Skip to content
PrivacyBack to TFA

Privacy

Privacy Policy

Effective September 8, 2026

The short version

Who this covers

This policy covers TFA — Technician Field Assistant — as used in a web browser and as the TFA app for iOS and Android. TFA is operated by Aspire USA LLC, doing business as Nexera.

You cannot sign yourself up for TFA. Accounts are created by the dealership or service organization you work for, using a work email address they provide. That organization decides who gets an account, what each person can see, and when an account is closed. If you are not sure who administers your account, ask your service manager.

Because your employer provisions the account, the service data in TFA — calls, machines, service history, and the documentation library — belongs to them, and Nexera processes it on their instruction.

That split decides what this page can usefully tell you. This is the privacy policy for the TFA app and for you as the person using it — what it collects about you, what leaves the app and where it goes, and how to get a question answered. The wider commitments Nexera makes to your employer about their data, including how long it is retained and what happens to it if they stop using TFA, are set by the agreement between them and Nexera. Where the two touch the same subject that agreement governs, and this page defers to it rather than making a promise it is not the right document to make.

What we collect

TFA collects 6 principal categories of information. Apple and Google organise and name these categories differently in their own store disclosures, so the wording there will not match this list word for word:

  • Name

    App functionality · linked to your account · not used for tracking

    Your first and last name, as your employer entered them when they created your account.

    It is how TFA addresses you, and how colleagues at your dealer see who worked a call.

  • Email address

    App functionality · linked to your account · not used for tracking

    The work email address your employer used to create your TFA account.

    It is how you sign in, and how we can reach you about your account.

  • User ID

    App functionality · linked to your account · not used for tracking

    The account identifier TFA assigns you, and the dealer you belong to.

    It ties your session to your own work, and limits what you can see to your dealer's data.

  • Other user content

    App functionality · linked to your account · not used for tracking

    What you type to the assistant, any documents you upload to the library, and anything you write when you report or comment on an assistant response.

    The assistant cannot answer a question it was not asked, an uploaded manual is only useful if it is kept, and a report is no use to us without the words explaining what was wrong.

  • Product interaction

    Analytics, App functionality · linked to your account · not used for tracking

    Which screens and features you use, whether a briefing was opened before a call, whether you rated an assistant response helpful or reported it, and whether you opened a notification.

    It tells us which parts of TFA are earning their place and which are being ignored, and a report on the assistant is how we find and correct bad answers.

  • Device ID

    App functionality · linked to your account · not used for tracking

    A push notification token, issued by Apple or Google, for each device you install the app on.

    It is the address a notification would be delivered to, if you allow notifications and we send one.

We also record ordinary technical details when you sign in — the time, your device type, and the IP address the request came from — so that a session can be expired and an unexpected sign-in can be investigated.

What we do not collect

TFA may ask permission to send you push notifications. Notifications are optional: declining them leaves the rest of the app working normally. You can also turn them off later — either in your device settings, which silences that one device, or with the push notifications switch in your TFA account menu, which covers every device you are signed in on. It is a permission to show you something, not a permission to read anything from your device.

Beyond notifications and network access the app requests nothing. It cannot read any of the following, and does not ask:

  • Location, precise or approximate
  • Camera or microphone
  • Your photo library
  • Contacts or calendars
  • Health, fitness, or financial information
  • Advertising identifiers

TFA contains no advertising software and no third-party analytics or tracking SDKs. We do not build advertising profiles, and we do not track you across other companies' apps or websites. Nothing in TFA is sold.

The assistant, and Google Gemini

TFA's assistant is built on Google's Gemini API. When you ask it something, your question is sent to Google along with the service context needed to answer it, and Google returns a reply. Google acts as our subprocessor: it processes that content to serve your request, on our instruction, and not for its own purposes.

Before the assistant will answer a question you type, we ask you to agree to this. You do not have to. Declining leaves the rest of TFA working normally — you simply do not get assistant answers — and you can change your mind later from your account menu, in either direction. If you withdraw, the assistant stops answering until you turn it back on.

