Legal
Privacy Policy
Effective date: March 24, 2026
1. Introduction
NEPOLIX SANCTUM LLC (“NEPOLIX SANCTUM,” “we,” “us,” or “our”) provides Sanctum OS and related websites, applications, and services (collectively, the “Services”). Sanctum OS is a cloud-based, multi-tenant business operations and productivity platform. Depending on your plan and configuration, the Services may include document and file management, financial and operational recordkeeping, task and workflow tools, calendaring, collaboration features, notifications, integrations with third-party products, analytics or reporting, administrative settings, and related websites, APIs, and software we make available.
This Privacy Policy explains how we collect, use, disclose, and protect personal information, and the choices available to you. It applies to our public websites, Sanctum OS accounts, and related support channels.
By using the Services, you acknowledge this Privacy Policy. If you do not agree, please do not use the Services. Use of the Services is also governed by our Terms of Service.
2. Who this policy covers
This policy applies to:
- Visitors to our public websites and marketing pages
- Individual users who create or are invited to a Sanctum OS account (including organization members and administrators)
- People who contact us by email, phone, or other support channels
- Where applicable, individuals whose information is submitted by an organization that uses the Services
3. Roles: account data vs. customer content
Account and service data. For information we collect to operate accounts, authentication, billing (if any), security, and the Services themselves (for example your login email, profile fields, and usage logs), we generally act as the business / controller of that personal information.
Customer Content. Content that organizations and users upload, create, import, or store in the Services—such as files, records, notes, tasks, messages, financial entries, configurations, and similar business data (“Customer Content”)—is controlled by the customer organization (or individual customer) that owns the workspace. In that capacity we act as a service provider / processor and process Customer Content to provide the Services under our agreement with that customer and the instructions of authorized users.
If you are an end user of an organization, your organization’s policies and administrators may further control how Customer Content is managed, retained, or shared. Please contact your organization for those questions first.
4. Information we collect
Information you provide. This may include name, email address, phone number, organization or company name, job title, profile photo, timezone, notification and preference settings, support requests, and any other information you choose to submit.
Authentication data. We may use passwordless or other supported sign-in methods (for example one-time codes sent by email). We process related authentication events and session information. Where we use passwordless email codes, we do not store traditional account passwords for Sanctum OS.
Customer Content. Anything you or your organization store in the Services, including documents and files, structured business records, comments, attachments, activity history, and metadata.
Automatically collected technical data. IP address, device and browser type, operating system, referring URLs, timestamps, log data, approximate location derived from IP, crash/error diagnostics, and product interaction data needed to operate, secure, and improve the Services.
Integrations and third parties. If you or your organization connect optional third-party services—including Google Calendar (connected with Google OAuth), and other optional third-party services we may offer from time to time—such as additional calendar, identity, email, storage, messaging, or productivity tools—we receive the credentials, tokens, profile identifiers, and content needed to provide that connection, as described in Section 5, subject to your authorization and the third party’s terms.
Information from your organization. Administrators or other authorized users may provide your contact details when inviting you or managing membership.
Communications. Records of emails, calls, and support messages you exchange with us.
We do not require you to provide sensitive categories of personal information (such as government ID numbers, health information, or precise biometric data) to use the core Services. Please do not upload regulated or highly sensitive data unless the Services are expressly offered for that purpose under a separate written agreement.
5. Third-party integrations and OAuth
The Services may offer optional integrations with third-party platforms so features such as calendaring, task sync, or productivity tools can work together. Current and planned examples include Google Calendar (connected with Google OAuth), and other optional third-party services we may offer from time to time—such as additional calendar, identity, email, storage, messaging, or productivity tools. Connecting an integration is optional; core account features work without it unless a specific feature depends on that connection.
How connections work. When you choose to connect a third-party service, you are typically redirected to that provider (for example Google) to sign in and grant permissions via OAuth or a similar authorization flow. We receive and store access credentials (such as access and refresh tokens), the account identifiers the provider returns (for example email address associated with the connected account), granted scopes, connection status, and technical metadata needed to keep the connection working.
Google Calendar (example of current scope). If you connect Google Calendar, we may access—subject to the permissions you grant in Google’s consent screen—your Google account email and calendar event data as needed to create, update, delete, or import calendar events related to items in the Services (for example tasks or events you choose to sync). We store OAuth tokens securely on our backend, associated with your user account, and may store provider event identifiers needed to keep items in sync. We request only the scopes required for the features we offer (for example calendar events and basic account email), and we may expand or reduce scopes if features change, always subject to your re-authorization when the provider requires it.
Other integrations. If we add other OAuth or API integrations later, we will process similar categories of data from those providers (credentials, identifiers, and the content types needed for the feature) under this same framework. In-product screens will describe the connection; this Privacy Policy covers those integrations generally without requiring a full rewrite for each new provider.
How we use integration data. We use connected account data and third-party content solely to provide, maintain, secure, and improve the integration features you enable—for example syncing calendar events, showing connection status, troubleshooting failures, and enforcing our Terms. We do not sell Google user data or other third-party integration data. We do not use that data for advertising. We do not allow humans to read integration content except with your consent, for security/compliance investigation, or where required by law—or as needed for aggregated, non-identifying engineering metrics.
Sharing. Integration data may be processed by our infrastructure providers that host the Services. Data also flows to and from the third-party provider you connected (for example Google) according to your authorization. We do not share integration data with unrelated third parties for their own marketing.
Your controls. You may disconnect an integration in product settings (for example Settings → Integrations) or by revoking access in the third-party provider’s security/permissions console (for example your Google Account permissions). After disconnect, we stop new API calls with those credentials and delete or disable stored tokens within a reasonable period, subject to backups and legal retention. Some references (for example past sync identifiers on items) may remain in Customer Content until you or your organization remove them.
