Legal

Privacy Policy

Effective July 6, 2026 · Applies to the NexGate website, web application, and Chrome extension

The short version: NexGate collects no analytics, sets no trackers, and shares nothing with third parties. Your data goes to exactly one place — the NexGate server you (or your organization) run — and the sensitive parts are encrypted with a passphrase that is never stored anywhere.

1. Who we are

NexGate is a self-hosted password and multi-factor authentication manager published by Odoonex. Questions about this policy: [email protected].

Because NexGate is self-hosted, we — the software publisher — never receive, store, or have access to your data. All data described below stays between your browser and the NexGate server instance you connect to (for example gate.odoonex.app or your own deployment). The operator of that server is the data controller for your account.

2. This website

This site is static. It sets no cookies, runs no analytics, embeds no third-party scripts, fonts, or pixels, and makes no requests to any external service. Standard web-server access logs (IP address, requested page, timestamp) may be kept by the hosting infrastructure for security and reliability, and are not used for profiling.

3. The web application

When you use a NexGate server, it processes:

4. The Chrome extension

The extension is a client for your NexGate server. It communicates with that server only — it contains no analytics, no advertising, no telemetry, and no third-party network calls of any kind.

4.1 What the extension processes

4.2 Permissions, and why each one exists

Permission Why the extension needs it
storage Holds your vault passphrase in in-memory session storage while the browser is open. Nothing is written to persistent storage.
tabs Reads the active tab's hostname to show the vault entry that matches the site you're on. No history is recorded.
Host access to your NexGate server Sends API requests (sign-in, list, save, reveal, one-time codes) to the single server you configure — the only network destination.
Content script on web pages Detects login forms to place the autofill icon, fill credentials you choose, generate passwords, and offer to save a just-submitted login. Runs locally; sends nothing off the page.

4.3 What the extension never does

5. Data retention and deletion

6. Security

Passwords and MFA secrets are encrypted client-of-the-database: the server's database and configuration alone cannot decrypt them. Accounts are protected by per-account lockout, per-IP rate limiting, and an audit log. The web application enforces a strict Content-Security-Policy with every asset self-hosted. Details are on the security section of this site.

7. Children

NexGate is a workplace/personal infrastructure tool and is not directed at children under 13.

8. Changes to this policy

If this policy changes, the effective date above is updated and material changes are noted here. Continued use after a change constitutes acceptance.

9. Contact

Privacy questions or requests: [email protected].