Security at Nexora
A plain-language explanation of how Nexora limits account and business access, what users can control, and where the limits are.
Last Updated: September 8, 2026
1. The basic idea
Nexora uses sign-in checks, business relationships, roles, access controls, and encrypted network connections to reduce unauthorized access. These controls work together; no single control removes every risk.
2. Account access
An account must pass Nexora's sign-in checks before it can use private features. The server checks the account and its current business relationship for protected requests.
- Phone ownership is confirmed with a verification code during the relevant sign-in, recovery, or phone-change flow.
- Choosing a business on the device does not by itself grant access; the server checks the account's relationship with that business.
- When the signed-in identity changes or signs out, Nexora's client cleanup flow removes or moves account-scoped device data according to its data rules.
3. Business roles and permissions
Business access depends on both a current personnel relationship and an access level. Nexora uses full, standard, and restricted personnel levels, while the business owner has owner-only controls.
- A role can limit which screens, records, and actions a person can use.
- Protected server actions check the person's business relationship and required permission again.
- Business owners can change a personnel access level and should update or remove access when responsibilities change.
4. Business and customer information
Customer, appointment, package, personnel, service, and payment records belong to a business workspace. Access is limited by the signed-in account's verified business relationship and role.
- Customer-facing appointment responses leave out private personnel notes and personnel phone identifiers.
- Customers cannot use owner or personnel actions that create or change private appointment notes.
- Nexora's in-app payment entries are business records; they are separate from App Store or Google Play subscription billing.
5. Devices and notifications
Nexora uses device information and push tokens to operate app sessions and notifications. Device permissions and delivery providers also affect what works.
- A push token identifies an app installation for notification delivery; it is not displayed as a business record.
- You can turn notification permission off in device settings. A sent notification may still be delayed or rejected by the device or delivery provider.
- Keep the operating system and Nexora app updated so current account and platform controls are available.
6. What you can do
A few simple actions help keep account and business access current:
- Do not share verification codes or let another person use your account as you.
- Keep your account phone and email details current.
- If you own a business, lower or remove personnel access when a person's responsibilities or relationship changes.
- Review device permissions and delete your account when you no longer want to use Nexora.
7. Limits of these controls
Internet services, devices, app stores, notification providers, and user choices can all affect security. Nexora changes its controls as the product changes, but this page is not a promise that an account or service can never be compromised or interrupted.
8. Report a security concern
If you believe an account or business was accessed without permission, or you found a security problem in Nexora, email support with enough detail to identify the affected account or feature. Do not send passwords or verification codes.
Frequently asked questions
Who can see a business's information?
The server checks the signed-in account's current relationship with the business and the permission required for the requested action. Available screens and records can differ by role.
Can customers see private personnel notes?
Customer-facing appointment responses leave out private personnel notes and personnel phone identifiers, and customers cannot use private-note write actions.
Does deleting a Nexora account cancel a store subscription?
No. Account deletion and App Store or Google Play subscription cancellation are separate actions. Cancel a store subscription in the same store account.
How do I report a suspected security problem?
Email support@getnexora.app with the affected account or feature and what you observed. Do not include a password or verification code.