This page summarizes how iMagic Nexa handles privacy, payments, and account security. It's a plain-language overview - the binding documents are our Privacy Policy and Terms of Service.
Privacy
- We collect only what's needed to run your account (email, display name, viewing progress, saved list, profile choices).
- We do not sell your data and we do not use it for third-party advertising.
- You can delete profiles, saved lists, and continue-watching history from Settings at any time.
- Account deletion is handled within 30 days of request. Contact support to initiate it.
Payments
- All card payments are processed by Paystack, a PCI-DSS compliant payment processor.
- We never see or store your card number, CVV, or expiration date.
- Charges appear on your statement as "Paystack / iMagic Nexa".
- Subscription webhooks are validated with HMAC signatures before we grant access.
Account security
- Passwords are hashed by our authentication provider - we never see your password in plain text.
- Optional leaked-password protection blocks passwords found in known breach lists.
- Sign-in with Google is supported for a passwordless option.
- Each account is limited to two active devices. When you sign in on a third device, you'll be asked to revoke one first.
- All traffic to the app is served over HTTPS with modern TLS.
- Kids profiles require a PIN to enter or exit, so children cannot leave the family-friendly view without a parent.
Data hosting
Application data (accounts, profiles, saved lists, watch progress, subscription status) is stored in a managed Postgres database with row-level security policies scoped to the signed-in user.
Reporting a security issue
If you believe you've found a security vulnerability in iMagic Nexa, please email security@imagicnexa.com. We will acknowledge your report within two business days.
