N3X
N3X Privacy

Privacy Policy

What data n3x.pl processes, why it is processed, who may receive it and the rights available to users.

Version 3.1 · effective:

Key points: most calculators run locally in the browser, desktop applications have no N3X telemetry, and self-hosted instances remain under their owner's control. Do not enter into tools or AI any data you do not want to disclose to the provider identified for that function.

1. Controller and contact

Controller: Usługi Informatyczne „nex-IT” Jakub Potoczny, NIP 5040061950, REGON 382557666, Przemysłowa 7A/22, 89-400 Sępólno Krajeńskie, Polska.

For privacy matters and rights requests: studio@n3x.pl, telephone +48 531 425 277.

No data protection officer has been appointed because the current processing scope has not been assessed as creating a statutory appointment requirement. The Controller handles privacy contact directly.

2. Scope and self-hosted products

This Policy covers n3x.pl, its public APIs, the N3X Studio and managed hosting forms, shared quotes, the administration panel, statistics and communications with N3X.

N3X Remote Server, N3X Market, N3X Remiza, N3X Flow and N3X Vault are self-hosted products. N3X normally does not receive data stored in a private instance. N3X Vault additionally encrypts vault content in the browser, while the instance stores ciphertext and minimal protocol metadata. The person or organisation operating an instance is its data controller and is responsible for its own privacy notice, lawful basis, access controls, retention, backups and security.

N3X desktop applications do not send usage telemetry to N3X. Downloads and update checks connect to GitHub, which receives ordinary connection metadata under its own policy.

3. Purposes, data and legal bases

  • Providing a requested tool or function: entered domains, IP addresses, URLs, headers or other technical parameters; Article 6(1)(b) GDPR, or Article 6(1)(f) where the user is not a contracting party (providing the requested service).
  • Contact and preparing an offer: name, email, optional company and telephone, selected product, deployment stage and scale, preferred contact method, budget and enquiry content; Article 6(1)(b) GDPR (steps requested before a contract) and Article 6(1)(f) (correspondence and legal claims).
  • Free technical alerts: email address, language, selected domain or URL, monitor type, results and delivery history; Article 6(1)(b) GDPR — providing the requested continuing service. The address is confirmed by double opt-in, and the alert can be paused or removed through a private link without creating an account.
  • N3X product news: email address, language, acquisition source, date and consent evidence; Article 6(1)(a) GDPR. Consent is entirely optional, separate from the technical alert and may be withdrawn at any time.
  • My N3X and email-link sign-in: email address, Supabase user identifier, active alerts, saved targets, shared reports and selected subscriptions; Article 6(1)(b) GDPR — providing the dashboard requested by the user. The link is single-use and no N3X password is created.
  • Domain profiles and reports: domain or public host, technical check results, label, creation time and a random sharing token; Article 6(1)(b) or (f) GDPR. A public report is available only to someone holding the long random URL and expires automatically.
  • Shared quotes: recipient name supplied by the creator, items, prices, notes, terms, identifier and expiry; Article 6(1)(b) or (f) GDPR — providing the requested function and handling a quote.
  • Security and abuse prevention: IP address processed briefly in rate-limiter memory, error logs and incident information; Article 6(1)(f) GDPR — protecting the site, users and infrastructure.
  • Administrator authentication: email address, account and session identifiers, TOTP factors, WebAuthn/FIDO2 public credentials (such as YubiKey), and technical cookies; we receive neither biometric data nor a device private key; Article 6(1)(f) GDPR — access control and administration-panel security.
  • Aggregate statistics: tool-run, download-click, install-action and hosting-information-open counters, a daily external versus internal/test breakdown, country code for external traffic, and anonymous Vercel statistics; Article 6(1)(f) GDPR — product improvement, usefulness measurement, exclusion of our own tests and assessment of market interest. N3X does not build user profiles or link these counters to email addresses.
  • Legal obligations: data needed for accounting, authority requests or data-subject rights; Article 6(1)(c) GDPR.

4. Web tools and external sources

Purely local tools, including browser generators, encoding tools, calculators and converters, process content on the device and do not send it to the server unless the interface clearly identifies a server-side or sharing function.

