Skip to main content
← Back to Home

Privacy Policy

Last updated: August 23, 2026

Version 2026-08-23

This Privacy Policy explains how NextStep ("NextStep," "we," "our," or "us") collects, uses, discloses, and protects personal information in connection with the NextStep website at joinnextstepai.com, our browser extension, and related services (the "Service"). It also serves as our Notice at Collection for purposes of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA").

NextStep is currently operated by a single individual as a sole proprietorship — no separate company has been formed. There is no registered legal-entity name distinct from "NextStep" itself, so this Policy (and our Terms of Service) refer to the operator simply as NextStep. For privacy questions, data-rights requests, or any notice under this Policy, the address of record is the email address in Section 16 (Contact), not a mailing address.

The Service is intended for U.S. residents only. If you are outside the United States, please do not use the Service. By using the Service you agree to the collection and use of information in accordance with this Policy and our Terms of Service.

1. Notice at Collection — Categories We Collect About You

If you are a NextStep user, we collect the following CCPA-enumerated categories of personal information about you, from the sources and for the purposes described below. We do not sell personal information for money. We do not knowingly collect information from children under 13. If you are not a NextStep user, see Section 2 instead — different information, collected a different way, is described there.

CategoryExamples
Identifiersname, email, username, phone (if provided), IP address, device identifiers, cookie / session identifiers.
Customer-records info (Cal. Civ. Code § 1798.80(e))account credentials (hashed), profile, billing address (collected by Stripe).
Commercial informationsubscription plan, billing history, products purchased, usage entitlements consumed.
Internet / network activitypages visited within the Service, feature use, error logs, approximate geolocation derived from IP.
Professional / employment-related inforésumé content, work history, education, skills, target roles, applications you track, notes you write, AI drafts you generate.
Electronic / digital infoIf you connect Outlook: structured extracts and short excerpts of job-related email (sender, recipient, subject, dates, snippets) processed for classification and timeline display.
Inferencesprofile-derived signals such as application stage, contact-relevance ranking, recommended drafts.

Sensitive personal information. We do not collect government IDs, financial-account numbers, precise geolocation, racial/ethnic origin, religion, union membership, genetic data, biometric data, health data, or sex-life information. Email content you authorize us to read may incidentally contain sensitive details; we process such content only for the purposes described and do not use it to infer characteristics for advertising. Stripe, our payment processor, separately handles your payment-card details under its own privacy practices; we never see, store, or transmit full card numbers.

Sources. Information about you comes (a) directly from you, (b) automatically from your device and use of the Service, (c) from your authorized integrations (Microsoft / Outlook), and (d) from our service providers (Stripe billing events, analytics tooling).

2. Information About People Who Are Not NextStep Users

NextStep's core feature helps a user find the right professional contacts at a company they are applying to. Doing that necessarily means we discover and store a limited amount of information about people who have never signed up for NextStep — the contacts themselves. This section describes that separately from Section 1 because it is a different kind of collection with a different purpose, and because it is the section most likely to be about you if you are reading this policy after being contacted by, or discovered through, a NextStep user.

What we store about a discovered contact. Typically: their name, job title, employer, a public LinkedIn profile URL if one was found, and short excerpts of professionally-relevant public web content that support why we believe they hold that role (e.g., a snippet from a company "About" or leadership page). When a user's search calls for it, we also attempt to identify a likely work email address for the contact. When we can, we verify that address through a third-party email-verification service before showing it to the user; when we cannot verify it, we may still show a pattern-based guess we constructed ourselves (e.g., from the contact's name and the company's email domain), clearly labeled to the user as an unverified guess rather than a confirmed address.

Where it comes from. This information is gathered from public web search results returned by third-party search providers (currently Brave Search, Tavily, Google Programmable Search, SerpAPI, and Perplexity) and, for contact enrichment and email verification specifically, from third-party services (currently Apollo for company and contact enrichment, and Hunter.io for email verification). We do not scrape LinkedIn directly. Most of what we store is assembled from what is already publicly discoverable about the contact's professional role; a work email address we show, however, may instead be a pattern-based guess we generated ourselves rather than something we found published — see above for how that is labeled.

