Privacy Policy

PersonaXpand · Operated by Nextoria Information Technology LLC

Last Updated: September 25, 2026

1. Introduction

Nextoria Information Technology LLC (“Nextoria,” “we,” “us,” or “our”) operates the PersonaXpand application (“the App”). This Privacy Policy explains what data we collect, why we collect it, how we protect it, and your rights over it.

By using the App, you agree to the practices described in this Policy. If you do not agree, please discontinue use and contact us at [email protected] to request deletion of your data.

2. Data We Collect

2.1 Account Information

When you register, we collect your name, email address, and mobile phone number, along with any profile information you provide. Your mobile number is used solely to send a one-time SMS verification code — through our SMS provider, Twilio — to confirm your identity and help prevent duplicate or fraudulent accounts. We do not use your phone number for marketing.

2.2 Connected Social Media Accounts

When you connect a social platform via OAuth, we store:

  • Platform-specific access tokens and refresh tokens (encrypted at rest with AES-256)
  • Platform user ID, page names, page IDs, and ad account identifiers
  • Token expiry dates and last-successful-call timestamps
  • The OAuth scopes you granted

Supported platforms: Google (YouTube), Facebook, Instagram, Threads, LinkedIn, X (Twitter), TikTok, Snapchat, Telegram, Pinterest, and Bluesky.

2.3 Content You Create
  • Posts, captions, images, and videos you draft or publish through the App
  • Scheduled post data and publishing history
  • Content planner entries, brand voice profiles, and user goals
  • Strategy clone configurations
2.4 Data Processed by AI Features

When you use AI-powered features (content optimization, onboarding, reply suggestions, Strategy Clone), the following data is transmitted to Google Gemini for processing:

  • Your post text and media type
  • Your brand voice settings (tone, industry, target audience)
  • Your user goals and content style preferences
  • For reply suggestions: The text of incoming messages received on your connected social accounts.
  • For YouTube specifically: incoming viewer comment text is sent to Gemini only when you have explicitly enabled AI reply suggestions for YouTube. Suggested replies are presented as drafts and are only submitted to YouTube after you, the channel owner, review and approve them. The app does not post YouTube comments autonomously.

This data is sent to Google’s Gemini API solely to generate a real-time response for you. We do not store these API requests beyond what is needed to display the result.

2.5 Analytics Data (Background)

We periodically fetch the following from your connected platforms on your behalf:

  • Follower counts and growth metrics
  • Post impressions, reach, engagement rates, and video views
  • YouTube channel statistics
2.6 Google Calendar Sync

If you connect Google Calendar, we sync event titles and dates to schedule social posts. Deleting a calendar event automatically deletes the corresponding scheduled post.

2.7 Technical & Log Data
  • Last API call timestamps per platform connection
  • Error messages from failed API calls (stored per connection)
  • AutoReply log entries (incoming message metadata and AI-generated reply text)
  • Sign-in history — the IP address, browser/device user-agent, and timestamp of each sign-in, shown to you in Account Settings and retained so you can spot unauthorised access to your account
  • Push notification device token — an identifier issued by Apple or Google that lets us deliver push notifications to the mobile app; stored only if you enable notifications, and deleted when you disable them or delete your account

3. How We Use Your Data

Data Purpose Feature
Account credentialsAuthentication & account managementAll
OAuth tokensMaking API calls to social platforms on your behalfAll posting & analytics features
Post contentPublishing, scheduling, AI-assisted optimizationPost, ContentPlanner, Schedule
Brand voice & goalsPersonalizing AI-generated content suggestionsPost, AutoReply, StrategyClone
Incoming messagesGenerating reply drafts via Google Gemini — drafts are submitted only after user review and approvalAutoReply
Analytics metricsDisplaying performance data in your dashboardAnalytics, Dashboard
Calendar eventsCoordinating scheduled social media postsSchedule, Calendar Sync
Content reports & blocksReviewing content you report as objectionable and enforcing sender blocksGlobal Inbox moderation
Content Moderation

When you report content in your inbox as objectionable, we keep a record of the report — including a snapshot of the reported message, the sender’s public platform identifier and username, and the reason you selected — and our moderation team reviews it, which includes reading the reported content. When you block a sender, we store a block record (your account, the platform, and the sender’s public platform identifier) so their messages can be filtered automatically. Reports and block records are used solely for safety and moderation and are never used for advertising or any other purpose.