Container Center in N3XShell reads Docker and Kubernetes/K3s state and performs approved actions directly through the saved SSH connection, including when the user explicitly enables sudo mode. Its sudo password remains in memory only until that window closes. The separate root-shell feature lets the user choose one-time use, memory until disconnect, or explicit per-host storage in the operating system credential vault; the secret never reaches terminal input, shell history, or logs. N3X does not proxy the connection or receive inventory, passwords, logs, or operation results; the data remains in the app and on the managed host.

Update Center in N3XShell reads the operating-system version, APT metadata, available updates, dpkg state, free space, and configured Debian or Ubuntu sources over the direct SSH connection. This data is not sent to N3X. Simulation runs on the managed host, while a package or release-changing command is inserted into a separate root tmux session and waits for the operator's manual approval; the app never runs the update automatically, and the Debian plan's source backup does not replace a full system backup.

Port Scanner sends the selected public host and scan settings to the N3X server, which performs a limited number of TCP connection attempts or safe UDP service probes. Private and reserved addresses are blocked, and the user's IP is used briefly only for abuse rate limiting. Sharing encodes the host, settings and result directly in the link parameter: the report is not stored in the N3X database and opening it does not trigger another scan, but anyone who knows the link can read its contents.

The N3X Scan desktop app uses the same mechanism for its scan from the internet: the target address and the selected profile are sent to the N3X server, and the default target is the public address the user connects from. Scanning any other address requires confirming authorisation in the app. The result returns to the app and is stored locally; local network scanning still happens without the server.

Network tools must perform an external request. Depending on the function, a technical parameter may be sent to RDAP/WHOIS registries and whoisjson.com, Google Public DNS, ip-api.com, ipapi.co, the Polish Ministry of Finance, European Commission VIES, KRS, CEIDG, crt.sh, HackerTarget, macvendors.com, Have I Been Pwned, OpenStreetMap or Cloudflare. When the N3X server makes the request, the provider receives the parameter and N3X server connection metadata. Do not enter confidential or third-party data without a lawful basis.

The speed test makes some connections directly from the device: when the page opens, ipapi.co receives the public IP address and returns approximate location/ISP data; after the test starts, Cloudflare receives measurement traffic and the public IP. Coverage-map tiles are loaded directly from OpenStreetMap, which also sees connection metadata. N3X does not store this data in its database; the test result remains in browser state unless the user copies, downloads or places it in a sharing URL.

The HIBP password check uses k-anonymity: only the initial portion of a SHA-1 hash is sent, never the password or full hash. Email checking opens the HIBP website and then takes place directly between the user and HIBP.

5. AI functions

The N3X Assistant and YAML generator send the message, required conversation context or YAML fragment to GroqCloud (Groq LLC, United States) to generate a response. The interface identifies that the user is interacting with AI. N3X does not store conversation history in its database.

The N3XShell AI Copilot is disabled by default and does not use an N3X service. Only after configuration and separate approval of the preview does the app send the question and a locally redacted terminal excerpt directly to the active profile's provider (OpenAI, Anthropic, Google Gemini, local Ollama, or a custom OpenAI-compatible endpoint). Multiple profiles can be stored and assigned to servers; their metadata stays local and every API key has an isolated entry in the OS credential store. The active profile provider's terms govern processing of the submitted context.

Groq states that ordinary inference data is not retained by default, except temporary logs required for reliability or abuse investigations, retained for up to 30 days; customers can enable Zero Data Retention. Data retained by Groq is located in the United States and transfers may rely on Standard Contractual Clauses. Do not enter personal data, secrets, passwords, keys or special-category data.

AI responses may be incomplete or wrong. They are not automated decisions producing legal effects or legal, medical or investment advice.

6. Analytics and quote statistics

Vercel Web Analytics operates without third-party cookies and provides N3X with aggregate data. N3X removes URL query strings, fragments and quote or short-link identifiers before an event is sent.

When a shared quote is opened, we record the date, general device type, browser, operating system, hosting-provided country code and referrer origin only. We do not store raw IP addresses, full user agents, cities or internet providers and do not send an IP address to a geolocation service.