Why we store it. Solely to help a NextStep user identify and reach appropriate professional contacts for their own job search at a specific company. We do not use this information for advertising, do not sell it, and do not make it available for any purpose unrelated to the job-search use it was gathered for.

How long we keep it. A discovered contact's record stays eligible to be reused — so a later search at the same company does not have to re-discover the same person from scratch — for up to 45 days after it was last verified. Past that window, the record is no longer reused to seed a new search, but it is not automatically deleted; a fresh search can independently re-find and re-verify the same person. We remove a stored record earlier than that only when a later search turns up strong, direct evidence (the person's own LinkedIn profile) that they no longer work at that company. Some of the underlying search-provider results this process draws on are themselves cached for a short period (see Section 5, "Search Vendor Sub-Processors").

Your right to ask us to remove your information. If you believe we have discovered and stored information about you as a professional contact, you — or anyone — may ask us to remove it by emailing [email protected] with your name and the company. We will delete the discovery record(s) that match from our contact-discovery database. Please note the limits of this, in plain terms: that delete reaches the discovery record itself, but copies may remain for a short time in operational logs, encrypted backups, and short-lived search caches; and if a NextStep user has already saved your details into their own contact list, or an email address was separately generated for you as part of that user's search, this request does not reach into their account — tell us and we will remove that too. Deleting a record also does not prevent a future, independent search by another user from re-discovering and re-storing publicly available information about your professional role, since that discovery is core to how the Service works. We will act on every request we receive.

3. How We Use Personal Information

We use personal information for the following business purposes:

  • provide, maintain, and operate the Service, including authentication, sessions, and entitlements;
  • process Subscriptions and payments through Stripe;
  • classify job-related email and build the timeline view of your applications (only when you have authorized Outlook access);
  • discover and rank professional contacts, and generate AI Output — drafts, summaries, recommendations — using third-party LLM and search providers;
  • communicate transactional notices (verification, password reset, billing receipts, security alerts, service announcements);
  • secure the Service, prevent abuse, fraud, and credential stuffing, and enforce our Terms;
  • comply with law and respond to lawful requests from public authorities;
  • improve product quality through aggregated, de-identified analytics.

4. Automated Decision-Making and AI Processing

We use automated systems, including third-party large language models accessed through a single AI gateway, to (a) generate drafts of outreach messages and résumé suggestions, (b) classify whether a given email relates to a specific application, and (c) rank potential professional contacts by estimated relevance. These outputs are recommendations only; no decision with a legal or similarly significant effect on you is made solely by automated processing. AI Output is delivered to you for your review; the decision to act on it (whether to send, save, or rely on it) is yours.

We do not use Your Content, AI Output, or the professional-contact information described in Section 2 to train any third-party general-purpose model. The AI providers we use (which currently include OpenAI and Anthropic models, reached through our AI gateway) process what we send them only to generate the response we asked for, under commercial API terms that exclude using that data for training.

5. How We Share Personal Information

We share personal information with the following categories of recipients, only as needed to provide the Service and under contractual confidentiality / use restrictions:

Sub-processor / categoryPurpose
Stripe, Inc.Payments, billing, tax computation, fraud prevention.
Supabase, Inc.Managed Postgres database, file storage.
Vercel, Inc.Web hosting, edge / serverless compute, CDN, and our AI gateway.
Microsoft CorporationOutlook / Graph API for email integration (only with your authorization).
Resend / email deliveryTransactional email (verification, receipts, password reset).
OpenAI, Anthropic, and other AI model providersAI Output generation, reached through our AI gateway, under API-tier no-training terms.
Search vendors — Brave, Tavily, Google Programmable Search, SerpAPI, PerplexitySurfacing publicly-available professional-contact information (Section 2). See "Search Vendor Sub-Processors" below for storage differences between vendors.
Apollo, Hunter.ioApollo: company and contact enrichment. Hunter.io: third-party verification of a discovered contact's work email address before it is shown to a user.
SentryError monitoring; user identifiers are hashed before being sent.
PostHog (if enabled)Product analytics with sensitive fields redacted.