One thing does go to Gemini without you asking, and it is worth being clear about. When you open a service call, TFA writes you a short briefing on it — what the call is about, the machine's relevant history, and anything in the documentation that looks pertinent. That is generated the same way, by Gemini under the same terms, and it happens because you opened the call rather than because you asked a question. Its input is your dealer's own service record and it contains nothing you wrote, which is why it sits outside the assistant switch: it is your employer's data being summarised for their work, not a personal choice of yours. Briefings are cached, so re-opening the same call does not send it again. If you add your own notes to a briefing and regenerate it, that text is yours, and it is covered by the agreement above like any other question.

Nexera bills for this service under a paid Google account, and under those terms Google does not use prompts or responses to train or improve its models. No model, at Google or at Nexera, is trained on your data. There is no fine-tuning and no per-dealer model, so nothing you ask today shapes an answer given to anyone tomorrow.

Google does log prompts and responses for a limited period in order to detect abuse of the service, and it acts as a data processor under its own data processing terms. We would rather say that than tell you Google keeps nothing, which would not be true. On this service tier there is no regional processing commitment, so content may be processed in any country where Google operates facilities.

What accompanies your question comes from your dealer's own records, and depends on what you asked. It can include a length-capped excerpt of the call's description or notes, the machine and its service history, passages from relevant documentation, and the equipment and customer identifiers attached to the call. It does not include your email address, your account identifier, or your session token.

You can rate an assistant response, and report one as offensive or inappropriate. A report records which response you flagged, the conversation and service call it came from, and anything you write in the comment box. We read reports and use them to correct and constrain what the assistant produces — that is their whole purpose, and they are not used for anything else.

Email addresses, telephone numbers, and web addresses are removed from service and dispatch notes before any of this is sent. That check looks for those specific shapes, so it is reliable for contact details and does not detect personal, company, or place names — if a name was typed into a note, it may be included. What you type to the assistant yourself is sent as you wrote it, so do not put anything into it that you would not put into a work system generally.

Files you upload

Documents you add to the library are stored in storage that Nexera operates, not in a third-party document service. Download links are short-lived: a link generated for you expires within minutes and cannot be shared as a permanent URL.

They are visible to everyone at your dealer. A document is scoped to your organization rather than to you — any TFA user there can search and read it. No other dealer can. If you are about to upload something that not every one of your own colleagues should see, that is worth knowing first.

Making a document searchable means Google processes it. The text of each indexed passage is sent to Google's embedding service, which returns the numeric form searches run against, and pages whose meaning is carried by a diagram or photograph are sent as images so they can be transcribed. So your documents are private to your dealer within TFA, but "private to your dealer" is not the same as "never processed by Google." They are handled under the terms above.

Administrators and service managers at your dealer can withdraw a document from search and the assistant, and then delete it permanently. Deleting it removes the document's extracted text and everything the search index and the assistant hold about it — immediately, irreversibly, and with no copy kept — and deletes the stored file itself. In the uncommon case that the storage system refuses that last step, the document is already unreachable from anywhere in TFA, but the underlying file can remain in storage until it is removed.

Who else sees it

We do not sell personal information and we do not share it for advertising. Data reaches third parties in only two situations: a subprocessor that runs part of the service for us, and a legal obligation we cannot refuse.

  • Google (Gemini API)

    Receives: Your question, a redacted and length-capped excerpt of the call's notes, machine and service history detail, and passages from any documentation relevant to the question.

    In order to: Generating the assistant's replies, reading service calls into a structured diagnosis, and indexing uploaded documents so they can be searched.

  • Apple (Push Notification service)

    Receives: A push token for your iPhone or iPad, and the title and text of the notification being delivered to it.

    In order to: Delivering notifications to iOS devices. Apple is the only route by which any notification can reach an iPhone.

  • Google (Firebase Cloud Messaging)

    Receives: A push token for your Android device, and the title and text of the notification being delivered to it.

    In order to: Delivering notifications to Android devices.