Google API Limited Use. Sanctum OS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. See Google API Services User Data Policy.
Third-party services are governed by their own terms and privacy policies (for example Google’s). We are not responsible for those providers’ practices. Do not connect an integration unless you have the right to authorize access to that third-party account and its data.
6. How we use information
We use personal information and Customer Content as appropriate to:
- Provide, operate, maintain, and improve the Services
- Create and manage accounts, authenticate users, and maintain sessions
- Enable multi-organization tenancy, roles, permissions, and sharing controls
- Operate optional third-party integrations you enable (including Google Calendar sync and future OAuth-connected services)
- Deliver notifications, security alerts, and service-related communications
- Provide customer support and respond to inquiries
- Generate exports, reports, backups, and features you or your organization request
- Monitor performance, debug issues, prevent fraud and abuse, and enforce our Terms
- Analyze usage in aggregate or de-identified form to improve the product
- Comply with law, legal process, and regulatory requirements
- Protect the rights, safety, and property of users, the public, and NEPOLIX SANCTUM
Where we send marketing communications, you may opt out using the instructions in those messages or by contacting us. We may still send transactional or service messages (for example security notices, billing, or product-critical updates).
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising as those terms are commonly defined under applicable U.S. state privacy laws. We do not use Customer Content to train third-party general-purpose artificial intelligence models.
7. Legal bases (where required)
If applicable law requires a “legal basis” for processing (for example in the EEA/UK), we rely on one or more of: performance of a contract with you or your organization; legitimate interests in operating a secure, efficient business platform (balanced against your rights); your consent where we request it; and compliance with legal obligations.
8. How we share information
We may disclose information in the following circumstances:
- Service providers. Vendors that host, store, authenticate, deliver email, provide analytics or support tooling, or otherwise help us run the Services, under confidentiality and data-protection obligations appropriate to their role.
- Within your organization. Content and membership data may be visible to other users in your organization according to roles and settings configured by administrators or authorized users.
- Sharing and collaboration features. If you create share links, invitations, or external access, information is available to recipients you (or your organization) designate.
- Integrations. Data may flow to and from third-party services you choose to connect (including Google when Google Calendar is connected), as described in Section 5.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to continued protection of the information.
- Legal, safety, and compliance. When we believe disclosure is required by law, legal process, or governmental request, or to protect rights, safety, or integrity of the Services or people.
- With your direction. When you or an authorized administrator instruct us to share information.
9. U.S. state privacy notices (including California)
Depending on where you live, you may have rights to know, access, correct, delete, or obtain a portable copy of certain personal information, and to appeal a denied request. California residents may also have rights under the CCPA/CPRA regarding categories of personal information collected, sources, purposes, and disclosures.
Categories we may collect include identifiers (such as name and email), commercial or account information, internet or electronic activity (usage and device data), professional or employment-related information (such as company and role if provided), and inferences drawn from usage for product improvement. We collect this information for the purposes described in this policy.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law, except as needed to provide the Services you request or as otherwise permitted.
To exercise rights, email hello@nepolix.com. We will verify your request and respond within the time required by law. If we deny a request, you may appeal by replying to our decision email. Authorized agents may submit requests with proof of authority where permitted by law. We will not discriminate against you for exercising privacy rights.
If you are an end user of a customer organization, we may refer certain requests about Customer Content to that organization, which controls the relevant workspace.
10. Cookies and similar technologies
We and our providers may use cookies, local storage, session storage, pixels, or similar technologies to remember preferences (such as theme), maintain sessions, measure performance, and secure the Services. You can control cookies and storage through browser settings; some features may not function if storage is disabled. We do not use advertising cookies on our marketing site to sell personal information.
11. Security
We implement administrative, technical, and organizational measures designed to protect personal information and Customer Content, which may include access controls, encrypted transport (HTTPS), authentication safeguards, and least-privilege practices for privileged operations. No method of transmission or storage is completely secure. You are responsible for protecting access to your email, devices, and accounts, and for configuring organization-level permissions appropriately.
12. Retention
We retain personal information and Customer Content for as long as needed to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and for legitimate business purposes such as security and backups. Retention periods vary by data type and customer configuration. OAuth tokens and integration credentials are retained while a connection remains active and are deleted or disabled after disconnect as described in Section 5. When you or your organization delete data or close an account, residual copies may remain in backups or logs for a limited period, or longer if required by law or legal hold.
13. International transfers
We primarily operate in the United States. If you access the Services from another country, your information may be processed in the United States and other locations where we or our service providers operate. Those locations may have data-protection laws different from your jurisdiction. Where required, we use appropriate safeguards for cross-border transfers.
14. Children’s privacy
The Services are intended for business and professional use by adults. They are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
15. Automated processing
We may use automated systems for security monitoring, spam/abuse detection, routing notifications, and product analytics. We do not make decisions that produce legal or similarly significant effects solely by automated means without human involvement where prohibited by law.
16. Third-party sites and services
The Services may link to or integrate with third-party websites and products we do not control (including Google and other OAuth providers). Their privacy practices are governed by their own policies. We are not responsible for third-party practices. Optional OAuth integrations are also described in Section 5.
17. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the effective date. For material changes, we may provide additional notice through the Services or by email when appropriate. Continued use after the effective date constitutes acceptance of the updated policy, except where applicable law requires otherwise.
18. Contact us
Privacy inquiries and requests:
NEPOLIX SANCTUM LLC
Email: hello@nepolix.com
Phone: (972) 331-1133
Questions? Contact us at hello@nepolix.com.
