iMagic Nexa
Home

Compliance

Effective July 2026

This page summarizes how iMagic Nexa handles privacy, payments, and account security. It's a plain-language overview - the binding documents are our Privacy Policy and Terms of Service.

Privacy

  • We collect only what's needed to run your account (email, display name, viewing progress, saved list, profile choices).
  • We do not sell your data and we do not use it for third-party advertising.
  • You can delete profiles, saved lists, and continue-watching history from Settings at any time.
  • Account deletion is handled within 30 days of request. Contact support to initiate it.

Payments

  • All card payments are processed by Paystack, a PCI-DSS compliant payment processor.
  • We never see or store your card number, CVV, or expiration date.
  • Charges appear on your statement as "Paystack / iMagic Nexa".
  • Subscription webhooks are validated with HMAC signatures before we grant access.

Account security

  • Passwords are hashed by our authentication provider - we never see your password in plain text.
  • Optional leaked-password protection blocks passwords found in known breach lists.
  • Sign-in with Google is supported for a passwordless option.
  • Each account is limited to two active devices. When you sign in on a third device, you'll be asked to revoke one first.
  • All traffic to the app is served over HTTPS with modern TLS.
  • Kids profiles require a PIN to enter or exit, so children cannot leave the family-friendly view without a parent.

Data hosting

Application data (accounts, profiles, saved lists, watch progress, subscription status) is stored in a managed Postgres database with row-level security policies scoped to the signed-in user.

Reporting a security issue

If you believe you've found a security vulnerability in iMagic Nexa, please email security@imagicnexa.com. We will acknowledge your report within two business days.