Privacy policy
v1.0.0
Nidex is a secure-browsing product developed and operated by Logstr.io (“Logstr.io,” “Nidex,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, store, disclose, and protect information when you use the Nidex website, Nidex Desktop application, Nidex WebGuard browser extension, related support services, and enterprise-managed Nidex services collectively referred to as the “Services.”
Nidex is designed to separate untrusted web content from the operating-system environment containing your files, credentials, applications, local network access, and everyday browser data. Some Nidex functions operate entirely on your device. Other functions may transmit limited information when you enable a networked feature or use an enterprise-managed profile.
If your employer, school, or another organization provides or manages your Nidex account, that organization may control certain settings, logging, retention, and access decisions. You should also review that organization’s privacy notice.
1. Information We Collect
We collect information according to how you interact with the Services, the features you enable, and any policies applied by an organization managing your account.
Information you provide
We may collect:
Your name, email address, phone number, account credentials, and other contact information;
Organization, workspace, role, or enterprise-enrollment information;
Billing, subscription, and transaction information;
Information submitted when you request support, report an issue, book a demonstration, join a waitlist, or contact us;
Marketing preferences and newsletter subscriptions;
Files, screenshots, diagnostic packages, messages, or other materials you voluntarily provide to support personnel.
Please do not send passwords, authentication tokens, private keys, or browsing content to support unless we specifically request that information through an approved secure process.
Website and service-usage information
When you use our website or networked Services, we may automatically receive:
IP address and approximate location derived from it;
Browser type, operating system, device type, and language;
Pages viewed, links selected, referral source, and interaction times;
Cookie identifiers and similar technical identifiers;
Application version, installation status, crash information, and service-performance data;
Security events associated with suspected misuse or attempts to compromise the Services.
We may use necessary cookies to provide website functionality. With consent where required, we may use preference or analytics cookies to understand website performance. We do not use personal information for cross-context behavioral advertising.
Nidex Desktop information
Depending on your configuration, Nidex Desktop may create or store information on your device, including:
Local browser-profile settings and user preferences;
Disposable or persistent browser-session data;
Installation identifiers, enrollment tokens, and workspace information;
Managed-profile manifests and verified policy assets;
Protected private keys and mutual-TLS certificates;
Network-monitoring information and traffic summaries;
Temporary session-trace databases;
Native-host, virtual-machine, and diagnostic logs;
VPN, network-isolation, file-transfer, clipboard, media, credential, passkey, extension, and privacy-control settings.
Disposable sessions use a session-specific copy-on-write disk that is deleted when the session ends by default. If you or an administrator enables persistence, cookies, browser history, local storage, extensions, downloaded material, and other session data may remain until the persistent profile is deleted or reset.
Nidex WebGuard information
WebGuard may store the following information locally in Chrome storage:
Filtering and protection settings;
Link-interception preferences;
Trusted, blocked, forced-intercept, and bypass domain lists;
Recent security-alert summaries;
Filter-list and ruleset state;
Custom filters and per-site settings.
WebGuard may evaluate destination URLs using local heuristics. When you choose Open in Nidex, WebGuard sends the destination URL, originating page URL, and applicable risk reasons through Chrome native messaging to the locally installed Nidex application.
Recent WebGuard alerts are intended as limited local interface history, not as a complete browsing or security-event history.
Reputation and phishing-analysis information
If an optional network reputation feature is enabled, Nidex or WebGuard may send a domain or other limited destination information to a configured reputation service.
If remote phishing analysis is enabled, structured signals about the page may be transmitted to the configured analysis service. Depending on the configuration, those signals may describe characteristics of the page, forms, destination, or detected behavior.
Local URL heuristics, local filtering, forced and bypass-list matching, disposable virtual-machine execution, and local alert history can operate without sending that information to Logstr.io.
Session tracing and observability
Nidex can be configured to record different levels of browsing-session information:
Disabled: No HTTP session trace;
Basic: Timestamp, request method, URL, status, and timing;
Headers: Basic information plus request and response headers and selected request data;
Full: Header-level information plus response bodies, POST data, and form-field values.
A trace may also include MIME types, redirects, tab or frame context, initiators, navigation types, errors, and truncation status.
Full tracing is highly sensitive. It may capture credentials, tokens, form entries, personal communications, response content, and other confidential information. Full tracing should be enabled only when necessary and with appropriate authority, notice, access controls, and retention limits.
For personal profiles, traces may remain locally on the device unless you export or transmit them. An enterprise-managed profile may require trace upload to an organization-controlled or Logstr.io-hosted service. Uploaded trace envelopes may identify the organization, installation, user, profile, and session.