We do not use your data for advertising, sell it to third parties, or use it to train any AI or machine learning model. This applies to all data — including data received from TikTok, Meta (Facebook/Instagram/Threads), Google, X, LinkedIn, Snapchat, Pinterest, and Bluesky platforms.

4. AI Processing Disclosure

The App uses Google Gemini (operated by Google LLC) to power content suggestions, onboarding guidance, AutoReply generation, and strategy analysis.

  • Content you write, and messages received on your social accounts (including Instagram, Facebook, Threads, X, YouTube, and Bluesky), may be transmitted to Google Gemini for real-time processing.
  • Google processes this data under its own Privacy Policy and Generative AI Additional Terms.
  • We do not use your data, or data received from any social platform, to train AI models. We use Google’s Gemini API under terms that do not permit Google to use API inputs for model training.

Per-platform commitments: We do not use TikTok, X (Twitter), Meta, Google, LinkedIn, Snapchat, Pinterest, or Bluesky account data, message content, or media for AI training, advertising profiling, or any model training pipeline. Platform data is accessed solely to perform the action you requested (publish, fetch analytics, generate a reply for you).

5. Google API Services — Data Access, Use & Disclosures

Our use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

This section describes, in detail, the Google APIs we access (YouTube Data API v3, YouTube Analytics API, Google Calendar API, and Google OAuth), the specific data each OAuth scope authorizes us to read or write, how we use it, and how you can revoke our access at any time.

5.1 Google Data We Access

When you sign in with Google or connect your YouTube channel to PersonaXpand via OAuth, we may access the following Google data, depending on the scopes you grant:

  • Identity (openid, profile, email): your Google account ID, name, profile picture URL, and email address — used to create and identify your PersonaXpand account.
  • Google Calendar (calendar.events): event title, time, and event ID. PersonaXpand creates, updates, and deletes events on your primary Google Calendar to mirror posts you schedule inside the app, and reads events within a date range (via an incremental sync token) to show your schedule in the in-app content planner. We access calendar events only — never the calendars themselves.
  • YouTube channel info (youtube.readonly): your channel ID, channel title, channel statistics (subscriber count, view count), and the list of your uploaded videos — used to confirm the correct channel is connected and to associate analytics. Endpoints: channels?mine=true, videos.list.
  • YouTube uploads (youtube): used solely to upload videos you explicitly compose and submit through the PersonaXpand post composer, and to set their title, description, tags, and privacy. Endpoints: videos.insert, videos.update.
  • YouTube comment replies (youtube.force-ssl): required by the YouTube Data API for the comments.insert endpoint, used solely to post replies that you, the channel owner, author within PersonaXpand to viewer comments on your videos. The app does not post YouTube comments autonomously, and does not modify or delete any comments authored by other users.
  • YouTube analytics (yt-analytics.readonly): read-only access to aggregated channel performance metrics (views, watch time, subscribers gained/lost) used to populate the YouTube analytics dashboard inside PersonaXpand.
5.2 How We Use Google Data
  • To display your YouTube channel, scheduled posts, calendar events, and analytics inside PersonaXpand.
  • To publish videos and post comment replies on YouTube only after you initiate the action inside the app.
  • To mirror posts you schedule onto your Google Calendar so you can see your content pipeline alongside other commitments.
  • To generate optional reply drafts via Google Gemini, when you have explicitly enabled AI reply suggestions. Suggested replies are presented as drafts; only replies you review and approve are submitted to the YouTube API.
5.3 What We Do NOT Do With Google Data
  • We do not use Google user data for advertising, audience profiling, or marketing analytics directed at any party.
  • We do not use Google user data, including YouTube comment text, video metadata, or channel statistics, to train AI or machine learning models — either our own or any third party’s.
  • We do not sell, rent, or otherwise transfer Google user data to any third party, except as strictly necessary to provide a feature you requested.
  • We do not modify or delete videos or comments that were not authored by the connected channel owner.
  • We do not post videos, comment replies, or calendar events without an explicit action by you inside the app.
  • We do not read any Google Calendar events that PersonaXpand did not create.
  • We do not retain Google user data longer than necessary to deliver the feature for which it was collected (see Section 12 for retention windows).
5.4 Sub-Processor for Google Data

