Privacy Notice
Effective June 22, 2026 · Version 3.0 · Last updated June 22, 2026
Plain-English Summary
Nexiom is a personal-productivity and founder-support platform. We store the data you log — your daily entries, body activity, finances, tasks, mood, reflections, and (where community features are enabled) your posts and messages — only so we can provide the service to you. We do not sell, rent, or share your personal data with advertisers.
You can export a full copy of everything we hold on you as a JSON file and permanently deleteyour account at any time from Settings → Privacy & data.
1. Who We Are — Data Fiduciary
MarshallRidge Consulting Private Limited(“Company”, “we”, “us”) operates the Nexiom application available at nexiom.marshallridgeconsulting.com. We are the Data Fiduciary within the meaning of the DPDP Act, 2023, in respect of all personal data we process about you.
Our registered address is MarshallRidge Consulting Private Limited, A Unit No 52, 2nd Flr, P No C-39A, Gami Ind. Park, MIDC, Thane 400705, Maharashtra, India. For all privacy questions or to exercise your Data Principal rights, please contact our Grievance Officer at contact@marshallridgeconsulting.in.
2. What We Collect & Why
We collect personal data only to the extent necessary for the specific purposes stated below (data minimisation principle):
- Account data — your name, email address, optional phone number, timezone, and account preferences. Used to authenticate you, personalise the app, and communicate with you about your account.
- Profile & goal data — life roles, custom roles, goals, currency preference, display name. Used to render your home dashboard and tracker features.
- Daily tracker logs — daily intent, mood rating, energy level, reflection text, and time-per-role entries. Used to compute your streak, score, trend charts, and reports.
- Body & fitness data — workout entries, intensity (RPE), subjective feel, optional body measurements (weight, waist, body-fat %, and other metrics you choose to log), and personal records. Stored solely to display your progress to you. Never shared externally.
- Business ledger data — income and expense entries you choose to log. Stored solely to display your business snapshot to you. Never shared or disclosed externally.
- Task data — tasks you create, their due dates, status, and notes. Stored to provide task management and optional reminders.
- AI wisdom queries— questions you submit to the Wisdom Corner are sent to Anthropic’s Claude API (a US-based sub-processor) to generate an answer. Both your question and the AI response are stored against your account so you can revisit them. Anthropic does not use API inputs to train models per its published API policy.
- Community content & messages — where community features are enabled: posts, comments, direct messages, and profile content you publish. This content may be visible to other users in accordance with your privacy settings and the Terms of Use.
- Push notification subscription — only if you opt in: the browser push endpoint, public key, and auth key necessary to deliver notifications to your device.
- Operational & security data — IP address and user-agent at the moment of sensitive operations (sign-in, password change, account deletion, plan change). Stored in an audit log visible only to you in Settings.
- Billing & subscription data — if you subscribe, your plan name, subscription status, billing period, and payment timestamps. Card, UPI, and banking credentials are never seen or stored by Nexiom — handled directly by Razorpay.
- Usage & analytics data — aggregated feature usage statistics and performance telemetry (no individual profiling for advertising). Used solely to identify bugs and improve the Platform.
3. Legal Basis for Processing (DPDP Act 2023)
We process your personal data on the following legal bases under the DPDP Act, 2023:
- Consent (§ 7 DPDP): For processing that is not strictly necessary to perform the service contract — such as optional notifications, AI wisdom queries, and community features — we rely on the freely given, specific, informed, and unambiguous consent you provide at account creation or when you enable a feature.
- Contract performance (§ 7 DPDP): For processing necessary to deliver the subscription service you have signed up for — such as storing your daily logs, generating reports, and managing your account and billing.
- Legal obligation: For audit logs (fraud prevention and platform security) and retention of tax invoices (legal obligation under GST law).
You may withdraw consent at any time by disabling a specific feature or by deleting your account. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
4. Visibility, Sharing Controls & What We Do Not Do
Private by default. Your daily tracker entries, body data, business ledger, task data, and AI wisdom queries are private to you by default and are never visible to other users, coaches, or administrators except as described below.
Household sharing. If you join a household group, certain optional shared features (shared streaks, cheer) may be visible to other members of your household, subject to the privacy settings you configure.
Community content. Content you publish to community areas of the Platform (posts, profiles, comments) is visible to other users as configured by your privacy settings. You can update or delete community content at any time.
