Privacy Policy
Version 1.0.0 · Effective August 15, 2026
This Privacy Policy describes how PostGrad LLC (“Nexloss”, “we”, “us”, or “our”) collects, uses, shares, and protects personal information when you use nexloss.com, app.nexloss.com, Nexloss Inspect, our mobile applications, and related services (collectively, the “Service”). By using the Service, you agree to the practices described here.
1. Information We Collect
- Account information: name, email address, telephone number, hashed password, company name, professional license number where you provide it, billing address, and payment card details (processed by our payment processor; we do not store full card numbers).
- Inspection and claim content: property addresses, photographs and video of properties, audio recordings of inspection walkthroughs and their transcripts, moisture and psychrometric readings, measurements, signatures, notes, and generated reports.
- Location data: GPS coordinates embedded in photographs you capture, and device location at the time of capture where you permit it. This is precise geolocation, collected because photograph location is evidentiary in a property claim. You may disable it in your device settings; photographs without location are marked as such.
- Information about other people: content you upload routinely includes personal information about policyholders, claimants, tenants, carrier representatives, and other third parties. See Section 3.
- Communications: messages you send and receive through the Service, including SMS and email, and their delivery metadata.
- Usage and device data: API keys (hashed), request timestamps, IP addresses, user-agent strings, endpoint paths, response codes, usage volumes, and session cookies necessary to operate the Service.
2. How We Use Information
- Provide, operate, maintain, secure, and improve the Service.
- Authenticate users, issue API keys, and prevent fraud and abuse.
- Process inspection content through artificial intelligence to produce damage analysis, transcription, material identification, scope suggestions, completeness review, and report narrative (see Section 6).
- Generate the reports, estimates, and documents you create.
- Process payments, meter AI usage, and send billing communications.
- Send transactional notifications, security alerts, and service announcements.
- Comply with legal obligations and respond to lawful requests.
- Conduct internal analytics and aggregated reporting. We do not use personal information for targeted advertising and we do not build advertising profiles.
3. Our Role: Controller and Processor
For account information about our own customers and their users, Nexloss is a controller.
For inspection and claim content, including personal information about policyholders, claimants, and other third parties, our customer is the controller and Nexloss is a processor acting on that customer’s documented instructions. We process that content to provide the Service and not for our own purposes.
If you are a policyholder or claimant whose information appears in Nexloss because an adjuster, contractor, or other professional is handling your claim, that professional decides what is collected and how long it is kept. Direct access, correction, and deletion requests to them. If you contact privacy@nexloss.com we will refer your request to the relevant customer and assist them in responding.
4. Legal Bases (GDPR)
For users in the European Economic Area, the United Kingdom, and Switzerland, we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)) to deliver the Service you signed up for.
- Legal obligation (Article 6(1)(c)) to retain audit records, respond to lawful process, and meet tax and accounting requirements.
- Legitimate interests (Article 6(1)(f)) to secure the Service, prevent fraud, and improve product quality, balanced against your rights. You may object by contacting privacy@nexloss.com.
- Consent (Article 6(1)(a)) for optional cookies, marketing communications, and device location, where required. You may withdraw consent at any time without affecting prior lawful processing.
5. Sub-Processors
We share personal information only with vetted sub-processors who help us operate the Service, each bound by a written data-processing agreement:
- Supabase - Database, authentication, file storage
- Vercel - Website and application hosting
- Stripe - Payment processing
- Resend - Transactional and customer email delivery
- Twilio - SMS and voice
- Google (Gemini) - Transcription, document retrieval, text embedding
- OpenRouter and the model providers it routes to - AI analysis and generation
- Composio, CompanyCam, GoHighLevel - Only where you connect these integrations
We do not sell personal information. We do not share personal information for cross-context behavioral advertising or with advertisers. We may disclose information if required by law, subpoena, or court order, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of Nexloss, our users, or the public.
6. Artificial Intelligence Processing
When you use AI features, the relevant content (for example a photograph, an audio recording, or a structured summary of an inspection) is transmitted to the model providers listed in Section 5 for processing, and the result is returned and stored in your account.
We contract for enterprise or API-tier access on terms under which submitted content is not used to train the providers’ general-purpose models. Providers may retain content briefly for abuse monitoring in line with their own policies. We do not use your inspection or claim content to train models of our own that would be made available to other customers. Aggregate, de-identified usage statistics, such as how often a suggestion is accepted or dismissed, are used to improve the Service.
7. Retention
We retain your content for as long as your account is active. Because claim records often carry professional retention obligations, we do not delete inspection content on a fixed schedule while your account remains open. After termination you may export your data for thirty (30) days, after which we may delete it in the ordinary course. Backups persist for a limited period thereafter. Account and billing records are retained as long as required for tax, accounting, and audit purposes.
8. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to processing, and to withdraw consent. California residents have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA as amended by the CPRA; as stated above, we do not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising these rights.
To exercise a right, contact privacy@nexloss.com. We will verify your request and respond within the period required by applicable law. If your information is held in a customer’s account as described in Section 3, we will refer your request to that customer.
9. Cookies and Tracking
We use strictly necessary cookies for authentication, session management, and security. We do not use third-party advertising cookies or cross-site tracking. Because there is no industry-accepted standard for Do Not Track signals, we do not alter our practices in response to them; we do not engage in the tracking DNT is designed to prevent. You may disable cookies in your browser, but parts of the Service may not function correctly.
10. Security
We use encryption in transit and at rest, per-tenant data isolation enforced at the database level, hashed credentials and API keys, scoped access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information we will notify you and any regulator as required by applicable law.
11. International Transfers
We operate in the United States and our sub-processors may process information in the United States and other countries. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses or another lawful transfer mechanism.
12. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under eighteen (18). If you believe a child has provided us personal information, contact privacy@nexloss.com and we will delete it.
13. Changes and Contact
We may update this Policy. The revised Policy will carry an updated version number and effective date. Material changes will be communicated by email at least thirty (30) days before they take effect.
Questions, requests, or complaints: privacy@nexloss.com, or write to PostGrad LLC, Orlando, Orange County, Florida.