Preparing your experience...
Preparing your experience...
Last updated: December 8, 2025
Your privacy is important to us. It is NexVigilant, LLC's policy to respect your privacy regarding any information we may collect from you across our website and services. This policy outlines how we collect, use, and protect your information in a transparent manner aligned with our core values of independence and integrity.
We collect information you provide directly to us when you:
When you access or use our services, we automatically collect:
We respect browser Do Not Track (DNT) signals. Our analytics systems are designed with privacy-first principles and do not engage in cross-site tracking.
We use the information we collect to:
We do NOT sell your personal information to third parties. We do NOT share your data with pharmaceutical companies or other industry entities for marketing purposes, in accordance with our founding principles of independence.
We adhere to the principle of data minimization. We only collect personal information that is necessary for the specific purposes described in this policy. We do not collect data "just in case" it might be useful later. When data is no longer needed for its original purpose, we delete or anonymize it in accordance with our retention schedule.
We understand that your professional details (job title, employer, credentials, areas of expertise) are provided in trust. We commit to:
Where we rely on consent as a legal basis for processing, we obtain it through clear, affirmative actions:
You can withdraw consent at any time through your account settings or by contacting us at privacy@nexvigilant.com. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
We use Google Firebase for authentication and data storage. Firebase may collect device and usage information for service operation and security. Learn more: firebase.google.com/support/privacy
We use Vercel Analytics to monitor site performance and usage. Vercel Analytics collects:
Vercel Analytics is privacy-friendly and GDPR compliant:
Learn more: Vercel Analytics Privacy Policy
We use Vercel Speed Insights to monitor and improve site performance. Speed Insights collects:
Speed Insights data is anonymized and used solely for performance optimization. No personal information is collected.
We use Vercel BotID to protect our services from automated abuse, spam, and fraudulent activity. BotID works by:
What BotID protects:
Privacy safeguards:
BotID is essential for maintaining platform integrity and protecting all users from abuse. Learn more: Vercel Security Documentation
We use Google's Gemini AI (via Firebase Genkit) to power certain features of our platform, including:
How AI processes your data:
AI processing is covered by Google Cloud's Data Processing Terms. Learn more: Google Cloud Data Processing Addendum
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data based on the following legal grounds under GDPR:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and service delivery | Contract Performance - Necessary to provide our services to you |
| Payment processing | Contract Performance - Necessary to fulfill subscription agreements |
| Analytics and platform improvement | Legitimate Interests - Improving our services and user experience |
| Security and fraud prevention | Legitimate Interests - Protecting our platform and users from abuse |
| AI-powered features | Legitimate Interests - Providing enhanced functionality and personalization |
| Marketing emails | Consent - Only sent with your explicit opt-in permission |
| Service-related communications | Contract Performance - Necessary for service operation |
| Legal compliance and tax records | Legal Obligation - Required by applicable laws |
Where we rely on legitimate interests, we have conducted balancing tests to ensure your rights and freedoms are not overridden. You may object to processing based on legitimate interests by contacting us at privacy@nexvigilant.com.
We store your data using industry-standard security measures:
While we implement strong security measures, no internet transmission is 100% secure. We cannot guarantee absolute security but commit to promptly notifying affected users and relevant authorities of any data breaches within 72 hours as required by GDPR.
We rely on infrastructure providers with recognized security certifications:
We conduct regular security reviews of our application code and access controls. We are committed to achieving independent security certifications as we scale, and will update this policy accordingly.
We retain your information for specific periods based on the type of data and our legal obligations:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data (profile, preferences) | Duration of account + 30 days | Service provision and account recovery |
| Capability pathway progress | Duration of account + 1 year | Certificate verification and records |
| Community posts and content | Duration of account + 30 days | Content integrity; may be anonymized rather than deleted |
| Analytics data (Vercel) | 26 months | Platform improvement (anonymized) |
| Security and audit logs | 12 months | Security monitoring and incident response |
| Payment and transaction records | 7 years | Legal requirement (tax and financial regulations) |
| Support correspondence | 3 years | Service quality and dispute resolution |
| Marketing consent records | Duration of consent + 3 years | Proof of consent for compliance |
When you delete your account, we will delete or anonymize your personal information within 30 days, except where longer retention is required by law (such as payment records).
Data in Backups: Deleted data may persist in encrypted backups for up to 30 additional days before being automatically purged. Backup data is not actively processed and is protected by the same security measures as primary data.
We use cookies and browser local storage for:
We use the following cookies:
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| __session | Essential (1st party) | Firebase authentication session | Session / 14 days |
| __stripe_mid | Essential (3rd party) | Stripe fraud prevention | 1 year |
| __stripe_sid | Essential (3rd party) | Stripe session identifier | Session |
Note: Vercel Analytics does not use cookies. We do not use advertising or tracking cookies.
