Skip to content

00Legal

Privacy policy
Effective September 15, 2026.

NextOS is built by Kumin Consulting LLC. This page explains what we store, who we share it with, and how long we keep it. For the technical detail behind every claim here - encryption, exact data flows, our current SOC 2 status - see Security & compliance.

What we store

NextOS is a full desktop that runs mostly in your browser. We only store what a feature you use genuinely needs:

Account data

Your email, sign-in method, and plan/subscription status. If you sign in with Google or GitHub, we receive the profile fields those providers share on sign-in (name, email, avatar) - nothing more.

Files you sync

Your OS filesystem lives in your browser (IndexedDB). If you connect Google Drive, OneDrive, SharePoint, Dropbox, Box, S3 or WebDAV, your files sync directly between your browser and that provider - see /nextos/security’s data-flow section for exactly which paths touch our servers at all (most do not).

Site data

If you publish a site, its files, visitor form submissions ("leads"), and anonymized analytics are stored on our infrastructure so the site can actually be served.

Meters and usage

How much of your plan’s allowances you’ve used (hosted AI spend, gateway requests, storage) - counts, not content.

Team and organization data

If you create or join a team: membership, roles, governance policy, and an audit trail of governance-relevant actions, owned by the organization rather than any one member.

Sub-processors

We use the following services to provide NextOS. Each only receives what its role requires.

  • Vercel — hosting, serverless functions, and Vercel Blob file storage
  • Upstash — the Redis database behind accounts, sites, teams and background runs
  • Resend — transactional email (invites, notifications, exported-data links)
  • Square — billing and payment processing for paid plans
  • Google, and any other AI provider you connect — model calls you make with your own connected provider key, or through the hosted model plane
  • Twilio — SMS delivery, only if a workflow or automation you configure sends a text message

Retention

Team and organization owners set their own audit and run-history retention (Settings > Governance). Personal account data is kept for as long as your account exists. If you delete your account (Settings > Privacy > “Delete my account”), we cancel any active subscription immediately and permanently purge your account data 14 days later - a grace period you can cancel from the same place any time before it runs. Site visitor leads and site analytics follow the site owner’s own retention, deleted when the site is.

Your rights

You can exercise the following directly from Settings > Privacy, without contacting us:

  • Export all your data - a downloadable copy of everything this service holds about your account.
  • Delete your account - a 14-day grace period, then a permanent purge of the key data families listed in that export.
  • Correct your account details - your email and sign-in method are managed through your identity provider (Google/GitHub) or Settings > NextOS ID.

If you’d rather reach a person, use Support. Organizations with a signed Data Processing Addendum should also see /dpa.

Cookies

This site sets no non-essential cookies. The only cookie you get is the session cookie created when you sign in, which is strictly necessary to keep you signed in - see the footer for the same disclosure.

Changes to this policy

If this policy changes materially, we’ll update the effective date above and, for signed-in accounts, note it in-app.