Privacy Policy
NEXUSCORTEX LLC is a limited liability company registered in Wyoming, United States, and operates Invokora. This policy explains how we handle your personal information when you visit our website, use a buyer or merchant workspace, call an API, buy a service, or contact support.
Updated September 9, 2026.Who is responsible for your information
NEXUSCORTEX LLC is responsible for how Invokora handles account, transaction, billing, security, and website analytics data. We do not sell personal information or use API requests and responses, order messages, service content, or sensitive credentials for advertising profiles, model training, or public display.
When you call a merchant API, Invokora forwards your request through its API Gateway to the merchant server. The merchant is responsible for how it uses and stores that data in its own systems. For service orders, the merchant receives the buyer details, requirements, messages, files, and any credentials you share through the credential handoff feature that are needed to deliver the order.
When we process personal information on a business customer’s instructions, the parties should agree on the scope and their responsibilities in a Data Processing Addendum (DPA). We remain responsible for account, transaction, security, and other processing whose purposes we determine ourselves.
Information we collect
Account and security information: email address, display name, password-verification information, email-verification status, sign-in status, API access credentials, language preference, IP address, and browser and device information. We also record sign-ins, additional identity checks, security events, and administrator actions. Merchants can choose to tell us how they heard about Invokora when registering.
If you choose Google or GitHub sign-in, we receive your account identifier, email address, and email-verification information from that provider to verify your identity and create or link a buyer account.
Merchant business information: legal name, country or region, registration number, website, business email, proof of delivery capability, and identity-verification and payout status from Stripe. When a manual review is needed, we keep its outcome and reasons.
Purchase and usage information: the product, plan or quote selected, plan approval questions and your answers, approval decisions, orders, subscriptions, API usage, bandwidth, overage charges, prices, currencies, taxes, and billing address. We also keep refund, payment dispute, merchant earnings, and settlement records, along with the terms, language, time, and acceptance records at payment.
After issuing a buyer API key, we store only an irreversible digest used to verify it and its issuance records. We cannot recover the key from those records. When you pay for a service through Stripe without signing in, we receive the payment contact email to verify the purchase and link the order.
How we use information
To provide the service: manage accounts and subscriptions, check API access, forward requests, handle plan approvals, calculate usage and charges, process quotes and orders, send notices, and provide support. We do this to perform our contract with you or take steps you request before entering a contract.
To meet legal obligations: handle tax, keep transaction records required by law, and respond to lawful regulatory requests.
To protect the platform and its users: check transaction eligibility, prevent fraud and abuse, diagnose faults, investigate security incidents, and keep necessary audit records. Where applicable, these legitimate interests are our legal basis for processing, and we consider the effect on your rights.
To understand website use: with your consent, learn which pages and features people use. Before using information for a new purpose that is incompatible with the original purpose, we will tell you and obtain consent where required.
API requests and uploaded files
For API Gateway requests, we forward the request method, path, query parameters, necessary headers, and body to the merchant and return its response to you. Query parameters, request and response headers, and bodies are handled temporarily for forwarding and are not written to persistent storage.
Each call leaves a record of its request identifier, product and endpoint, buyer, plan version, time, status, duration, bytes transferred, and links to usage or billing records. We use these records for billing and troubleshooting. They do not contain the API request body or returned content.
Files uploaded for quotes and service orders are stored along with their name, type, size, uploader, purpose, scan result, and associated order. A file must pass a security scan before it can be used for an order. Files sent directly through an API are forwarded with the request and do not go through this order-file scan.
Order messages and temporary credentials
We store inquiries, quotes, requirements, messages, attachments, delivered files, acceptance, revisions, disputes, and maintenance records with the order. The buyer and merchant can view them according to their order permissions. Support staff or administrators may access the records needed to handle reviews, disputes, and similar matters.
If delivery requires a temporary credential, use Secret Handoff. The designated merchant account must verify its password again before viewing the credential for a limited time. We delete the credential content when the merchant acknowledges receipt, you revoke it, or it expires. We keep access and activity records without the content. Support and administrator pages do not provide a way to view the credential in plain text.
Payments and risk checks
Stripe processes payments, including card credentials, billing address, tax location, and identity-verification information. Invokora does not store full card numbers. We receive and keep customer and transaction identifiers, amounts, currencies, transaction status, and failure reasons for reconciliation, tax, refunds, disputes, and merchant settlement.
We use account and transaction information, merchant identity, and status information from Stripe for eligibility and risk checks. To detect repeated refunds and payment abuse, we also keep necessary customer identifiers, irreversible payment-identification information, relevant transaction periods, holds, and manual-review outcomes.