The only sub-processor that may receive Google-derived data is Google LLC (Gemini API), used solely to generate optional AI-assisted reply drafts when you have explicitly enabled this feature for a relevant YouTube comment. Because Gemini is operated by Google, Google user data sent to Gemini remains within the Google ecosystem and is processed under Google’s own privacy terms. Google does not use Gemini API inputs to train its models under the API terms applicable to our account. No Google user data is shared with any third party outside of Google.

5.5 Required YouTube Disclosures

By using the YouTube features of PersonaXpand, you also agree to and acknowledge the following:

You may review and manage all third-party app permissions for your Google account at any time at https://myaccount.google.com/permissions, and your Google security settings at https://myaccount.google.com/security.

5.6 Revoking Google & YouTube Access

You can revoke our app’s access to your Google account, YouTube channel, and Calendar, and delete all Google-derived data we hold about you, in two ways:

  1. From within PersonaXpand: Social Media → YouTube → Disconnect, and Account Settings → Disable Google Calendar Sync. This immediately revokes our stored tokens, deletes locally cached YouTube comment data and analytics, and stops all background calendar sync.
  2. From Google: visit https://myaccount.google.com/permissions, find PersonaXpand, and click Remove access. Google will invalidate our tokens immediately. Any Google-derived data we hold will then be purged from our active systems within 24 hours and from backup snapshots within 7 days.

For deletion requests by email, contact [email protected] with the subject line “Google Data Deletion Request — PersonaXpand”, and we will confirm completion within 30 days.

6. TikTok Platform Data — Content Posting API

Our access to and use of data received from TikTok APIs (the TikTok for Developers Content Posting API) adheres to TikTok’s Developer Terms of Service, Content Sharing Guidelines, and the TikTok Privacy Policy.
6.1 TikTok Data We Access

When you connect your TikTok account (Personal, Creator, or Business) to PersonaXpand via OAuth, we may access the following TikTok platform data, depending on the scopes you grant:

  • Profile basics (user.info.basic): your TikTok open_id, union_id, display name, and avatar URL — used to identify which connected account is acting.
  • Video upload & publish (video.upload, video.publish): the videos and captions you choose to publish through PersonaXpand are uploaded to TikTok using the Content Posting API.
6.2 How We Use TikTok Data
  • To show which TikTok account is connected, and your scheduled and published TikTok posts, inside PersonaXpand.
  • To publish videos on your behalf only after you create or schedule the post.
6.3 What We Do NOT Do With TikTok Data
  • We do not sell or rent TikTok user data to any third party.
  • We do not use TikTok user data or media to train AI or machine learning models, our own or any third party’s.
  • We do not use TikTok data for advertising, audience profiling, or marketing analytics directed at any party other than the connected account owner.
  • We do not share TikTok data with sub-processors except our database hosting provider, for storage.
  • We do not aggregate, anonymize, or combine TikTok data with data from other users or other platforms to build profiles.
6.4 Sub-Processor for TikTok Data

PersonaXpand does not read TikTok messages or comments, so no TikTok-derived data is sent to Google Gemini or any other AI service. No TikTok data is shared with any third party for any purpose, other than our hosting provider storing it.

