Trust & Privacy

BetaPolicy update in progress

Trust & Privacy Center

We build products that use context, AI, and user feedback to make decisions easier. This center explains how we handle data, AI-assisted outputs, user contributions, beta features, privacy choices, and product-specific safeguards.

Overview

Next Up is in public beta. We aim to collect the minimum useful data needed to make the product work, improve the experience, and respect user choices. We avoid sending raw private content or sensitive profile details to analytics.

This page describes how the product is designed today. It is not a substitute for formal legal review. Where something is still being built we label it Being updated or In progress.

Privacy choices

Privacy choices

Manage what we use and share

These choices are stored on this device. We are working on a signed-in version that syncs across devices.

  • Essential product functionality

    Always on

    Sign-in, recommendation generation, billing, and consent storage. Always on — the product needs these to work.

  • Analytics

    Default on

    Coarse usage events sent to Google Analytics and Amplitude. Raw notes and sensitive fields are filtered out before send.

  • Product personalization

    Default on

    Use your taste signals and feedback to tune recommendations inside Next Up.

  • Cross-product personalization

    Default off

    Allow non-sensitive taste signals to improve other Lumenfolk products you sign in to.

  • Approved partner / API use

    Default off

    Allow approved partner APIs to receive non-sensitive signals for features you opt in to.

  • Sensitive context use

    Default off

    Allow optional sensitive context (e.g. mood, family setting) to influence personalization. Off by default.

  • Marketing & contact

    Default off

    Occasional product updates by email. Off by default.

  • Do not use my signals for personalization

    Default off

    A hard switch that turns off every optional scope above. Core product still works.

Privacy laws vary by location. This panel is designed to help you understand and manage privacy choices. It is not a substitute for legal review.

Data we may collect

Only the categories below apply to Next Up. Anything else is Not collected.

  • Account data

    Email, sign-in identifier, and a Stripe customer reference if you subscribe.

    So you can sign in, get receipts, and recover access.

    Personalization: no · Cross-product with consent: no

  • Usage data

    Optional

    Coarse events like which page you opened, which lane you used, counts and timings.

    To see which beta surfaces are useful. Raw text and sensitive details are never sent.

    Personalization: no · Cross-product with consent: no

  • Consent preferences

    Your choices about analytics, personalization, sensitive use, and sharing.

    So we can respect those choices on every visit.

    Personalization: no · Cross-product with consent: no

  • Product inputs

    Optional

    Things you type or paste into Next Up: taste notes, titles, intents, moment chips.

    To produce a recommendation for you in that moment.

    Personalization: yes · Cross-product with consent: yes

  • Profile signals

    Optional

    Lightweight inferred taste tags built from your inputs and feedback.

    To make next recommendations more accurate for you.

    Personalization: yes · Cross-product with consent: yes

  • Feedback and corrections

    Optional

    Thumbs up / thumbs down, reason codes, and 'not for me' signals.

    To learn what to show more or less of.

    Personalization: yes · Cross-product with consent: yes

  • Recommendation interactions

    Optional

    Which recommendations you opened, saved, or skipped.

    To rank future suggestions.

    Personalization: yes · Cross-product with consent: yes

  • Contribution requests

    Optional

    Items you tell us are missing from the catalog, plus optional source URL.

    So we can grow the curated catalog. Submissions are reviewed before any public use.

    Personalization: no · Cross-product with consent: no

  • Resource interactions

    Planned / not currently collectedOptional

    Clicks on streaming or store links we surface.

    To show what is reachable and to improve link quality.

    Personalization: no · Cross-product with consent: no

  • Uploaded or pasted content

    May be sensitiveOptional

    Optional pasted text or imported lists.

    To seed your taste faster. Raw text is never sent to analytics.

    Personalization: yes · Cross-product with consent: yes

  • Payment or inquiry intent

    Optional

    Subscription status from Stripe, or that you opened a privacy / contact form.

    To run billing and respond to your requests. We never see card numbers.

    Personalization: no · Cross-product with consent: no

How we use data

  • To run the product: sign-in, billing, generating recommendations.
  • To improve the product: feedback loops, catalog requests, beta surfaces.
  • To respect your choices: storing consent and applying it on every visit.
  • To respond to you: privacy and contact requests you send through our intake form.

Analytics & personalization

We avoid sending raw private content or sensitive profile details to analytics. Analytics events use coarse categories, reason codes, counts, and consent-safe properties only.

Status: the analytics opt-out is honored before any event is sent to Google Analytics or Amplitude. We default analytics to on with easy opt-out; Default-off gating in progress for stricter regions before any GA4 / Amplitude code loads.

Sensitive data

Sensitive context is optional unless required for the product to function. We aim to use the minimum information needed and avoid exposing sensitive details unnecessarily.

