// privacy
Privacy Policy
Last updated 21 August 2026
1. Operator, scope and roles
NEXUSV TECHNOLOGIES PRIVATE LIMITED operates the HYN-view dashboard at www.hyn-view.in and www.hyn-view.info(the “Hosted Service”). Privacy, grievance, security and support questions may be sent to vivek.aryanvbw@gmail.com.
The open-source agent runs on a server owned or administered by its installer. It can work locally without an account. NexusV receives no server telemetry from an unlinked agent, although the agent can still make the built-in and configured outbound requests listed below. Linking and approving a server starts submissions to the optional Hosted Service.
NexusV is controller or Data Fiduciary for account, authentication, service security and operator-administration data. A customer that decides why and how to monitor its server is normally controller of that telemetry, and NexusV processes it for the customer. A self-hosted portal has a separate operator responsible for its own privacy notice and compliance.
2. What the agent can read
Depending on version and settings, local measurements can include:
- hostname or node label, OS and kernel, uptime, CPU model and clocks, load, temperature sensors and service status;
- CPU, memory, swap, pressure, filesystem capacity, disk throughput and utilisation;
- interface and connection counters, latency, packet loss, DNS timing and throughput tests, plus optional local or public IP, MAC, gateway and Wi-Fi name;
- process names and resource use. Only when an administrator sets
notify_access_details=on, local alerts or reports can include run-as and session usernames, session source addresses and the source IP with the most rejected logins. The default isoff; and - unit names, states, restarts, versions and diagnostic summaries. Older agents or optional diagnostic fields can include a short service-log excerpt, so administrators should upgrade and review settings before linking a sensitive machine.
This information stays on the server unless its administrator links a portal or configures an outbound notification or endpoint. Install and use the agent only with the machine owner's authority.
Built-in and default outbound requests
An agent can make network requests without being linked. Default settings and installed timers can contact:
- Cloudflare
1.1.1.1and Google8.8.8.8for latency and packet-loss probes, plus the local gateway; - the machine's configured DNS resolver to resolve
cloudflare.comfor DNS timing; api.ipify.org, falling back toifconfig.me, for public-IP discovery;- an installed Ookla Speedtest or
speedtest-cliprovider, orspeed.cloudflare.comas the curl fallback, for throughput tests; install.hiwaynetwork.iofor the optional Highway version manifest; andregistry.npmjs.orgfor update checks.
A configured notification provider, heartbeat URL or linked portal is also contacted. Every external endpoint necessarily receives the server's public or egress source IP and ordinary request metadata; the system resolver sees DNS queries. Diagnostic endpoints do not receive the hosted telemetry payload, but notification destinations receive their message content and a linked portal receives the payload described below. Disable these functions with latency_targets=, dns_probe=off, public_ip=off, speedtest_per_day=0, highway_update_check=off or highway_track=off, and auto_update=off, as applicable.
3. What the Hosted Service handles
Accounts and authentication
- email address and, if supplied, name;
- a protected password verifier and authentication records handled by Supabase Auth, or identity information from an enabled OAuth provider;
- strictly necessary session cookies and account-security records; and
- IP address, user agent, timestamp, error and security metadata generated by Vercel, Supabase or the application.
NexusV does not receive or display a user's plaintext password. Supabase Auth processes the password and keeps a protected verifier. If Google sign-in is enabled, HYN-view does not receive the user's Google password.
Servers, telemetry and administration
- node name, hostname, OS and agent versions, pairing and last-seen times, settings and administrative status;
- CPU, memory, load, temperature, storage, network, process-name, service, alert and throughput-test fields sent by the installed agent version;
- notification destination and delivery metadata, including subject, result and error details;
- administrator actions and reasons; and
- the selected visual theme stored locally in the browser.
The Hosted Service is not intended to collect file contents, command arguments, environment variables, keystrokes, database contents or application records. The default notify_access_details=offexcludes run-as and session usernames, session source addresses and the source IP with the most rejected logins from notifications. It does not make every notification anonymous: depending on the alert, report and settings, a message can still contain hostname, wireless SSID, local or public IP, gateway, DNS details, mount paths, and process or service context. Setting it to onadditionally permits the access identities in messages sent directly to the administrator's configured destinations.
Notification destinations and provider credentials are configured on each monitored server. API keys, SMTP passwords, tokens and webhook URLs are not stored in Supabase or returned by the Hosted Service. They remain in the root-only /etc/hyn-view/secrets file until the server administrator removes them. The agent contacts the selected provider directly and can separately report destination and delivery-result metadata to the Hosted Service.
