Trust & Privacy
BetaPolicy update in progressTrust & Privacy Center
We build products that use context, AI, and user feedback to make decisions easier. This center explains how we handle data, AI-assisted outputs, user contributions, beta features, privacy choices, and product-specific safeguards.
Overview
Next Up is in public beta. We aim to collect the minimum useful data needed to make the product work, improve the experience, and respect user choices. We avoid sending raw private content or sensitive profile details to analytics.
This page describes how the product is designed today. It is not a substitute for formal legal review. Where something is still being built we label it Being updated or In progress.
Privacy choices
Privacy choices
Manage what we use and share
These choices are stored on this device. We are working on a signed-in version that syncs across devices.
Essential product functionality
Always onSign-in, recommendation generation, billing, and consent storage. Always on — the product needs these to work.
Analytics
Default onCoarse usage events sent to Google Analytics and Amplitude. Raw notes and sensitive fields are filtered out before send.
Product personalization
Default onUse your taste signals and feedback to tune recommendations inside Next Up.
Cross-product personalization
Default offAllow non-sensitive taste signals to improve other Lumenfolk products you sign in to.
Approved partner / API use
Default offAllow approved partner APIs to receive non-sensitive signals for features you opt in to.
Sensitive context use
Default offAllow optional sensitive context (e.g. mood, family setting) to influence personalization. Off by default.
Marketing & contact
Default offOccasional product updates by email. Off by default.
Do not use my signals for personalization
Default offA hard switch that turns off every optional scope above. Core product still works.
Privacy laws vary by location. This panel is designed to help you understand and manage privacy choices. It is not a substitute for legal review.
Data we may collect
Only the categories below apply to Next Up. Anything else is Not collected.
Account data
Email, sign-in identifier, and a Stripe customer reference if you subscribe.
So you can sign in, get receipts, and recover access.
Personalization: no · Cross-product with consent: no
Usage data
OptionalCoarse events like which page you opened, which lane you used, counts and timings.
To see which beta surfaces are useful. Raw text and sensitive details are never sent.
Personalization: no · Cross-product with consent: no
Consent preferences
Your choices about analytics, personalization, sensitive use, and sharing.
So we can respect those choices on every visit.
Personalization: no · Cross-product with consent: no
Product inputs
OptionalThings you type or paste into Next Up: taste notes, titles, intents, moment chips.
To produce a recommendation for you in that moment.
Personalization: yes · Cross-product with consent: yes
Profile signals
OptionalLightweight inferred taste tags built from your inputs and feedback.
To make next recommendations more accurate for you.
Personalization: yes · Cross-product with consent: yes
Feedback and corrections
OptionalThumbs up / thumbs down, reason codes, and 'not for me' signals.
To learn what to show more or less of.
Personalization: yes · Cross-product with consent: yes
Recommendation interactions
OptionalWhich recommendations you opened, saved, or skipped.
To rank future suggestions.
Personalization: yes · Cross-product with consent: yes
Contribution requests
OptionalItems you tell us are missing from the catalog, plus optional source URL.
So we can grow the curated catalog. Submissions are reviewed before any public use.
Personalization: no · Cross-product with consent: no
Resource interactions
Planned / not currently collectedOptionalClicks on streaming or store links we surface.
To show what is reachable and to improve link quality.
Personalization: no · Cross-product with consent: no
Uploaded or pasted content
May be sensitiveOptionalOptional pasted text or imported lists.
To seed your taste faster. Raw text is never sent to analytics.
Personalization: yes · Cross-product with consent: yes
Payment or inquiry intent
OptionalSubscription status from Stripe, or that you opened a privacy / contact form.
To run billing and respond to your requests. We never see card numbers.
Personalization: no · Cross-product with consent: no
How we use data
- To run the product: sign-in, billing, generating recommendations.
- To improve the product: feedback loops, catalog requests, beta surfaces.
- To respect your choices: storing consent and applying it on every visit.
- To respond to you: privacy and contact requests you send through our intake form.
Analytics & personalization
We avoid sending raw private content or sensitive profile details to analytics. Analytics events use coarse categories, reason codes, counts, and consent-safe properties only.
Status: the analytics opt-out is honored before any event is sent to Google Analytics or Amplitude. We default analytics to on with easy opt-out; Default-off gating in progress for stricter regions before any GA4 / Amplitude code loads.
Sensitive data
Sensitive context is optional unless required for the product to function. We aim to use the minimum information needed and avoid exposing sensitive details unnecessarily.