Enterprise-managed information
If your device is enrolled with an organization, we may process:
Organization and user identifiers;
Installation identity and enrollment token;
Assigned managed profiles and policy versions;
Profile-synchronization and verification timestamps;
Security certificates and public-key information;
Session, bypass, policy-compliance, and audit events;
Network or browsing traces permitted by the organization’s policy;
Device and service diagnostics needed to administer the deployment.
Your organization should tell you whether URLs are submitted for scoring, whether remote analysis is enabled, which trace level is used, who can access the resulting information, how long it is retained, and whether traffic is routed through a managed VPN or gateway.
Capability bridges and information you release
Nidex restricts host capabilities such as clipboard access, file transfer, webcam, microphone, printing, passwords, and passkeys. These capabilities are not intended to be automatically available to an isolated session.
If you or an administrator enables one of these bridges, information may pass between your host device and the isolated browsing session. Information deliberately released through an enabled bridge is no longer protected by complete separation from that session.
Information from third parties
We may receive information from:
Your employer or organization;
Payment processors;
Authentication providers;
Reputation, phishing-analysis, or malware-scanning services;
VPN and network-service providers;
Support, hosting, analytics, and security providers;
Publicly available security intelligence sources.
2. How We Use Your Information
We may use information to:
Create and administer Nidex accounts, subscriptions, and workspaces;
Launch, manage, isolate, monitor, and terminate browsing sessions;
Evaluate suspicious links and display explainable risk information;
Route selected destinations from WebGuard into Nidex Desktop;
Apply personal or enterprise security policies;
Provide network monitoring, tracing, export, and diagnostic features;
Synchronize signed and encrypted managed profiles;
Authenticate installations and protect enterprise communications;
Provide customer support and investigate technical problems;
Process payments and maintain transaction records;
Detect fraud, abuse, security incidents, and unauthorized access;
Maintain, test, troubleshoot, and improve the Services;
Communicate service notices, security advisories, and product updates;
Send marketing communications when you have consented or where otherwise legally permitted;
Comply with legal obligations and enforce our agreements.
WebGuard risk scoring may involve automated analysis of URLs, domains, transport properties, and reputation information. This scoring helps present a security warning or routing choice. It does not establish that a website is safe or malicious, and it is not used to make decisions producing legal or similarly significant effects about an individual.
Where applicable, our legal bases for processing may include performing a contract with you, complying with law, protecting our legitimate interests in operating and securing the Services, and your consent. You may withdraw consent where processing depends on consent.
Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including security, contractual, tax, accounting, dispute-resolution, and legal requirements.
Different information follows different retention rules:
Disposable session disks are deleted when the session closes by default;
Persistent-profile information remains until the profile is deleted or reset;
Local WebGuard settings and alert summaries remain until cleared, reset, or removed with the extension;
Local traces remain until deleted by the user, removed according to application settings, or uploaded under an enterprise policy;
Enterprise traces and audit data follow the retention period established in the applicable enterprise notice or agreement;
Account information is retained while the account is active and for [insert period] after closure;
Native-host and diagnostic logs are retained for no longer than [insert period], subject to security and legal needs;
Support communications are retained for [insert period];
Billing records may be retained for the period required by tax and accounting law.
We may retain limited records necessary to document requests, prevent fraud, enforce legal rights, or honor marketing opt-outs. We may also retain aggregated or de-identified information that no longer reasonably identifies an individual.
3. Sharing Your Information
We may disclose information in the following circumstances.
Service providers
We may engage service providers for infrastructure hosting, payment processing, authentication, support, communications, analytics, security monitoring, software distribution, reputation checking, phishing analysis, malware scanning, enterprise analytics, and related operations.
These providers may process information only for the services they provide to us and subject to appropriate contractual restrictions.
Organizations managing Nidex
If an organization manages your Nidex profile, its authorized administrators may receive or access profile information, session metadata, policy status, bypass events, network information, traces, diagnostics, and audit records according to the organization’s configuration.
For organization-managed processing, the organization may act as the data controller or business, while Logstr.io may act as its processor or service provider. Requests concerning organization-controlled information may need to be directed to that organization.
Third-party features you enable
Information may be transmitted to a VPN provider, reputation service, phishing-analysis provider, malware-scanning provider, authentication provider, or other third party when you or your administrator enables that integration.
Websites you visit
Websites opened inside Nidex remain third-party websites. They may receive your session’s public IP address, browser characteristics, requests, information you submit, and other data normally communicated during browsing.