6.5 TikTok-Specific Retention
  • TikTok OAuth tokens: retained until you disconnect TikTok or delete your account.
  • TikTok publishing history (post text, references to media you uploaded): retained until you delete the post or your account.
  • TikTok analytics (views and engagement counts) fetched via API: kept until you delete your account.
6.6 Revoking TikTok Access & Deleting TikTok Data

You can revoke our app’s access to your TikTok account and delete all TikTok-derived data we hold about you in two ways:

  1. From within PersonaXpand: Social Media → TikTok → Disconnect. This revokes our token at TikTok and deletes the TikTok tokens we hold.
  2. From TikTok: open the TikTok app → Settings and privacy → Security and permissions → Manage app permissions → PersonaXpand → Revoke access. Our access ends immediately; to also delete the TikTok data we hold, disconnect TikTok in PersonaXpand or email us as below.

For deletion requests by email, contact [email protected] with the subject line “TikTok Data Deletion Request” and we will confirm completion within 30 days.

7. Pinterest Platform Data

Our access to and use of data received from the Pinterest API adheres to Pinterest’s Developer Guidelines and the Pinterest Privacy Policy.
7.1 Pinterest Data We Access

When you connect your Pinterest account to PersonaXpand via OAuth, we request only these permissions: user_accounts:read, boards:read, boards:write, pins:read, and pins:write. With them we access:

  • Account basics: your Pinterest account ID and username, used to show which account is connected.
  • Your boards: the list of your boards, so you can choose which board each Pin is saved to.
  • Pin publishing: creating the Pins you compose in PersonaXpand and choose to publish, and deleting them when you ask us to.
  • Pin performance: performance numbers for your own Pins, shown to you in PersonaXpand.
7.2 How We Use Pinterest Data
  • We publish a Pin only when you choose that Pin and its board. PersonaXpand never publishes to Pinterest automatically or in bulk without your choice.
  • If a Pin’s image was created with PersonaXpand’s AI image tool, we label the Pin as AI-modified using Pinterest’s own AI disclosure field.
  • Pin performance numbers are fetched live from Pinterest when you view them and are not stored on our servers.
7.3 What We Store
  • Your Pinterest access and refresh tokens, encrypted at rest with AES-256.
  • Your Pinterest account ID and username.
  • For each Pin you publish through PersonaXpand: the board you chose and the Pin’s ID, so you can find and delete it from PersonaXpand.
7.4 What We Do NOT Do With Pinterest Data
  • We do not sell, rent, or share Pinterest data with any third party.
  • We do not use Pinterest data for advertising, audience profiling, or marketing directed at anyone other than you.
  • We do not use Pinterest data to train AI or machine learning models, our own or any third party’s.
  • We do not combine Pinterest data with data from other users or build profiles from it.
7.5 Disconnecting Pinterest & Deleting Pinterest Data
  1. From within PersonaXpand: Social Media → Pinterest → Disconnect. This immediately deletes the Pinterest tokens and account details we hold.
  2. From Pinterest: you can also remove PersonaXpand from the apps connected to your account in your Pinterest settings, which ends our access on Pinterest’s side.

For deletion requests by email, contact [email protected] with the subject line “Pinterest Data Deletion Request” and we will confirm completion within 30 days.

8. Bluesky Data

8.1 Bluesky Data We Access

When you connect your Bluesky account to PersonaXpand through Bluesky’s own sign-in (AT Protocol OAuth), we access:

  • Account basics: your account identifier (DID), your handle, and the address of the server that hosts your account.
  • Posting: creating the posts you compose and choose to publish, uploading the images or video attached to them, and deleting posts when you ask us to.
  • Replies and mentions: replies to your posts and posts that mention you, so they appear in your PersonaXpand inbox. We also mark these notifications as seen on Bluesky once PersonaXpand has read them.
  • Post performance: likes, reposts, quotes, and replies on your own posts, read from Bluesky’s public data.
8.2 How We Use Bluesky Data
  • We publish a post only when you create or schedule it.
  • If you use reply suggestions, the text of a reply or mention may be sent to Google Gemini to write a draft. Every Bluesky reply waits for your approval; PersonaXpand never replies on Bluesky automatically.
8.3 What We Store
  • Your Bluesky access and refresh tokens and a signing key unique to your connection, all encrypted at rest with AES-256.
  • Your DID, handle, and hosting server address.
  • Reply and mention entries in your AutoReply log, kept under the same retention as other platforms (see Section 12).
8.4 What We Do NOT Do With Bluesky Data
  • We do not sell, rent, or share Bluesky data with any third party, except Google Gemini for reply drafts you asked for.
  • We do not use Bluesky data for advertising or audience profiling.
  • We do not use Bluesky data to train AI or machine learning models, our own or any third party’s.
8.5 Disconnecting Bluesky & Deleting Bluesky Data