Search Vendor Sub-Processors — storage differs by vendor. We cache certain search results as permitted by each provider's own terms, so we do not have to re-purchase the same search repeatedly. Concretely: results from most of our search vendors, including Perplexity, may be cached for up to 24 hours (shorter if the search returned no results) and reused across different users' searches during that window. We do not keep Brave Search's result listings in that shared cache, consistent with Brave's own terms of service; short excerpts of Brave-sourced page content may still be saved as part of a discovered contact's record, as described in Section 2.

We may also share personal information (a) with your direction or consent, (b) to comply with law, legal process, or a lawful government request, (c) to protect our rights, property, or safety, or those of our users or others, (d) in connection with a corporate transaction (merger, acquisition, financing, or sale of assets), in which case we will provide notice and continued protection of your information, and (e) in an aggregated or de-identified form that cannot reasonably identify you.

No sale of personal information for money. We do not sell personal information for monetary consideration. Some analytics, search-vendor, or LLM-provider relationships could be construed as "sharing" or "selling" under the broad CCPA definitions; if so, you may exercise the "Do Not Sell or Share" right described in Section 11.

6. Microsoft / Outlook Email Integration

If you connect a Microsoft account, you authorize us to access your mailbox through Microsoft Graph using the scopes Mail.ReadWrite (read and create draft messages), User.Read (your name and email address), and offline_access (to refresh access without re-prompting). We read only your Inbox and Sent folders. We use this access to identify and classify job-related email, extract structured fields (sender, recipient, subject, dates), and store short snippets necessary to render your application timeline. The Mail.ReadWrite scope is required so we can create draft replies for your review; we do not send mail from your account without an explicit action you take.

By default we do not read the full body text of your email — our classification looks only at the subject and a short preview. We offer an optional AI email-analysis feature that, when it is enabled, sends the text of an email we have already identified as job-related to our AI provider (see Section 4) to extract job details such as company, role title, and location. When this optional feature is enabled, that email text is processed only to extract those details and is not stored by us; the body is otherwise never read. This feature is off unless we have turned it on.

You can disconnect at any time from Settings → Email & Integrations, which revokes our stored OAuth refresh token.

7. The Browser Extension

The NextStep browser extension has one job: detect a job you apply to on a supported job board or career site and, only when you confirm the save, send that job's details to your own NextStep account. Specifically:

  • Your NextStep sign-in token is stored locally in the browser and sent to our servers to prove each request comes from your signed-in Account.
  • Job-page details, when you save a job: the company name, job title, page URL, location, pay if shown, and an excerpt of the posting text (capped at roughly 22,000 characters), plus the page title. Nothing is sent until you confirm the save.
  • A public hiring contact's name, title, and profile link, when one is visible on a job page you are viewing — only while you are signed in; signed-out browsing sends nothing.
  • Your own saved profile details (e.g., name, contact info, work history already stored in your NextStep account) can be used to fill in an application form you are actively completing, at your request. This is a round trip through your own account — it is not collected from the pages you visit.

The extension does not read email, chat, or messages, does not track your general browsing history (it only runs on the specific job-board and applicant-tracking domains it lists), and does not collect device location. Everything the extension sends goes only to NextStep's own servers — never directly to a third party.

8. Cookies and Similar Technologies

We use first-party cookies (or equivalent local storage) for authentication, session persistence, CSRF protection, preference storage, and basic product analytics. We do not currently use third-party advertising cookies. We do not yet have an automated system that recognizes browser Global Privacy Control (GPC) signals; to opt out of any "sale" or "sharing" of your information under the CCPA, use the request method in Section 11 and we will honor it manually.