We treat the following as sensitive or restricted by default:
- health or medical context
- legal context
- financial hardship or benefits context
- child or family context
- precise location
- identity or community context
- sexuality, gender identity, race, ethnicity, religion
- biometric or identity verification data
- raw uploaded documents
- free-text private notes
- mental health or crisis-related context
- employment or income vulnerability
- immigration or citizenship context
Your rights & requests
You can ask us to:
- Access the data we hold about you
- Correct your data
- Delete your data
- Export your data
- Suppress or do not use a specific signal
- Restrict cross-product use
- Opt out of sale, share, or targeted advertising where applicable
- Limit sensitive data use where applicable
- Ask a privacy question
Data rights & requests
BetaMake a request
Download your data instantly, or open a request that a person will review. Beta turnaround for reviewed requests is typically a few business days.
Download my data
BetaGet a JSON file with the taste profile, recommendation history, feedback, catalog requests, and (if signed in) account data tied to you. Billing records held in our payment processor are not included — request those via the intake form below.
Your request status
No requests yet. When you download an export or start an inquiry, you'll see its status here: queued → ready → delivered, or awaiting review for requests a person will handle.
Access my data
Get a summary of the taste signals, feedback, and account data we hold for you.
Start request →Correct my data
Fix a profile fact, taste signal, or account detail that looks wrong.
Start request →Delete my data
Remove your taste profile, feedback, and account data. Billing records may be kept for tax/audit minimums.
Start request →Export my data
Receive a machine-readable copy of the data tied to your account or anonymous session.
Start request →Suppress a specific signal
Ask us to stop using a particular signal (e.g. a sensitive context) for personalization.
Start request →Restrict cross-product use
Keep your signals inside Next Up only — don't reuse them in other Lumenfolk products.
Start request →Ask a privacy question
Anything else — vendors, retention, sensitive use, regional rights.
Start request →
We may need to verify your identity (for example, by emailing the address on file) before acting on requests that change or remove data.
Privacy laws vary by location. This page is designed to help users understand and manage privacy choices. It is not a substitute for legal review.
AI & automated assistance
Some product experiences may use AI or automated systems to summarize, rank, classify, parse, recommend, or generate drafts. AI-assisted outputs may be incomplete or wrong. Important outputs should be reviewed before relying on them.
- Not medical advice, diagnosis, or treatment.
- Not legal advice.
- Not financial advice.
- Not identity verification.
- Not a guarantee of outcomes.
Product profiles & CanonIQ
Product-specific profiles (like the Next Up Taste Profile) help a single product work better. They are not the same as the full CanonIQ.
Full CanonIQ is a deeper personal context profile. No user receives the full CanonIQ output unless they purchase or are granted access to the full CanonIQ product.
CanonIQ is not biometric authentication, legal identity verification, or a mental health diagnosis. It is a personal context and surface-personalization layer.
Contributions & user-submitted content
Catalog requests and feedback you submit are stored so our team can review them. We label submissions User suggested until a reviewer has checked them, and gate any public use behind Public use hold.
Regional privacy readiness
We design our data systems around privacy-by-default principles, data minimization, consent controls, user correction, deletion/export request paths, sensitivity labeling, and regional privacy-readiness for stricter regions including:
- California (CCPA / CPRA)
- European Union / EEA (GDPR)
- South Korea (PIPA)
- Brazil (LGPD)
Formal legal review is required before making jurisdiction-specific compliance claims. We do not currently claim GDPR, CCPA, LGPD, PIPA, HIPAA, or SOC 2 compliance.
Vendors & processors
We work with the processors below to run Next Up. Region values marked Needs review are being confirmed.
| Vendor | Purpose | Region | Policy |
|---|---|---|---|
| Supabase | Managed Postgres database, authentication, and storage for Lovable Cloud. | Needs review | Link |
| Stripe | Subscription billing. Card data is entered into Stripe's hosted fields and never reaches our servers. | Needs review | Link |
| Google Analytics 4 | Coarse usage analytics. Gated by the analytics consent toggle. | Needs review | Link |
| Amplitude | Coarse product analytics. Gated by the analytics consent toggle. | Needs review | Link |
| Fillout | Inquiry, feedback, and privacy-request intake form. | Needs review | Link |
| Cloudflare (Lovable hosting) | Hosting and request delivery for the Next Up site. | Needs review | Link |
| Lovable AI Gateway | AI-assisted features (summaries, classification). No raw private notes are sent at this time. | Needs review | Link |
Cross-border transfers
Data processing and storage locations may vary by vendor and product. We are reviewing our systems as products move from prototype to public beta. Legal review needed
Retention & deletion
We are preparing our systems so user records can be deleted, anonymized, suppressed, archived, or expired on request. If automatic deletion for a given record type is not yet wired, our team will action your request through the privacy request form.
Policy links
We are updating our public policy center as products move from prototype to public beta.
Contact
Send privacy questions, deletion requests, or feedback through our inquiry form.