Legal & Data Protection

Privacy Policy

Effective Date: January 1, 2026 • Last Reviewed: January 1, 2026

1. Introduction & Overview

This Privacy Policy governs the manner in which Fortilabs - Fortified Solutions Ltd ("Company", "we", "our", or "us") collects, uses, maintains, and discloses information collected from users ("User", "you") of the Nexloom website ("Website", "Service") located at https://nexloom.site.

We are committed to full transparency regarding data privacy. We believe that modern web utilities should respect intellectual property and user privacy. For this reason, our core utility, the HeroPrompt Generator, has been engineered with a stateless client-side architecture that processes prompt parameters directly within your browser session without storing your input headlines or unpublished content on remote servers.

2. Information We Do Not Collect (Stateless Architecture)

Unlike conventional Software-as-a-Service (SaaS) applications, HeroPrompt does not require user account registration, login credentials, passwords, or credit card information. When you use our prompt engineering tools:

  • We do not store, log, or record your article headlines, topics, or generated prompts on our databases.
  • We do not build behavioral profiles or tracking dossiers based on your prompt generation history.
  • We do not claim any ownership, copyright, or intellectual property rights over the text prompts generated by the Service.
  • Recent generation history is stored exclusively in your local browser storage (localStorage) and never leaves your local device.

3. Information We May Collect

We only collect minimal, standard information necessary for basic website operation, security, and voluntary correspondence:

A. Direct Correspondence (Contact Form)

If you voluntarily contact us via our Contact Page or direct email, we collect your name, email address, subject matter, and message body. This information is used solely to respond to your inquiry and is never sold, rented, or shared with third-party marketing brokers.

B. Technical Log Data & Web Analytics

Like virtually all web servers, our hosting infrastructure automatically collects standard server log files for network security, intrusion prevention, and operational debugging. These logs may include your Internet Protocol (IP) address, browser type, operating system version, referring URLs, date and time stamps, and pages viewed. This log data is retained for short security retention windows and is never linked to personally identifiable information.

4. Cookies & Local Storage Practices

Our website utilizes minimal technical cookies and local browser storage mechanisms:

  • Session Security Cookies: Necessary to prevent Cross-Site Request Forgery (CSRF) on contact forms and maintain administrative authentication.
  • Browser LocalStorage: Used exclusively to persist your last 10 generated prompt sets locally on your device for your own convenience. You can clear this at any time by clearing your browser cache.

For detailed information, please review our dedicated Cookie Policy.

5. General Data Protection Regulation (GDPR) Compliance

For residents of the European Economic Area (EEA) and the United Kingdom (UK), Fortilabs - Fortified Solutions Ltd acts as the Data Controller under Regulation (EU) 2016/679 (GDPR). Because our Service operates statelessly without collecting personally identifiable information during standard tool usage, our processing of voluntary contact inquiries relies on the legal basis of Legitimate Interests (Article 6(1)(f) GDPR) to respond to communications.

Under the GDPR, you possess the following statutory rights:

  • Right of Access: You may request copies of any personal correspondence we hold regarding you.
  • Right to Rectification: You may request correction of inaccurate contact information.
  • Right to Erasure ("Right to be Forgotten"): You may request permanent deletion of your communication logs.
  • Right to Restrict or Object to Processing: You may restrict how we handle your communication data.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your national Data Protection Authority (such as the UK Information Commissioner's Office - ICO).

6. California Consumer Privacy Act (CCPA / CPRA) Compliance

Under the California Consumer Privacy Act (Cal. Civ. Code ยง 1798.100 et seq.), California residents have specific statutory rights:

  • Right to Know & Access: You have the right to request disclosure of categories of personal information collected.
  • Right to Delete: You have the right to request deletion of personal information collected from you.
  • Right to Non-Discrimination: We will never deny services, charge different prices, or provide a lower quality of service for exercising your privacy rights.
  • Zero Sale of Personal Data: We do not sell, rent, or share personal data with data brokers. We have not sold any consumer personal data in the preceding 12 months.

7. Third-Party Services & External Links

Our Service may contain links to external third-party websites, including AI generation platforms (Midjourney, OpenAI), developer resources, and social networks. We have no control over the privacy practices, content, or policies of third-party sites. We encourage you to review the privacy statements of any external service you visit.

8. Children's Online Privacy Protection Act (COPPA)

Our Service is designed for professional creators, bloggers, and software developers. We do not knowingly collect personal information from children under the age of 13. If you believe a child has provided us with personal information, please contact us immediately at support@nexloom.site so we can promptly delete the data.

9. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at our discretion. Any revisions will be reflected on this page with an updated "Effective Date" at the top of the policy. We encourage users to periodically review this page for any changes.

10. Contacting the Data Controller

If you have any questions regarding this Privacy Policy, your statutory data rights, or our data handling practices, please contact our Data Protection Officer:

Fortilabs - Fortified Solutions Ltd
Attention: Syed Shoaib Ejaz, Founder & Lead Software Engineer
Website: https://fortilabs.dev
Email: support@nexloom.site
Contact Form: Submit an Inquiry

11. Data Security and Technical Safeguards

We employ industry-standard technical and organizational security measures to protect the integrity of our web servers. All data transmitted to and from our website is encrypted using 256-bit Secure Sockets Layer / Transport Layer Security (SSL/TLS) cryptographic protocols. We enforce HTTP Strict Transport Security (HSTS), Content Security Policy (CSP) headers, and strict cross-origin isolation to safeguard our users against man-in-the-middle attacks and cross-site scripting vulnerabilities.