9. Data Retention

We retain personal information for as long as your Account is active or as needed to provide the Service. Specific retention rules:

  • Account & profile data: until you delete your Account.
  • Application timelines, résumés, drafts: until you delete them or your Account.
  • Outlook OAuth tokens: until you disconnect or revoke.
  • Email extracts & snippets: retained for the lifetime of the linked application; deleted when the application is deleted.
  • Discovered professional-contact records (Section 2): the discovery record itself is retained until we delete it on request — see Section 2 for what that delete does and does not reach; reuse for pre-filling a new search stops after 45 days without re-verification, but a record is not automatically deleted at that point.
  • Cached search-vendor results: up to 24 hours for most vendors (shorter for no-result queries); we do not keep Brave Search's result listings in this shared cache (see Section 5).
  • Billing records: retained for at least 7 years to satisfy tax and accounting obligations.
  • Operational logs (errors, security events): typically retained 30–90 days.
  • Backups: may persist in encrypted backups for up to 30 days after deletion.
  • Aggregated / de-identified data: retained indefinitely; not associated with you.

10. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption in transit, encryption-at-rest provided by Supabase and Vercel, hashed passwords (bcrypt/argon2), encrypted OAuth tokens, fail- closed rate limiting on sensitive endpoints, narrow least-privilege access, and monitoring. No system is perfectly secure. You must use a strong, unique password and notify us immediately of any unauthorized use of your Account at [email protected].

11. Your California Rights (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know the categories and specific pieces of personal information we have collected about you in the last 12 months;
  • Delete personal information we hold about you (subject to exceptions, including completion of a transaction, security, error correction, internal use compatible with the relationship, and legal obligations) — this applies whether you are a NextStep user (Account data) or a discovered professional contact (Section 2);
  • Correct inaccurate personal information;
  • Opt out of "sale" or "sharing" of personal information — email the request below; we do not yet have an automated system that recognizes browser Global Privacy Control (GPC) signals, so a GPC request is honored manually the same way;
  • Limit the use of sensitive personal information (we do not collect any of the CCPA categories of sensitive personal information);
  • Non-discrimination for exercising your rights — we will not deny service, charge different prices, or provide a different level of service in retaliation for an exercise of these rights;
  • Authorized agent. You may designate an authorized agent to make a request on your behalf. We will require proof of the agent's authority and will verify the agent's identity.

How to exercise your rights. Email [email protected] . If you have a NextStep Account, you may also use the in-app data export and Account deletion tools at Settings → Privacy & Data. We will verify an Account-holder's request by reference to information in their Account; a non-user removal request under Section 2 is verified by matching the name and company you provide against our records. We will respond within 45 days, with up to one 45-day extension where reasonably necessary, as permitted by law. We do not charge a fee for verifiable consumer requests, but may do so for manifestly unfounded or excessive requests as permitted by law. You may also appeal a denial by replying to our response email.

12. California "Shine the Light"

California Civil Code § 1798.83 permits California residents to request, once per year, certain information regarding our disclosure of personal information to third parties for those third parties' direct-marketing purposes. We do not disclose personal information to third parties for their own direct-marketing purposes. To request information under § 1798.83, contact us at [email protected].

13. Users Outside the United States

The Service is hosted in the United States and is intended only for U.S. residents. By using the Service from outside the U.S., you consent to processing of your information in the U.S. We do not target users in the European Economic Area, the United Kingdom, or other jurisdictions with comprehensive data-protection regimes, and we do not represent compliance with the GDPR, UK GDPR, or similar regimes.

14. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us personal information, contact us at [email protected] and we will delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. For non-material changes we will update the "Last updated" date and the version. For material changes that adversely affect your rights, we will provide at least 30 days' advance notice by email or in-app notice and require affirmative re-acceptance. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

16. Contact

For privacy questions, to exercise your rights, or to request removal of information about you as a discovered professional contact (Section 2), contact:

Email: [email protected]

NextStep does not yet publish a physical mailing address; the email address above is our address of record for notices under this Policy.