We treat the following as sensitive or restricted by default:

  • health or medical context
  • legal context
  • financial hardship or benefits context
  • child or family context
  • precise location
  • identity or community context
  • sexuality, gender identity, race, ethnicity, religion
  • biometric or identity verification data
  • raw uploaded documents
  • free-text private notes
  • mental health or crisis-related context
  • employment or income vulnerability
  • immigration or citizenship context

Your rights & requests

You can ask us to:

  • Access the data we hold about you
  • Correct your data
  • Delete your data
  • Export your data
  • Suppress or do not use a specific signal
  • Restrict cross-product use
  • Opt out of sale, share, or targeted advertising where applicable
  • Limit sensitive data use where applicable
  • Ask a privacy question

Manage privacy request →

Data rights & requests

Beta

Make a request

Download your data instantly, or open a request that a person will review. Beta turnaround for reviewed requests is typically a few business days.

Download my data

Beta

Get a JSON file with the taste profile, recommendation history, feedback, catalog requests, and (if signed in) account data tied to you. Billing records held in our payment processor are not included — request those via the intake form below.

Your request status

No requests yet. When you download an export or start an inquiry, you'll see its status here: queued → ready → delivered, or awaiting review for requests a person will handle.

  • Access my data

    Get a summary of the taste signals, feedback, and account data we hold for you.

    Start request →
  • Correct my data

    Fix a profile fact, taste signal, or account detail that looks wrong.

    Start request →
  • Delete my data

    Remove your taste profile, feedback, and account data. Billing records may be kept for tax/audit minimums.

    Start request →
  • Export my data

    Receive a machine-readable copy of the data tied to your account or anonymous session.

    Start request →
  • Suppress a specific signal

    Ask us to stop using a particular signal (e.g. a sensitive context) for personalization.

    Start request →
  • Restrict cross-product use

    Keep your signals inside Next Up only — don't reuse them in other Lumenfolk products.

    Start request →
  • Ask a privacy question

    Anything else — vendors, retention, sensitive use, regional rights.

    Start request →

We may need to verify your identity (for example, by emailing the address on file) before acting on requests that change or remove data.

Privacy laws vary by location. This page is designed to help users understand and manage privacy choices. It is not a substitute for legal review.

AI & automated assistance

Some product experiences may use AI or automated systems to summarize, rank, classify, parse, recommend, or generate drafts. AI-assisted outputs may be incomplete or wrong. Important outputs should be reviewed before relying on them.

  • Not medical advice, diagnosis, or treatment.
  • Not legal advice.
  • Not financial advice.
  • Not identity verification.
  • Not a guarantee of outcomes.

Product profiles & CanonIQ

Product-specific profiles (like the Next Up Taste Profile) help a single product work better. They are not the same as the full CanonIQ.

Full CanonIQ is a deeper personal context profile. No user receives the full CanonIQ output unless they purchase or are granted access to the full CanonIQ product.

CanonIQ is not biometric authentication, legal identity verification, or a mental health diagnosis. It is a personal context and surface-personalization layer.

Learn about CanonIQ →

Contributions & user-submitted content

Catalog requests and feedback you submit are stored so our team can review them. We label submissions User suggested until a reviewer has checked them, and gate any public use behind Public use hold.

Regional privacy readiness

We design our data systems around privacy-by-default principles, data minimization, consent controls, user correction, deletion/export request paths, sensitivity labeling, and regional privacy-readiness for stricter regions including:

  • California (CCPA / CPRA)
  • European Union / EEA (GDPR)
  • South Korea (PIPA)
  • Brazil (LGPD)

Formal legal review is required before making jurisdiction-specific compliance claims. We do not currently claim GDPR, CCPA, LGPD, PIPA, HIPAA, or SOC 2 compliance.

Vendors & processors

We work with the processors below to run Next Up. Region values marked Needs review are being confirmed.

VendorPurposeRegionPolicy
SupabaseManaged Postgres database, authentication, and storage for Lovable Cloud.Needs reviewLink
StripeSubscription billing. Card data is entered into Stripe's hosted fields and never reaches our servers.Needs reviewLink
Google Analytics 4Coarse usage analytics. Gated by the analytics consent toggle.Needs reviewLink
AmplitudeCoarse product analytics. Gated by the analytics consent toggle.Needs reviewLink
FilloutInquiry, feedback, and privacy-request intake form.Needs reviewLink
Cloudflare (Lovable hosting)Hosting and request delivery for the Next Up site.Needs reviewLink
Lovable AI GatewayAI-assisted features (summaries, classification). No raw private notes are sent at this time.Needs reviewLink

Cross-border transfers

Data processing and storage locations may vary by vendor and product. We are reviewing our systems as products move from prototype to public beta. Legal review needed

Retention & deletion

We are preparing our systems so user records can be deleted, anonymized, suppressed, archived, or expired on request. If automatic deletion for a given record type is not yet wired, our team will action your request through the privacy request form.

Policy links

We are updating our public policy center as products move from prototype to public beta.

Contact

Send privacy questions, deletion requests, or feedback through our inquiry form.