Social Media → Bluesky → Disconnect immediately deletes the Bluesky tokens and signing key we hold, after which PersonaXpand can no longer act on your account. For deletion requests by email, contact [email protected] with the subject line “Bluesky Data Deletion Request” and we will confirm completion within 30 days.

9. Data Deletion Instructions

9.1 Self-Service In-App Deletion

You may delete your account and all associated data at any time, directly within the App, by visiting Account Settings → Delete My Account. After you confirm your identity (your password, or “Confirm with Google” if you sign in with Google), your account is deactivated immediately and enters a 7-day grace period — sign in again before it elapses and the deletion is automatically cancelled. After the 7 days, we permanently delete:

  • Your account and profile information
  • All connected social media account tokens (and we revoke app permissions at each platform)
  • All posts, drafts, schedules, and content planner data
  • All analytics data, brand voice profiles, and AutoReply configurations
  • All uploaded media files stored on our servers

If you are unable to access your account, you may alternatively email [email protected] with the subject line “Data Deletion Request — PersonaXpand” and we will process your request within 30 days.

9.2 Facebook / Meta — Revoking App Access

If you connected your Facebook or Instagram account and wish to remove our access and delete data we received via the Facebook Platform:

  1. Go to your Facebook Account Settings → Security and Login → Apps and Websites
  2. Find PersonaXpand and click Remove
  3. Facebook will automatically notify our system via a Data Deletion Callback, which triggers immediate deletion of all data associated with your Facebook account

Facebook will show you a confirmation code and a status URL (of the form /facebook/deletion-status?id=<code>) where you can verify completion.

9.3 TikTok — Revoking App Access

See Section 6.6 above for the dedicated TikTok revocation process.

9.4 Google & YouTube — Revoking App Access

See Section 5.6 above for the dedicated Google & YouTube revocation process.

9.5 Pinterest and Bluesky

See Section 7.5 (Pinterest) and Section 8.5 (Bluesky) above.

10. Third-Party Services & Data Sharing

We share data with the following services only to the extent necessary to operate the App:

ServicePurposeData SharedData Region
Google Gemini APIAI content generation & reply suggestionsPost content, brand voice, incoming message textUnited States
Google APIs (YouTube, Calendar)Publishing & calendar syncVideo content, calendar events, channel analyticsUnited States
Facebook / Instagram Graph APIPost publishing, analytics, DM auto-replyPost content, page access tokens, incoming messagesUnited States / Ireland
LinkedIn APIPost publishing, comment managementPost content, comment textUnited States
X (Twitter) API v2Post publishing, analytics, DM auto-replyTweet content, incoming DMsUnited States
TikTok Content Posting APIVideo publishingVideo file, caption text, privacy preferencesSingapore / United States
Pinterest API v5Pin publishing, board list, Pin performancePin image, title, description, link, chosen boardUnited States
Bluesky (AT Protocol)Post publishing, replies and mentions, post performancePost text and media, replies you approveUnited States (or the server hosting your Bluesky account)
Snapchat Marketing APIAd account accessOAuth credentialsUnited States
Telegram Bot APIMessaging featuresMessages sent via connected botMultiple (Telegram-managed)
SendGridTransactional emailEmail address onlyUnited States
TwilioSMS account verification (one-time passcodes)Mobile phone number onlyUnited States
Google Analytics 4 (optional, consent-based)Website traffic measurement on our public pagesPage views, traffic source, device and browser type, approximate (city-level) location; collected only after you accept the cookie bannerUnited States
Microsoft Azure (App Service & Azure SQL Database)Application hosting & database storageAll data stored at restIndia
10.1 Cookies & Website Analytics

