data here.
  • Germany / EEA — Hetzner hosts our servers and databases here.

Where we transfer data out of the EEA or the UK, we rely on appropriate safeguards: the EU Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum / IDTA, and the EU-US Data Privacy Framework where the importer is certified. Hong Kong is not the subject of an EU/UK adequacy decision; we have assessed the transfer risk (including potential government-access exposure under applicable Hong Kong/PRC law) in a Transfer Impact Assessment. A key risk-reducing factor is that terminal content is end-to-end encrypted and unreadable by us or any provider. You can request information about the safeguards in place by emailing [email protected].

8. How long we keep your data

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymize it:

DataRetention
Account dataUntil you delete your account; a 30-day soft-delete grace period applies, after which it is anonymized
Sessions (IP / device / GeoIP)Until the session expires or you log out, then removed by periodic cleanup
Encrypted terminal metadataUntil the related terminal/workspace/agent or your account is deleted
Push subscriptionsUntil you remove the device or it becomes invalid
Support tickets and messagesFor the life of the account, then deleted/anonymized with the account
Marketing send log (recipient email)Removed about 6 months (182 days) after the message is sent
Suppression list (unsubscribes)Retained to honor your opt-out (kept by email, even after account deletion)
Audit logsRetained for 12 months for security and accountability
Billing records and invoicesRetained as required by applicable tax and accounting law

9. Your rights

Depending on where you live, you may have the right to:

  • Access — get a copy of your personal data.
  • Rectification — correct inaccurate or incomplete data (you can edit most of it in Settings).
  • Erasure — ask us to delete your data.
  • Portability — receive your data in a machine-readable format.
  • Restriction / Objection — limit or object to certain processing based on legitimate interests.
  • Withdraw consent — e.g. unsubscribe from marketing at any time.

To exercise any of these rights, email [email protected]. You may also contact our EU/EEA or UK representative (Section 2). We will respond within the time limits set by applicable law. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

10. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not use your data for that kind of profiling. Automated checks used to detect abuse or fraud are limited to protecting the Service and do not by themselves produce such effects.

11. Changes to this policy and how to contact us

We may update this Privacy Policy from time to time. We will post the new version here and update the "Last updated" date; for material changes we will provide additional notice. For any privacy question or request, contact us at [email protected].

Nexioty Electronics Limited — Flat/RM 1019B, 10/F, Liven House, 61-63 King Yip Street, Kwun Tong, Kowloon, Hong Kong.