Privacy Policy
Last updated: August 20261. Introduction
Welcome to Nexura Security. This Privacy Policy explains how we collect, use, and protect your data when you use our website (nexurasecurity.com) and the Nexura Security WordPress plugin. We are committed to protecting your privacy and ensuring full transparency in our data practices.
2. Open Source License
Nexura Security (free version) is an open-source software distributed under the GNU General Public License v2.0 or later (GPLv2+). The full source code is publicly available on GitHub and WordPress.org.
This means you are free to use, study, modify, and redistribute the software, subject to the terms of the GPLv2+ license.
3. Data Collection via the Plugin
The Nexura Security plugin is designed to operate primarily on your own server. We do not track, collect, or store personal data of your website visitors on our servers. However, some security features require communication with third-party APIs to verify threats:
- Cloudflare Turnstile & Google reCAPTCHA: If enabled, visitor browser signals are processed by Cloudflare or Google to prevent bot spam. Subject to their respective privacy policies.
- HaveIBeenPwned API: If enabled, only the first 5 characters of a SHA-1 hash of user passwords are checked to ensure they haven't been breached (k-Anonymity model). Passwords are never sent in plain text.
- Google Safe Browsing: Site URLs may be checked for malware and phishing flags via Google's Safe Browsing API. When this feature is active, your site's URLs (but no visitor personal data) are transmitted to Google to verify their safety status. This process is subject to Google's Privacy Policy.
- Nexura Threat Intel Cloud: Malicious IP addresses attacking your site may be anonymously synced to our global blocklist to protect all network users. No personal data is shared.
4. AI Deep Scan Feature (Pro Edition)
For users of Nexura Security Pro, the "AI Deep Scan & Auto-Fix" feature may transmit suspicious file snippets to our external AI providers (Cloudflare and OpenAI) for deep analysis. We take your privacy and data security seriously when handling this process:
- What is sent: Only explicitly flagged, highly suspicious PHP or JavaScript file contents are analyzed. We do not send your database content, user data, passwords, or configuration files (like wp-config.php).
- Data Retention: Sent file snippets are analyzed in real-time and are not used to train OpenAI's public models. Data is temporarily processed and discarded immediately after the analysis is complete.
- Consent & Opt-out: This feature is strictly opt-in. By default, all scans run locally on your server. You must explicitly enable the AI Deep Scan feature in your plugin settings, and you can disable it at any time.
- Sensitive Data Handling: Before transmission, our engine attempts to automatically redact recognizable sensitive strings (such as API keys or passwords) from the suspicious code snippet.
5. Data Collection via the Website & Free Scanner
When you visit nexurasecurity.com or use our free vulnerability scanner, we process specific data to provide the service:
- Website Scanner: When you submit a URL to our free scanner, we temporarily process the domain name to perform external API lookups (e.g., DNS, Blacklist databases).
- Email Reports: Email addresses submitted for scanner reports are used strictly to deliver the requested one-time security report. They are not added to any promotional lists.
- IP Processing: Standard diagnostic data (IP addresses, browser types) is collected via server logs solely to prevent abuse and DDoS attacks against our scanning infrastructure.
6. Data Retention Policy
We believe in strict data minimization. We only keep data as long as necessary to provide our security services:
- Scanner Logs: Domains and email addresses used in the free scanner are automatically purged from our temporary cache within 24-48 hours after report delivery.
- Threat Intelligence IPs: Malicious IPs synced to our global blocklist are retained only while they pose an active threat, typically expiring after a period of inactivity.
7. Freemius Integration
If you opt-in to usage tracking during plugin activation, diagnostic data (such as WordPress version, PHP version, and plugin settings) will be securely transmitted to our licensing partner, Freemius. This helps us improve the plugin. You can opt out at any time from your WordPress dashboard.
8. Cookies & Analytics
Our website uses essential cookies required for site functionality and basic privacy-first analytics. Third-party services integrated on the site (e.g., Cloudflare for DDoS protection) may set their own security cookies as described in their respective privacy policies. We do not use third-party advertising trackers.
9. Your Rights
You have the right to:
- Access, modify, or delete any personal information we may hold about you
- Opt out of usage tracking at any time
- Request data portability or erasure under GDPR
Since the plugin stores data on your own server, you have complete control over your security logs and user data within your WordPress dashboard.
10. Children's Privacy
Our services are not directed at individuals under the age of 13. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised "Last updated" date.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: [email protected]
- WordPress.org: Support Forum
- GitHub: Issue Tracker