Our public website pages (the landing page, marketing pages, and sign-in pages) use Google Analytics 4 to measure visits and traffic sources, and only if you accept the cookie banner shown on your first visit. If you accept, Google Analytics sets first-party cookies (such as _ga) and receives your page views, referring source, device and browser type, and approximate (city-level) location. If you decline, or until you make a choice, no analytics script loads and no analytics cookies are set. Your choice is remembered for 180 days, and you can change it at any time by clearing this site's cookies in your browser. Google Analytics is never loaded inside the PersonaXpand mobile apps or the logged-in application.

Separately from analytics, we set a single first-party cookie (px_attr) on your first visit that records how you reached us: the website that referred you, the page you landed on, and any campaign tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content) or advertising click identifier present in the link you followed. It exists so that, if you go on to create an account, we can tell which source brought you to us. It is read once at sign-up and then deleted; if you never create an account it simply expires after 30 days. The cookie is HttpOnly, stays on our own domain, is never sent to or shared with any third party, is not used to build a profile or to target advertising, is not set inside the PersonaXpand mobile apps, and is not set at all if you arrive directly at our home page without a referrer or campaign tag.

We also count visits to our public pages ourselves, without any third party. To do that we set one first-party cookie (px_vid) holding a random identifier — 22 characters of randomness, with no name, email address, or any identifier that could follow you to another website. Against it we record which of our pages you viewed, how long you were actively reading, how far down each page you scrolled, and which of a small, fixed set of buttons and links you pressed, so we can see which pages and which sources bring people to PersonaXpand. Alongside this we record four details that your browser and our network already send with every request: the country you are connecting from, the type of device (phone, tablet or desktop), the browser and operating system family, and the language your browser asks for. We store the country only, never a city and never your IP address, and we keep only the family names of your browser and operating system, not their full version strings. It is HttpOnly, never leaves our own servers, is never sold, shared, or used for advertising or profiling, and expires after 180 days. It is not set inside the PersonaXpand mobile apps, and it is not set at all if you decline the cookie banner. If you later create an account, this identifier tells us which visit led to that signup; it never tells us who you were before you signed up.

Inside the logged-in application we collect first-party product analytics tied to your account: which product pages you visit, how long you actively use them, how far down a page you scrolled, and key product actions such as signing in, connecting a social account, publishing a post, and completing a purchase. This data is collected and stored on our own servers only, is never sent to or shared with any third party, is not used for advertising, and exists solely so we can understand how PersonaXpand is used and improve it. It never includes the content of your posts, messages, or replies. On our public pages the same first-party system records only what is described in the paragraph above, and nothing else. The country, device, browser and language details described there are collected on our website only; they are never collected inside the PersonaXpand mobile apps.

We do not integrate Meta Pixel or any third-party advertising or behavioral tracking SDKs. We do not sell or rent your personal data to any third party. We do not share platform data with any sub-processor not listed above.

11. Data Security & Incident Response

11.1 Technical Safeguards
  • AES-256 encryption at rest for all OAuth access tokens and refresh tokens stored in our database
  • HTTPS (TLS 1.2+) for all data in transit — all connections between your browser and our servers are encrypted; HTTP requests are automatically redirected to HTTPS
  • HMAC-SHA256 signed state tokens to prevent cross-site request forgery (CSRF) during OAuth authorization flows
  • PKCE (Proof Key for Code Exchange) for X/Twitter OAuth to prevent authorization code interception
  • Session and authentication cookies enforced with Secure and HttpOnly flags
  • Webhook signature verification (HMAC-SHA256) for all inbound platform events (Meta, X)
  • Role-based access control on internal systems; production credentials are never logged
  • Automated daily backups of the production database with 7-day retention
11.2 Incident Response & Breach Notification

In the event of a data breach or security incident affecting your personal data, we will:

  • Notify affected users by email within 72 hours of confirmed discovery, in accordance with GDPR Article 33 and UAE PDPL requirements.
  • Notify the relevant supervisory authority (e.g., UAE Data Office, EU Data Protection Authorities) within the timelines required by applicable law.
  • Notify affected platform partners (TikTok, Meta, Google, X, LinkedIn, Pinterest, Bluesky) where the incident involves data received via their APIs, within the timelines specified in their developer terms.
  • Publish a post-incident report describing the scope, root cause, remediation, and preventive measures.

