Compliant by Design

Most apps promise to protect your data. Nexus was built so we never have it.

Compliant by Avoidance

Nexus has no servers, no databases, no analytics endpoints. Your contacts, notes, and interactions stay on your device and in your private iCloud account. Most privacy regulations exist to control what companies do with your data — we eliminated that question entirely.

  • No data breach risk — there's nothing to breach
  • No right-to-delete requests — we don't have your data to delete
  • No cross-border transfer concerns — your data stays in your iCloud region
  • No tracking or profiling — we have no analytics infrastructure

Compliant by Proxy

The infrastructure Nexus does rely on — Apple's iCloud and Cloudflare's CDN — carries world-class security certifications. Your data is protected by the same standards that serve governments and Fortune 500 companies.

Apple

ISO 27001 ISO 27018 FIPS 140-3 Global CBPR

Cloudflare

ISO 27001 SOC 2 Type II PCI DSS Level 1 FedRAMP Moderate

Regulation Coverage

Regulation Jurisdiction Status
GDPR European Union Compliant
CCPA/CPRA California Compliant
DPDP India Compliant
Apple App Store Global Compliant
COPPA United States — Not applicable
CAN-SPAM United States — Not yet applicable

How It Works

📱

Your Device

All processing happens here. Contacts, notes, audits, reminders.

☁️

Your iCloud

Sync between your own devices. Apple-encrypted, Apple-certified.

🌐

Our Websites

Hosted by Cloudflare. No user data passes through them.

There is no fourth column. We have no servers.

Processor Transparency

Apple (iCloud/CloudKit)

Syncs your Nexus data between your devices

Apple Privacy →

Apple (App Store)

Handles app distribution and subscription billing

Apple Privacy →

Cloudflare

Hosts our websites (nexuscontacts.com, commonnexus.com)

Trust Hub →

Your contacts deserve better than a server.