4. Purposes and legal bases
We process data to register and authenticate users; link authorised servers; show requested health information; apply alert rules; send service messages; provide support; maintain security and availability; prevent abuse; enforce the Terms; and meet legal obligations.
Where EU/EEA GDPR applies, the legal bases are performance of the service contract, legitimate interests in operating and securing the service, legal obligation, and consent where applicable law requires it for an optional feature. A customer that submits information about other people must provide its own lawful basis, notices and rights process.
5. Who can access data
Standard accounts can access only their own tenant data through the normal dashboard, enforced by database row-level policies. Authorised NexusV deployment administrators have privileged access across tenants where needed to operate, secure and support the Hosted Service, investigate abuse or comply with law. This access does not transfer ownership of customer data or permit unrelated use.
Providers receive only what is needed for their function. The primary providers are Vercel for web hosting and request processing, Supabase for database and authentication, and Resend for transactional email. Google is involved only if enabled and selected for sign-in. Administrator-selected notification destinations are contacted directly by a monitored server only when configured locally. See the provider and subprocessor list. Information may also be disclosed when law requires it or where reasonably necessary to protect users and service security, subject to applicable safeguards.
6. Regions and transfers
The operator has configured the Supabase project's primary database region as Mumbai, India. That does not mean every request, copy, log or backup is processed only in Mumbai. Vercel uses distributed infrastructure, and Vercel, Supabase, Resend and optional providers may process data in other countries.
Where EU/EEA transfer restrictions apply, an appropriate transfer mechanism and supplementary safeguards must apply before a restricted transfer. A business customer can review the public Data Processing Addendum and request signed data-processing or transfer terms at vivek.aryanvbw@gmail.com.
7. Security and credentials
Safeguards include HTTPS, Supabase authentication, tenant row-level policies, restricted administrator roles, hashed node credentials and pairing codes, and root-only local secret files where configured. Pairing codes become unusable immediately when they expire after 15 minutes; expired database records are physically deleted on the next pairing request or a maintenance cleanup cycle. No internet service is perfectly secure. Keep node tokens, notification credentials and local root access protected.
Report suspected security or privacy incidents privately under the Security Policy to vivek.aryanvbw@gmail.com.
8. Retention and deletion
- Hosted metrics are ordinarily kept on a rolling 30-day basis and pruned during successful ingestion. If a node stops sending, older rows can remain until maintenance or deletion.
- Pairing codes become unusable after 15 minutes; expired records are physically deleted on the next pairing request or maintenance cleanup cycle.
- Other configuration, alert, speed-test, notification and administrative records are kept while needed for the account, security or law, or until the related node or account is deleted.
- On the server, default local metric history is 8 days, the default alert log is 31 days, and speed-test history is limited to the latest 90 records. Local configuration remains until removed or purged by the administrator.
sudo hyn unlink stops future submissions but does not delete data already hosted. To request deletion, email vivek.aryanvbw@gmail.com from the account email and identify the account and nodes. After verification, we will delete requested data from active Hosted Service systems within 7 days. Limited copies can remain temporarily in provider backups, security records or where law requires retention; they remain isolated from ordinary use and expire under the applicable schedule.
9. Choices and rights
You may use the open-source agent without linking the Hosted Service. Settings can also disable optional public-IP lookups, latency or DNS probes, throughput tests, update checks, service tracking and outbound notifications. Keep notify_access_details=off unless a legitimate monitoring need, lawful basis and restricted destination justify access identifiers in messages. That setting hides those access identities, not the other system context an alert or report needs to describe the server.
Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability or withdrawal of consent at vivek.aryanvbw@gmail.com. We may verify identity. If NexusV processes telemetry only for your organisation, direct the request to that organisation first. EEA residents may complain to their competent supervisory authority; Indian users may use the grievance contact and available statutory complaint process.
10. Adults, automated decisions and changes
Registration is for people aged 18 or older. Alert rules compare measurements with administrator-selected thresholds and do not make decisions producing legal or similarly significant effects about people.
For material policy changes we will provide email or prominent dashboard notice at least 30 days in advance where practical. Urgent legal or security changes may take effect sooner, with notice as soon as reasonably possible.
Operator: NEXUSV TECHNOLOGIES PRIVATE LIMITED
Contact: vivek.aryanvbw@gmail.com