We store the following data in your browser's localStorage:
| Key | Purpose | Retention |
|---|---|---|
| nexvigilant_behavior_metrics | Tracks page visits and feature usage for UX improvement | Until cleared |
| nexvigilant_behavior_tracking_enabled | Your opt-in preference for behavior tracking | Until cleared |
| nexvigilant_lesson_progress | Saves your pathway progress and completed lessons | Until cleared |
| nex_discovery_quiz | Stores your career discovery quiz responses | Until cleared |
| emailVerificationBannerDismissed | Remembers if you dismissed the email verification banner | Until cleared |
| nex_discovery_quiz_preview | Stores preview quiz responses (public page) | Until cleared |
| nex_enhanced_quiz_progress | Saves in-progress enhanced discovery quiz answers | Until cleared |
| nex_enhanced_discovery_quiz | Stores completed enhanced discovery quiz results | Until cleared |
| nexvigilant_cookie_consent | Stores your cookie preferences (essential, analytics, functional) | 1 year |
| nexvigilant_marketing_consent | Stores your marketing email preferences | Until cleared |
| nexvigilant_skip_onboarding | Remembers if you bypassed onboarding flow | Until cleared |
| nexvigilant-seen-version | Tracks which release version you've seen | Until cleared |
| nexvigilant-release-dismissed | Remembers if you dismissed a release notification | Until cleared |
| nexvigilant-whats-new-seen | Tracks if you've viewed the "What's New" modal | Until cleared |
| nexvigilant-tour-completed-{tourId} | Remembers which guided tours you've completed | Until cleared |
| lesson-{lessonId}-objective-{index}-completed | Tracks which learning objectives you've completed | Until cleared |
| quiz-{userId}-{enrollmentId}-{lessonId} | Saves your quiz answers and progress within lessons | Until cleared |
| nexvigilant-assessment-{assessmentId} | Saves your assessment progress and responses | Until cleared |
You can clear this data at any time through your browser settings (Settings → Privacy → Clear browsing data → Cookies and site data).
You can control cookies through your browser settings. Disabling essential cookies may prevent you from signing in or using certain features.
We use the following third-party services to operate our platform. These entities process data on our behalf under data processing agreements:
| Service | Purpose | Location | Privacy Policy |
|---|---|---|---|
| Google Firebase | Authentication, database, hosting | USA | Link |
| Google Cloud AI (Gemini) | AI-powered features | USA | Link |
| Vercel | Hosting, analytics, security | USA | Link |
| Stripe | Payment processing | USA | Link |
| Resend | Transactional email delivery | USA | Link |
When you make a payment, Stripe processes your transaction. Stripe collects:
Stripe is PCI DSS Level 1 compliant (the highest level of certification). For fraud prevention purposes, Stripe acts as an independent data controller. See Stripe's Privacy Policy for details.
You have the right to:
To exercise these rights, contact us at privacy@nexvigilant.com. We will verify your identity before fulfilling requests and respond within 30 days (or sooner where required by law). Some requests may be limited where we must retain data for legal, security, or compliance reasons.
Your information is processed primarily in the United States, where our service providers are located. If you are located outside the United States, your data will be transferred internationally.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we ensure appropriate safeguards for international transfers through:
You may request a copy of the SCCs by contacting privacy@nexvigilant.com.
Our services are designed for professionals and are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately and we will delete such information.
We may update this privacy policy from time to time. We will notify you of material changes by:
Your continued use of our services after changes constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
In the past 12 months, we have collected the following categories:
Submit requests to privacy@nexvigilant.com or call us at the number below. We will verify your identity and respond within 45 days.
Do Not Sell or Share My Personal Information: We do not sell or share personal information. No opt-out action is required.
If you are in the European Economic Area (EEA) or United Kingdom, you have rights under the General Data Protection Regulation (GDPR) and UK GDPR:
If you believe we have violated your privacy rights, you have the right to lodge a complaint with a supervisory authority. For EEA residents, you can find your local authority at: European Data Protection Board Members. For UK residents, contact the Information Commissioner's Office (ICO).
We encourage you to contact us first at privacy@nexvigilant.com so we can address your concerns directly.
If you have any questions about this privacy policy or how we handle your data, please contact us:
For privacy inquiries, we aim to respond within 5 business days. For formal data rights requests, we will respond within 30 days (or the timeframe required by applicable law).
Our Commitment to Privacy
As stated in our founding principles, NexVigilant is committed to independence and transparency. We will never accept pharmaceutical company funding that could compromise our objectivity, and we extend that same principle to your data: we will never sell your information or use it in ways that conflict with your interests as a healthcare professional.