Automated checks determine whether a subscription or API key is valid, whether access or usage limits have been exceeded, and whether an account or transaction presents a risk. These checks may block a request, pause sales, or refer a case for manual review. If you think a decision is wrong, contact us to explain the situation and ask for a review.
Cookies and website analytics
Necessary cookies and browser storage keep you signed in, support security checks, remember your language and cookie choices, and help you resume unfinished actions.
We load Google Analytics 4 only after you consent. We send page categories and events such as contact clicks, registration, sign-in, and checkout starts. We do not send email addresses, names, free text, registration discovery source, API content, order content, sensitive credentials, order amounts, payment details, or account and order identifiers.
You can withdraw consent at any time through Cookie settings at the bottom of the page. Declining analytics does not affect your account, purchases, or API calls. Your cookie choice is valid for 180 days. We ask again if the analytics purpose or related policy changes materially.
Who receives your information
In addition to the merchant handling your API request or service order, we share information with providers of payments, sign-in verification, email, messaging, hosting, databases, file storage, security scanning, and key management as needed for their work. Stripe provides payment services. Google or GitHub verifies your identity when you choose its sign-in option. Website analytics data is sent to Google Analytics only with your consent.
If you contact us through Telegram, another messaging service, or email, that provider handles messages under its own privacy policy. We use the messages and delivery records to reply, handle support or security issues, and complete the follow-up you request.
We may disclose necessary information to public authorities, professional advisers, or parties to a corporate transaction to meet legal obligations, handle disputes, investigate fraud or security incidents, or carry out a reorganization. We limit disclosure to what the purpose and law permit.
Where information is processed
We and our service providers may process information in the United States or other countries where services are provided. Their privacy laws may differ from those where you live.
International transfers must comply with applicable law. We assess the recipient and processing location and use the required contractual or other safeguards. We will not offer a service involving a transfer until the necessary safeguards are in place. Contact us for details about the locations and safeguards relevant to your information.
How long we keep information
API call records are kept for no more than 30 days. API query parameters, request and response headers, and bodies are not stored. Aggregate usage and financial records follow the transaction-record criteria below.
Uploads that are not linked to a quote or order become due for cleanup after 24 hours. Attachments and delivered files have a retention period of 180 days after the quote closes or service order ends. Temporary credentials are valid for 24 hours by default and no more than 72 hours; they are deleted earlier if the merchant acknowledges receipt or you revoke them.
Sign-in sessions stop working when they expire or are revoked. Password-reset and account-linking links also stop working after use. Necessary security records may be kept longer for an investigation. Cookie choices are kept for 180 days. The language cookie lasts up to one year; the language preference in browser local storage remains until you change or clear it.
We keep account and support records for as long as needed to provide the service, handle requests, and protect accounts. Transaction, tax, contract, settlement, refund, and dispute records are kept according to legal retention requirements, limitation periods, and the need to resolve disputes. After a file or credential is deleted, scan, cleanup, and audit records that do not contain its content may remain for these reasons.
Legal duties, disputes, or regulatory requirements may pause deletion of affected records. They do not affect the normal deletion of unrelated information.
Your rights and choices
Depending on applicable law, you may have the right to access, correct, delete, or obtain a copy of your personal information, receive it in a portable format, restrict or object to processing, withdraw consent, or request review of an adverse decision. Withdrawing consent does not affect processing carried out on that basis before withdrawal. You may also complain to a data-protection authority where you live, work, or believe a violation occurred.
Buyers can request a data copy or account deletion in their workspace. For other privacy requests, including merchant requests, use the email address at the bottom of this page. We verify your identity and respond free of charge within the time required by applicable law. We charge a reasonable fee or refuse a manifestly unfounded or excessive request only where the law permits.
Online requests require identity verification and manual review. The tool cannot yet complete a data-copy or account-deletion request automatically. Submitting a request does not mean your data has been exported or deleted. We mark it complete only after verifying those actions and any required withdrawal of account access or subscription handling. Records we must keep by law are not deleted with the account.
Information you must provide
Registration, payment, and service pages identify required information. Without the details needed to create an account, verify identity, process payment and tax, authorize API access, or deliver an order, we may be unable to provide the relevant feature. Optional information can be left blank.
Invokora is for users aged 18 or older. If you believe a minor has provided personal information to us, please contact us.
Security and policy updates
We protect information through access permissions, encrypted connections, credential encryption, private file storage, security scanning, and activity logs. Please do not include passwords, private keys, or sensitive personal information in API requests or orders unless they are needed for that use.
When we update this policy, we change the date at the top of the page. For material changes to how we use information or to your rights, we will notify you in the product or by email where appropriate and ask for consent where required. An updated policy will not retroactively authorize a use of data we did not previously disclose.
Contact us
For privacy questions or to exercise your rights, email: contact@invokora.com