Coaches & administrators. Coaches with administrative access can view aggregated platform statistics but do not have access to your individual private entries, body data, business data, or messages unless you explicitly share them.
What we do not do:
- We do not sell, rent, or broker your personal data to any third party.
- We do not use your private data for advertising or targeted marketing.
- We do not use your data to train AI models without your separate, express consent.
- We do not share your data with third parties except as described in § 5 (sub-processors) or as required by law.
5. Sub-Processors & Cross-Border Transfers
We share data with the following sub-processors, who process it solely to help us provide the Platform. We maintain appropriate data-protection arrangements with each:
- Supabase, Inc. — Database, authentication, file storage. Data region: Mumbai (ap-south-1), India.
- Vercel, Inc. — Web application hosting & edge delivery. Data region: Global edge with primary in Mumbai.
- Anthropic PBC — AI model that powers Wisdom Corner answers. Data region: United States (data not used for training per Anthropic's API policy).
- Google FCM / Apple APNS — Web push notification delivery (when you enable notifications). Data region: Global.
- Razorpay Software Pvt. Ltd. — Payment processing (only when you upgrade to a paid plan). Data region: India.
- Google LLC (Google Analytics) — Website usage analytics — loads only after you accept cookies. Data region: United States / Global.
- Meta Platforms, Inc. (Meta / Facebook Pixel) — Website analytics & ad measurement — loads only after you accept cookies. Data region: United States / Global.
Cross-border transfers. Our primary data storage is in Mumbai, India (Supabase ap-south-1). However, some data crosses India’s borders:
- AI inference (Anthropic, US):When you use the Wisdom Corner, your query is sent to Anthropic’s servers in the United States. Anthropic does not retain API inputs beyond the inference request and does not use them to train models per its enterprise API policy. All data is encrypted in transit (TLS).
- Push notifications (Google FCM / Apple APNS, Global): If you enable push notifications, only notification content (e.g., a daily reminder) is passed through these services. No private health, financial, or tracker data is included.
- Edge delivery (Vercel, Global):Static application assets may be served from Vercel’s global edge network. Your personal data (logged entries, etc.) remains in Supabase Mumbai.
Where cross-border transfers occur, we ensure appropriate safeguards as required by the DPDP Act and applicable law, including contractual protections with sub-processors.
Cookies & website analytics.Our marketing website uses analytics and advertising cookies — Google Analytics and the Meta (Facebook) Pixel — which load only after you accept cookies via our consent banner. They record website page views and ad effectiveness using your browser and device data, and may transfer it to Google and Meta in the United States. They do not access your private in-app data (your daily tracker, body, business, or Wisdom entries). You can Declineat any time; clearing your browser’s site data resets the choice and shows the banner again.
6. Data Retention & Auto-Deletion
- Active accounts: We retain your personal data for as long as your account is active and you are using the Platform.
- Account deletion:If you delete your account (Settings → Privacy & data → Delete my account), all your personal data is permanently deleted within 24 hours.
- Mandatory legal retention: We retain: (a) GST invoices and billing records for 8 years as required by Indian tax law; and (b) security and fraud audit logs for 12 months, after which they are automatically purged.
- Inactive trial accounts: If you created an account on a free trial and have not logged in for 90 consecutive days, your account and all associated data are automatically purged. You will receive an email warning 7 days before auto-purge.
- Community content: Content you post to community areas may remain visible after you delete individual posts, to preserve conversation context. You may request full erasure of your community content by contacting our Grievance Officer.
7. Your Rights as a Data Principal (DPDP Act §§ 11–14)
Under the DPDP Act, 2023, you have the following rights:
- Right to access information (§ 11):You have the right to know what personal data we hold about you. You can export everything we hold as a JSON file instantly from Settings → Privacy & data → Export my data.
- Right to correction and erasure (§ 12):You may correct inaccurate data (edit your profile, roles, goals, and entries directly in the app) and erase data that is no longer necessary (delete your account from Settings → Privacy & data → Delete my account — this is irreversible).
- Right to withdraw consent (§ 6): You may withdraw consent for any specific feature at any time by disabling that feature in settings, or withdraw all consent by deleting your account.