While we take commercially reasonable steps to protect your data, no system is 100% secure. Please notify us immediately at [email protected] if you suspect unauthorized access.

12. Data Retention

Data CategoryRetention Period
Account and profile dataUntil account deletion
OAuth tokens (all platforms)Until you disconnect the platform or delete your account
Published post historyUntil you delete your account
Analytics metrics (followers, post performance)Until you delete your account
Pinterest Pin performanceNot stored; fetched live when you view it
Incoming comments and messages (all platforms)Deleted after 90 days, except ones you have starred or that still have a reply waiting for your approval
Reply log (a record of each reply sent)The text of the message you replied to is removed after 90 days (30 days for YouTube). The record that a reply was sent, and your own reply text, are kept until you delete your account, because plan reply limits are counted from them.
My Twin reply examples (your own replies, used to learn your writing style)Up to 60 of your replies, each with a short excerpt of the message it answered (YouTube excerpts removed after 30 days), kept until you delete your account
Application log files7 days, then deleted
Backup snapshots7 days, then deleted

We do not retain data longer than necessary for the purposes described in this Policy. When you request account deletion, your account is deactivated immediately and permanently deleted after a 7-day grace period (signing in during that window cancels the request). Once deletion completes, your data is removed from our active systems within 24 hours and from backup snapshots within 7 days. For fraud-prevention and legal, tax, and accounting obligations, we thereafter retain only a one-way hashed identifier of the deleted account; this is never used to rebuild your profile.

13. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you
CorrectionRequest correction of inaccurate data
Deletion (Erasure)Request permanent deletion of all your data
PortabilityRequest your data in a machine-readable format
RestrictionRequest that we limit how we process your data
Opt-Out of AI ProcessingDisable AI-assisted features (AutoReply, content suggestions) to prevent your data from being sent to Google Gemini
Withdraw ConsentRevoke OAuth permissions for any connected platform at any time

Applicable frameworks: EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA), UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL), and India’s Digital Personal Data Protection Act (DPDP) 2023.

To exercise any of these rights, email [email protected]. We will respond within 30 days. Residents of the EU/EEA may also lodge a complaint with their local data protection authority.

14. Children’s Privacy

The App is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at [email protected].

15. International Data Transfers

Nextoria is based in Dubai, UAE. Your PersonaXpand account data, content, and uploaded media are hosted and stored at rest on Microsoft Azure infrastructure located in India. When you connect social platforms, data may additionally be transferred to and processed in the United States, Singapore, Ireland, and other countries where these platforms operate (see Section 10 for per-service regions). We rely on your explicit consent (provided via OAuth authorization) and, where applicable, standard contractual clauses or equivalent safeguards for such transfers. TikTok user data may be processed in TikTok’s data centers located in Singapore, Malaysia, the United States, and Ireland, in accordance with TikTok’s data residency policies.

16. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification. The “Last Updated” date at the top will always reflect the most recent revision. Continued use of the App after a revision constitutes acceptance of the updated Policy.

17. Contact Us

Nextoria Information Technology LLC

Airport Rd, Al Garhoud, Dubai, United Arab Emirates

Email: [email protected]

  • Data Deletion Requests: Subject — Data Deletion Request — PersonaXpand
  • Data Access / Portability Requests: Subject — Data Access Request — PersonaXpand
  • TikTok Data Deletion: Subject — TikTok Data Deletion Request
  • Pinterest Data Deletion: Subject — Pinterest Data Deletion Request
  • Bluesky Data Deletion: Subject — Bluesky Data Deletion Request
  • Security / Breach Reports: Subject — Security Incident Report