Effective date: July 12, 2026
Factory Nexus is operated by Factory Nexus by TynHub (“we”, “us”). This policy explains what information we collect when you use the platform, how we use it, and the choices you have. Questions or requests go to support@notify.factory-nexus.ai.
If you connect GitHub, we receive your profile and verified email via OAuth, and — only when you enable repository features — access to the repositories you choose. GitHub tokens are stored encrypted at rest and used solely to perform actions you initiate, such as importing a repository, pushing an agent’s branch, or opening a pull request. We do not browse or copy repositories you have not connected. You can revoke access at any time from your GitHub settings.
We do not sell your personal information or your code.
When you start a task — an agent run, code review, chat message, or estimate — your prompt and the repository context relevant to that task are sent to third-party AI providers to generate the result. We currently use Anthropic, models routed through OpenRouter, and DigitalOcean serverless inference. Data is sent only for tasks you initiate, and Factory Nexus does not use your code or prompts to train models. See How we use AI for a plain-language description.
Payments are processed by Stripe. Your card details go directly to Stripe and are never stored on Factory Nexus servers. We keep subscription status and invoice records.
We use browser local storage to keep you signed in (authentication tokens) and to remember interface preferences such as theme and mode. We do not use third-party advertising trackers.
You can delete individual projects at any time from the dashboard. To delete your account and its associated data, or to request a copy of the data we hold about you, email support@notify.factory-nexus.ai from your account email. We will act on verified requests within 30 days, except where we must retain records for legal or billing reasons.
We use encryption in transit (TLS) and at rest for sensitive credentials such as GitHub tokens and provider API keys, isolate agent execution, and restrict internal access to production data. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you.
The service is not directed at children and may not be used by anyone under 16. We do not knowingly collect data from children.
We may update this policy as the service evolves. For material changes we will give notice by email or in-product before the changes take effect. The effective date at the top always reflects the current version.