- Right to nominate (§ 14): You may nominate another individual to exercise your Data Principal rights in the event of your death or incapacity. To register a nominee, email contact@marshallridgeconsulting.in.
- Right to grievance redressal (§ 13): You have the right to have your privacy grievance addressed promptly and fairly.
To exercise any right other than those available self-service in the app, contact our Grievance Officer at contact@marshallridgeconsulting.inwith subject line “Data Principal Rights Request”, your name, registered email address, and the specific right you wish to exercise.
8. Grievance Officer & How to Complain
We have appointed a Grievance Officer in accordance with the DPDP Act, 2023 and IT Rules 2021:
- Name: Narendra Pratap Singh Tomar
- Email: contact@marshallridgeconsulting.in
- Postal address: MarshallRidge Consulting Private Limited, A Unit No 52, 2nd Flr, P No C-39A, Gami Ind. Park, MIDC, Thane 400705, Maharashtra, India
- SLA: We will acknowledge your complaint within 7 working days and endeavour to resolve it within 30 days of receipt.
If your complaint is not resolved within 30 days, or if you are not satisfied with our resolution, you may escalate to the Data Protection Board of India established under Section 18 of the DPDP Act, 2023.
9. Security Measures
We implement appropriate technical and organisational security measures, including:
- Encryption in transit: All connections are TLS-encrypted (HTTPS-only).
- Encryption at rest: Your personal data is encrypted at rest by our database provider (Supabase) in Mumbai.
- Authentication: Passwords are hashed using bcrypt. Access tokens are signed JWTs with short expiry windows.
- Row-level security: Every row in our database is protected by database-level row-level security policies ensuring users can only access their own data.
- Access controls: Production data access by Company staff is restricted to incident response scenarios, requires multi-factor authentication, and is logged.
- Sensitive field encryption: Sensitive fields are encrypted using a field-level encryption key stored separately from the data.
- Audit logging: Sensitive operations (sign-in, password reset, account deletion, plan changes) are logged with timestamp, IP address, and user-agent.
No security measure is 100% effective. If you believe your account has been compromised, please sign out of all devices from Settings → Security and immediately contact us at contact@marshallridgeconsulting.in.
10. Children (18+)
The Platform is not directed to persons under 18 years of age. We do not knowingly collect, process, or solicit personal data from minors. If you are under 18, do not create an account or submit any personal data.
If you believe that a person under 18 has registered an account, please notify us immediately at contact@marshallridgeconsulting.in and we will promptly investigate and, where confirmed, terminate the account and permanently delete all associated data.
11. Personal Data Breach Notification
In the event of a personal data breach likely to result in risk to your rights and freedoms as a Data Principal, we will:
- Notify the Data Protection Board of India within the timeframe prescribed under the DPDP Act, 2023 and its rules.
- Notify CERT-In within 6 hours of becoming aware of a qualifying cybersecurity incident, in accordance with the CERT-In Directions (April 2022).
- Notify affected Data Principals (you) of the breach, its nature, and the steps taken to address it, within the timeframe prescribed by applicable law.
12. Non-Waivable Statutory Rights
Nothing in this Privacy Notice or our Terms of Use waives or limits any right you have under:
- the Digital Personal Data Protection Act, 2023 (including your rights as a Data Principal);
- the Consumer Protection Act, 2019 (for users accessing the Platform in an individual consumer capacity); or
- any other applicable law that confers rights that cannot lawfully be excluded or limited by contract.
Your right to approach the Data Protection Board of India cannot be waived or restricted by any agreement with us.
13. Changes to This Notice
We may update this Privacy Notice from time to time. For material changes (such as a new category of data collection, a new sub-processor in a new country, or a change in retention periods), we will notify you in-app and by email before the changes take effect and may require you to re-accept. Non-material changes (clarifications, formatting) are reflected in the “Last updated” date above.
14. Contact
Grievance Officer: Narendra Pratap Singh Tomar
Email: contact@marshallridgeconsulting.in
Postal address: MarshallRidge Consulting Private Limited, A Unit No 52, 2nd Flr, P No C-39A, Gami Ind. Park, MIDC, Thane 400705, Maharashtra, India
For general support, write to contact@marshallridgeconsulting.in.
For data-related complaints unresolved within 30 days, you may approach the Data Protection Board of India at its official portal (when operational under the DPDP Act, 2023).