Browser isolation protects the host environment; it does not prevent a visited website or an extension installed within the same isolated session from observing information available inside that session.
Legal and safety disclosures
We may disclose information when reasonably necessary to:
Comply with applicable law, legal process, or a valid governmental request;
Protect the rights, safety, and security of users, Logstr.io, or others;
Investigate fraud, abuse, security incidents, or violations of our agreements;
Establish, exercise, or defend legal claims.
Where legally permitted, we will seek to limit disclosures and notify affected users when appropriate.
Business transfers
Information may be transferred as part of a merger, financing, acquisition, restructuring, bankruptcy, or sale of all or part of our business. A recipient will be required to handle personal information consistently with applicable law and the commitments in effect at the time of transfer.
No sale of personal information
We do not sell or rent personal information. We do not share personal information for cross-context behavioral advertising.
4. Data Security
Nidex uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, destruction, and loss.
Depending on the feature and deployment, these safeguards may include:
Hardware-virtualized Linux environments with separate kernels and process trees;
Disposable copy-on-write session disks;
Host-side network filtering and optional private-network isolation;
Explicit, policy-controlled bridges for files, clipboard, media, credentials, and other host capabilities;
Validation of native-messaging callers and accepted URL schemes;
Signed and encrypted enterprise-profile delivery;
Protected installation keys, tokens, certificates, and private-key storage;
Mutual TLS for configured enterprise trace uploads;
Field-level trace filtering;
Bounded message sizes, queues, and processing timeouts;
Access controls, logging, secure transmission, and least-privilege practices;
Procedures for vulnerability management and security-incident response.
No security control, virtual machine, network filter, encryption method, or storage system can guarantee absolute security. Heuristic detection may also produce false positives or false negatives. Users should continue using endpoint protection, identity security, software updates, strong authentication, and safe browsing practices.
If we become aware of a security incident involving personal information, we will investigate, mitigate the incident, and provide notifications when required by law.
5. Your Rights and Choices
Depending on where you live, you may have the right to:
Know whether and how we process your personal information;
Access or obtain a copy of personal information associated with you;
Correct inaccurate or incomplete personal information;
Request deletion, subject to legal and operational exceptions;
Request restriction of certain processing;
Object to processing based on legitimate interests or direct marketing;
Withdraw consent when processing is based on consent;
Receive certain information in a portable, machine-readable format;
Opt out of the sale or sharing of personal information;
Limit certain uses of sensitive personal information;
Exercise privacy rights without unlawful discrimination;
Appeal our response where applicable;
Lodge a complaint with an applicable privacy or data-protection authority.
You can unsubscribe from marketing messages through the link included in those messages. Essential service and security communications are not marketing communications and may continue while you use the Services.
You may manage local profiles, WebGuard history, filters, trusted or bypass lists, traces, persistent disks, and other locally stored information through the applicable product controls.
To exercise a privacy right, contact us using the information in Section 9. We may request information necessary to verify your identity and authority. We will use verification information only to process and document your request.
If an organization controls the requested information, we may direct you to that organization.
6. Third-Party Links and Services
The Services may contain or open links to websites and services not operated by Logstr.io. We do not control their content, security, tracking, or privacy practices.
WebGuard may warn about or block a destination, but a warning or risk score is not a complete evaluation of that website’s privacy or security. Choosing to continue to a website, including inside an isolated Nidex session, subjects your interaction to that website’s terms and privacy practices.
Third-party browser extensions installed inside a Nidex session may access browsing information available within that session. VPNs, reputation services, phishing-analysis providers, scanning services, and authentication providers may also process information under their own privacy policies.
Review the applicable third-party policies before submitting information or enabling an integration.
7. Children’s Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Children under 13 must not create a Nidex account or provide personal information through the Services. Where a higher age of digital consent applies, users below that age may require authorization from a parent or guardian.
If we learn that we collected personal information from a child in violation of applicable law, we will take reasonable steps to delete it. A parent or guardian who believes a child provided personal information may contact us using Section 9.
8. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to Nidex, our data practices, legal requirements, or security architecture.
When we make changes, we will update the effective date and publish the revised Policy. If a change materially affects how we use previously collected personal information, we will provide additional notice or request consent when required.
We encourage you to review this Policy periodically.
9. Contact Us
If you have questions, concerns, complaints, or privacy requests, contact:
Logstr.io - Nidex Privacy
Email: privacy@logstr.io
Website: https://logstr.io
Mailing address: [Insert official business mailing address]
Please ensure that the email address above is active and monitored before publishing this Policy.