If we send you a notification, its title and text pass through Apple or Google to reach your device, and your device may show them on the lock screen without it being unlocked. We give the push service the device token and the notification itself, and nothing else about you. Apple and Google will also handle the technical information they need to route and deliver it, under their own terms. Neither service is used for advertising, and neither is used to track you.

Beyond those, TFA does not run on a third-party cloud. The application, its database, and the store holding your dealer's documents all run on servers Nexera operates, in a data centre where Nexera leases space, power, and connectivity. The people who run that building have no access to the application or to anything in it. There is no other company processing your TFA data.

Your employer can see your activity in TFA. That is the point of the product: a service manager can see which calls were briefed and how the tool is being used by their team.

Nexera's service intelligence draws on patterns across many dealers, and a diagnosis derived from your dealer's calls contributes to it. What crosses that boundary is a structured reading of the call — symptom, failing component, resolution — not your notes, and it carries no attribution to your dealer. Another dealer's technician is shown constrained diagnostic values, never free text from your calls and never your customer's identity.

How long we keep it

Signed-in sessions. On mobile, a session ends after 30 days without use, and always after 90 days regardless of use. In a browser the limits are shorter: 12 hours idle and 14 days absolute. Signing out ends a session immediately. Expired session records are deleted after 30 days.

Notification registrations. When you sign out, or when your device's push token stops working, we mark that registration inactive so nothing further is sent to it, and we delete the record about three months later. A registration that stays silent for roughly nine months — an app deleted without signing out, for instance — is retired automatically and then deleted on the same schedule.

Your account. Kept while your employer keeps it open. When they close it, access stops immediately.

Conversations, documents, and service records. Retained as part of your dealer's service record, so that history stays useful over the life of a machine. There is no automatic expiry. How long your dealer's data is kept, and what happens to it if they stop using TFA, is governed by their agreement with Nexera rather than by this page — that data belongs to your employer, and it is not ours to set a policy for on their behalf.

Security

All traffic between the app and our servers is encrypted in transit. On iOS and Android your session credential is held in the operating system's secure store — the iOS Keychain or the Android Keystore. It is stored device-only: it is excluded from encrypted device backups and is never synchronised to another device through iCloud or any equivalent service.

Access to your dealer's data is checked on every request against the account the session belongs to. No security measure is perfect, and we do not claim otherwise; if you think an account has been misused, tell your service manager and email us at the address below.

Your choices

Signing out is the reliable way to end a session. It clears the credential from the device and revokes it on our servers, so it cannot be used again. Uninstalling the app removes its ordinary local data, but on iOS a credential in the Keychain can outlive the app it belonged to and be picked up by a later reinstall. If you are handing the device to someone else, or you no longer want that account reachable on it, sign out before you uninstall.

Two settings in your account menu are yours to change at any time. The AI assistant switch controls whether questions you type are sent to Google Gemini; turning it off stops the assistant answering and leaves everything else working. The Push notifications switch controls whether we send notifications to your phone. It applies to your account rather than to one handset, so it covers every device you are signed in on, and your in-app notification list keeps working either way.

Because your employer provisions and controls your account,requests to see, correct, export, or delete your information should start with them. They can act on it directly or ask us to. You can also write to us at the address below and we will route your request to the right administrator; where the law gives you a right that your employer cannot satisfy, we will handle it ourselves.

TFA is an employer-provisioned workplace service intended for authorised adult users. Accounts require you to be at least 18. TFA is not directed at children or minors, and we do not knowingly collect information from them.

Changes

TFA is in active development, and this policy will change as the product does. The effective date at the top of this page always reflects the current version. If a change materially affects how your information is handled, we will tell your organization rather than rely on you noticing a new date here.

Contact

Questions about this policy, or about your information in TFA:

support@nexera.net

Please say that your question is about TFA privacy so it reaches the right person. Written requests can be sent to Aspire USA LLC, doing business as Nexera, 7405 Rte Transcanadienne, Suite 100, Montreal, Quebec H4T 1Z2, Canada.