Privacy Policy
The short version. NEXA is a personal media server. Your media files, your library database, your watch history and your user accounts are stored on a computer you own and operate — not on our servers. We run a small optional cloud service (nexaapp.tv) that only exists to help your devices find and reach your server. We don't show ads, we don't use third-party analytics or tracking SDKs, and we never sell or rent personal information.
1. Who is responsible for your data
NEXA has two very different parts, and it matters which one you are using:
- Your NEXA Server is software you install on your own hardware. Everything it stores stays on that hardware. The person who runs the server (the “server owner”) controls that data — including the data of any friends or family they invite. We have no access to it.
- nexaapp.tv is an optional account and relay service operated by us. For the limited data described in section 3, Romeoz Apps is the data controller.
2. Data stored on your own server
When you or someone you invite uses a NEXA Server, the server keeps the following on that machine only:
| Data | Why |
|---|---|
| Username, display name, email address and a salted, hashed password | To sign in and to tell users apart. Passwords are never stored in plain text. |
| Your media library (file names, paths, technical details, artwork and descriptions) | To build the library you browse. |
| Watch history, playback position, watchlist, ratings and requests | Continue Watching, On Deck and requests. |
| Active playback sessions (title, position, device type, IP address) | The “Now Playing” dashboard and to enforce stream limits. Sessions are cleared shortly after playback stops. |
| Library-access permissions and invite codes | So the server owner can decide what each user may see. |
| Push notification tokens | To notify you about new titles and request updates, if you turn notifications on. |
| Optional: live-TV provider address and credentials you enter | Only so the server can play channels from a service you already subscribe to. |
| Optional: smart-home device credentials you enter | Only to switch your lights when playback starts or stops. |
| Server logs | Troubleshooting. Logs stay on the server and are never sent to us. |
If you are an invited user, the server owner can see your username, what you have watched on their server and the device you used — the same way any shared media server works. Ask the owner if you want your account or history removed.
3. Data we process (nexaapp.tv)
You can use NEXA entirely without a nexaapp.tv account by connecting to your server's address directly. If you choose to create one, we store:
- Account: username, email address and a salted, hashed password.
- Server registration: a name and an opaque identifier for each server you link, so your apps can find it. We do not store a list of your media.
- Relay traffic: when you watch away from home, video is proxied through our relay so your home IP address is never revealed to viewers. The relay forwards encrypted traffic in real time and does not record or retain the media passing through it. We keep short-lived connection logs (timestamp, source IP, bytes transferred) for up to 30 days for abuse prevention and capacity planning.
- Support email: anything you send to [email protected].
4. Data on your device
The NEXA apps store your server address, a sign-in token and small caches of artwork and settings on the device so the app opens quickly. This data never leaves the device except to talk to your own server (or nexaapp.tv, if you use it). Signing out removes the token; deleting the app removes everything.
The iOS app may ask for permission to send push notifications. Denying it only disables notifications. The apps do not access your contacts, photos, camera, microphone, location or advertising identifier.
5. Third-party services
| Service | What is sent | Purpose |
|---|---|---|
| The Movie Database (TMDb) | Titles, years and episode numbers of items in your library — sent from your server, never tied to your identity | Posters, descriptions, cast and ratings. NEXA uses the TMDb API but is not endorsed or certified by TMDb. |
| Apple Push Notification service / Firebase Cloud Messaging | A device token and the notification text | Delivering notifications you opted into. |
| Cloudflare | Standard connection metadata for nexaapp.tv | DDoS protection and TLS for our website and relay. |
| Your live-TV provider (optional) | The credentials you enter | Playing channels from your own subscription. We have no relationship with any such provider. |
| Philips Hue / Wyze (optional) | The credentials you enter | Controlling your own lights. |
NEXA contains no advertising SDKs and no analytics or crash-reporting SDKs. The only telemetry the server sends us is an anonymous version check so it can offer updates.
6. How we use information
We use the nexaapp.tv data above only to operate your account, connect your devices to your server, keep the service secure and answer your support requests. We do not use it for advertising, profiling or sale.
7. Sharing
We do not sell, rent or trade personal information. We share it only with the service providers listed in section 5, strictly to provide NEXA; when required by law or a valid legal process; or to protect the rights, safety and property of our users or the public. If Romeoz Apps is ever acquired, this policy will continue to apply and you will be notified of any change.
8. Retention & deletion
- On your server: data stays until the server owner deletes it. Server owners can delete any user from the Users page; deleting a user removes their watch history. Uninstalling NEXA Server and deleting its data folder removes everything.
- nexaapp.tv: delete your account from the account page at nexaapp.tv, from the app's Settings screen, or by emailing us. Your account and server registrations are removed within 30 days; relay connection logs expire on their own within 30 days.
9. Your rights
Depending on where you live (including the EU/UK under GDPR and California under CCPA/CPRA) you may have the right to access, correct, export, restrict or delete personal information we hold, and to object to certain processing. Because we hold so little, the fastest route is simply to email [email protected]; we respond within 30 days and never discriminate against you for exercising a right. For data on a friend's server, contact that server's owner. We do not sell personal information and do not respond to “Do Not Track” signals because we do not track.
10. Security
Traffic between the apps, nexaapp.tv and your server is encrypted with TLS whenever you use HTTPS or the relay. Sign-in uses expiring bearer tokens, passwords are hashed with bcrypt, and stream links are signed and short-lived. No system is perfectly secure; if you believe your account has been compromised, change your password and contact us. Server owners are responsible for keeping their own server updated and behind appropriate network protection.
11. Children
NEXA is not directed at children under 13 (or the age of digital consent where you live) and we do not knowingly collect personal information from them. A server owner may create accounts for family members and is responsible for the content those accounts can access. If you believe a child has provided us with personal information, contact us and we will delete it.
12. Changes & contact
We will post any changes to this policy on this page and update the effective date; material changes will also be announced in the app or by email to nexaapp.tv account holders. Questions or requests: [email protected] — Romeoz Apps, Mount Airy, Maryland, USA.