When a tool is actually run, an application download is clicked, an installation action is selected or hosting information is opened, the server briefly reads the connection IP solely to compare it with a server-side list of internal/test addresses. Once the event is classified, the address is immediately discarded: N3X stores neither a raw nor a shortened or hashed IP address. Only a daily external or internal/test counter remains in the database. A two-letter country code increments a separate daily counter for external traffic only.

The mechanism stores no session identifier, city, precise location, full user agent or individual event, uses no analytics cookies and cannot reconstruct one person's activity across tools. Contact details and email addresses are processed separately and are not attached to traffic statistics.

Download-click statistics measure interest on n3x.pl. They do not reveal the country of direct GitHub downloads or the operation, updating or use of a desktop application. They also exclude sessions, devices and agents in private N3X Remote instances and data held by N3X Market, N3X Remiza, N3X Flow or N3X Vault instances.

7. Recipients and transfers outside the EEA

To the extent required to provide the service, data may be processed by:

  • Vercel Inc. — hosting, content delivery, protection and analytics;
  • Supabase Inc. — database, authentication and site backend;
  • Groq LLC — AI response generation;
  • Resend Inc. or the configured SMTP operator — delivery of form email;
  • GitHub, Inc. — releases, downloads, updates and GHCR images;
  • registry and API providers identified for the tools — performing the requested check;
  • professional advisers, accounting providers or public authorities — only where there is a lawful need.

Some providers operate in the United States. Transfers rely on an appropriate GDPR Chapter V mechanism, particularly an adequacy decision or Standard Contractual Clauses with supplementary measures, depending on the provider and agreement. Information about safeguards may be requested from the Controller; confidential elements may be redacted.

8. Retention periods

  • tool queries: normally only for processing and technical caching; no person-linked search history is created;
  • in-memory IP rate limiter: approximately 10 minutes or until the server instance ends;
  • global aggregate counters without geographic breakdown: indefinitely because they contain no person identifier; daily external/internal counters and daily country counters: up to 24 months;
  • quote-view details: up to 90 days;
  • quote content: the period stated in the link followed by an administrative buffer of up to 30 days;
  • form correspondence: until the matter is closed and up to 3 years after the last contact, unless a contract, legal obligation or claim requires longer;
  • technical alert: until unsubscribe or permanent delivery failure; after unsubscribe, operational alert data and consent history are erased or restricted within 30 days, except for the minimum evidence needed to demonstrate consent or objection;
  • check history in My N3X: available for 30 days after alert deletion or cancellation, then hidden and permanently deleted during daily maintenance; resuming monitoring before the alert is removed cancels this period. This does not apply to active or paused alerts' history;
  • notification delivery log: up to 90 days, without retaining message content;
  • administrator account and sessions: until account removal or session expiry/revocation, subject to security logs;
  • hosting and security logs: for the provider's standard technical period and no longer than required for security, diagnostics or a legal obligation.

9. Cookies and device storage

The site uses no advertising cookies or profiling. Supabase cookies are required only for administrator sign-in, while tool settings stored in localStorage remain on the device. The complete inventory, purposes and deletion instructions are in the Cookies and Browser Storage Policy.

10. User rights

Subject to the GDPR, users have rights of access, rectification, erasure, restriction, portability, objection under Article 21 GDPR to processing based on legitimate interests, and withdrawal where a particular operation relies on consent. Withdrawal does not affect prior lawfulness.

Requests may be sent to studio@n3x.pl. The Controller may ask for information needed to verify identity. A response will normally be provided within one month, subject to the statutory extension for complex requests.

A complaint may be lodged with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.

11. Voluntary provision, sources and automated decisions

Providing data is voluntary, but omitting a tool parameter, return address in a form or session cookie during sign-in prevents the relevant function. Data comes from the user, their device, public registries/APIs or technical connection headers.

N3X does not make solely automated decisions about users that produce legal or similarly significant effects. Tool popularity sorting uses global counters only.

12. Security, minors and changes

We use proportionate measures including TLS, access control, data minimisation, abuse limits, secret separation and updates. No system guarantees absolute security; incidents are handled according to risk and legal duties.

The services are not directed at children. A minor should not submit contact details, AI content or public quotes without a parent or guardian.

A material policy change will be published with a new date; where it changes the purpose or basis of existing processing, users will be informed as required by law.