Nexa FlowBy Afraz Khan ↗

Effective October 1, 2026

Privacy policy

This policy explains how Nexa Flow, operated by Afraz Khan, handles personal information when you use our automation service, Google Workspace integrations, and public pages on afrazkhan.com.

1. Information we access and collect

We collect information you provide for account administration, workflow setup, billing, and support, such as your name, contact details, and configuration instructions. We also process technical information such as IP addresses, browser information, service logs, and workflow execution results.

When you connect Google, we receive OAuth authorization tokens and, where permitted, basic account information such as your name, email address, and account identifier. We do not receive your Google password. The Google authorization screen identifies the permissions requested for your connection.

Depending on the services you enable and permissions you grant, Google data may include Gmail messages, headers, attachments, drafts, and labels; Drive files and metadata; Docs and Slides content; Sheets cells and workbook information; Forms definitions and responses; Calendar events and attendees; Tasks; Contacts; Chat spaces and messages; and Meet meeting information and available artifacts. Other supported Workspace integrations may process service-specific records disclosed during setup. Administrator-only data is accessed only with the necessary administrative permissions. We request access for enabled features, not automatically for every Workspace app.

2. How we use Google data

We use Google data to connect your account, run the workflows you authorize, present execution results, and maintain and troubleshoot those user-facing features. Actions may include reading, creating, updating, sending, organizing, or deleting records when the configured workflow and granted permissions require them. Scheduled workflows may access the relevant services while you are offline.

We do not sell Google data, use it for advertising or ad targeting, build unrelated profiles, determine creditworthiness, or use it to train or improve generalized AI or machine-learning models. An AI service receives Google data only if you explicitly configure and authorize a disclosed AI-powered workflow that requires that transfer.

3. Storage and security

OAuth credentials, workflow configuration, and operational records are stored on infrastructure used to operate Nexa Flow and its workflow engine. Workflow inputs, outputs, Google content, and error details may also be retained in execution history or in destinations you select. OAuth tokens allow authorized workflows to continue until the connection expires or access is revoked.

We use HTTPS for public service connections and restrict access to operational systems to authorized personnel. Credentials are handled through the workflow engine’s credential storage. No storage or transmission method can guarantee absolute security. Our hosting and service providers may process information outside your country.

4. Sharing and human access

Information is processed by hosting, database, and infrastructure providers as needed to operate the service. A workflow may transfer Google data to destinations, applications, recipients, or AI services you explicitly choose, solely to provide the authorized feature. Review those destinations and their policies before enabling a workflow.

We may disclose information when necessary for security, to meet applicable legal obligations, or in connection with a business transfer only with prior explicit consent where required by Google’s rules. We do not share Google data with advertising platforms, data brokers, or information resellers.

Human access to Google user data is limited to your affirmative agreement to inspect specific data, necessary security investigations, legal obligations, or aggregated and anonymized internal operations permitted by Google’s policy. Support access is not a general permission to read your Google content.

5. Retention and deletion

We retain connection information while it is needed for your enabled integrations. Workflow records and execution history are retained as needed to provide the service and diagnose issues, subject to the applicable workflow retention settings. We do not promise a single automatic deletion period for every workflow or connected destination.

You can request deletion of your connection credentials, stored Google data, execution history, or account by contacting us below and identifying the connected account. We verify your authority before fulfilling requests, delete data no longer needed, and explain any records that must be retained for legal or security reasons. Backup copies may remain until the applicable backup rotation completes; retained copies are not used for new workflows. Data already sent to a destination you control must also be deleted from that destination.

6. Your choices and revoking Google access

You can decline permissions, stop workflows, disconnect an integration, or revoke access through Google Account connections. Revoking access stops future authorized Google API access but does not automatically delete information previously stored by Nexa Flow or sent to your chosen destinations. Contact us to request that deletion. You may also request access to or correction of personal information we hold about you.

7. Website analytics

The public website uses Google Analytics to understand page visits and interactions. It may collect browser and device information, page URLs, and usage events using cookies or similar technologies. This website analytics activity is separate from your Google Workspace connection; we do not use Workspace content or OAuth credentials for analytics or advertising. You can control cookies through your browser.

8. Google API Limited Use

Nexa Flow’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. These restrictions also apply to data derived from Google API data.

9. Children and policy changes

Nexa Flow is intended for business users and is not directed to children under 13. If you believe a child has provided personal information, contact us to request removal. We publish updates on this page with a revised effective date. If we introduce a new use of Google data, we will disclose it and obtain any required consent before that use begins.

10. Privacy contact

Contact Afraz Khan, operator of Nexa Flow, on WhatsApp at +92 305 3181710 for privacy questions, data access, or deletion requests. Include “Nexa Flow privacy” and your connected account identifier. Do not send passwords or access tokens.