Privacy policy

Nex Guardian LLC · dba NexGuardian

Effective date: 3 October 2026

Last updated: 3 October 2026


1. Who we are

Nex Guardian LLC, doing business as "NexGuardian" ("we", "us", "our"), is a limited liability company registered in the State of Wyoming, United States, and managed by its members. Our registered agent's mailing address on file is 30 N Gould St Ste R, Sheridan, WY 82801; that address is a registered-agent mailing address, not a place of business.

We build NexGuardian Gateway, an AI privacy-gateway product. The gateway is designed to sit between a customer's staff and third-party AI ("LLM") vendors: to redact personal information before prompts leave the customer's environment, to apply the customer's own rules about which AI tools and uses are allowed, to keep an audit trail, and to route items the customer flags as sensitive to a human reviewer that the customer chooses on their own side. The product is middleware. It does not make final decisions for our customers, and it does not decide anything on its own. Nothing is deployed for any customer today: the redaction engine is complete and demonstrable in a running build, and the interception, audit and review-routing components are in build; none of them is available for customer use yet, and this policy will be updated before any of them is.

This Privacy Policy explains what we do with personal information in two settings:

Where we process data for a Customer, the Customer is the controller and we are the processor. Their own privacy notice governs how they use the data they put into the gateway. Our processing is governed by the agreement we sign with that Customer, which includes our Data Processing Addendum.

The product is currently pre-launch. We have no product customers yet.

2. What our Site collects

The Site is a static marketing site. We keep data collection to a minimum.

We use this information only to run and secure the Site, to respond to you, and to understand general traffic. We do not sell personal information, and we do not use Site data to build advertising profiles.

3. Cookies and similar technologies

The Site as designed does not use advertising or analytics cookies, and we do not run third-party tracking pixels. Our CDN provider may set strictly necessary security cookies as part of protecting the Site from abuse. If we later add analytics or any non-essential cookie, we will update this policy and, where required, ask for consent first.

4. What the product processes, and our role

When a Customer deploys NexGuardian Gateway, prompts and documents that the Customer's staff route through the gateway are processed so the product can do its job. That can include:

For all of this, the Customer decides what goes in and why. We process it on their instructions. The Customer is the controller; we are the processor. We do not use Customer content for our own purposes, we do not sell it, and we do not use it to train our own models.

None of the product processing described above runs for any customer today: nothing is deployed for any customer today, and this policy will be updated before any of these activities is available for customer use.

5. Sub-processors

We use a small set of service providers ("sub-processors"). The ones we actually use or plan to use:

Sub-processorWhat it doesStatus
CloudflareDNS, CDN, site hosting (Cloudflare Pages), and email routingIn use
OpenRouterLLM API routing used for our own internal toolingIn use
LLM vendors a Customer connectsThe third-party AI model providers the Customer chooses to route prompts toDetermined per Customer
StripePayment processingPlanned — not in use yet

When a Customer connects a particular LLM vendor, that vendor becomes a sub-processor for that Customer's deployment. We will maintain a current sub-processor list and give Customers notice of changes, as set out in the Data Processing Addendum we sign with each Customer (NexGuardian Gateway — Data Processing Addendum (Short Form)).

6. International transfers

We are based in the United States, and the sub-processors above are primarily US-based. If we process personal information that originates in the EEA, the UK, or Switzerland, we will put appropriate transfer safeguards in place (for example, Standard Contractual Clauses and, where relevant, a transfer impact assessment) before that processing happens. Because the product is pre-launch, these safeguards are not yet executed and must be in place before we onboard any Customer in those regions.

7. How long we keep data

8. Security

We take technical and organisational steps to protect personal information. These are the steps the product takes today:

This section describes the measures we have today. It does not claim measures we do not have. The processing terms we sign with each Customer set these measures out in more detail. No system is perfectly secure, and we do not claim the gateway makes any organisation "fully compliant" or free of risk. What we provide is a control that reduces exposure; the Customer remains responsible for their own compliance obligations.

9. Your rights

Depending on where you live, you may have rights over your personal information.

If you are in the EEA, the UK, or Switzerland (GDPR / UK GDPR): you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where processing is based on consent. You also have the right to complain to your local data protection authority.

If you are in California (CCPA / CPRA): you may have the right to know what personal information we collect and how we use it, to delete it, to correct it, to opt out of the "sale" or "sharing" of personal information, and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under California law.

To exercise any of these rights, email us at [email protected]. We will respond within the time the applicable law requires. We may need to verify your identity first. Where we act as a processor for a Customer, requests about data the Customer put into the gateway should go to that Customer, and we will assist them as their processor.

10. Children

The Site and the product are business tools. They are not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at [email protected] and we will take appropriate steps.

11. Changes to this policy

We may update this policy from time to time. When we do, we will change the "Last updated" date above and post the revised policy on the Site. For a material change, we will take reasonable steps to bring it to your attention.

Changes apply from the date we post them and only to your use of the Site from that date. Your continued use of the Site after we post a revised version means you accept it for that use. Nothing posted on the Site changes the terms on which we process product data for a Customer: where we process data for a Customer, the agreement with that Customer and the Data Processing Addendum we sign with them govern that processing, and no change to a signed agreement takes effect unless both parties sign a written change.

12. How to contact us

Privacy contact: [email protected] Postal address: Nex Guardian LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA (registered agent mailing address — not a place of business)